Security Engineer
Quick Summary
Applicants must be authorized to work in the United States. In alignment with federal contract requirements, certain roles may also require U.S.
Oddball believes that the best products are built when companies understand and value the things they are working on. We value learning and growth and the ability to make a big impact at a small company. We believe that we can make big changes happen and improve the daily lives of millions of people by bringing quality software to the federal space.
We're looking for a Security Engineer to join our SEC team, working alongside our DevSecOps engineers to harden our cloud environment, maintain our ATO, and actively drive down the program's POAM backlog.
Responsibilities
~1 min read- →Deploy and automate CI/CD pipelines and establish IaC using modern DevSecOps techniques including serverless and Zero Trust patterns
- →Own the POAM process end to end — develop a plan of attack with target dates, track progress in real time, and close findings proactively
- →Assess incoming security findings, identify duplicates and dependencies, and develop LOEs for remediation
- →Conduct Security Impact Analyses (SIAs) to achieve and maintain ATO
- →Implement data tagging and sensitivity management practices to reduce the SEC's ATO management burden
- →Engage directly with engineers and external stakeholders to drive remediation forward
- →Maintain a live dashboard and tracker for all security findings and POAM status
- Hands-on experience remediating POAMs and navigating the federal ATO process
- Proficiency with AWS environments and cloud security practices
- Experience with CI/CD pipelines, CloudFormation, and infrastructure as code
- Familiarity with Zero Trust principles and federal cybersecurity frameworks including FISMA and NIST 800-53
- Strong organizational skills with the ability to manage multiple findings, timelines, and stakeholders simultaneously
- Comfortable engaging directly with engineers and external stakeholders to move remediation forward
- Experience with Docker and containerized environments is a plus
- Thrives in a remote, collaborative Agile environment and genuinely enjoys working closely with a cross-functional team
- Communicates clearly and openly, whether updating a tracker or presenting findings to leadership
- Performs other related duties as assigned
Requirements
~1 min read- Applicants must be authorized to work in the United States. In alignment with federal contract requirements, certain roles may also require U.S. citizenship and the ability to obtain and maintain a federal background investigation and/or a security clearance.
- Bachelor’s degree
What We Offer
~1 min readLocation & Eligibility
Listing Details
- Posted
- September 28, 2026
- First seen
- September 28, 2026
- Last seen
- September 28, 2026
Posting Health
- Days active
- -1
- Repost count
- 1
- Trust Level
- 69%
- Scored at
- September 28, 2026
Signal breakdown
Similar Security Engineer jobs
View all →Browse Similar Jobs
Stay ahead of the market
Get the latest job openings, salary trends, and hiring insights delivered to your inbox every week.
No spam. Unsubscribe at any time.