Description
The CDC National Healthcare Safety Network (NHSN) is seeking a Cybersecurity Engineer to support the modernization of one of the nation's largest public health surveillance platforms. This role will serve as the program's primary cybersecurity engineering resource, embedding security throughout the software development lifecycle while supporting NHSN's migration to modern cloud-native technologies, including Microsoft Azure, Databricks, and AI-assisted software engineering.
Working closely with software engineers, cloud engineers, data engineers, solution architects, and technical leadership, the Cybersecurity Engineer will implement secure engineering practices across applications, APIs, cloud infrastructure, data platforms, and DevSecOps pipelines. This position focuses on hands-on engineering, application security, cloud implementation, and data protection while working closely with CDC's Office of the Chief Information Officer (OCIO), Cybersecurity Program Office (CSPO), Office of Managed Hosting Services (OMHS), and Microsoft Azure enterprise security services to ensure the NHSN modernization effort aligns with
CDC's enterprise cybersecurity strategy, architecture, policies, standards, and operational processes.
The ideal candidate combines strong software engineering skills with practical cybersecurity expertise and enjoys building secure, scalable, cloud-native solutions that support CDC's public health mission.
Key Responsibilities
Secure Software Engineering
- Integrate cybersecurity throughout the Software Development Lifecycle (SDLC).
- Implement secure coding practices, application hardening, and secure design principles across NHSN applications.
- Perform application security reviews, vulnerability analysis, and remediation activities.
- Support secure implementation of authentication, authorization, API security, encryption, and secrets management.
- Partner with software engineers to resolve security findings and improve application resiliency.
Cloud Security Engineering
- Implement security controls within NHSN's Microsoft Azure environment.
- Support secure deployment and configuration of Azure App Services, Azure Container Apps, Azure Kubernetes Service (AKS), Azure SQL, Azure Storage, and related Azure services.
- Assist with cloud resource hardening, identity integration, logging, monitoring, and secure configuration management.
- Collaborate with cloud engineering teams to implement Zero Trust principles and secure Infrastructure-as-Code (IaC) practices.
Data Platform Security
- Implement security controls supporting NHSN's migration from SAS to Databricks.
- Secure Azure Databricks workspaces, Delta Lake storage, Azure SQL, and enterprise data pipelines.
- Support secure ingestion, transformation, storage, and processing of sensitive public health data.
- Implement encryption, access controls, auditing, and monitoring to protect NHSN data assets.
DevSecOps
- Integrate automated security testing into Azure DevOps CI/CD pipelines.
- Implement source code scanning, dependency analysis, container image scanning, Infrastructure-as-Code validation, and security automation.
- Support continuous vulnerability management and remediation throughout the software delivery lifecycle.
- Promote secure engineering practices across development teams.
Application & Integration Security
- Support secure integration with CDC enterprise services, including Secure Access Management Services (SAMS).
- Implement secure authentication and authorization for NHSN applications, APIs, and cloud services.
- Support secure transmission and ingestion of healthcare data through NHSNLink, FHIR-based interfaces, and other enterprise integration services.
- Coordinate and execute penetration testing, security validation, and remediation of application and infrastructure vulnerabilities.
Collaboration & Compliance
- Work closely with CDC's enterprise cybersecurity organizations to ensure NHSN solutions comply with enterprise security policies, standards, and compliance requirements.
- Support implementation of security controls required for CDC cloud environments and application deployments.
- Participate in architecture reviews, security assessments, and technical planning activities as needed.
- Assist engineering teams in evaluating and securely implementing emerging technologies, including AI-assisted software development and automation.
Required Qualifications:
- Bachelor's degree in Computer Science, Cybersecurity, Software Engineering, Information Technology, or a related discipline.
- Eight (8) or more years of experience in cybersecurity engineering, application security, cloud security, DevSecOps, or secure software engineering.
- Experience implementing security controls within Microsoft Azure cloud environments.
- Experience supporting secure software development using Java, C#, Python, or other modern programming languages.
- Experience with Azure DevOps, Git, CI/CD pipelines, and modern software engineering practices.
- Experience securing cloud-native applications, REST APIs, containers, or distributed systems.
- Experience performing vulnerability assessments, application security testing, and remediation activities.
- Working knowledge of authentication, authorization, encryption, identity management, and API security.
- Strong communication and collaboration skills with cross-functional engineering teams.
Preferred Qualifications:
- Experience with Azure Kubernetes Service (AKS), Azure Container Apps, Azure SQL, Azure Storage, Azure Key Vault, Microsoft Defender, and Azure Monitor.
- Experience securing Azure Databricks, Delta Lake, Azure Data Factory, or enterprise data platforms.
- Experience implementing DevSecOps practices and automated security testing.
- Experience supporting healthcare, public health, or other regulated data environments.
- Experience with FHIR, HL7, healthcare APIs, or secure healthcare data exchange.
- Familiarity with NIST Cybersecurity Framework (CSF), NIST SP 800-53, FISMA, FedRAMP, Zero Trust, and secure cloud engineering principles.
- Security certifications such as Security+, CISSP, CCSP, Microsoft Certified: Azure Security Engineer Associate, GIAC, or equivalent.
Desired Characteristics
The successful candidate will possess:
- Strong hands-on engineering and problem-solving skills.
- A practical approach to implementing cybersecurity within modern software development environments.
- Experience working collaboratively with software developers, cloud engineers, and data engineers.
- A passion for automation, DevSecOps, and cloud-native engineering.
- The ability to balance security, performance, scalability, and maintainability.
- Strong analytical, communication, and collaboration skills.
- A commitment to continuously improving secure engineering practices.
If you're looking for comfort, keep scrolling. At Leidos, we outthink, outbuild, and outpace the status quo — because the mission demands it. We're not hiring followers. We're recruiting the ones who disrupt, provoke, and refuse to fail. Step 10 is ancient history. We're already at step 30 — and moving faster than anyone else dares.
Original Posting:
July 21, 2026
For U.S. Positions: While subject to change based on business needs, Leidos reasonably anticipates that this job requisition will remain open for at least 3 days with an anticipated close date of no earlier than 3 days after the original posting date as listed above.
Pay Range:
Pay Range $107,900.00 - $195,050.00
The Leidos pay range for this job level is a general guideline only and not a guarantee of compensation or salary. Additional factors considered in extending an offer include (but are not limited to) responsibilities of the job, education, experience, knowledge, skills, and abilities, as well as internal equity, alignment with market data, applicable bargaining agreement (if any), or other law.
About Leidos
Leidos is an industry and technology leader serving government and commercial customers with smarter, more efficient digital and mission innovations. Headquartered in Reston, Virginia, with 47,000 global employees, Leidos reported annual revenues of approximately $16.7 billion for the fiscal year ended January 3, 2025. For more information, visit www.Leidos.com.
Pay and Benefits
Pay and benefits are fundamental to any career decision. That's why we craft compensation packages that reflect the importance of the work we do for our customers. Employment benefits include competitive compensation, Health and Wellness programs, Income Protection, Paid Leave and Retirement. More details are available at www.leidos.com/careers/pay-benefits.
Securing Your Data
Beware of fake employment opportunities using Leidos’ name. Leidos will never ask you to provide payment-related information during any part of the employment application process (i.e., ask you for money), nor will Leidos ever advance money as part of the hiring process (i.e., send you a check or money order before doing any work). Further, Leidos will only communicate with you through emails that are generated by the Leidos.com automated system – never from free commercial services (e.g., Gmail, Yahoo, Hotmail) or via WhatsApp, Telegram, etc. If you received an email purporting to be from Leidos that asks for payment-related information or any other personal information (e.g., about you or your previous employer), and you are concerned about its legitimacy, please make us aware immediately by emailing us at LeidosCareersFraud@leidos.com.
If you believe you are the victim of a scam, contact your local law enforcement and report the incident to the U.S. Federal Trade Commission.
Commitment to Non-Discrimination
All qualified applicants will receive consideration for employment without regard to sex, race, ethnicity, age, national origin, citizenship, religion, physical or mental disability, medical condition, genetic information, pregnancy, family structure, marital status, ancestry, domestic partner status, sexual orientation, gender identity or expression, veteran or military status, or any other basis prohibited by law. Leidos will also consider for employment qualified applicants with criminal histories consistent with relevant laws.
#Remote