About the role
The Security Engineer will integrate security into the software development lifecycle through automation and testing while remediating application and infrastructure vulnerabilities. They will also develop tools to improve security and operational visibility while supporting compliance activities.
What they look for
Requirements
Candidates must have at least 3 years of engineering experience and familiarity with federal cloud security requirements like FISMA. Proficiency in at least one programming language and one infrastructure-as-code language is required, along with authorization to work in the United States.
Benefits
Full description
About Corbalt
Corbalt is a technology company that partners with federal agencies to modernize and operate complex technology ecosystems. We build shared platforms, engineering foundations, and reusable services that enable mission teams to deliver software faster, operate more efficiently, and scale with confidence.
Our roots trace back to the Healthcare.gov recovery effort, where we saw firsthand what talented, mission-driven teams could accomplish together. That experience shaped how we work today: solving complex technical challenges through collaboration, pragmatic engineering, and a relentless focus on delivering value.
Today, we support critical healthcare modernization efforts at the Centers for Medicare & Medicaid Services (CMS), helping build and operate the platforms, tools, and services that enable teams across Medicare and Medicaid to deliver secure, resilient digital experiences.
We're a remote-first team that values curiosity, kindness, ownership, and continuous learning. We enjoy solving hard technical problems, partnering closely with our clients, and building technology that makes government work better for the people who rely on it.
Contingent Position: This position is contingent upon Corbalt's successful contract award. Employment offers and start dates are dependent on the award of the associated government contract.
Security Engineer
We're looking for a Security Engineer who enjoys building secure software, improving engineering platforms, and helping teams deliver with confidence. You'll work closely with software engineers to integrate security into the development lifecycle, automate security practices, and build resilient cloud-native systems that support critical government services.
Responsibilities
- Integrate security into the software development lifecycle through automation, testing, and continuous improvement.
- Identify, investigate, and remediate application and infrastructure vulnerabilities.
- Develop tools and automation in Python, Go, or Terraform that improve security, developer productivity, and operational visibility (it’s not important that you know these languages).
- Support security assessments, compliance activities, and continuous monitoring.
- Contribute to security best practices across engineering teams.
Skills
- Strong software engineering fundamentals and experience writing production code.
- Experience with application security, DevSecOps, or cloud security.
- Understanding of secure software design, authentication/authorization, and common application vulnerabilities.
- Familiarity with at least one commonly used programming language and one infrastructure-as-code language.
- Strong communication and collaboration skills with engineering and technical stakeholders.
Experience
- 3+ years of engineering experience
- Demonstrated ability to operate independently and ramp quickly in complex environments
- Experience supporting security assessments, compliance, or continuous monitoring in regulated environments
- Familiarity with federal cloud and security requirements (e.g., FISMA)
- Demonstrated experience operating and analyzing systems in AWS, Azure, or Google Cloud.
Values
- Growth-oriented mindset
- Intrinsic motivation to learn, grow, and do great work
- Kindness
- Grit / perseverance / resilience
Compensation & Benefits
The base salary range for this position is: $138,677 - $182,296 per year.
In addition to the base salary, Corbalt offers:
- Medical, dental, vision benefits
- Profit sharing and discretionary bonuses
- A company 401(k) contribution equal to 3% of your salary
- Paid vacation, sick time, and company holidays
- Reimbursement for reasonable expenses that are helpful for work
- In-person company retreats
Hiring Process
- The first stage is an informal conversation to learn more about each other, answer questions, and discuss the role.
- The second stage is a mini-project based on something we've actually worked on. The goal of this is to get an idea of what working together is like.
- The last stage is: a 10-20 minute presentation to the team describing what you did on a previous project and two 30 minute conversations with other people on the team to get an additional perspective on what our work is like.
Other Requirements
- Due to contractual requirements applicants must:
- Be authorized to work in the United States
- Currently reside in the United States or its territories
- Have resided in the United States or its territories for three of the last five years
- Have at least three years of professional experience
- Due to contractual and security requirements, all work must be performed while physically present within the United States or its territories. Work performed while outside the U.S. or its territories is strictly forbidden.
- Corbalt participates in E-Verify. Upon hire, your Form I-9 information will be provided to the federal government to confirm you are authorized to work in the United States.
Corbalt is an Equal Opportunity Employer, including disability and protected veteran status.
\n
\n
Similar roles
-
Cybersecurity Administrator
Coastal Ridge Columbus, Ohio, United States
-
Information System Security Engineer
SAIC Colorado Springs, Colorado, United States
-
System Cybersecurity Engineer
Odyssey Systems Consulting Group, Ltd. Colorado Springs, Colorado, United States · $130K–$165K/yr
-
Senior Security Engineer - Ardán Inc
Westcor Land Title Insurance Company® Orange County, Florida, United States
-
Cybersecurity Analyst I, II, or III
New American Funding Santa Ana, California, United States · $90K/yr
-
CYBERSECURITY EXPERT
Kave Home Sils, Catalonia, Spain