🎁 Before you apply, rehearse this interview. Create your free WorkMundi account and get an Interview Training on HelpsYouSpeak — no cost, no card. I want my training →
Location: Fairfax, VA (On-site, full-time) Employment Type: Full-time Status: Immediate Eligibility: U.S. Citizenship or Green Card required. Public Trust eligibility required, no active security clearance needed. About the Role Most of the critical infrastructure systems that keep the lights on, money moving, and crucial public services running were built long before today's threat landscape existed. Someone has to modernize them without disrupting the services people depend on every day. That's where you come in. Signal Hill Technologies is seeking a software engineer and project manager to embed security throughout the technology lifecycle for our government and commercial clients, protecting the assets that communities and institutions rely on every day. This is a technical program management role where mentoring, hands-on engineering, and earning the trust of the people you serve carry equal weight. Also known as a DevSecOps Engineer, Application Security Engineer, Security Software Engineer, Secure DevOps Engineer, or Technical Program Manager, you'll be the day-to-day connection between our engineering team and the client's system owners and program leadership, translating technical status, risk, and priorities in both directions, and helping less technical stakeholders genuinely adopt new tools and processes. Driving change inside a public institution is its own kind of engineering challenge, and doing it well is a real part of the job. The ideal candidate has several years of software development experience and is ready to grow into a more senior position. You bring a software engineering background with exposure to security requirements and a willingness to engage with critical legacy systems, building modern controls directly into CI/CD. As a technical leader, you'll work across the hardware to application stack: reviewing code and pipeline configurations, running and triaging security scans, and partnering with engineering teams to assess applications and infrastructure. Position Responsibilities Interface between the engineering team and client stakeholders, clearly communicate status updates, technical findings, and secure-coding guidance to both technical and non-technical audiences. Develop secure software testing and validation procedures for applications moving through the CI/CD pipeline (e.g., Jenkins, GitHub Actions). Perform risk analysis whenever an application or system undergoes a major chang. Address security implications across the software acceptance phase, including completion criteria, risk acceptance and documentation, and independent testing methods. Integrate and tune code quality and security scanning tools (e.g., SonarQube) within build and release pipelines. Consult with engineering and development staff to evaluate the interface between hardware, software, and infrastructure, and to identify security issues around steady-state operation and end-of-life management. Partner with the security team to triage scan output, validate true positives, and help remediate vulnerabilities prior to release. Support the ongoing development of our DevSecOps processes, pipeline security gates, and reporting standards. Minimum Qualifications Strong collaborative and interpersonal skills, with the ability to clearly communicate technical findings and secure-coding guidance to both technical and non-technical audiences. 4+ years of hands-on software engineering experience, including 1+ years of hands-on application security experience. Public Trust eligible (U.S. citizenship or green card required and ability to pass a background investigation) - no active clearance required. Familiarity with DevSecOps concepts, including CI/CD pipelines, Jenkins and/or GitHub Actions, and SAST/DAST integration and automation. Scripting/programming proficiency in Python and/or PowerShell. Working familiarity with common vulnerability classes (e.g., injection, cross-site scripting, buffer overflow) and secure coding basics. Preferred Qualifications Familiarity with the Risk Management Framework and related security/privacy controls (NIST SP 800-37, NIST SP 800-53) and/or FedRAMP. Experience maintaining, modernizing, or porting legacy codebases and systems to run on current platforms. Application security exposure, such as SAST/DAST tool ownership beyond SonarQube (e.g., Checkmarx, Burp Suite Professional), threat modeling, OWASP ASVS/DSOMM. Cloud security experience in AWS and/or Azure, including IAM policy and configuration. Benefits Compensation: $150k–185k annually (depending on experience) Company health plan 401(k) plan with employer match Paid holidays and paid time off Education reimbursement How to Apply Submit a detailed resume (including complete work history with month/year for each role and all certifications) directly through LinkedIn. Please account for any gaps in employment and specify all relevant training and degrees with the year and month earned. About Signal Hill Technologies Founded and led by veteran cyber operators, Signal Hill Technologies delivers advanced cybersecurity solutions to DoD, Intelligence Community, financial services, and critical infrastructure clients, with many years of experience defending both US Government and commercial clients against sophisticated, well-funded, motivated adversaries. We are relentless about real results and operationally proven expertise. Our mission is to provide the best technical solutions and hands-on support to address each customer's unique cyber risks. Signal Hill Technologies is an equal opportunity employer. We do not discriminate based on race, color, religion, sex, national origin, age, disability, protected veteran status, or any other characteristic protected by applicable law.
Here's how to pick the right one and stand out in your application.
144.883Jobs
31.687IN
81%EN
That number is real. WorkMundi's database shows 144,883 open engineer roles across the world. India has the most with 31,687 jobs, followed by the United States with 30,084. If you just finished reading one job ad and felt paralyzed by choice, you're not alone—but this scale is actually an advantage. It means you can afford to be selective.
Start by geography and language. The majority of engineer ads—117,837 of them—have the job posting text written in English. Use that as one filter, but remember: the ad text language tells you nothing about whether the role actually requires you to speak English day-to-day. Read the job description carefully. Then check which countries have the volume you're targeting. Singapore, Poland, and Australia round out the top five after India and the US.
Next, learn who's hiring. Accenture has posted 2,801 engineer roles. andurilindustries, speechify, and jobgether are also actively recruiting. If you're applying to one of these names, research their hiring patterns and interview style before you apply. That homework pays off.
When you interview, expect the question every engineer hears: 'Tell me about a time you had to debug a problem that wasn't in your job description.' Have a specific story ready—not a general one. Name the tools, the deadline pressure, and what you learned. Hiring managers listen for whether you see problem-solving as part of the role itself, not a favour.