Quick Overview
Salary
$67/hr
Seniority
Mid Senior
Work mode
Remote
Location
United States
Posted
Yesterday
Job Description
Location: REMOTE,GA
Expected Start Date: Nov 2, 2026
Title: Tech Lead, Security Remediation Standards-101111
Location: remote but only open to candidates CURRENTLY local to city's or surrounding areas; Philadelphia, Boca Raton, NYC, Chicago, Tampa, San Diego, Atlanta, and/or Dallas - If local to ATL
they would like some flexibility in this person coming onsite
Pay: $67.33/hr w2 MAX rate- w2 only for conversion
Hours: Expectation is to work EST times, busiest is in the morning some meetings start 8.30am EST.
Type: Contract
Length: 9-months; possibility to extend
Screenings: tech prior to submission, full panel drug and background once hired
IV process: 1 screen with swoon- client 2 steps (first with hiring manager, second is onsite with the team)
MUST HAVES:
10+ years of software engineering experience across the full development lifecycle, including Tech Lead roles.
Experience designing and operating CI/CD, build, or developer platform capability adopted at scale across multiple development teams.
Experience in Linux environments; Windows exposure preferred.
Experience delivering in regulated environments with audit and evidence obligations.
Experience in a shared-services or centralized delivery model supporting multiple application teams with competing priorities.
Required Technical Experience
Track record driving adoption of engineering standards across teams outside direct reporting lines.
Container build systems, including base images, multi-stage builds, minimal and hardened images, and the runtime impacts of adoption.
Vulnerability management, including interpreting scanner findings, exploitability and reachability assessment, prioritization, compensating controls, and exception documentation.
Working proficiency in Java, .NET, and Python sufficient to specify and review code changes.
Test strategy for request-serving services and for batch and pipeline workloads, including output-correctness verification.
Cloud platform depth in AWS or Azure.
CI/CD tooling and pipeline automation, such as Jenkins, GitHub Actions, GitLab, or equivalent.
Infrastructure as code, such as Terraform, Ansible, or equivalent.
Desired Knowledge and Experience
Programmatic extraction of inventory, dependency, and configuration data from codebases at scale.
Policy as code.
Software supply chain controls, including SBOM generation, build provenance, and artifact signing.
Secure base image providers, cloud security posture management, or equivalent platforms.
Excellent verbal and written communication, with the ability to convey technical detail to audiences at varying technical levels.
Responsibilities
We are seeking a Tech Lead to define and deliver the application security standards used across the BC2 remediation program within Data Engineering.
This is a centralized role that translates InfoSec control requirements into executable engineering specifications, establishes hardened reference implementations for each application type in the estate, and validates remediation prior to production implementation.
The role works alongside remediation engineers who execute against those standards, and partners with Information Security, Platform Engineering, application development teams, and operational support. Application owners retain sign-off and risk acceptance for their own systems.
Duties
Translate InfoSec control requirements into scoped, assignable engineering work with defined acceptance criteria and audit evidence.
Create and maintain well-defined development tickets with clear requirements and measurable outcomes, enabling effective tracking of developer progress, delivery, and performance
. Classify the application estate into a small number of types, based on build and runtime characteristics, and maintain that classification as the estate changes.
Establish, or specify for others to build, the tooling, environments, and pipeline capability required to deliver and validate standards at scale.
Design, build, and maintain a hardened reference implementation for each type, covering approved base images, required security controls, verification, and evidence generation.
Define migration paths for end-of-life runtimes and frameworks and identify workloads where retirement or replacement is lower cost than remediation.
Analyze scan findings and exception requests to determine exploitability, identify false positives, and specify compensating controls where remediation is not viable, including applications where source changes are not possible.
Define acceptance criteria and rollback procedures with the accountable application owner prior to production implementation, escalating where ownership is unresolved.
Ensure remediation evidence is generated by the build rather than assembled manually.
Provide technical direction to remediation engineers executing against published standards.
Produce standards documentation, migration procedures, developer guidance, and remediation evidence.
Expected Start Date: Nov 2, 2026
Title: Tech Lead, Security Remediation Standards-101111
Location: remote but only open to candidates CURRENTLY local to city's or surrounding areas; Philadelphia, Boca Raton, NYC, Chicago, Tampa, San Diego, Atlanta, and/or Dallas - If local to ATL
they would like some flexibility in this person coming onsite
Pay: $67.33/hr w2 MAX rate- w2 only for conversion
Hours: Expectation is to work EST times, busiest is in the morning some meetings start 8.30am EST.
Type: Contract
Length: 9-months; possibility to extend
Screenings: tech prior to submission, full panel drug and background once hired
IV process: 1 screen with swoon- client 2 steps (first with hiring manager, second is onsite with the team)
MUST HAVES:
10+ years of software engineering experience across the full development lifecycle, including Tech Lead roles.
Experience designing and operating CI/CD, build, or developer platform capability adopted at scale across multiple development teams.
Experience in Linux environments; Windows exposure preferred.
Experience delivering in regulated environments with audit and evidence obligations.
Experience in a shared-services or centralized delivery model supporting multiple application teams with competing priorities.
Required Technical Experience
Track record driving adoption of engineering standards across teams outside direct reporting lines.
Container build systems, including base images, multi-stage builds, minimal and hardened images, and the runtime impacts of adoption.
Vulnerability management, including interpreting scanner findings, exploitability and reachability assessment, prioritization, compensating controls, and exception documentation.
Working proficiency in Java, .NET, and Python sufficient to specify and review code changes.
Test strategy for request-serving services and for batch and pipeline workloads, including output-correctness verification.
Cloud platform depth in AWS or Azure.
CI/CD tooling and pipeline automation, such as Jenkins, GitHub Actions, GitLab, or equivalent.
Infrastructure as code, such as Terraform, Ansible, or equivalent.
Desired Knowledge and Experience
Programmatic extraction of inventory, dependency, and configuration data from codebases at scale.
Policy as code.
Software supply chain controls, including SBOM generation, build provenance, and artifact signing.
Secure base image providers, cloud security posture management, or equivalent platforms.
Excellent verbal and written communication, with the ability to convey technical detail to audiences at varying technical levels.
Responsibilities
We are seeking a Tech Lead to define and deliver the application security standards used across the BC2 remediation program within Data Engineering.
This is a centralized role that translates InfoSec control requirements into executable engineering specifications, establishes hardened reference implementations for each application type in the estate, and validates remediation prior to production implementation.
The role works alongside remediation engineers who execute against those standards, and partners with Information Security, Platform Engineering, application development teams, and operational support. Application owners retain sign-off and risk acceptance for their own systems.
Duties
Translate InfoSec control requirements into scoped, assignable engineering work with defined acceptance criteria and audit evidence.
Create and maintain well-defined development tickets with clear requirements and measurable outcomes, enabling effective tracking of developer progress, delivery, and performance
. Classify the application estate into a small number of types, based on build and runtime characteristics, and maintain that classification as the estate changes.
Establish, or specify for others to build, the tooling, environments, and pipeline capability required to deliver and validate standards at scale.
Design, build, and maintain a hardened reference implementation for each type, covering approved base images, required security controls, verification, and evidence generation.
Define migration paths for end-of-life runtimes and frameworks and identify workloads where retirement or replacement is lower cost than remediation.
Analyze scan findings and exception requests to determine exploitability, identify false positives, and specify compensating controls where remediation is not viable, including applications where source changes are not possible.
Define acceptance criteria and rollback procedures with the accountable application owner prior to production implementation, escalating where ownership is unresolved.
Ensure remediation evidence is generated by the build rather than assembled manually.
Provide technical direction to remediation engineers executing against published standards.
Produce standards documentation, migration procedures, developer guidance, and remediation evidence.
Seniority Level
Mid-Senior level
Employment Type
Similar jobs
- QP
Front Office Receptionist - Hurricane WV
NewQualDerm Partners
Hurricane, West Virginia🇺🇸On-site14 hours agoEMRSchedulingAdministrative - FP
Administrative Assistant - Property Management
NewF&F Properties
San Diego, California🇺🇸On-site10 hours agoMicrosoft OfficeAdministrative - TM
Community Administrator/Assistant Manager
NewTaylor Management
Fair Lawn, New Jersey🇺🇸On-site10 hours agoAdministrative - LC
Procurement Manager
NewLV Collective
Austin, Texas🇺🇸On-site11 hours agoBudgetingComplianceProcurement+3Administrative - KA
Office Manager
NewKayne Anderson Capital Advisors
Boca Raton, Florida🇺🇸On-site12 hours agoEmployee EngagementHVACOffice Management+1Administrative - IT
Procurement Specialist
NewITAC
Chester, Virginia🇺🇸$60k - $68k/yrOn-site12 hours agoMicrosoft OfficeAdministrative