This position is listed on behalf of a partner company, who manages all applications and next steps. Our partner is looking for a IS Security Developer III based in United States.
This role leads enterprise secure application development and DevSecOps automation initiatives supporting critical federal cybersecurity missions.
You will define secure development standards and architect scalable automation frameworks across cloud, hybrid, and on-premises environments.
The position plays a key role in embedding security controls throughout CI/CD pipelines and the software development lifecycle.
You will ensure application security practices align with NIST Risk Management Framework, Secure Software Development Framework, and agency-specific requirements.
As a technical authority, you will guide secure software architecture decisions and help establish rigorous, repeatable security testing practices.
The role also involves assessing application security risk, driving remediation strategies, and communicating security posture and progress to executive stakeholders.
This is an opportunity to contribute to complex government technology environments while advancing secure, modern software delivery practices.
Accountabilities:
- Lead enterprise secure application development and DevSecOps automation initiatives supporting federal cybersecurity objectives.
- Define and maintain secure software development standards, practices, and technical guidelines.
- Architect scalable automation frameworks that integrate security throughout the software development lifecycle.
- Embed and integrate application security controls into CI/CD pipelines across cloud, hybrid, and on-premises environments.
- Ensure application-layer security controls align with NIST RMF, NIST SP 800-218 SSDF, and agency-specific cybersecurity mandates.
- Provide technical leadership and authority for secure software architecture and security-related design decisions.
- Validate the rigor, coverage, and effectiveness of application security testing and automated security controls.
- Assess application security risks and support the development and execution of remediation strategies.
- Monitor security posture across application environments and identify opportunities to strengthen secure development practices.
- Prepare and communicate executive-level reporting on application security risks, remediation progress, and overall security posture.
- Collaborate with development, cybersecurity, infrastructure, and other technical stakeholders to advance secure software delivery.
Requirements:
- Bachelor’s degree in Cybersecurity, Information Systems, Computer Science, or a related technical field.
- 9+ years of relevant professional experience in cybersecurity, secure software development, application security, DevSecOps, or related areas.
- Additional relevant professional experience may substitute for formal education.
- Strong understanding of secure application development and DevSecOps practices.
- Experience designing or implementing security automation and integrating security controls into CI/CD pipelines.
- Familiarity with cloud, hybrid, and on-premises technology environments.
- Knowledge of NIST Risk Management Framework, NIST SP 800-218 Secure Software Development Framework, and agency-specific security requirements.
- Ability to provide technical direction on secure software architecture and application security decisions.
- Strong analytical and problem-solving skills, with the ability to evaluate security risks and develop practical remediation approaches.
- Excellent written and verbal communication skills, including the ability to present technical security information to executive audiences.
- U.S. citizenship is required.
- Ability to obtain and maintain the level of government security clearance determined by the sensitivity of the assigned work.
- Security+ or another relevant cybersecurity certification is recommended.
- A relevant software development or security-focused certification is a plus.
Benefits:
- Competitive compensation aligned with experience and role requirements.
- Opportunities to support complex federal cybersecurity and technology modernization initiatives.
- Work performance flexibility across government sites, contractor facilities, or authorized remote environments, depending on assignment requirements.
- Exposure to cloud, hybrid, on-premises, secure application development, and DevSecOps environments.
- Opportunities to work on enterprise-scale cybersecurity and secure software initiatives.
- Professional development opportunities through exposure to modern security frameworks, automation, and government technology environments.