Staff Security Engineer

Important Notice for Applicants:
At Bixal, we want to ensure a transparent and secure application process for all candidates. Official communication will come from an email address ending in @bixal.com or from @bixal.na.teamtailor-mail.com. Messages from other sources may be fraudulent, and you should exercise care to avoid any links or attachments included.
Bixal will ensure that individuals with disabilities are provided reasonable accommodation to participate in the job application or interview process, to perform essential job functions, and to receive other benefits and privileges of employment.
Need Assistance or a Reasonable Accommodation?
If you need assistance or a reasonable accommodation to complete your application, we're here to help. Please reach out to us at talent@bixal.com and let us know how we can support you. You do not need to share personal details or disclose the nature of your request. You can expect a response from a team member within 24 hours during the regular work week and on the next operating day during the weekend or holidays.
Why Bixal?
Bixal is a consulting company headquartered in Fairfax, VA, working alongside governments and organizations to help them deliver better services and experiences to the communities they serve. Using evidence-based knowledge and technology, Bixal empowers clients to deliver on their missions more effectively by fostering a culture of learning and continuous improvement.
Our values:
People-First: Emphasizing the importance of people in all aspects of work.
Collaboration and Transparency: Valuing teamwork and open communication.
Growth Mindset: Encouraging innovation and continuous improvement.
Creating Lasting Impact: Focusing on meaningful outcomes and positive change.
About the role:
In this role, you'll embed secure-by-design controls directly into a federal agency developer platform, policy-as-code, identity federation, and automated audit-evidence collection, so that security and compliance become part of the golden path rather than a separate gate. You'll partner closely with ISSO and ISSE functions and the broader platform team to keep FedRAMP-authorized systems continuously compliant while enabling engineering velocity.
This role offers you a unique opportunity to make a meaningful impact on a mission-critical federal platform that aligns with Bixal's mission of delivering innovative, human-centered solutions. At Bixal, we support your professional journey, ensuring your experience reflects our purpose-driven culture and prepares you for future success.
Location
This role can work remotely from anywhere in the USA. You must be legally authorized to work in the US. Bixal does not provide visa sponsorship.
Compensation:
The salary range for this role is $145,000 – $155,000. In the spirit of transparency, most offers tend to land near the midpoint of the range. We make compensation decisions thoughtfully, considering your experience, the skills you bring, and our commitment to internal equity. Fairness and transparency are core to how we operate.
Responsibilities:
Design and implement secure-by-design controls, policy-as-code, and identity federation across the platform.
Build audit-evidence automation to support continuous compliance and reduce manual audit burden.
Lead threat modeling, code scanning, dependency controls, and vulnerability remediation efforts.
Align technical controls and evidence collection to regulatory, privacy, and federal audit requirements (e.g., NIST SP 800-53, FedRAMP).
Design and implement identity, access, encryption, and data protection controls in production systems.
Reduce security risk through automation, monitoring, and preventive controls embedded directly in delivery workflows.
Act as an engineering partner who ships fixes and enables teams to move fast safely, not solely a checklist-based reviewer.
Collaborate with ISSOs/ISSEs and the Platform Enablement team on ATO and continuous monitoring (ConMon) activities.
Other relevant duties as qualified and trained to perform.
Qualifications:
Bachelor's degree and at least 8 years of related experience, or an equivalent combination of education and experience.
Demonstrated leadership building secure engineering practices, including threat modeling, code scanning, dependency controls, and vulnerability remediation.
Experience aligning technical controls and evidence collection to regulatory, privacy, and audit requirements.
Proven ability to design and implement identity, access, encryption, and data protection controls in production systems.
Hands-on track record reducing security risk through automation, monitoring, and preventive controls embedded in delivery workflows.
Experience supporting FISMA Moderate or higher ATO processes for federal systems.
Must be able to obtain and maintain a Tier 4 High Risk Public Trust clearance.
Nice to Have Skills and Experience:
Familiarity with policy-as-code tooling, Terraform security modules, and CI/CD-embedded security scanning (e.g., Snyk, CodeQL).
Experience with identity federation (OIDC/SAML) in federal environments (e.g., Login.gov integration).
Prior experience supporting federal financial-data systems.
How We Support Our Team:
Flex hours
401K with matching incentive
Parental Leave
Medical/dental/vision benefits
Flex Spending Account
Company provided short-term disability and life insurance
Commuter benefits
Paid Time Off (PTO)
11 Paid holidays
Our company is committed to providing equal employment opportunities for all individuals and complies with all applicable federal, state, and local anti-discrimination laws. Employment decisions are based on merit, qualifications, and business needs.
- Department
- Client Delivery
- Role
- Cybersecurity
- Locations
- Remote within United States
- Remote status
- Fully Remote
About Bixal
We leverage technology, communications, data, and human-centered design to help governments and leading organizations be more efficient, effective, and impactful.