Software Engineer (Security)

Signal Hill Technologies
Fairfax, VAFull-time$150,000–$185,000Posted Sep 18, 2026

About the role

Location: Fairfax, VA (On-site, full-time)

Employment Type: Full-time

Status: Immediate

Eligibility: U.S. Citizenship or Green Card required. Public Trust eligibility required, no active security clearance needed.

About the Role

Most of the critical infrastructure systems that keep the lights on, money moving, and crucial public services running were built long before today's threat landscape existed. Someone has to modernize them without disrupting the services people depend on every day. That's where you come in.

Signal Hill Technologies is seeking a software engineer and project manager to embed security throughout the technology lifecycle for our government and commercial clients, protecting the assets that communities and institutions rely on every day. This is a technical program management role where mentoring, hands-on engineering, and earning the trust of the people you serve carry equal weight.

Also known as a DevSecOps Engineer, Application Security Engineer, Security Software Engineer, Secure DevOps Engineer, or Technical Program Manager, you'll be the day-to-day connection between our engineering team and the client's system owners and program leadership, translating technical status, risk, and priorities in both directions, and helping less technical stakeholders genuinely adopt new tools and processes.

Driving change inside a public institution is its own kind of engineering challenge, and doing it well is a real part of the job.

The ideal candidate has several years of software development experience and is ready to grow into a more senior position. You bring a software engineering background with exposure to security requirements and a willingness to engage with critical legacy systems, building modern controls directly into CI/CD. As a technical leader, you'll work across the hardware to application stack: reviewing code and pipeline configurations, running and triaging security scans, and partnering with engineering teams to assess applications and infrastructure.

Position Responsibilities

Interface between the engineering team and client stakeholders, clearly communicate status updates, technical findings, and secure-coding guidance to both technical and non-technical audiences.

Develop secure software testing and validation procedures for applications moving through the CI/CD pipeline (e.g., Jenkins, GitHub Actions).

Perform risk analysis whenever an application or system undergoes a major change.

Address security implications across the software acceptance phase, including completion criteria, risk acceptance and documentation, and independent testing methods.

Integrate and tune code quality and security scanning tools (e.g., SonarQube) within build and release pipelines.

Consult with engineering and development staff to evaluate the interface between hardware, software, and infrastructure, and to identify security issues around steady-state operation and end-of-life management.

Partner with the security team to triage scan output, validate true positives, and help remediate vulnerabilities prior to release.

Support the ongoing development of our DevSecOps processes, pipeline security gates, and reporting standards.

Minimum Qualifications

Public Trust eligible (U.S. citizenship or green card required and ability to pass a background investigation - no active clearance required).

Strong collaborative and interpersonal skills, with the ability to clearly communicate technical findings and secure-coding guidance to both technical and non-technical audiences.

4+ years of hands-on software engineering experience, including 1+ years of hands-on application security experience.

Familiarity with DevSecOps concepts, including CI/CD pipelines, Jenkins and/or GitHub Actions, and SAST/DAST integration and automation.

Scripting/programming proficiency in Python and/or PowerShell.

Working familiarity with common vulnerability classes (e.g., injection, cross-site scripting, buffer overflow) and secure coding basics.

Nice to Have Qualifications

Familiarity with the Risk Management Framework and related security/privacy controls (NIST SP 800-37, NIST SP 800-53) and/or FedRAMP.

Experience maintaining, modernizing, or porting legacy codebases and systems to run on current platforms.

Application security exposure, such as SAST/DAST tool ownership beyond SonarQube (e.g., Checkmarx, Burp Suite Professional), threat modeling, OWASP ASVS/DSOMM.

Cloud security experience in AWS and/or Azure, including IAM policy and configuration.

Benefits

Compensation: $150k–185k annually (depending on experience)

Company health plan

401(k) plan with employer match

Paid holidays and paid time off

Education reimbursement

How to Apply

Submit a detailed resume with complete month/year dates for every role (please note any employment gaps), plus all certifications, training, and degrees with the year and month earned.

About Signal Hill Technologies

Founded and led by veteran cyber operators, Signal Hill Technologies delivers advanced cybersecurity solutions to DoD, Intelligence Community, financial services, and critical infrastructure clients, with many years of experience defending both US Government and commercial clients against sophisticated, well-funded, motivated adversaries. We are relentless about real results and operationally proven expertise. Our mission is to provide the best technical solutions and hands-on support to address each customer's unique cyber risks.

Signal Hill Technologies is an equal opportunity employer. We do not discriminate based on race, color, religion, sex, national origin, age, disability, protected veteran status, or any other characteristic protected by applicable law.

Responsibilities

  • Interface between the engineering team and client stakeholders, clearly communicate status updates, technical findings, and secure-coding guidance to both technical and non-technical audiences.
  • Develop secure software testing and validation procedures for applications moving through the CI/CD pipeline.
  • Perform risk analysis whenever an application or system undergoes a major change.
  • Address security implications across the software acceptance phase.
  • Integrate and tune code quality and security scanning tools within build and release pipelines.
  • Consult with engineering and development staff to evaluate the interface between hardware, software, and infrastructure.
  • Partner with the security team to triage scan output, validate true positives, and help remediate vulnerabilities prior to release.
  • Support the ongoing development of our DevSecOps processes, pipeline security gates, and reporting standards.

Qualifications

  • Public Trust eligible (U.S. citizenship or green card required).
  • Strong collaborative and interpersonal skills.
  • 4+ years of hands-on software engineering experience, including 1+ years of hands-on application security experience.
  • Familiarity with DevSecOps concepts, including CI/CD pipelines.
  • Scripting/programming proficiency in Python and/or PowerShell.
  • Working familiarity with common vulnerability classes and secure coding basics.

Benefits

  • Compensation: $150k–185k annually.
  • Company health plan.
  • 401(k) plan with employer match.
  • Paid holidays and paid time off.
  • Education reimbursement.

Skills mentioned

PythonDevOpsCI/CDJenkinsGitHub ActionsSoftware TestingCybersecurityVulnerability ManagementOWASPThreat Modeling

About Signal Hill Technologies

Adapt to an evolving cybersecurity landscape. Signal Hill helps large enterprises fortify their cyber posture against sophisticated adversaries. Working with our veteran consultants, clients can optimize their cyber risk management strategy and leverage our hands-on technology expertise to implement it.

Computer and Network Security11-50 employeesManassas, Virginia