
Software Engineer
- $150k – $185k
- |Glen Burnie
- |4 years of exp
- |Full Time
In office
Not Available
About the job
Location: Fairfax, VA (On-site, full-time)
Employment Type: Full-time
Status: Immediate
Eligibility: U.S. Citizenship or Green Card required. Public Trust eligibility required, no active security clearance needed.
About the Role
Most of the systems that keep the lights on, money moving, and crucial public services running were built long before today's threat landscape existed. Someone has to modernize them without disrupting the services people depend on every day. That's where you come in.
Signal Hill Technologies is seeking a software engineer and project manager to embed security throughout the technology lifecycle for our government and commercial clients, protecting the assets that communities and institutions rely on every day. This is a technical program management role where mentoring, hands-on engineering, and earning the trust of the people you serve carry equal weight. You'll be the day-to-day connection between our engineering team and the client's system owners and program leadership, translating technical status, risk, and priorities in both directions, and helping less technical stakeholders genuinely adopt new tools and processes.
Driving change inside a public institution is its own kind of engineering challenge, and doing it well is a real part of the job.
The ideal candidate has several years of software development experience and is ready to grow into a more senior position. You bring a software engineering background with exposure to security requirements and a willingness to meet critical legacy systems on their own terms, building modern controls directly into CI/CD. As a technical leader, you'll work across the hardware to application stack: reviewing code and pipeline configurations, running and triaging security scans, and partnering with engineering teams to assess applications and infrastructure.
About Signal Hill Technologies
Founded and led by veteran cyber operators, Signal Hill Technologies delivers advanced cybersecurity solutions to DoD, Intelligence Community, financial services, and critical infrastructure clients, with many years of experience defending both US Government and commercial clients against sophisticated, well-funded, motivated adversaries. We are relentless about real results and operationally proven expertise. Our mission is to provide the best technical solutions and hands-on support to address each customer's unique cyber risks.
Position Responsibilities
- Interface between the engineering team and client stakeholders, clearly communicate status updates, technical findings, and secure-coding guidance to both technical and non-technical audiences.
- Develop secure software testing and validation procedures for applications moving through the CI/CD pipeline (e.g., Jenkins, GitHub Actions).
- Perform risk analysis whenever an application or system undergoes a major chang.
- Address security implications across the software acceptance phase, including completion criteria, risk acceptance and documentation, and independent testing methods.
- Integrate and tune code quality and security scanning tools (e.g., SonarQube) within build and release pipelines.
- Consult with engineering and development staff to evaluate the interface between hardware, software, and infrastructure, and to identify security issues around steady-state operation and end-of-life management.
- Partner with the security team to triage scan output, validate true positives, and help remediate vulnerabilities prior to release.
- Support the ongoing development of our DevSecOps processes, pipeline security gates, and reporting standards.
Minimum Qualifications
- Strong collaborative and interpersonal skills, with the ability to clearly communicate technical findings and secure-coding guidance to both technical and non-technical audiences.
- 4+ years of hands-on software engineering experience, including 1+ years of hands-on application security experience.
- Public Trust eligible (U.S. citizenship or green card required and ability to pass a background investigation) - no active clearance required.
- Familiarity with DevSecOps concepts, including CI/CD pipelines, Jenkins and/or GitHub Actions, and SAST/DAST integration and automation.
- Scripting/programming proficiency in Python and/or PowerShell.
- Working familiarity with common vulnerability classes (e.g., injection, cross-site scripting, buffer overflow) and secure coding basics.
Preferred Qualifications
- Familiarity with the Risk Management Framework and related security/privacy controls (NIST SP 800-37, NIST SP 800-53) and/or FedRAMP.
- Experience maintaining, modernizing, or porting legacy codebases and systems to run on current platforms.
- Application security exposure, such as SAST/DAST tool ownership beyond SonarQube (e.g., Checkmarx, Burp Suite Professional), threat modeling, OWASP ASVS/DSOMM.
- Cloud security experience in AWS and/or Azure, including IAM policy and configuration.
Benefits
- Compensation: $150k–185k annually (depending on experience)
- Company health plan
- 401(k) plan with employer match
- Paid holidays and paid time off
- Education reimbursement
How to Apply
Submit a detailed resume (including complete work history with month/year for each role and all certifications) directly through LinkedIn. Please account for any gaps in employment and specify all relevant training and degrees with the year and month earned.
Signal Hill Technologies is an equal opportunity employer. We do not discriminate based on race, color, religion, sex, national origin, age, disability, protected veteran status, or any other characteristic protected by applicable law.
About the company
