Jobs and Careers
EC

Senior Security Engineer

ECS
United Statesfull_timeVerifiedPosted 6 Jan 2026
💰 $140,000/yr($125,000/yr$140,000/yr)

About the role

ECS is seeking a Senior Security Engineer to work in our Suitland, MD office.  

Position Summary: 

ECS Federal is a leading information security and information technology company in Washington, DC. We are looking to hire a Senior Security Engineer to support a full range of cyber security services on a long-term contract in Washington DC. The position is full time/permanent and will support a US Government civilian agency. The position is available immediately upon finding a qualified candidate with the appropriate background clearance. 

The Senior Security Engineer is responsible for designing, operating, and advancing the organization’s security monitoring and detection capabilities. This role leads a team of approximately 6 security engineers and owns event management, log ingestion, log retention, and detection engineering across hybrid and cloud environments. The position requires deep hands-on experience with Microsoft Sentinel, SIEM platforms, cloud native security tooling, and Infrastructure as Code (IaC), while operating within compliance-driven federal environments. 
 

Position Responsibilities: 

  • Stay informed on emerging data collection patterns, cloud service telemetry offerings, and platform-native security logging features, ensuring the security monitoring architecture remains modern, scalable, and cost-effective. 
  • Serve as a technical advisor to DevOps initiatives, enabling seamless integration of security monitoring and telemetry while maintaining high developer and security velocity. 
  • Design and implement creative, scalable solutions for custom log ingestion and detection engineering to support advanced security monitoring use cases. 
  • Provide technical recommendations to ensure cloud capabilities are implemented securely, optimized for cost, and consistently deployed through validated Infrastructure as Code (IaC) pipelines. 
  • Conduct Privacy Impact Assessments (PIAs) of the application’s security design for the appropriate security controls, which protect the confidentiality and integrity of Personally Identifiable Information (PII). 
  • Design and develop cybersecurity or cybersecurity-enabled products. 
  • Design hardware, operating systems, and software applications to adequately address cybersecurity requirements. 
  • Design or integrate appropriate data backup capabilities into overall system designs and ensure that appropriate technical and procedural processes exist for secure system backups and protected storage of backup data. 
  • Develop and direct system testing and validation procedures and documentation. 
  • Develop detailed security design documentation for component and interface specifications to support system design and development. 
  • Develop Disaster Recovery and Continuity of Operations plans for systems under development and ensure testing prior to systems entering a production environment. 
  • Develop specific cybersecurity countermeasures and risk mitigation strategies for systems and/or applications. 
  • Identify and direct the remediation of technical problems encountered during testing and implementation of new systems (e.g., identify and find workarounds for communication protocols that are not interoperable). 

Salary Range: $125,000-140,000

General Description of Benefits

 

Qualifications
  • Strong written and verbal communication skills. 
  • Knowledge of secure configuration management techniques. (e.g., Security Technical Implementation Guides (STIGs), cybersecurity best practices on cisecurity.org). 
  • Knowledge of software development models (e.g., Waterfall Model, Spiral Model). 
  • Knowledge of software engineering. 
  • Knowledge of structured analysis principles and methods. 
  • Experience designing architectures and frameworks. 
  • Knowledge of system design tools, methods, and techniques, including automated systems analysis and design tools. 
  • Knowledge of the systems engineering process. 
  • Knowledge of Supply Chain Risk Management Practices (NIST SP 800-161) 
  • Knowledge of critical infrastructure systems with information communication technology that were designed without system security considerations. 
  • Knowledge of network security architecture concepts including topology, protocols, components, and principles (e.g., application of defense-in-depth). 
  • Knowledge of network systems management principles, models, methods (e.g., end-to-end systems performance monitoring), and tools. 
  • Knowledge of SIEM, Logging & Detection. 
  • Knowledge of Endpoint & Platform

Apply for this role

Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.

Apply Now →Generate Application Kit

Free account required — sign up in 30s

Company

ECS

View company profile →