Lead Security Engineer
Listed on 2026-06-06
-
IT/Tech
Cybersecurity, Systems Engineer
Lead Security Engineer
Location: Suitland, MD (Hybrid)
Terms: Full-time
Clearance/Work Authorization: U.S. Citizenship with the ability to obtain and maintain a Public Trust is required
Travel: 0-20%
Project DescriptionThis position supports Revolutional's federal customer as part of an application transformation and modernization initiative. This program is driving a large‑scale transformation of systems into a data‑centric, cloud‑native ecosystem capable of supporting high-volume, near real‑time data processing and advanced analytics. The work includes modernization of legacy applications, development of new cloud‑native solutions, and implementation of Dev Sec Ops and scaled Agile practices across the organization.
The core challenge: orchestrating complex, multi‑contractor delivery while transforming both technology and operating models without disrupting mission‑critical operations.
As a Lead Security Engineer at Revolutional, you will define and drive enterprise security engineering strategy and execution across a large‑scale federal modernization program. You will be responsible for integrating security into every layer of the environment, including applications, APIs, data platforms, cloud infrastructure, CI/CD pipelines, and operational processes. You will work across architecture, engineering, operations, and vendor teams to ensure security is proactive, automated, measurable, and aligned with federal compliance requirements.
This role requires someone who can balance security rigor, operational resiliency, and delivery velocity while supporting secure modernization across complex system‑of‑systems environments.
- Provide technical leadership across enterprise security engineering efforts within a large‑scale modernization program
- Design and implement security controls across cloud, application, API, data, and infrastructure layers
- Integrate security into Dev Sec Ops pipelines using automated scanning, policy enforcement, CI/CD controls, and security governance practices
- Support Authority to Operate (ATO) processes, POA&M management, continuous monitoring, audit support, and remediation tracking activities
- Ensure compliance with federal security frameworks and standards including NIST 800‑53, FedRAMP, FISMA, Zero Trust, MFA, secure SDLC, and federal ATO requirements
- Secure system‑of‑systems (SoS) environments spanning multiple vendors, contractors, integrated platforms, and distributed architectures
- Implement and govern IAM strategies including RBAC, ABAC, MFA, privileged access management, authentication, authorization, and Zero Trust principles
- Design and support API and microservices security architectures, including secure API design, token‑based authentication, and authorization frameworks
- Conduct penetration testing, threat modeling, SAST/DAST scanning, vulnerability assessments, and end‑to‑end remediation coordination
- Support supply chain security initiatives including Software Bill of Materials (SBOM), dependency risk analysis, and third‑party software validation
- Implement security controls supporting encryption, sensitive data protection, PTA/PIA requirements, privacy standards, and secure data handling practices
- Support security operations activities including monitoring, alerting, incident response, root cause analysis, and operational troubleshooting
- Design and maintain dashboards, KPIs, risk reporting, compliance metrics, and security posture reporting
- Develop and maintain security documentation including architecture artifacts, playbooks, operational procedures, compliance documentation, and governance materials
- Collaborate across architecture, engineering, operations, and vendor teams to align security requirements with modernization and delivery objectives
- Mentor engineering and security teams on secure coding, secure architecture, operational security practices, and Dev Sec Ops standards
- Cloud‑native environments (AWS, Azure)
- Dev Sec Ops pipelines and CI/CD automation frameworks
- SIEM, monitoring, alerting, and security analytics platforms
- Container security, image scanning, and runtime protection tools
- APIs, microservices, and…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).