FEDERAL HOME LOAN BANKS OFFICE OF FINANCE

Sr Security Engineer

FEDERAL HOME LOAN BANKS OFFICE OF FINANCE Reston, Virginia, United States · $140K–$202K/yr

Capital Markets · 51-200 employees

5 h ago
security Senior (5-10 yrs) Full-time United States
Log in to apply, save this posting, or score it against your profile with AI.

About the role

The Senior Security Engineer will design, implement, and operate security controls across applications and supporting platforms, with a primary focus on application security. They will partner with DevOps and development teams to build secure-by-default applications and integrate security into CI/CD pipelines.

What they look for

Application Security SDLC CI/CD Web Application Firewall API Security Container Security Vulnerability Assessment Penetration Testing OAuth OpenID Identity Management Cloud Security Automation Risk Assessment Security Monitoring Network Troubleshooting

Requirements

Candidates must have 6 to 8 years of experience in application security, including hands-on expertise with OWASP Top 10, WAF, and container security. A Bachelor's degree in Information Security, Computer Science, or a related engineering field is required.

Full description

FEDERAL HOME LOAN BANKS OFFICE OF FINANCE

POSITION: Senior Security Engineer DATE: September 2026

DEPARTMENT: Information Technology FLSA: Exempt

REPORTS TO: Director, Information Security

SUMMARY OF POSITION

The Senior Security Engineer designs, implements, operates, and continuously improves OF’s security technologies and controls across applications and supporting platforms. Primary focus is Application Security-embedding security into the SDLC and CI/CD pipelines, strengthening web/API protections, and enabling proactive detection, while contributing broadly to Security Engineering capabilities (identity, cloud/on prem security platforms, logging/telemetry, and automation). The role partners closely with development, DevOps, and operations teams to build secure-by-default applications and services.

We’re proud of the way our teammates have a positive impact on everything we do. Our employees are committed to and exemplify our Core Values:

  • Integrity through accountability, consistency, transparency and trust
  • Agility through adaptability, continuous improvement, expertise, and flexibility
  • Partnership through collaboration, communication, leadership, and teamwork
  • Inclusivity through diversity, relationships, respect, and support

PRINCIPAL RESPONSIBILITIES

  • Develop and maintain software application security policies and procedures
  • Implement software application security controls
  • Partner with DevOps in developing a secure CI/CD pipeline
  • Design and operate web application firewall (WAF) and API protections; tune rules, reduce false positives, and automate policy updates
  • Identify application security vulnerabilities and issues, perform risk assessments and provide mitigations
  • Develop security monitoring for application stack
  • Conduct technical investigations of application security incidents
  • Interface with senior stakeholders across the IT leadership team to proactively interpret risks and priorities.
  • Support the OF’s diversity and inclusion strategy by following policies and procedures that ensure opportunities for employees and diverse business partners.
  • Assist with other job duties as assigned.

PRINCIPAL JOB REQUIREMENTS

  • A minimum [TF4.1]of 6 to 8 years of experience in Application Security (designing, implementing, and operating security controls in enterprise application environments).
  • Hands-on experience with web application security, including OWASP Top 10 vulnerabilities
  • Hands-on experience with WAF/API security (policy design, rule tuning, automation), container security (runtime hardening, image scanning, vulnerability risk assessments)
  • Hands-on experience with conducting web application security scans, vulnerability assessments and/or penetration testing
  • Experience in investigating problems and processes within established methodologies and best practices.
  • Experience working with Authentication and Authorization services like OAuth and OpenID
  • Experience in operating on-prem or cloud based security platforms
  • Ability to troubleshoot security and network-related issues and communicate technical findings effectively
  • Ability to listen and integrate ideas from diverse groups of individuals, build and maintain respectful relationships, collaborate with others, and resolve conflicts constructively.
  • Bachelor’s Degree in Information Security or Computer Science or Computer/Electrical Engineering, and/or equivalent field experience.
  • Proof of eligibility to work in the United States.

This position has an annualized salary range of $140,441 - $202,303. The final salary offered within this range is dependent on various factors, including but not limited to the responsibilities of the position, the experience, skill set and other relevant qualifications of the applicant and internal pay equity.

EQUAL EMPLOYMENT OPPORTUNITY

The Federal Home Loan Banks Office of Finance is committed to equal employment opportunity without regard to race (including traits historically associated with race, such as hair texture, hair type and protective hairstyles), color, religion, sex, pregnancy (including childbirth, lactation, and related medical conditions), national origin or ancestry, age, physical or mental disability, veteran status, uniformed service member status, military status, sexual orientation, gender identity, status as a parent, marital status, genetic information (including testing and characteristics), citizenship status, or any other characteristic protected by applicable federal, state, or local law.

Similar roles