Security Engineer - Federal (FieldOps)
Tysons, United States · Full-time
- Posted 1mo ago
- From C3 AI’s careers page
- Location
- Tysons, United States
- Type
- Full-time
- Experience
- 5+ years
- Department
- Engineering
Apply on C3 AI’s site
Opens the listing on c3.ai
Let the right jobs find you
In your inbox every Wednesday and SaturdayPersonalised suggestions from verified career pages, matched to your role, location, level and skills.
About the role
Responsibilities:
- Own per-release gate evidence across the 8 gates defined in the Federal Release-Gate Standard (image CVE disposition, allowlist, SCAP/STIG, FIPS validation, Federal BOM) — no evidence, no GA
- Work with cross-functional teams to build and maintain ConMon automation: generated Bill of Materials (BOM), automated drainable-vs-structural POA&M classification, and a live ConMon metrics feed
- Serve as the engineering-level interface with SMX on FedRAMP boundary-register items (image provenance, patch-uplift vs. CA-6, SCAP scope)
- Address unique Federal customer security requirements without compromising core solution integrity
- Support high-visibility defense and intelligence projects with stringent security requirements
- Triage and resolve security vulnerabilities reported by Federal customers
- Ensure solutions comply with technical security requirements for domain-specific programs (e.g., STIG, SCAP/OpenSCAP)
- Manage hardened container registries (e.g., Iron Bank, Chainguard) for Federal deployments
- Work with product, engineering, and compliance teams to upstream controls and resolve issues
- Overlay customer-specific controls while maintaining C3 AI's standard security posture
- Discover and remediate security vulnerabilities in Federal systems and applications
- Collaborate with Information Security, Product, Engineering, and Operations to implement security best practices and ensure compliance with industry standards
- Stay up-to-date with the latest security trends, vulnerabilities, and technologies
Qualifications:
- Bachelor's degree in Computer Science, Information Security, or a related field
- Minimum of 5+ years of experience in information security, DevSecOps, or a related field
- Strong understanding of security principles, practices, and technologies
- Experience with vulnerability management activities (CVEs, IOCs, etc.)
- Experience with Linux and scripting languages such as JavaScript, Shell, and/or Python
- Excellent problem-solving skills and attention to detail
- Strong communication and collaboration skills
- Active DoD 8570 IAT II or above certification (e.g., CISSP or Security+), or ability to obtain
- Hands-on experience with SCAP/OpenSCAP tooling and automated STIG scanning/remediation
Preferred Qualifications:
- Experience with cloud security and securing cloud-based applications
- Familiarity with regulatory requirements and industry standards such as NIST 800-53, CMMC, and FedRAMP
- Experience with security automation and orchestration tools
- Experience with hardened container registries (e.g., Iron Bank, Chainguard), FIPS 140-2/3 validation, and SBOM generation/traceability tooling
Skills they ask for
Pick one to see other roles that ask for it.
About C3 AI
Enterprise AI software and applicationsC3 AI develops enterprise AI software, including an AI platform and applications for industries such as manufacturing, energy, utilities, healthcare, and defense.
See all 45 roles at C3 AIMore roles at C3 AI
See all 45- Payroll AnalystRedwood City · On-siteFinance and Accounting · On-siteRedwood City, United States1d
- Associate Site Reliability Engineer/Site Reliability EngineerRedwood City · Entry LevelEngineering · Entry LevelRedwood City, United States1d
- Chief Marketing OfficerRedwood City · ExecutiveMarketing · ExecutiveRedwood City, United States3d
- Communications ManagerRedwood CityMarketingRedwood City, United States1w
Share this role
Let the right jobs find you
In your inbox every Wednesday and SaturdayPersonalised suggestions from verified career pages, matched to your role, location, level and skills.