Mid-Level Security Engineer
Listed on 2026-09-30
-
IT/Tech
Cybersecurity, Information Security & Data Protection
That’s RIVA.
We’re a mission-driven IT services company and systems integrator supporting digital transformation and modernization for federal government agencies. Since 2009, we’ve partnered with our customers to solve complex challenges through smart, practical innovation to deliver real outcomes where they matter most. Our teams are made up of industry-leading experts who are passionate about doing great work and making a difference. We don’t just develop solutions, we support efforts that strengthen communities and serve the public good.
RIVA’s culture is built on four core values:
Results, Innovation, Values, and Accountability. They guide how we work, how we collaborate, and how we measure success. Our employee-first approach is rooted in trust, ownership, and meaningful work. By investing in our people and fostering a flexible, supportive environment, employees have the opportunity to grow their skills, contribute ideas, and make an impact from day one. all while supporting missions that matter.
OVERVIEW
This role performs hands‑on security analysis, vulnerability testing, and Dev Sec Ops integration work within the RIVA Git Lab CI/CD software factory and the USPTO's approximately 4,000‑container Kubernetes environment. The Security Engineer operates under the guidance of senior security personnel and is a primary contributor to the AI Artifact Security objective (SOO 4.1.3), embedding automated security gates into the pipeline and ensuring findings flow through the Service Now SMP remediation workflow.
CORERESPONSIBILITIES
- Operate and maintain Wiz Code within the USPTO Git Lab CI/CD software factory: configure container image scanning and infrastructure-as-code (IaC) template analysis gates, triage findings, and ensure no code reaches production on a contractor‑only path—every enforcement change ships through USPTO's Git Lab review gates
- Run Snyk Agent Scan on AI‑native artifact types—Markdown prompt files, cursor rules, Git Hub Copilot instruction files, and Model Context Protocol (MCP) configuration files—within the Git Lab pipeline; triage scan results and route confirmed findings into the Service Now SMP remediation queue with appropriate severity tags
- Maintain and tune Kubernetes security posture across the USPTO container estate: configure admission controls, monitor runtime alerts from Wiz Defend, and escalate container‑level findings through the defined remediation workflow
- Correlate DSPM findings with Axonius asset context and Tenable vulnerability data to prioritize remediation backlogs; maintain and update the risk‑scored source inventory in coordination with the DSPM SME
- Monitor XSIAM and QRadar SIEM telemetry for security events correlated to DSPM findings; triage alerts, update the POA&M, and contribute structured findings to the three‑tier evidence chain (operational, compliance, executive reporting)
- Perform security audits, risk analysis, application‑level vulnerability testing, and security code reviews for the DSPM implementation and integrated AI platforms including AWS Bedrock and UGAP API service broker endpoints
- Support ATO (Authority to Operate) documentation, system security plan (SSP) maintenance, and FISMA reporting; contribute security evidence to the compliance reporting and dashboard package
- Participate in Agile sprint ceremonies; contribute to security user stories, acceptance criteria, and definition‑of‑done security checks within the two‑week sprint cadence
- Bachelor’s degree and 5 years of relevant experience, or Master’s degree and 3 years of relevant experience in cybersecurity, information assurance, or a related technical field
- Hands‑on experience with Git Lab CI/CD pipeline…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).