
Security Engineer
QBA Worldwide
Visa & sponsorship
- Reserved for United States nationals (a nationalization requirement such as Saudization/Emiratization) — not open to expatriates.
- A US security clearance is required, which effectively means citizens only.
Job description
We are building a team for one of the U.S. Federal Government's largest technology modernization programs, underpinning the U.S. capital markets.
Built on AWS and leveraging an AI-powered software engineering platform, this program offers a unique opportunity to gain hands-on experience with next-generation AI, Agentic AI, cloud technologies, and AI-driven engineering.
If you are looking for technically challenging work, exceptional learning, and a résumé-defining opportunity with national impact, I would love to connect.
Job Title
Security Engineer
Position Type
Full-Time
Location:
Hybrid (2 days onsite)
Days Remote
3 days remote
Position Summary
The Security Engineer is responsible for implementing, operating, and supporting security controls for a cloud-native federal platform hosted on AWS. This role performs vulnerability scanning and security testing, tracks remediation activities, supports security authorization and continuous-monitoring requirements, and helps maintain the platform’s overall security and compliance posture.
Working closely with DevSecOps engineers, application teams, security leadership, and other technical stakeholders, the Security Engineer supports Authority to Operate evidence collection, threat detection, incident response, and security automation. The role also leverages AI-assisted security tools to improve threat identification, analysis, and triage across the operating environment.
Key Responsibilities
-
Implement, configure, and maintain security controls across the AWS cloud environment.
-
Perform vulnerability scanning, security testing, and technical security assessments.
-
Analyze security findings and coordinate vulnerability remediation and closure activities.
-
Track identified vulnerabilities, remediation plans, risk acceptance decisions, and supporting evidence.
-
Support the collection, organization, and maintenance of Authority to Operate evidence.
-
Assist with documenting security-control implementation aligned with NIST SP 800-53 and FedRAMP requirements.
-
Operate and support continuous-monitoring, threat-detection, and security-analysis tools.
-
Review security alerts and events to identify potential threats, vulnerabilities, or unauthorized activity.
-
Collaborate with DevSecOps engineers to integrate security controls and automated testing into CI/CD pipelines.
-
Support incident-response investigations, evidence collection, and basic forensic-analysis activities.
-
Develop or maintain scripts and automation that improve security monitoring, testing, reporting, and remediation.
-
Leverage AI-assisted security tools to support threat detection, alert analysis, investigation, and triage.
-
Work with application, infrastructure, cloud, and security teams to resolve security issues and strengthen the platform’s security posture.
-
Maintain security documentation, test results, remediation records, and continuous-monitoring evidence.
-
Communicate security findings, risks, remediation status, and technical recommendations to relevant stakeholders.
Minimum Experience
-
3+ years of professional security engineering experience.
-
Experience implementing or operating security controls within cloud environments.
-
Hands-on experience with AWS security concepts and services.
-
Experience with vulnerability management, security testing, and remediation tracking.
-
Working knowledge of NIST SP 800-53 or FedRAMP security controls.
Mandatory Skills
-
Security engineering.
-
AWS cloud security.
-
Vulnerability management and security testing.
-
Security monitoring and threat detection.
-
NIST SP 800-53 or FedRAMP controls.
-
Scripting or security automation.
Non-Technical Skills
-
Strong analytical, troubleshooting, and communication skills.
-
U.S. citizenship.
-
Ability to pass a background investigation and obtain and maintain the required U.S. government clearance.
Nice-to-Have Skills
-
Security+, AWS Certified Security – Specialty, or a comparable security certification.
-
Federal Authority to Operate experience.
-
Continuous-monitoring experience within a federal or regulated environment.
-
Experience supporting incident response and digital forensics.
-
Experience integrating security testing into CI/CD pipelines.
-
Familiarity with AI-assisted security analysis and triage tools.
-
Experience supporting cloud-native enterprise applications.
-
Federal government IT delivery experience.
Degrees and Certifications
Required
- Bachelor’s degree in Cybersecurity, Computer Science, Information Systems, Information Technology, or a related technical discipline, or equivalent professional experience.
Preferred
-
CompTIA Security+.
-
AWS Certified Security – Specialty.
-
Certified Information Systems Security Professional (CISSP).
-
Other relevant cloud or cybersecurity certification.