1

Director Isa Security Jobs (NOW HIRING)

Direct Static and Dynamic Application Security Testing (SAST/DAST), vulnerability assessments, and ... Agreements (ISA), security playbooks, and incident response in accordance with current ...

Lead Security Engineer

Suitland, MD · On-site

$120K - $190K/yr

Direct Static and Dynamic Application Security Testing (SAST/DAST) , vulnerability assessments, and ... Agreements (ISA) , security playbooks, and incident response in accordance with current ...

Lead Security Engineer

Suitland, MD · On-site

$120K - $190K/yr

Direct Static and Dynamic Application Security Testing (SAST/DAST) , vulnerability assessments, and ... Agreements (ISA) , security playbooks, and incident response in accordance with current ...

Direct Static and Dynamic Application Security Testing (SAST/DAST) , vulnerability assessments, and ... Agreements (ISA) , security playbooks, and incident response in accordance with current ...

Direct Static and Dynamic Application Security Testing (SAST/DAST) , vulnerability assessments, and ... Agreements (ISA) , security playbooks, and incident response in accordance with current ...

Direct Static and Dynamic Application Security Testing (SAST/DAST) , vulnerability assessments, and ... Agreements (ISA) , security playbooks, and incident response in accordance with current ...

Lead Security Engineer

Suitland, MD · On-site

$120K - $190K/yr

Direct Static and Dynamic Application Security Testing (SAST/DAST) , vulnerability assessments, and ... Agreements (ISA) , security playbooks, and incident response in accordance with current ...

Direct Static and Dynamic Application Security Testing (SAST/DAST) , vulnerability assessments, and ... Agreements (ISA) , security playbooks, and incident response in accordance with current ...

Direct Static and Dynamic Application Security Testing (SAST/DAST) , vulnerability assessments, and ... Agreements (ISA) , security playbooks, and incident response in accordance with current ...

Overview The Senior Director of Operational Technology (OT) Security is a strategic executive ... Security Architecture * Provide executive leadership for: * Purdue Model architecture * ISA/IEC ...

Overview The Senior Director of Operational Technology (OT) Security is a strategic executive ... Security Architecture * Provide executive leadership for: * Purdue Model architecture * ISA/IEC ...

Overview The Senior Director of Operational Technology (OT) Security is a strategic executive ... Security Architecture * Provide executive leadership for: * Purdue Model architecture * ISA/IEC ...

next page

Showing results 1-20

Director Isa Security information

See salary details

$37K

$104.5K

$167K

How much do director isa security jobs pay per year?

As of Jul 27, 2026, the average yearly pay for director isa security in the United States is $104,452.00, according to ZipRecruiter salary data. Most workers in this role earn between $85,000.00 and $117,500.00 per year, depending on experience, location, and employer.
What cities are hiring for Director Isa Security jobs? Cities with the most Director Isa Security job openings:
What are the most commonly searched types of Isa Security jobs? The most popular types of Isa Security jobs are:
What states have the most Director Isa Security jobs? States with the most job openings for Director Isa Security jobs include:
Infographic showing various Director Isa Security job openings in the United States as of July 2026, with employment types broken down into 1% As Needed, 84% Full Time, 12% Part Time, 1% Temporary, and 2% Contract. Highlights an 92% Physical, 3% Hybrid, and 5% Remote job distribution, with an average salary of $104,452 per year, or $50.2 per hour.
Lead Security Engineer

Lead Security Engineer

InstantServe LLC

Suitland, MD • On-site

Full-time

Posted 8 days ago


Job description

Job Summary
We are seeking a Subject Matter Expert (SME)-level Lead Security Engineer to lead application security across a large-scale, cloud-native federal modernization program supporting the U.S. Census Bureau's Decennial Transformation and Application Modernization (DTAM) effort. This role provides technical and management leadership on major security tasks, embedding security into every phase of the System Development Life Cycle (SDLC) using a DevSecOps methodology. The ideal candidate will architect and enforce Zero Trust principles, drive Authorization to Operate (ATO) activities, and direct application security testing, threat modeling, and vulnerability remediation across a System of Systems (SoS). This position interfaces with senior Government stakeholders and the Office of Information Security (OIS), and decision-making and domain knowledge may have a critical impact on overall program implementation. May supervise others.
Responsibilities
  • Lead the design and implementation of application security solutions, frameworks, and processes across all phases of the SDLC, in compliance with U.S. Census Bureau (USCB) and Office of Information Security (OIS) policies
  • Implement Zero Trust (ZT) principles for applications, workloads, and data, aligned with EO 14028, OMB M-22-09, and NIST SP 800-207 (Zero Trust Architecture)
  • Integrate security into DevSecOps CI/CD pipelines, establishing security gates, automated code inspection, and supply-chain controls including Software Bill of Materials (SBOM) generation
  • Direct Static and Dynamic Application Security Testing (SAST/DAST), vulnerability assessments, and penetration testing to identify, triage, and remediate security weaknesses
  • Lead threat modeling exercises to analyze application architecture, identify attack vectors, and document mitigation strategies throughout design, development, testing, and deployment
  • Support the Authorization to Operate (ATO) process, including security control assessment, artifact and evidence collection, Privacy Threshold Analysis/Privacy Impact Assessment support, and Plan of Action and Milestones (POA&M) management
  • Implement security controls in accordance with the NIST Cybersecurity Framework and NIST SP 800-53, and remediate identified vulnerability and compliance findings
  • Design and implement secure architecture patterns - secure API design, authentication/authorization, input validation, encryption, secure logging and monitoring (SIEM), and secure error/session/configuration management
  • Develop and maintain metrics, dashboards, and reporting to track application security posture, threat trends, and remediation progress over time
  • Support the development and management of Interagency Security Agreements (ISA), security playbooks, and incident response in accordance with current cybersecurity policies
  • Collaborate with application developers, data engineers, systems engineers, and OIS to identify and mitigate vulnerabilities, and provide expert security consultation to development teams
  • Assist in FedRAMP certification activities and the assessment/remediation of independent penetration testing results, as applicable

Education and Experience
  • Bachelor's degree in Information Technology, Computer Science, Cybersecurity, or a related field
  • 15+ years of relevant IT/cybersecurity experience, providing technical and management leadership on major tasks or technology assignments (SME level)

Certifications
Required:
  • Certified Information Systems Security Professional (CISSP)
  • Certified Cloud Security Professional (CCSP)

Desired:
  • Certified Information Security Manager (CISM)
  • Certified Information Systems Auditor (CISA)

Required Skills
  • Demonstrated expertise integrating security into a DevSecOps SDLC, including CI/CD security gates and automated security testing
  • Hands-on experience implementing Zero Trust Architecture and applying NIST SP 800-53 controls and the NIST Cybersecurity Framework
  • Proven experience leading vulnerability assessments, penetration testing, and threat modeling for enterprise applications
  • Experience supporting the ATO lifecycle and managing POA&Ms, security artifacts, and evidence collection

Desired Skills
  • Experience generating Software Bill of Materials (SBOMs) and implementing software supply-chain security controls
  • Familiarity with SIEM deployment, container/image hardening, and secure baseline configuration
  • Experience in large-scale, multi-cloud federal environments and FedRAMP processes
  • Strong analytical, problem-solving, written, and verbal communication skills, including the ability to brief senior Government stakeholders

InstantServe logo

About InstantServe

Sourced by ZipRecruiter

InstantServe provides a one-stop solution to all Healthcare, IT/Non-IT Staffing needs. Established in 2016, InstantServe is a strong workforce of over 100+ go-getters with a demonstrated background in IT/Non-IT service. We are a nationally certified SBE from the Department of Administration (State of PA). As a proud Minority Woman Owned Small Business Enterprise (M/WBE), InstantServe boasts of a strong team of professionals who have extensive experience catering to several Federal, Public, Commercial, and Healthcare Clients which includes 26 States and 46 government agencies. InstantServe is a client-centric organization that offers cost-effective and reliable solutions. Client satisfaction is sacrosanct! Our team strives to provide the best staffing and IT solutions to take your business to the next level.

Industry

Recruiting and staffing services

Company size

11 - 50 Employees

Headquarters location

Wayne, PA, US

Year founded

2016

Social media