Назад
Company hidden
6 дней назад

Cybersecurity Consultant (Embedded Systems)

Формат работы
onsite
Тип работы
fulltime
Грейд
senior
Английский
b2
Страна
US
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Cybersecurity Consultant (Embedded Systems): Building security into custom hardware, embedded systems, firmware, operating systems, and application software with an accent on secure boot, software supply-chain security, SBOMs, and DoD security requirements. Focus on mapping DISA STIGs and NIST SP 800-53 controls, analyzing vulnerabilities, and designing pragmatic remediation strategies for resource-constrained defense platforms.

Location: Portsmouth, New Hampshire, United States — on-site; occasional travel between hirify.global facilities and customer locations.

Company

hirify.global develops defense technology, including embedded and soldier-portable systems.

What you will do

  • Partner with hardware and software engineers to implement security-by-design practices across custom hardware, firmware, operating systems, and applications.
  • Map DISA STIGs and SRGs to embedded systems and application software.
  • Establish SBOM processes and track third-party dependencies, open-source software, and software supply-chain vulnerabilities.
  • Review architectures, documentation, and software builds against NIST SP 800-53 Rev. 5 controls.
  • Analyze static code analysis, vulnerability scanning, and SBOM findings, then develop practical remediation strategies with engineers.
  • Support external cybersecurity and compliance stakeholders through system accreditation while balancing security with power, weight, processing, and latency constraints.

Requirements

  • Bachelor’s degree in Cybersecurity, Computer Science, Computer Engineering, or a related technical discipline.
  • 5+ years of experience in system security engineering, cybersecurity consulting, or a related advisory role.
  • Strong knowledge of NIST SP 800-53 Rev. 5 and DISA STIG/SRG implementation.
  • Understanding of federal software supply-chain security requirements, SBOM standards such as SPDX and CycloneDX, and dependency-management tools.
  • Experience or familiarity with Android, embedded Linux, or RTOS environments, plus C/C++ or low-level software development and hardware security principles.
  • Strong communication skills and the ability to translate cybersecurity requirements into actionable engineering guidance.

Nice to have

  • Experience automating SBOM generation and vulnerability scanning in CI/CD pipelines.
  • Experience securing embedded or hardware-focused products.
  • Exposure to DoD Risk Management Framework processes.
  • Experience with tactical, soldier-portable, IoT, or other resource-constrained platforms.
  • Practical experience with TPMs, hardware roots of trust, Secure Boot, and code signing.

Culture & Benefits

  • Collaborative, engineering-focused advisory role working directly alongside hardware and software engineers.
  • Pragmatic approach to meeting security requirements without unnecessary development friction.
  • 40 hours per week, Monday–Friday.
  • Security clearance is not required.
  • Contract position with occasional travel to facilities and customer locations.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →