Defense Unicorns

Cybersecurity Engineer

Remote US
USD 185k - 246k
Kubernetes AWS GCP Azure Terraform
Description

EMPLOYER IS A CONTRACTOR FOR THE U.S. GOVERNMENT. THIS POSITION WILL REQUIRE U.S. CITIZENSHIP.

Role Description: 

As the cybersecurity lead for our Space Launch efforts, you will be responsible for owning all aspects of the RMF process from accreditation of the platform to establishing a cATO for our Software Factory implementation.  You will be expected to champion modern, continuous security implementations within DoD environments and systems (approval processes).  Your perpetual goal will be to accelerate the ATO process while simultaneously improving our security posture, thus pushing for cultural change away from security theater and towards responsive and resilient systems.  While working within the existing DoD processes, you will also work with other 🦄 engineers to find the best paths forward and even contribute to 🦄 capabilities and open source solutions to further streamline ongoing and future efforts.

Responsibilities: 

  • Leading and pathfinding the effort to achieve accreditation in accordance with NIST-800 series requirements.
  • Developing and implementing cybersecurity policies, procedures, and controls necessary to meet DoD accreditation standards.
  • Conducting comprehensive risk assessments and vulnerability analyses to identify potential security threats and mitigate risks.
  • Collaborating with cross-functional teams including software developers, system architects, and other Government stakeholders to integrate cybersecurity measures into the software development lifecycle.
  • Performing security testing and evaluation of our software platform to identify vulnerabilities and weaknesses (STIGs, ACAS, CI/CD security testing, etc.)
  • Providing guidance and support to ensure continuous monitoring and maintenance of cybersecurity controls.
  • Preparing and maintaining documentation required for the accreditation process, including System Security Plans (SSPs), Security Assessment Reports (SARs), and other relevant artifacts.
  • Staying up-to-date with evolving cybersecurity threats, technologies, and regulations to proactively address security challenges and compliance requirements.
  • Serving as a subject matter expert on cybersecurity best practices, standards, and procedures within the organization.
  • Supporting automated Compliance-as-Code capabilities that continuously evaluate the cybersecurity posture of the tech stack.

The listed responsibilities are not exhaustive and additional responsibilities may be assigned based on the evolving needs of the organization. We are seeking a dynamic individual who is able to adapt and take on new responsibilities as they arise. 

Preferred Experience and Qualifications:

  • Proven experience in cybersecurity engineering, with a focus on achieving accreditation for software systems within the DoD environment.
  • In-depth knowledge of NIST-800 series standards, particularly NIST-800-53, and experience applying these standards to achieve accreditation.
  • Skilled at translating technical implementation (infrastructure as code and configuration as code) into verifiable eMASS security control responses that Approving Officials (AOs), and their staffs, can understand.
  • Strong understanding of cybersecurity principles, technologies, and best practices, including encryption, authentication, access control, and secure coding practices.
  • Hands-on experience with security assessment tools and techniques, such as vulnerability scanning and security analysis.
  • Familiarity with software development methodologies and practices, particularly Agile and DevSecOps.
  • Excellent analytical and problem-solving skills, with the ability to assess complex systems and identify security risks.
  • Effective communication and interpersonal skills, with the ability to collaborate with cross-functional teams and communicate technical concepts to non-technical stakeholders.
  • Eligibility to obtain and maintain a DoD security clearance.
  • Eligibility to obtain and maintain privileged access in a Government Cloud Environment (relevant training and/or certifications).

Desired Experience:

  • Experience building and supporting continuous authority to operate (cATO) packages within the DoD
  • Experience with Open Security Controls Assessment Language (OSCAL)
  • Ability to use OSCAL to manage control implementation and statements as “compliance as code”
  • Understand how products and deployments affect the OSCAL lifecycle from upstream to operations
  • Familiarity with Department of the Air Force (DAF) security approval processes to include AFI 17-101
  • Familiarity with DAF Gov Cloud offerings and inherited controls in Gov Cloud environments
  • Familiarity with the Cloud Computing Security Requirements Guide (CC SRG)
  • Experience working in a remote team or asynchronous work environment where focus, discipline, and comfort navigating/leveraging various communication forms and frequencies to disseminate and prioritize information and keep stakeholders informed 

Full compensation packages are based on candidate experience. Compensation ranges are established using national benchmarking data and apply across all geographic locations within the United States. 

Remote - USA
$185,000$246,000 USD

Who We Are: Defense Unicorns delivers mission value by streamlining software delivery so our customers can focus on the most important challenges. We share a vision of freedom and security for the advancement of progress and innovation. Our commitment to this vision, and to our mission-driven customers, means a commitment to speed, user experience and optionality, without compromising security. Our team is composed of innovators, software engineers, and veterans with decades of experience delivering technology programs across the federal market.

What We Do: We create and deliver secure solutions for continuous software integration and delivery. Defense Unicorns consolidates the best practices for security pipelines, testing, and deployment automation in order to meet the high security requirements valued by mission owners. Our solutions are agnostic by design and we believe that growing a robust ecosystem of secure, cloud-native software solutions can help enterprise customers inside and outside the federal market buy and integrate software more easily.

Who We Serve: Defense Unicorns’ customers are mission-focused leaders across public and private enterprises. We proudly support defense and civil agencies across the U.S. government and we work closely with the creators of leading-edge software solutions to deliver value to the mission-owner by improving the security and consumability of commercial software products.

What We Work On:

  • Kubernetes
  • Cloud Environments (AWS/GCP and Azure)
  • Infrastructure-as-code (like Terraform/Pulumi)
  • Continuous Delivery and automation tooling
  • GitOps
  • Containers
  • CNCF projects and open source products and packages
  • Helm/Kustomize-Value Stream Mapping
  • Building and improving security delivery
  • Building Kubernetes and cloud native applications

Benefits Our Unicorns Enjoy:

Health:

  • Medical/Dental/Vision
  • Premiums are 100% Company Paid
  • Health Reimbursement Account
  • Life Insurance
  • Disability Insurance

Financial:

  • 401k with Employer Contribution (Regardless of Employee Contribution)
  • Company Stock Options
  • Home Office Setup Budget

Leave:

  • Unlimited paid time off, with a mandatory 10 days off on top of 11 federal government holidays, week of Thanksgiving, last two weeks of December (including New Year’s Day)
  • Paid Parental Leave

Learning:

  • Reimbursement for approved trainings/subscriptions
  • Conferences (travel, lodging, and fees)

Defense Unicorns is an equal opportunity employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, disability, sex, sexual orientation, gender identity or expression, age, national origin, veteran status, genetic information, union status and/or beliefs, or any other characteristic protected by federal, state, or local law.

CCPA DISCLOSURE

There are more than 50,000 engineering jobs:

Subscribe to membership and unlock all jobs

Engineering Jobs

50,000+ jobs from 4,500+ well-funded companies

Updated Daily

New jobs are added every day as companies post them

Refined Search

Use filters like skill, location, etc to narrow results

Become a member

🥳🥳🥳 223 happy customers and counting...

Overall, over 80% of customers chose to renew their subscriptions after the initial sign-up.

Cancel anytime / Money-back guarantee

Wall of love from fellow engineers