1,185,538open jobs
66,576companies
212,669added this week
Browse all
Salary
$100k – $155k per year
Location
In office (McLean)
Seniority
Senior · 5+ years exp

Confirmed on the employer's own hiring board on Oct 4, 2026. First seen by Alion on Oct 2, 2026.

Overview
Company
Impact
Profile match
Steampunk is a US government technology and design consultancy headquartered in McLean, Virginia, that delivers human-centered design, agile software development, cloud, DevSecOps, data and cybersecurity services to federal agencies. It applies its trademarked Design Intelligence approach to modernization programs for federal clients, combining a start-up culture with a design studio next to its Tysons Corner offices. It hires cloud and enterprise architects, DevSecOps and software engineers, Salesforce and ServiceNow specialists, data engineers, cybersecurity experts, service designers and program and project managers.

Overview

Steampunk is searching for a Security Engineer to support a government customer. This role is a strong fit for hands-on engineers, including software developers, system administrators, and technical subject matter experts, who want to apply their technical depth to cybersecurity. Your primary responsibility will be to ensure that the security posture documented in each system's security authorization is implemented and maintained at an acceptable level of risk. Success in this role takes initiative, organization, a customer-service mindset, and the flexibility to adapt in a fast-paced, fluid environment. You'll communicate clearly and decisively with all levels of the organization, solve practical problems, and exercise sound judgment with sensitive and confidential information.As a Security Engineer, you'll be the technical expert that development and operations teams rely on to resolve vulnerabilities. Your experience building software or running systems is what makes you effective: you'll understand what a finding means in the code or configuration, separate real risk from noise, and recommend fixes that teams can realistically implement. Rather than performing remediation yourself, you'll typically guide teams through it, tracking issues to closure and keeping systems compliant with federal requirements. If you want to keep coding, you'll find regular opportunities to do so, from building tools that automate compliance work to reviewing code (including AI-generated code) for vulnerabilities and validating fixes. You'll also have access to the latest AI models to speed up development and vulnerability responses.

Contributions

  • Review the security architecture of new systems, applications, and technologies, drawing on your development and infrastructure experience to identify and mitigate potential risks
  • Recommend appropriate mitigation measures and advise on design trade-offs, weighing potential impact against cost and benefit
  • Monitor and respond to DHS Information Security Vulnerability Management (ISVM) alerts, working with system teams to analyze vulnerabilities and drive them to remediation
  • Proactively monitor and update Plans of Action and Milestones (POA&Ms), working with developers and administrators to resolve weaknesses by their scheduled completion dates
  • Evaluate waivers and risk acceptance memos, bringing technical judgment to the management of system risk
  • Monitor the gates in the System Lifecycle Management (SLM) process and brief the customer on outstanding issues and risks before concurrence on system readiness
  • Participate in DevSecOps activities for assigned systems, helping teams integrate security into their Agile and DevOps processes
  • Proactively ensure security requirements are included throughout the development lifecycle (Waterfall, Agile, or DevSecOps)
  • Ensure configuration management (CM) processes are followed so that changes do not introduce new security risks
  • Conduct an annual assessment in accordance with the DHS Information Security Performance Plan
  • Review and update security authorization documents as needed and on the required schedule
  • Perform system self-assessments as part of the customer's Ongoing Authorization program
  • Provide audit support for assigned systems (financial, OMB Circular A-123, FISMA, DHS, internal, and others) before, during, and after each audit
  • Maintain knowledge of the hardware and software inventory within authorization boundaries
  • Use DHS-mandated enterprise information assurance (IA) compliance tools

Qualifications

  • Ability to obtain a U.S. government Security Clearance
  • No degree and 9 years of relevant experience; OR
    • Bachelor's degree and 5 years of relevant experience; OR
    • Master's degree and 3 year of relevant experience
  • Must hold at least one professional certification relevant to the technical services provided
  • Demonstrated knowledge of security concepts, practices, and procedures that ensure the secure integration and operation of systems
  • Specialized knowledge and experience evaluating system, network, or infrastructure security controls against FISMA, FIPS, and NIST requirements
  • Knowledge and experience with vulnerability scanning execution, assessment, and analysis
  • Knowledge and experience with application security, database security, and network security
  • Knowledge and experience using Splunk in an enterprise environment
  • Ability to assess and weigh current and evolving security threats in an operational environment
  • Excellent communication and interpersonal skills, including the ability to explain technical risk to both engineers and non-technical stakeholders

Preferred

  • Hands-on background in software development, system administration, or DevOps engineering
  • An information technology certification related to your subject matter expertise, such as a security certification (e.g., CISSP, CGRC, CSSLP, CCSP, CompTIA Security+ or SecurityX), a development certification (e.g., Oracle Certified Professional: Java SE Developer, AWS Certified Developer - Associate), or a systems or cloud certification (e.g., RHCE, CKA, AWS Certified Security - Specialty)
  • Proven experience as an Information Security Engineer, including current experience providing security support to DHS
  • In-depth knowledge of federal cybersecurity regulations and standards
  • Experience with scripting and automation (e.g., Python, PowerShell, or Bash)
  • Strong understanding of security infrastructure, risk management, and compliance
  • Proficiency in security tools, technologies, and best practices
  • Extensive specialized knowledge of cloud engineering or application design and development, with experience supporting systems hosted in cloud environments
  • Knowledge and experience with operating systems and network engineering (e.g., LAN and WAN)
  • Experience supporting systems and applications in Agile and DevOps environments

About steampunk

Steampunk relies on several factors to determine salary, including but not limited to geographic location, contractual requirements, education, knowledge, skills, competencies, and experience. The projected compensation range for this position is $100,000 to $155,000. The estimate displayed represents a typical annual salary range for this position. Annual salary is just one aspect of Steampunk’s total compensation package for employees. Learn more about additional Steampunk benefits here.

Identity Statement

As part of the application process, you are expected to be on camera during interviews and assessments. We reserve the right to take your picture to verify your identity and prevent fraud.

Steampunk is a Change Agent in the Federal contracting industry, bringing new thinking to clients in the Homeland, Federal Civilian, Health and DoD sectors. Through our Human-Centered delivery methodology, we are fundamentally changing the expectations our Federal clients have for true shared accountability in solving their toughest mission challenges. If you want to learn more about our story, visit http://www.steampunk.com.

We are an equal opportunity employer and all qualified applicants will receive consideration for employment without regard to race, color, religion, sex, national origin, disability status, protected veteran status, or any other characteristic protected by law. Steampunk participates in the E-Verify program.

Free account
Stop reading job ads. Get the ones that fit.
One free account turns this page into a shortlist built around your stack, your level and your pay.
Match on every job. Stack, seniority, pay and location, scored against your profile.
1,185,538 open roles. Read straight off company career pages, refreshed every day.
Unlimited applications. Every one you send is tracked in one place, on-site or on a company board.
3 tailored CVs a month. Rewritten for the exact job you are applying to. Included free.
Create a free account Continue with Google
Free forever. No card. Under a minute.

Your match

How well do you fit this role?
Two answers are enough for a real match. No account needed.
Check my fit
Answers stay in this browser until you create an account.

Recommended for you based on this role

Security
Similar stack
Same company
McLean
≈ $84k – $175k per year (Estimated) • In office • 3+ years exp • Atlanta
Cybersecurity
GDPR
Apply
≈ $119k – $215k per year (Estimated) • Remote (United States) • 5+ years exp • Seattle
Python
Java
Ruby
DevOps
GCP
AWS
Incident Management
Apply
≈ $110k – $215k per year (Estimated) • In office • 6+ years exp • Canton
DevOps
IAM
Cybersecurity
CyberArk
Microsoft Entra ID
Active Directory
Apply
$250k – $500k per year • Remote (United States) • Contractor • 15+ years exp • Bachelor's Degree
SQL
DevOps
Splunk
Azure
Windows Server
Cybersecurity
Sophos
Active Directory
Apply
$171k – $390k per year • Hybrid • 8+ years exp • Bachelor's Degree • Tallahassee
Apply
Hybrid • Full-Time • 3+ years exp • Pasig
Java
SQL
Java
Hibernate
DevOps
CI/CD
Git
Apply
Hybrid • Full-Time • 5+ years exp • Pasig
Python
JavaScript
SQL
Dart
Node JS
AI/ML
LLM
Frontend
Next.js
React.js
Mobile
Flutter
DevOps
CI/CD
Nginx
Linux
Management
Xero
Agile
Apply
Lead DevOps Engineer 12 hours ago
≈ $94k – $184k per year (Estimated) • Hybrid • Full-Time • London
Python
Databases
Amazon Aurora
AI/ML
AWS Bedrock
AWS Bedrock AgentCore
DevOps
Terraform
Ansible
Helm
GitHub Actions
Istio
Terragrunt
Datadog
CI/CD
ArgoCD
AWS
Kubernetes
Amazon EKS
AWS Lambda
Amazon EC2
SLI/SLO/SLA
IAM
API Gateway
Cybersecurity
Crowdstrike
CIS Benchmarks
PCI DSS
SIEM
Apply
≈ $109k – $182k per year (Estimated) • Hybrid • Full-Time • London
Python
SQL
Databases
Snowflake
AI/ML
dbt
AI Agents
DevOps
Prometheus
CI/CD
Git
AWS
Cortex
Analytics
Dimensional Modeling
Apply
$40k – $67k per year • In office
Python
AI/ML
NLP
PyTorch
LLM
Hugging Face
LLMOps
Apply
DevSecOps Engineer 3 days ago
$80k – $175k per year • In office • 5+ years exp • Master's Degree • McLean
Python
Ruby
PowerShell
Groovy
DevOps
Terraform
Ansible
GCP
OpenShift
Helm
GitHub Actions
Podman
Chef
CircleCI
CloudFormation
GitLab CI
Azure
CI/CD
Jenkins
Git
AWS
Docker
Kubernetes
Concourse
Bitbucket
GitHub
GitLab
Management
Agile
QA
Selenium
Apply
$130k – $180k per year • In office • 7+ years exp • Bachelor's Degree • McLean
Python
Ruby
PowerShell
DevOps
Rest API
Terraform
Ansible
Chef
CloudFormation
Git
AWS
Bitbucket
GitHub
GitLab
Cybersecurity
Zero Trust
Threat Modeling
SIEM
Management
Agile
Apply
$110k – $155k per year • In office • 5+ years exp • Bachelor's Degree • McLean
Python
Ruby
PowerShell
DevOps
Rest API
Terraform
Ansible
GCP
Chef
CloudFormation
Azure
Git
AWS
Concourse
Bitbucket
GitHub
GitLab
Cybersecurity
Zero Trust
Threat Modeling
SIEM
Management
Agile
Apply
$85k – $170k per year • In office • 5+ years exp • Bachelor's Degree • McLean
DevOps
Splunk
IAM
Cybersecurity
Crowdstrike
Wiz
Least Privilege
Tanium
Apply
$100k – $155k per year • In office • 5+ years exp • Master's Degree • McLean
Python
Java
C#
Java
Maven
Apache Tomcat
Databases
PostgreSQL
Oracle
DevOps
Ansible
Azure
Jenkins
AWS
Apache HTTP Server
Cybersecurity
Invicti
PKI
Management
Agile
Apply
$38k – $48k per year • In office • 1+ year exp • McLean
Management
Slack
Google Workspace
Marketing
Shopify
Apply
$230k – $250k per year • In office • TS/SCI • McLean
DevOps
IAM
Linux
BGP
Web3
Layer 2
Apply
$190k – $205k per year • In office • TS/SCI • McLean
DevOps
IAM
Linux
TCP/IP
BGP
Apply
$50k per year • In office • Part-Time • High School Diploma • McLean
Management
Agile
Apply
≈ $49k – $104k per year (Estimated) • In office • Part-Time • 1+ year exp • McLean
Apply
See all jobs
This is one of many
1,185,538 more open roles from verified company boards, updated every day.