The CDC National Healthcare Safety Network (NHSN) is seeking a Cybersecurity Engineer to support the modernization of one of the nation's largest public health surveillance platforms. This role will serve as the program's primary cybersecurity engineering resource, embedding security throughout the software development lifecycle while supporting NHSN's migration to modern cloud-native technologies, including Microsoft Azure, Databricks, and AI-assisted software engineering.
Working closely with software engineers, cloud engineers, data engineers, solution architects, and technical leadership, the Cybersecurity Engineer will implement secure engineering practices across applications, APIs, cloud infrastructure, data platforms, and DevSecOps pipelines. This position focuses on hands-on engineering, application security, cloud implementation, and data protection while working closely with CDC's Office of the Chief Information Officer (OCIO), Cybersecurity Program Office (CSPO), Office of Managed Hosting Services (OMHS), and Microsoft Azure enterprise security services to ensure the NHSN modernization effort aligns with
CDC's enterprise cybersecurity strategy, architecture, policies, standards, and operational processes.
The ideal candidate combines strong software engineering skills with practical cybersecurity expertise and enjoys building secure, scalable, cloud-native solutions that support CDC's public health mission.
Key Responsibilities
Secure Software Engineering
- Integrate cybersecurity throughout the Software Development Lifecycle (SDLC).
- Implement secure coding practices, application hardening, and secure design principles across NHSN applications.
- Perform application security reviews, vulnerability analysis, and remediation activities.
- Support secure implementation of authentication, authorization, API security, encryption, and secrets management.
- Partner with software engineers to resolve security findings and improve application resiliency.
Cloud Security Engineering
- Implement security controls within NHSN's Microsoft Azure environment.
- Support secure deployment and configuration of Azure App Services, Azure Container Apps, Azure Kubernetes Service (AKS), Azure SQL, Azure Storage, and related Azure services.
- Assist with cloud resource hardening, identity integration, logging, monitoring, and secure configuration management.
- Collaborate with cloud engineering teams to implement Zero Trust principles and secure Infrastructure-as-Code (IaC) practices.
Data Platform Security
- Implement security controls supporting NHSN's migration from SAS to Databricks.
- Secure Azure Databricks workspaces, Delta Lake storage, Azure SQL, and enterprise data pipelines.
- Support secure ingestion, transformation, storage, and processing of sensitive public health data.
- Implement encryption, access controls, auditing, and monitoring to protect NHSN data assets.
DevSecOps
- Integrate automated security testing into Azure DevOps CI/CD pipelines.
- Implement source code scanning, dependency analysis, container image scanning, Infrastructure-as-Code validation, and security automation.
- Support continuous vulnerability management and remediation throughout the software delivery lifecycle.
- Promote secure engineering practices across development teams.
Application & Integration Security
- Support secure integration with CDC enterprise services, including Secure Access Management Services (SAMS).
- Implement secure authentication and authorization for NHSN applications, APIs, and cloud services.
- Support secure transmission and ingestion of healthcare data through NHSNLink, FHIR-based interfaces, and other enterprise integration services.
- Coordinate and execute penetration testing, security validation, and remediation of application and infrastructure vulnerabilities.
Collaboration & Compliance
- Work closely with CDC's enterprise cybersecurity organizations to ensure NHSN solutions comply with enterprise security policies, standards, and compliance requirements.
- Support implementation of security controls required for CDC cloud environments and application deployments.
- Participate in architecture reviews, security assessments, and technical planning activities as needed.
- Assist engineering teams in evaluating and securely implementing emerging technologies, including AI-assisted software development and automation.
Required Qualifications:
- Bachelor's degree in Computer Science, Cybersecurity, Software Engineering, Information Technology, or a related discipline.
- Eight (8) or more years of experience in cybersecurity engineering, application security, cloud security, DevSecOps, or secure software engineering.
- Experience implementing security controls within Microsoft Azure cloud environments.
- Experience supporting secure software development using Java, C#, Python, or other modern programming languages.
- Experience with Azure DevOps, Git, CI/CD pipelines, and modern software engineering practices.
- Experience securing cloud-native applications, REST APIs, containers, or distributed systems.
- Experience performing vulnerability assessments, application security testing, and remediation activities.
- Working knowledge of authentication, authorization, encryption, identity management, and API security.
- Strong communication and collaboration skills with cross-functional engineering teams.
Preferred Qualifications:
- Experience with Azure Kubernetes Service (AKS), Azure Container Apps, Azure SQL, Azure Storage, Azure Key Vault, Microsoft Defender, and Azure Monitor.
- Experience securing Azure Databricks, Delta Lake, Azure Data Factory, or enterprise data platforms.
- Experience implementing DevSecOps practices and automated security testing.
- Experience supporting healthcare, public health, or other regulated data environments.
- Experience with FHIR, HL7, healthcare APIs, or secure healthcare data exchange.
- Familiarity with NIST Cybersecurity Framework (CSF), NIST SP 800-53, FISMA, FedRAMP, Zero Trust, and secure cloud engineering principles.
- Security certifications such as Security+, CISSP, CCSP, Microsoft Certified: Azure Security Engineer Associate, GIAC, or equivalent.
Desired Characteristics
The successful candidate will possess:
- Strong hands-on engineering and problem-solving skills.
- A practical approach to implementing cybersecurity within modern software development environments.
- Experience working collaboratively with software developers, cloud engineers, and data engineers.
- A passion for automation, DevSecOps, and cloud-native engineering.
- The ability to balance security, performance, scalability, and maintainability.
- Strong analytical, communication, and collaboration skills.
- A commitment to continuously improving secure engineering practices.
If you're looking for comfort, keep scrolling. At Leidos, we outthink, outbuild, and outpace the status quo — because the mission demands it. We're not hiring followers. We're recruiting the ones who disrupt, provoke, and refuse to fail. Step 10 is ancient history. We're already at step 30 — and moving faster than anyone else dares.
Original Posting:July 21, 2026For U.S. Positions: While subject to change based on business needs, Leidos reasonably anticipates that this job requisition will remain open for at least 3 days with an anticipated close date of no earlier than 3 days after the original posting date as listed above.
The Leidos pay range for this job level is a general guideline only and not a guarantee of compensation or salary. Additional factors considered in extending an offer include (but are not limited to) responsibilities of the job, education, experience, knowledge, skills, and abilities, as well as internal equity, alignment with market data, applicable bargaining agreement (if any), or other law.
Skills Required
- Bachelor's degree in Computer Science, Cybersecurity, Software Engineering, Information Technology, or related discipline.
- Eight (8) or more years of experience in cybersecurity engineering, application security, cloud security, DevSecOps, or secure software engineering.
- Experience implementing security controls within Microsoft Azure cloud environments.
- Experience supporting secure software development using Java, C#, Python, or other modern programming languages.
- Experience with Azure DevOps, Git, and CI/CD pipelines.
- Experience securing cloud-native applications, REST APIs, containers, or distributed systems.
- Experience performing vulnerability assessments, application security testing, and remediation activities.
- Working knowledge of authentication, authorization, encryption, identity management, and API security.
- Strong communication and collaboration skills with cross-functional engineering teams.
Leidos Compensation & Benefits Highlights
The following summarizes recurring compensation and benefits themes identified from responses generated by popular LLMs to common candidate questions about Leidos and has not been reviewed or approved by Leidos.
-
Healthcare Strength — Healthcare coverage is described as comprehensive, with multiple plan options, low office-visit copays in some plans, and access to mental health and wellness support tools. The availability of HSA/FSA options and employer contributions is positioned as a meaningful part of the total package.
-
Retirement Support — Retirement benefits are framed as a strong component of total rewards, highlighted by a 401(k) match and immediate vesting in the standard package. The Employee Stock Purchase Plan is also presented as an additional long-term wealth-building feature.
-
Wellbeing & Lifestyle Benefits — Wellbeing and lifestyle supports extend beyond core insurance, including wellness programs, fitness-related stipends, and assistance resources. Work flexibility and related perks are also included as part of the broader rewards experience.
Leidos Insights
What We Do
We Are Leidos For 50 years we have been tackling some of the biggest problems that face our nation and our world. OUR MISSION Through our culture of innovation and history of performance, we develop deep customer trust built on integrity and create enduring solutions that improve our world. Leidos is a science and technology solutions leader working to address some of the world’s toughest challenges in the defense, intelligence, homeland security, civil, and healthcare markets. The company’s 43,000 employees support vital missions for government and commercial customers. Headquartered in Reston, Va., Leidos reported annual revenues of approximately $11.09 billion for the fiscal year ended January 3, 2020. Leidos was cited for the meaningful work employees perform that is challenging, impactful, and aligned with our customers’ missions as reasons professionals want to work and stay at our company. Leidos has also been named to lists including Forbes’ Best Employers for Diversity, Forbes’ America’s Best Employers for Women, Military Times Best for Vets Employers, and Ethisphere Institute’s World's Most Ethical Companies®. Employees enjoy career enrichment opportunities available through mobility and development and experience rewarding relationships with supportive supervisors and talented colleagues and customers. Employees appreciate our flexible work environment, allowing for and encouraging a true work-life balance. Our professionals are also excited about our Employee Resource Groups, like the newly launched Collaborative Outreach with Remote and Embedded Employees (CORE), which strives to create an environment where every employee, regardless of location, feels fully engaged as a valued employee of Leidos. Your most important work is ahead.









