Senior Security Engineer
Listed on 2026-01-12
-
IT/Tech
Cybersecurity, Systems Engineer
Overview
Job Description ECS is seeking a Senior Security Engineer to work in our Suitland, MD office.
Position Summary: ECS Federal is a leading information security and information technology company in Washington, DC. We are looking to hire a Senior Security Engineer to support a full range of cyber security services on a long-term contract in Washington DC. The position is full time/permanent and will support a US Government civilian agency. The position is available immediately upon finding a qualified candidate with the appropriate background clearance.
The Senior Security Engineer is responsible for designing, operating, and advancing the organization’s security monitoring and detection capabilities. This role leads a team of approximately 6 security engineers and owns event management, log ingestion, log retention, and detection engineering across hybrid and cloud environments. The position requires deep hands-on experience with Microsoft Sentinel, SIEM platforms, cloud native security tooling, and Infrastructure as Code (IaC), while operating within compliance-driven federal environments.
PositionResponsibilities
- Stay informed on emerging data collection patterns, cloud service telemetry offerings, and platform-native security logging features, ensuring the security monitoring architecture remains modern, scalable, and cost-effective.
- Serve as a technical advisor to Dev Ops initiatives, enabling seamless integration of security monitoring and telemetry while maintaining high developer and security velocity.
- Design and implement creative, scalable solutions for custom log ingestion and detection engineering to support advanced security monitoring use cases.
- Provide technical recommendations to ensure cloud capabilities are implemented securely, optimized for cost, and consistently deployed through validated Infrastructure as Code (IaC) pipelines.
- Conduct Privacy Impact Assessments (PIAs) of the application’s security design for the appropriate security controls, which protect the confidentiality and integrity of Personally Identifiable Information (PII).
- Design and develop cybersecurity or cybersecurity-enabled products.
- Design hardware, operating systems, and software applications to adequately address cybersecurity requirements.
- Design or integrate appropriate data backup capabilities into overall system designs and ensure that appropriate technical and procedural processes exist for secure system backups and protected storage of backup data.
- Develop and direct system testing and validation procedures and documentation.
- Develop detailed security design documentation for component and interface specifications to support system design and development.
- Develop Disaster Recovery and Continuity of Operations plans for systems under development and ensure testing prior to systems entering a production environment.
- Develop specific cybersecurity countermeasures and risk mitigation strategies for systems and/or applications.
- Identify and direct the remediation of technical problems encountered during testing and implementation of new systems (e.g., identify and find workarounds for communication protocols that are not interoperable).
Salary Range: $,000
Required Skills- Strong written and verbal communication skills.
- Knowledge of secure configuration management techniques. (e.g., Security Technical Implementation Guides (STIGs), cybersecurity best practices on cisecurity.org).
- Knowledge of software development models (e.g., Waterfall Model, Spiral Model).
- Knowledge of software engineering.
- Knowledge of structured analysis principles and methods.
- Experience designing architectures and frameworks.
- Knowledge of system design tools, methods, and techniques, including automated systems analysis and design tools.
- Knowledge of the systems engineering process.
- Knowledge of Supply Chain Risk Management Practices (NIST SP 800-161)
- Knowledge of critical infrastructure systems with information communication technology that were designed without system security considerations.
- Knowledge of network security architecture concepts including topology, protocols, components, and principles (e.g., application of defense-in-depth).
- Knowl…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).