Lead Security Engineer (SME)

Onyx Government Services,LLC

$170K — $190K *
Information Technology
11 - 15 years of experience
Job Overview by Ladders

Qualifications

  • 5-7 years integrating security into a DevSecOps SDLC, including automated security testing
  • Hands-on experience with implementing Zero Trust Architecture and applying NIST controls
  • Proven experience in vulnerability assessments, penetration testing, and threat modeling
  • Experience in supporting the Authorization to Operate (ATO) lifecycle and managing security documentation
  • Bachelor's Degree in IT, Computer Science, Cybersecurity, or related field
  • 15+ years of relevant IT/cybersecurity experience at the SME level
  • Certifications: CISSP and CCSP

Responsibilities

  • Lead application security for a federal modernization program
  • Embed security in every phase of the System Development Life Cycle (SDLC)
  • Architect and enforce Zero Trust principles across systems
  • Drive Authorization to Operate (ATO) activities efficiently
  • Direct application security testing, threat modeling, and vulnerability remediation
  • Interface with senior Government stakeholders and the Office of Information Security
  • Possibly supervise team members for project execution

Benefits

  • Comprehensive medical, dental, and vision insurance
  • 401(k) retirement plan options
  • Paid time off (PTO) for work-life balance
  • Company-paid holidays throughout the year
  • Short-term and long-term disability insurance
  • Life insurance coverage for employees
Full Job Description
Job Summary
We are seeking a Subject Matter Expert (SME)-level Lead Security Engineer to lead application security across a large-scale, cloud-native federal modernization program supporting the U.S. Census Bureau's Decennial Transformation and Application Modernization (DTAM) effort. This role provides technical and management leadership on major security tasks, embedding security into every phase of the System Development Life Cycle (SDLC) using a DevSecOps methodology.

The ideal candidate will architect and enforce Zero Trust principles, drive Authorization to Operate (ATO) activities, and direct application security testing, threat modeling, and vulnerability remediation across a System of Systems (SoS). This position interfaces with senior Government stakeholders and the Office of Information Security (OIS), and decision-making and domain knowledge may have a critical impact on overall program implementation. May supervise others.

Work Location: Suitland, MD
Clearance: U.S. Citizenship required

***This position is contingent upon contract award. ***

Required Skills
  • Demonstrated expertise integrating security into a DevSecOps SDLC, including CI/CD security gates and automated security testing
  • Hands-on experience implementing Zero Trust Architecture and applying NIST SP 800-53 controls and the NIST Cybersecurity Framework
  • Proven experience leading vulnerability assessments, penetration testing, and threat modeling for enterprise applications
  • Experience supporting the ATO lifecycle and managing POA&Ms, security artifacts, and evidence collection

Desired Skills
  • Experience generating Software Bill of Materials (SBOMs) and implementing software supply-chain security controls
  • Familiarity with SIEM deployment, container/image hardening, and secure baseline configuration
  • Experience in large-scale, multi-cloud federal environments and FedRAMP processes
  • Strong analytical, problem-solving, written, and verbal communication skills, including the ability to brief senior Government stakeholders

Education and Experience
  • Bachelor's Degree in Information Technology, Computer Science, Cybersecurity, or a related field
  • 15+ years of relevant IT/cybersecurity experience, providing technical and management leadership on major tasks or technology assignments (SME level)
  • Certified Information Systems Security Professional (CISSP)
  • Certified Cloud Security Professional (CCSP)

Salary Range: $170,000- $190,000 annually

The salary range for this position represents the anticipated compensation at the time of posting. Actual compensation will be determined based on factors such as the candidate's qualifications, experience, education, skills, contract requirements, funding and other business considerations.

Benefits
Eligible employees have access to a comprehensive benefits package, which currently includes:
  • Medical, dental, and vision insurance
  • 401(k) retirement plan
  • Paid time off (PTO)
  • Company-paid holidays
  • Short-term and long-term disability insurance
  • Life insurance

Similar Jobs

More Jobs at Onyx Government Services,LLC

More Information Technology Jobs

Find similar Lead Security Engineer (SME) jobs: