Назад
Company hidden
11 дней назад

Senior DevSecOps Cybersecurity Engineer

Формат работы
remote (только USA)
Тип работы
fulltime
Грейд
senior
Английский
b2
Страна
US
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Senior DevSecOps Cybersecurity Engineer (RMF/CVE/Cloud Security): Enabling secure software delivery into accredited IL5 and IL6 government production environments with an accent on RMF execution, CVE analysis and remediation, and cybersecurity compliance. Focus on validating release readiness, developing risk-based mitigation strategies, maintaining authorization artifacts, and communicating cyber risk to government stakeholders.

Location: Remote, with primary work location associated with Ambridge, Pennsylvania and on-site support as required

Company

hirify.global provides engineering, systems integration, and cybersecurity solutions for national security and U.S. Space Force missions, including military satellite communications programs.

What you will do

  • Lead cybersecurity engineering activities within Agile and DevSecOps software delivery teams.
  • Guide security throughout the software lifecycle, from architecture and development through deployment.
  • Assess CVEs, exploitability, mission impact, remediation options, and risk-based mitigation plans.
  • Support RMF execution, NIST 800-53 control implementation, ATO activities, and continuous monitoring.
  • Validate security readiness for releases into accredited IL5 and IL6 production environments.
  • Coordinate with developers, cloud and infrastructure engineers, ISSMs, Authorizing Officials, mission owners, and government cybersecurity stakeholders.

Requirements

  • Ability to obtain and maintain a DoD Secret clearance.
  • Bachelor’s degree in engineering, computer science, information systems, cybersecurity, or a related technical field.
  • 7+ years of cybersecurity, information assurance, DevSecOps, system security engineering, or related defense experience.
  • Extensive experience with RMF, NIST 800-53 controls, DoD cybersecurity policies, ATO, and continuous monitoring.
  • Experience evaluating, explaining, mitigating, and remediating CVEs in accredited government production environments.
  • Ability to communicate technical cybersecurity risks to technical, executive, and government audiences and produce authorization documentation.

Nice to have

  • Active DoD Secret clearance or higher and experience with classified environments or U.S. Space Force programs.
  • Familiarity with Platform One, Cloud One, Kubernetes, Iron Bank, Big Bang, and DoD DevSecOps ecosystems.
  • Experience with SSDF, cATO, STIGs, SCAP, ACAS, Nessus, Fortify, SonarQube, Snyk, Prisma Cloud, or Twistlock.
  • Security certifications such as CISSP, CASP+, Security+, CISM, CCSP, GIAC, INCOSE CSEP, or ESEP.
  • Experience with Zero Trust, SATCOM, space operations, mission-critical systems, or software modernization.

Culture & Benefits

  • Remote work-from-home flexibility with minimal travel and standard working hours.
  • Collaborative small-team environment focused on national security and space defense missions.
  • Potential 401(k) plan with company match, medical, dental, vision, life insurance, AD&D, flexible spending, disability coverage, and paid time off.
  • Professional training, development, and career advancement opportunities.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →