Defense Unicorns Logo

Defense Unicorns

Cybersecurity Engineer

Posted 3 Days Ago
Remote
Hiring Remotely in United States
132K-197K Annually
Mid level
Remote
Hiring Remotely in United States
132K-197K Annually
Mid level
Lead and implement RMF process for DoD cybersecurity, develop policies, assess vulnerabilities, collaborate on integrations, and ensure continuous security compliance.
The summary above was generated by AI
EMPLOYER IS A CONTRACTOR FOR THE U.S. GOVERNMENT. THIS POSITION WILL REQUIRE U.S. CITIZENSHIP.

Role Description: 

As a cybersecurity SME within Delivery at Defense Unicorns, you will be responsible for owning all aspects of the RMF process from accreditation of the platform for our mission heroes. You will be expected to champion modern, continuous security implementations within DoD environments and systems (approval processes). Your perpetual goal will be to accelerate the ATO process while simultaneously improving our security posture, thus pushing for cultural change away from security theater and towards responsive and resilient systems. While working within the existing DoD processes, you will also work with other engineers to find the best paths forward and contribute to Unicorn mission capabilities and open source solutions to further streamline ongoing and future efforts. 


Responsibilities: 

  • Leading and pathfinding the effort to achieve accreditation in accordance with NIST-800 series requirements. 
  • Developing and implementing cybersecurity policies, procedures, and controls necessary to meet DoD accreditation standards. 
  • Conducting comprehensive risk assessments and vulnerability analyses to identify potential security threats and mitigate risks. 
  • Collaborating with cross-functional teams including software developers, system architects, and other Government stakeholders to integrate cybersecurity measures into the software development lifecycle. 
  • Performing security testing and evaluation of our software platform to identify vulnerabilities and weaknesses (STIGs, ACAS, CI/CD security testing, etc.)
  • Providing guidance and support to ensure continuous monitoring and maintenance of cybersecurity controls. 
  • Preparing and maintaining documentation required for the accreditation process, including System Security Plans (SSPs), Security Assessment Reports (SARs), and other relevant artifacts. 
  • Staying up-to-date with evolving cybersecurity threats, technologies, and regulations to proactively address security challenges and compliance requirements.
  • Serving as a subject matter expert on cybersecurity best practices, standards, and procedures within the organization. 
  • Supporting automated Compliance-as-Code capabilities that continuously evaluate the cybersecurity posture of the tech stack. 

The listed responsibilities are not exhaustive and additional responsibilities may be assigned based on the evolving needs of the organization. We are seeking a dynamic individual who is able to adapt and take on new responsibilities as they arise. 
*Job level and salary are contingent on candidate qualifications and interview performance.
Mid: $132,300 - $171,500
Senior: $162,000 - $197,100


Preferred Experience and Qualifications: 

  • Proven experience in cybersecurity engineering, with a focus on achieving accreditation for software systems within the DoD environment. 
  • Proven track record of thinking outside the box and pushing the boundaries of the RMF/ATO status quo.
  • In-depth knowledge of NIST-800 series standards, particularly NIST-800-53, and experience applying these standards to achieve accreditation. 
  • Skilled at translating technical implementation (infrastructure as code and configuration as code) into verifiable eMASS security control responses that Approving Officials (AOs), and their staffs, can understand. 
  • Strong understanding of cybersecurity principles, technologies, and best practices, including encryption, authentication, access control, and secure coding practices.
  • Hands-on experience with security assessment tools and techniques, such as vulnerability scanning and security analysis. 
  • Familiarity with software development methodologies and practices, particularly Agile and DevSecOps. 
  • Excellent analytical and problem-solving skills, with the ability to assess complex systems and identify security risks. 
  • Effective communication and interpersonal skills, with the ability to collaborate with cross-functional teams and communicate technical concepts to non-technical stakeholders. 
  • Eligibility to obtain and maintain a DoD security clearance. 
  • Eligibility to obtain and maintain privileged access in a Government Cloud Environment (relevant training and/or certifications). 

Desired Experience: 

  • Experience building and supporting continuous authority to operate (cATO) packages within the DoD 
  • Experience with Open Security Controls Assessment Language (OSCAL)
  • Ability to use OSCAL to manage control implementation and statements as “compliance as code” 
  • Understand how products and deployments affect the OSCAL lifecycle from upstream to operations 
  • Familiarity with Department of the Air Force (DAF) security approval processes to include AFI 17-101 
  • Familiarity with DAF Gov Cloud offerings and inherited controls in Gov Cloud environments 
  • Familiarity with the Cloud Computing Security Requirements Guide (CC SRG)
  • Experience working in a remote team or asynchronous work environment where focus, discipline, and comfort navigating/leveraging various communication forms and frequencies to disseminate and prioritize information and keep stakeholders informed 

Full compensation packages are based on candidate experience. Compensation ranges are established using national benchmarking data and apply across all geographic locations within the United States. 

Remote - USA
$132,300$197,100 USD
Who We Are

Defense Unicorns delivers mission value by streamlining software delivery so our customers can focus on the most important challenges. We share a vision of freedom and security for the advancement of progress and innovation. Our commitment to this vision, and to our mission-driven customers, means a commitment to speed, user experience and optionality, without compromising security. Our team is composed of innovators, software engineers, and veterans with decades of experience delivering technology programs across the federal market.

What We Do

We create and deliver secure solutions for continuous software integration and delivery. Defense Unicorns consolidates the best practices for security pipelines, testing, and deployment automation in order to meet the high security requirements valued by mission owners. Our solutions are agnostic by design and we believe that growing a robust ecosystem of secure, cloud-native software solutions can help enterprise customers inside and outside the federal market buy and integrate software more easily.

Who We Serve

Defense Unicorns’ customers are mission-focused leaders across public and private enterprises. We proudly support defense and civil agencies across the U.S. government and we work closely with the creators of leading-edge software solutions to deliver value to the mission-owner by improving the security and consumability of commercial software products.

What We Work On
  • Kubernetes
  • Cloud Environments (AWS/GCP and Azure)
  • Infrastructure-as-code (like Terraform/Pulumi)
  • Continuous Delivery and automation tooling
  • GitOps
  • Containers
  • CNCF projects and open source products and packages
  • Helm/Kustomize-Value Stream Mapping
  • Building and improving security delivery
  • Building Kubernetes and cloud native applications
Benefits Our Unicorns EnjoyHealth:
  • Medical/Dental/Vision
  • Premiums are 100% Company Paid
  • Health Reimbursement Account
  • Life Insurance
  • Disability Insurance
Financial:
  • 401k Retirement Plan
  • Company Stock Options
  • Home Office Budget
Leave:
  • Unlimited paid time off, with a mandatory 10 days off on top of 11 federal government holidays, week of Thanksgiving, last two weeks of December (including New Year’s Day)
  • Paid Parental Leave
Learning:
  • Reimbursement for approved trainings/subscriptions
  • Conferences (travel, lodging, and fees)

Don’t have all the preferred experience or qualifications? Studies show that underrepresented groups like women and people of color are less likely to apply to jobs if they don't meet every requirement listed. 

At Defense Unicorns, we're committed to diversity. If you're enthusiastic about the role but don't match every criteria, we encourage you to apply. You could be the perfect fit for this or another role! Defense Unicorns is an equal opportunity employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, disability, sex, sexual orientation, gender identity or expression, age, national origin, veteran status, genetic information, union status and/or beliefs, or any other characteristic protected by federal, state, or local law.

CCPA DISCLOSURE

Top Skills

Acas
AWS
Azure
Ci/Cd Security Testing
Containers
Emass
GCP
Gitops
Kubernetes
Nist-800 Series Standards
Open Security Controls Assessment Language (Oscal)
Pulumi
Rmf Process
Stigs
Terraform
HQ

Defense Unicorns Colorado Springs, Colorado, USA Office

555 E Pikes Peak Ave, Colorado Springs, CO, United States, 80903

Similar Jobs

6 Days Ago
Remote
USA
150K-195K Annually
Senior level
150K-195K Annually
Senior level
Software • Defense
The Senior Cybersecurity Engineer will design security solutions, improve protocols, lead incident response, and assess security for cloud and on-premises environments.
Top Skills: Amazon Machine ImagesBashCloud SecurityMobile Device ManagementPowershellSIEMSoarZero Trust
5 Days Ago
In-Office or Remote
7 Locations
Mid level
Mid level
Logistics • Software • Transportation
The Cybersecurity Engineer leads incident response, designs secure systems, analyzes network security, and reviews cybersecurity policies while collaborating with IT and vendors.
Top Skills: AutomationCloudFirewallIntrusion DetectionNetwork MonitoringNetwork SecurityScriptingVpnWeb Server Security
15 Days Ago
Remote
United States
67K-109K Annually
Mid level
67K-109K Annually
Mid level
Retail • Sports
The Cybersecurity Engineer II will manage and support IAM solutions, fulfill access requests, develop security policies, and respond to audits.
Top Skills: Active DirectoryApi IntegrationAzure Active DirectoryJIRAMicrosoft EntraPowershellPython

What you need to know about the Colorado Tech Scene

With a business-friendly climate and research universities like CU Boulder and Colorado State, Colorado has made a name for itself as a startup ecosystem. The state boasts a skilled workforce and high quality of life thanks to its affordable housing, vibrant cultural scene and unparalleled opportunities for outdoor recreation. Colorado is also home to the National Renewable Energy Laboratory, helping cement its status as a hub for renewable energy innovation.

Key Facts About Colorado Tech

  • Number of Tech Workers: 260,000; 8.5% of overall workforce (2024 CompTIA survey)
  • Major Tech Employers: Lockheed Martin, Century Link, Comcast, BAE Systems, Level 3
  • Key Industries: Software, artificial intelligence, aerospace, e-commerce, fintech, healthtech
  • Funding Landscape: $4.9 billion in VC funding in 2024 (Pitchbook)
  • Notable Investors: Access Venture Partners, Ridgeline Ventures, Techstars, Blackhorn Ventures
  • Research Centers and Universities: Colorado School of Mines, University of Colorado Boulder, University of Denver, Colorado State University, Mesa Laboratory, Space Science Institute, National Center for Atmospheric Research, National Renewable Energy Laboratory, Gottlieb Institute

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account