Senior Security Engineer, Federal

ArmadaBellevue, WA
$157,596 - $196,995Onsite

About The Position

Armada is seeking a Senior Security Engineer, Federal to own and drive security engineering strategy across their Azure cloud, hybrid infrastructure, and edge computing platform. This is a senior, hands-on role where you will set direction for detection engineering, application security testing, Kubernetes hardening, and CI/CD controls, while also advising other engineers and teams on complex security decisions. You will also help define the strategic approach to securing AI/ML workloads running at the edge. This role is office-based in Bellevue, Washington.

Requirements

  • Bachelor's degree in Computer Science, Cybersecurity, or a related field and 8+ years of experience; or Master's degree and 6+ years; or equivalent practical experience.
  • 8+ years in information security, including 5+ years focused on cloud security.
  • Deep, hands-on expertise with Azure security services including Defender for Cloud, Sentinel, Entra ID, Key Vault, Azure Policy, and network security.
  • Production experience across multiple of: SIEM, EDR/XDR, WAF, email security, CSPM/CNAPP, vulnerability management, with the judgment to adapt tooling strategy as needs evolve.
  • Proven experience securing Kubernetes and containerized workloads in production at scale.
  • Experience embedding security testing into CI/CD pipelines using SAST, DAST, SCA, secrets scanning, and IaC scanning.
  • Advanced application security testing experience covering web and API penetration testing and secure code review.
  • Proficiency with vulnerability management platforms such as Nessus, Nexpose, Qualys, or Defender Vulnerability Management.
  • Python and SQL/KQL for automation, tooling, and log analysis.
  • Strong working knowledge of NIST, ISO 27001, and SOC 2, with experience applying them to real audit and compliance cycles.
  • Experience leading incident response as the primary or senior responder on complex, high-stakes incidents.
  • Demonstrated experience advising or mentoring other engineers on security best practices.
  • U.S. Citizenship required.

Nice To Haves

  • Experience securing edge, disconnected, or intermittently connected environments.
  • Experience securing AI/ML or LLM-based systems, including OWASP Top 10 for LLM Applications and MITRE ATLAS.
  • Advanced detection engineering experience: writing and tuning KQL, detection-as-code, purple team exercises.
  • Infrastructure-as-code fluency with Terraform or Bicep.
  • Familiarity with MITRE ATT&CK for threat modeling and detection coverage mapping.
  • Experience leading or supporting SOC 2 Type II or FedRAMP audit cycles.
  • At least one from either group is preferred: CISSP, CCSP, Azure Security Engineer Associate (AZ-500), GCIH, GCIA, OSCP, OSWE, OSWP, OSEE, GPEN, GWAPT, CEH.

Responsibilities

  • Own and evolve security architecture strategy across Azure, hybrid infrastructure, and edge deployments, guiding design decisions across teams.
  • Direct the use of SIEM (Microsoft Sentinel), EDR/XDR, WAF, email security, and CSPM/CNAPP tooling, adapting approach as the environment evolves.
  • Design detection rules, correlation logic, and automated response playbooks, and guide others in building their own.
  • Lead incident response end-to-end, from triage through containment and remediation, serving as the senior escalation point for complex incidents.
  • Lead security assessments, vulnerability scanning, and penetration testing across cloud, infrastructure, and application layers.
  • Test web applications and APIs for authentication and authorization flaws, business logic abuse, and OWASP Top 10 issues.
  • Threat model new services and architectures before they ship, advising engineering teams on risk tradeoffs.
  • Own the vulnerability lifecycle end-to-end: risk-based prioritization, SLA tracking, and remediation follow-through, holding owning teams accountable.
  • Direct the integration of SAST, DAST, SCA, secrets scanning, IaC scanning, and container image scanning into CI/CD as automated gates.
  • Harden the software supply chain: build provenance, artifact signing, SBOM generation, dependency governance.
  • Define and enforce guardrails as policy-as-code using Azure Policy, OPA/Gatekeeper, or Kyverno.
  • Serve as a senior security reviewer for designs and code across engineering teams, influencing secure deployment practices org-wide.
  • Define and lead the approach to securing AI/ML development and deployment, including model and data supply chain integrity, inference endpoint exposure, prompt injection and agentic tool abuse, and training data governance.
  • Own security policies, standards, and procedures aligned to NIST, ISO 27001, and SOC 2, and drive their adoption across teams.
  • Produce audit evidence and lead customer security assessments.
  • Track emerging threats and translate them into roadmap priorities, advising leadership on risk.

Benefits

  • Competitive base salary and equity
  • Medical, dental, and vision (subsidized cost)
  • Health savings accounts (HSA), flexible spending accounts (FSA), and dependent care FSAs (DCFSA)
  • Retirement plan options, including 401(k) and Roth 401(k)
  • Unlimited paid time off (PTO)
  • 14 paid company holidays per year
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service