Senior DevSecOps Cybersecurity Engineer
$149,000–$186,000 year
HybridColorado Springs, Colorado, United States or El Segundo, California, United States
Job Summary
Lead cybersecurity engineering efforts for DevSecOps software delivery, evaluating architectures and deployment pipelines for DoD and Air Force compliance. Execute Risk Management Framework (RMF) activities across development and production environments, managing NIST 800-53 controls and ATO authorization packages. Analyze CVEs, develop mitigation strategies and Plans of Action and Milestones, and communicate risk-based explanations to government stakeholders and leadership. Validate cybersecurity readiness prior to secure software releases into IL5 and IL6 production environments while supporting Agile ceremonies and technical working groups.
Required Qualifications
- Able to obtain and maintain a DoD Secret clearance
- Bachelor's degree in engineering, computer science, information systems, cybersecurity or related technical field
- 7+ years of cybersecurity, information assurance, DevSecOps, system security engineering, or related defense experience
- Extensive experience implementing and supporting the Risk Management Framework (RMF)
- Strong understanding of NIST 800-53 security controls and DoD cybersecurity policies
- Demonstrated experience evaluating, explaining, mitigating, and remediating Common Vulnerabilities and Exposures (CVEs)
- Experience supporting software deployments within accredited government production environments
- Strong understanding of IL5 and IL6 cloud environments and associated cybersecurity requirements
- Experience supporting ATO and continuous monitoring activities
- Experience working directly with government cybersecurity organizations and mission stakeholders
- Ability to communicate technical cybersecurity issues to both technical and executive audiences
- Strong written communication skills supporting cybersecurity documentation, risk acceptance packages, and authorization artifacts
- Location: El Segundo, CA or Colorado Springs, CO (work-from-home flexibility with on-site support as required)
- Minimal travel
Desired Qualifications
- Active DoD Secret clearance or higher
- Master's degree in engineering, computer science, information systems, cybersecurity or related technical field
- Experience supporting Space Systems Command (SSC), Space Operations Command (SpOC), U.S. Space Force, or other DoD space organizations
- Experience supporting operational systems accredited under RMF within classified environments
- Familiarity with Platform One, Cloud One, Kubernetes, Iron Bank, Big Bang, and related DoD DevSecOps ecosystems
- Experience supporting Authority to Operate (ATO) and Continuous Authorization to Operate (cATO) initiatives
- Knowledge of Secure Software Development Framework (SSDF) and modern DevSecOps pipelines
- Experience supporting Cybersecurity Strategies (CSS), Cyber Vulnerability Identification (CVI) events, cybersecurity inspections, and COOP tabletop exercises
- Experience with STIG implementation, SCAP compliance, ACAS, Nessus, Fortify, SonarQube, Snyk, Prisma Cloud, Twistlock, or similar security tooling
- Security certifications such as CISSP, CASP+, Security+, CISM, CCSP, or GIAC certifications
- Experience supporting mission-critical systems deployed in classified cloud environments
- Experience supporting software modernization efforts within U.S. Space Force programs
- Familiarity with SATCOM, space operations, command and control systems, mission planning systems, or enterprise management platforms
- Experience implementing Zero Trust architectures within DoD environments
- Experience balancing mission delivery timelines with cybersecurity compliance requirements in operational production systems
- Experience supporting large-scale software factories or government-managed production environments
Hiring someone like this?
Get your role in front of qualified candidates on Sorce.