Sr Security Engineer
Listed on 2026-09-11
-
IT/Tech
Cybersecurity, Information Security & Data Protection, Systems Engineer
If you are unable to complete this application due to a disability, contact this employer to ask for an accommodation or an alternative application process.
Sr Security EngineerReston, VA, US
7 days ago Requisition
FEDERAL HOME LOAN BANKS OFFICE OF FINANCEPOSITION
:
Senior Security Engineer DATE
:
September 2026
DEPARTMENT
:
Information Technology
FLSA
:
Exempt
REPORTS TO: Director, Information Security
SUMMARY OF POSITIONThe Senior Security Engineer designs, implements, operates, and continuously improves OF's security technologies and controls across applications and supporting platforms. Primary focus is Application Security-embedding security into the SDLC and CI/CD pipelines, strengthening web/API protections, and enabling proactive detection, while contributing broadly to Security Engineering capabilities (identity, cloud/on prem security platforms, logging/telemetry, and automation). The role partners closely with development, Dev Ops, and operations teams to build secure-by-default applications and services.
We’re proud of the way our teammates have a positive impact on everything we do. Our employees are committed to and exemplify our Core Values:
- Integrity through accountability, consistency, transparency and trust
- Agility through adaptability, continuous improvement, expertise, and flexibility
- Partnership through collaboration, communication, leadership, and teamwork
- Inclusivity through diversity, relationships, respect, and support
- Develop and maintain software application security policies and procedures
- Implement software application security controls
- Partner with Dev Ops in developing a secure CI/CD pipeline
- Design and operate web application firewall (WAF) and API protections; tune rules, reduce false positives, and automate policy updates
- Identify application security vulnerabilities and issues, perform risk assessments and provide mitigations
- Develop security monitoring for application stack
- Conduct technical investigations of application security incidents
- Interface with senior stakeholders across the IT leadership team to proactively interpret risks and priorities.
- Support the OF's diversity and inclusion strategy by following policies and procedures that ensure opportunities for employees and diverse business partners.
- Assist with other job duties as assigned.
- A minimum [TF4.1]of 6 to 8 years of experience in Application Security (designing, implementing, and operating security controls in enterprise application environments).
- Hands-on experience with web application security, including OWASP Top 10 vulnerabilities
- Hands-on experience with WAF/API security (policy design, rule tuning, automation), container security (runtime hardening, image scanning, vulnerability risk assessments)
- Hands-on experience with conducting web application security scans, vulnerability assessments and/or penetration testing
- Experience in investigating problems and processes within established methodologies and best practices.
- Experience working with Authentication and Authorization services like OAuth and OpenID
- Experience in operating on-prem or cloud based security platforms
- Ability to troubleshoot security and network-related issues and communicate technical findings effectively
- Ability to listen and integrate ideas from diverse groups of individuals, build and maintain respectful relationships, collaborate with others, and resolve conflicts constructively.
- Bachelor's Degree in Information Security or Computer Science or Computer/Electrical Engineering, and/or equivalent field experience.
- Proof of eligibility to work in the United States.
This position has an annualized salary range of $140,441 - $202,303. The final salary offered within this range is dependent on…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).