waypointjobs

C3.ai, Inc.

Security Engineer - Federal (FieldOps)

tysons, VA

Check who can apply and the requirements below before continuing.

About this opportunity

C3.ai, Inc. lists this Security Engineer - Federal (FieldOps) opportunity in tysons, Virginia. Review the employer’s description below for duties, qualifications and application requirements.

Job description

C3 AI (NYSE: AI), is the Enterprise AI application software company. C3 AI delivers a family of fully integrated products including the C3 Agentic AI Platform, an end-to-end platform for developing, deploying, and operating enterprise AI applications, C3 AI applications, a portfolio of industry-specific SaaS enterprise AI applications that enable the digital transformation of organizations globally, and C3 Generative AI, a suite of domain-specific generative AI offerings for the enterprise.Learn more at: C3 AI

C3 AI is seekingan experienced Federal Security Engineer to serve as the named technical owner of release-gate evidence, Continuous Monitoring (ConMon) automation, and the security engineeringinterface with our FedRAMP and ATO boundary partner, for our Federal team in Tysons, Virginia. The ideal candidate will ensure Federal deployments meet C3 AI's rigorous security standards and comply with Federal Security Requirements across the full deployment lifecycle.

This role requires US Citizenship or US Permanent Residence. Active security clearance (Secret or higher) is preferred.

Responsibilities

Own per-release gate evidence across the 8 gates defined in the Federal Release-Gate Standard (image CVE disposition, allowlist, SCAP/STIG, FIPS validation, Federal BOM) - no evidence, no GA

Work with cross-functional teams to build and maintain ConMon automation: generated Bill of Materials (BOM), automated drainable-vs-structural POA&M classification, and a live ConMon metrics feed

Serve as the engineering-level interface with SMX on FedRAMP boundary-register items (image provenance, patch-uplift vs. CA-6, SCAP scope)

Address unique Federal customer security requirements without compromising core solution integrity

Support high-visibility defense and intelligence projects with stringent security requirements

Triage and resolve security vulnerabilities reported by Federal customers

Ensure solutions comply with technical security requirements for domain-specific programs (e.g., STIG, SCAP/OpenSCAP)

Manage hardened container registries (e.g., Iron Bank, Chainguard) for Federal deployments

Work with product, engineering, and compliance teams to upstream controls and resolve issues

Overlay customer-specific controls while maintaining C3 AI's standard security posture

Discover and remediate security vulnerabilities in Federal systems and applications

Collaborate with Information Security, Product, Engineering, and Operations to implement security best practices and ensure compliance with industry standards

Stay up-to-date with the latest security trends, vulnerabilities, and technologies

Qualifications

Bachelor's degree in Computer Science, Information Security, or a related field

Minimum of 5+ years of experience in information security, DevSecOps, or a related field

Strong understanding of security principles, practices, and technologies

Experience with vulnerability management activities (CVEs, IOCs, etc.)

Experience with Linux and scripting languages such as JavaScript, Shell, and/or Python

Excellent problem-solving skills and attention to detail

Strong communication and collaboration skills

Active DoD 8570 IAT II or above certification (e.g., CISSP or Security+), or ability to obtain

Hands‑on experience with SCAP/OpenSCAP tooling and automated STIG scanning/remediation

Preferred Qualifications

Experience with cloud security and securing cloud-based applications

Familiarity with regulatory requirements and industry standards such as NIST 800-53, CMMC, and FedRAMP

Experience with security automation and orchestration tools

Experience with hardened container registries (e.g., Iron Bank, Chainguard), FIPS 140-2/3 validation, and SBOM generation/traceability tooling

Candidates must be authorized to work in the United States without the need for current or future company sponsorship.

C3 AI provides excellent benefits, a competitive compensation package and generous equity plan.

Virginia Base Pay Range

$134,000 — $167,000 USD

C3 AI is proud to be an Equal Opportunity and Affittive Action Employer. We do not discriminate on the basis of any legally protected characteristics, including disabled and veteran status.

#J-18808-Ljbffr

Who can apply

Review the original listing for work authorization, qualifications and employer requirements.

Ready for your next step?Apply on the official website
Apply on WhatJobs ↗

Explore related searches

Current related jobs

SmartRecruiters, Inc.

WhatJobs

Senior Security Solutions Engineer (Pre-Sales)

st. louis, MO

Salary not specified

Check Point is seeking a seasoned pre-sales engineer to partner with the sales team in identifying prospects and showcasing our comprehensive sec…

Last received from source 2026-10-06View job

SmartRecruiters, Inc.

WhatJobs

Security Engineer

st. louis, MO

Salary not specified

At Check Point, what you do matters. Every day, we protect over 100,000 organizations worldwide from increasingly sophisticated cyber and AI-driv…

Last received from source 2026-10-06View job

JCPenney

WhatJobs

Senior Engineer -Creative Marketing

dallas, TX

$147,750.00 /Yr

Senior Engineer, Creative Marketing Role Overview Catalyst Brands is seeking a Senior Engineer, Creative Marketing to help us build platform …

Last received from source 2026-10-06View job

Nextpower LLC, USA

WhatJobs

Product & Supplier Quality Engineer

mesa, AZ

Salary not specified

Product & Supplier Quality Engineer Location: Mesa, AZ with travel Nextpower is seeking a Product & Supplier Quality Engineer to provide techni…

Last received from source 2026-10-06View job