Nava Logo

Nava

Sr./Principal Security Engineer (Federal Programs)

Reposted 11 Hours Ago
Remote
Hiring Remotely in USA
153K-171K Annually
Senior level
Remote
Hiring Remotely in USA
153K-171K Annually
Senior level
The Sr./Principal Software Engineer will implement and maintain security programs for government contracts, ensuring compliance and security in AWS cloud solutions.
The summary above was generated by AI
About Nava
Nava is a consultancy and public benefit corporation working to make government services simple and effective. Since 2015, federal, state, and local agencies have trusted Nava to help solve highly scrutinized technology modernization challenges.

As a client services company, we guide agencies constrained by legacy systems to a future with sharp user experiences built on secure, reliable, fault-tolerant cloud infrastructure. We bill for our time, offering our expertise and problem-solving approach to help our government partners enhance their digital products and services. People are at the heart of our work, from members of the public who rely on benefit programs to government agency staff. Through human-centered design and modern engineering best practices, we help our government partners understand user needs and deliver on their missions more effectively. This focus gives everyone at Nava the opportunity to do work that is meaningful, impactful, and deeply connected to public good.




Position summary

The Sr./Principal Security Engineer (Federal Programs) is a hands-on security leader at the heart of delivering secure, mission-critical systems for the federal government. In this role, you’ll design, implement, and evolve a robust information security program that protects sensitive data, enables fast and reliable delivery, and stands up to the highest federal standards.

You’ll own security and compliance for cloud-native platforms—primarily on AWS—guiding teams through complex requirements like FISMA and NIST while making smart, pragmatic tradeoffs that keep delivery moving.

Working side-by-side with engineering, operations, compliance, and executive leadership, you’ll embed security into how systems are designed, built, and operated—not bolted on after the fact. The ideal candidate is a security expert who thrives in modern DevSecOps environments, understands government risk and compliance deeply, and is motivated by real-world impact—protecting systems that millions of people depend on every day.

What you'll do

  • Design, implement, and maintain the organization’s security architecture in alignment with federal security standards (e.g., FISMA, NIST SP 800-53, 800-171) and contract requirements
  • Lead security planning and risk assessments for government systems hosted in AWS
  • Serve as the primary security point of contact for government programs, overseeing incident response, vulnerability management, and system hardening activities
  • Develop and maintain security documentation required for system authorization, including System Security Plans (SSPs), Plans of Action and Milestones (POA&Ms), Security Assessment Reports (SARs), and Continuous Monitoring strategies
  • Support the Authority to Operate (ATO) process across multiple projects, working closely with compliance teams, federal partners, and internal stakeholders
  • Architect, oversee and support implementation of security controls across AWS services (e.g., IAM, KMS, Security Hub, GuardDuty, CloudTrail, Config, WAF, etc.)
  • Perform regular audits, security assessments, and continuous monitoring to ensure compliance with government standards and internal policies
  • Collaborate with engineering teams to integrate security into SDLC/DevOps pipelines, using tools such as SonarQube, Snyk, Tenable, and Jenkins
  • Lead incident response efforts for government systems, including containment, eradication, and recovery, while maintaining proper documentation and communication protocols
  • Research and recommend emerging AWS security services and technologies to improve security posture and maintain compliance
  • Mentor junior DevSecOps team members and foster a culture of security-first thinking across the organization
  • Interface with federal agency stakeholders, auditors, and security assessors to represent the organization’s security practices and compliance efforts
  • Participate in proposal development and pre-award planning by advising on security architecture and compliance strategies for new federal opportunities

Required skills

  • Bachelor’s or Master’s degree in Computer Science, Information Security, Cybersecurity, or a related field
  • 5+ years of experience in information security, with at least 2 years supporting federal government contracts and managing system compliance efforts
  • Deep understanding of federal security frameworks, including FISMA, NIST 800-53, 800-171, and FedRAMP
  • Hands-on experience managing security for AWS cloud environments, including services such as: IAM, KMS, CloudTrail, Security Hub, GuardDuty, Config, VPC, EC2, Lambda, S3, RDS, DynamoDB, WAF, Shield, Inspector, Secrets Manager
  • Experience leading or supporting the ATO process, including documentation, control implementation, security testing, and coordination with third-party assessors or agency officials
  • Proficiency in modern DevSecOps toolchains and methodologies (e.g., Terraform, Jenkins, GitHub, New Relic, SonarQube, Snyk, Tenable Nessus)
  • Solid understanding of secure software development principles across languages and frameworks such as Java, Spring Boot, Python, Go, JavaScript/TypeScript, and Angular
  • Demonstrated ability to communicate security concepts to technical and non-technical stakeholders
  • Strong leadership, analytical, and problem-solving skills

Desired skills

  • CISSP, CISM, or equivalent federal security certification (e.g., CAP, GSLC)

Other requirements
All roles at Nava require the following:
Legal authorization to work in the United States
Ability to meet any other requirements for government contracts for which candidates are hired
Work authorization that doesn’t require visa sponsorship, now or in the future
May be subject to a government background check or security clearance, depending on the contract


Perks working with Nava
Health coverage — comprehensive medical, dental, and vision plans to support your overall health needs
Insurance coverage — Nava provides disability, life, and accidental death insurance at no cost
Time off — vacation, holidays (including Juneteenth), and floating holidays to rest and recharge
Company holidays — enjoy 12 paid federal holidays each year on top of your regular PTO
Annual bonus — when Nava meets its goals, eligible employees receive a performance-based annual bonus
Parental leave — paid time off for new parents, plus weekly meals delivered to your home
Wellness program — full platform offering physical, mental, & emotional health resources & support tools
Virtual care — see doctors online with no copay through UnitedHealthcare’s virtual visit program
Sabbatical leave — earn extended unpaid leave after continuous service for personal growth or rest
401(k) match — Nava matches 4% of your salary to support your retirement savings plan
Flexible work — remote-first environment with flexibility built around your schedule and responsibilities
Home office setup — company laptop & setup assistance provided via Staples for remote work needs
Utility support — monthly reimbursement to help offset eligible home office utility expenses
Learning opportunities — internal training programs and resources to help grow your professional skills
Development opportunities — LinkedIn Learning access & an annual allowance for courses, tuition, & certs 
Referral bonus — get rewarded when you refer great people who join the Nava team
Commuter benefits — pre-tax commuter programs to support in-office travel when applicable
Supportive culture — A collaborative and remote-friendly team environment where people genuinely care

Location
We have fully remote options if you reside in one of the following states: 

Alabama, Arizona, California, Colorado, DC, Delaware, Florida, Georgia, Illinois, Louisiana, Maine, Maryland, Massachusetts, Michigan, Minnesota, Missouri, Nevada, North Carolina, New Jersey, New York, Ohio, Oklahoma, Oregon, Pennsylvania, Rhode Island, South Carolina, Texas, Tennessee, Utah, Virginia, Washington, Wisconsin

*If you are not living in one of the states listed above, unfortunately, you will not be considered for a position at this time. 

Stay in touch
Sign up for our newsletter to find out about career opportunities, new partnerships, and news from the broader civic tech community.

Please contact the recruiting team at [email protected] if you would like to request reasonable accommodation during the application or interviewing process.  

We participate in E-Verify. Upon hire, we will provide the federal government with your Form I-9 information to confirm that you are authorized to work in the U.S. This role requires you to work from the contiguous United States. 

Equal Employment Opportunity
Nava is committed to providing equal employment opportunities without discrimination or harassment on the basis of race, gender and/or gender identity or expression, color, creed, religion, religious creed, age, national origin, ethnicity, disability, veteran or military status, sex, sexual orientation, reproductive health autonomy, pregnancy, childbirth, and medical conditions related to pregnancy or childbirth, genetic information, domestic violence victim status, marital status, citizenship status, or any other characteristic protected by law. Nava prohibits any such discrimination or harassment. This policy applies to all employees, applicants, contractors, and temporary workers of Nava.

Top Skills

Amazon Web Services (Aws)
Angular
Cloudtrail
Config
Git
Go
Guardduty
Iam
Java
JavaScript
Jenkins
Kms
New Relic
Python
Security Hub
Snyk
Sonarqube
Spring Boot
Tenable Nessus
Terraform
Typescript
Waf

Similar Jobs

52 Minutes Ago
Remote or Hybrid
Minnesota, USA
80K-131K Annually
Senior level
80K-131K Annually
Senior level
Automotive • Hardware • Internet of Things • Mobile • Software • App development • PropTech
The role involves driving sales growth within assigned territories, managing customer relationships, and providing training on products. Requires strong public speaking and extensive travel.
An Hour Ago
Remote or Hybrid
18 Locations
94K-136K Annually
Mid level
94K-136K Annually
Mid level
eCommerce • Mobile • Payments
The Account Manager drives campaign performance, manages client relationships, provides data-driven insights, and identifies upsell opportunities to meet revenue goals.
Top Skills: ExcelGoogle SuiteLooker
2 Hours Ago
Remote or Hybrid
United States
110K-146K Annually
Senior level
110K-146K Annually
Senior level
Fintech • Information Technology • Insurance • Financial Services • Big Data Analytics
The Director - Client Services leads a team, enhances client relationships, and implements process improvements while collaborating across departments.
Top Skills: AnalyticsBusiness OperationsFinancial ForecastingGroup Benefits Products

What you need to know about the Los Angeles Tech Scene

Los Angeles is a global leader in entertainment, so it’s no surprise that many of the biggest players in streaming, digital media and game development call the city home. But the city boasts plenty of non-entertainment innovation as well, with tech companies spanning verticals like AI, fintech, e-commerce and biotech. With major universities like Caltech, UCLA, USC and the nearby UC Irvine, the city has a steady supply of top-flight tech and engineering talent — not counting the graduates flocking to Los Angeles from across the world to enjoy its beaches, culture and year-round temperate climate.

Key Facts About Los Angeles Tech

  • Number of Tech Workers: 375,800; 5.5% of overall workforce (2024 CompTIA survey)
  • Major Tech Employers: Snap, Netflix, SpaceX, Disney, Google
  • Key Industries: Artificial intelligence, adtech, media, software, game development
  • Funding Landscape: $11.6 billion in venture capital funding in 2024 (Pitchbook)
  • Notable Investors: Strong Ventures, Fifth Wall, Upfront Ventures, Mucker Capital, Kittyhawk Ventures
  • Research Centers and Universities: California Institute of Technology, UCLA, University of Southern California, UC Irvine, Pepperdine, California Institute for Immunology and Immunotherapy, Center for Quantum Science and Engineering

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account