Defense Unicorns Logo

Defense Unicorns

Cybersecurity Engineer

Reposted Yesterday
Remote
Hiring Remotely in United States
123K-167K Annually
Mid level
Remote
Hiring Remotely in United States
123K-167K Annually
Mid level
The Cybersecurity Engineer will lead the RMF accreditation process, develop cybersecurity policies, conduct risk assessments, and integrate security measures in DoD environments. They will collaborate with teams, perform security testing, and maintain compliance documentation while staying updated on cybersecurity threats and best practices.
The summary above was generated by AI
EMPLOYER IS A CONTRACTOR FOR THE U.S. GOVERNMENT. THIS POSITION WILL REQUIRE U.S. CITIZENSHIP.Role Description: 

As a cybersecurity SME within Delivery at Defense Unicorns, you will be responsible for owning all aspects of the RMF process from accreditation of the platform for our mission heroes. You will be expected to champion modern, continuous security implementations within DoD environments and systems (approval processes). Your perpetual goal will be to accelerate the ATO process while simultaneously improving our security posture, thus pushing for cultural change away from security theater and towards responsive and resilient systems. While working within the existing DoD processes, you will also work with other engineers to find the best paths forward and contribute to Unicorn mission capabilities and open source solutions to further streamline ongoing and future efforts. 


Responsibilities: 

  • Leading and pathfinding the effort to achieve accreditation in accordance with NIST-800 series requirements. 
  • Developing and implementing cybersecurity policies, procedures, and controls necessary to meet DoD accreditation standards. 
  • Conducting comprehensive risk assessments and vulnerability analyses to identify potential security threats and mitigate risks. 
  • Collaborating with cross-functional teams including software developers, system architects, and other Government stakeholders to integrate cybersecurity measures into the software development lifecycle. 
  • Performing security testing and evaluation of our software platform to identify vulnerabilities and weaknesses (STIGs, ACAS, CI/CD security testing, etc.)
  • Providing guidance and support to ensure continuous monitoring and maintenance of cybersecurity controls. 
  • Preparing and maintaining documentation required for the accreditation process, including System Security Plans (SSPs), Security Assessment Reports (SARs), and other relevant artifacts. 
  • Staying up-to-date with evolving cybersecurity threats, technologies, and regulations to proactively address security challenges and compliance requirements.
  • Serving as a subject matter expert on cybersecurity best practices, standards, and procedures within the organization. 
  • Supporting automated Compliance-as-Code capabilities that continuously evaluate the cybersecurity posture of the tech stack. 

The listed responsibilities are not exhaustive and additional responsibilities may be assigned based on the evolving needs of the organization. We are seeking a dynamic individual who is able to adapt and take on new responsibilities as they arise. 


Preferred Experience and Qualifications: 

  • Proven experience in cybersecurity engineering, with a focus on achieving accreditation for software systems within the DoD environment. 
  • Proven track record of thinking outside the box and pushing the boundaries of the RMF/ATO status quo.
  • In-depth knowledge of NIST-800 series standards, particularly NIST-800-53, and experience applying these standards to achieve accreditation. 
  • Skilled at translating technical implementation (infrastructure as code and configuration as code) into verifiable eMASS security control responses that Approving Officials (AOs), and their staffs, can understand. 
  • Strong understanding of cybersecurity principles, technologies, and best practices, including encryption, authentication, access control, and secure coding practices.
  • Hands-on experience with security assessment tools and techniques, such as vulnerability scanning and security analysis. 
  • Familiarity with software development methodologies and practices, particularly Agile and DevSecOps. 
  • Excellent analytical and problem-solving skills, with the ability to assess complex systems and identify security risks. 
  • Effective communication and interpersonal skills, with the ability to collaborate with cross-functional teams and communicate technical concepts to non-technical stakeholders. 
  • Eligibility to obtain and maintain a DoD security clearance. 
  • Eligibility to obtain and maintain privileged access in a Government Cloud Environment (relevant training and/or certifications). 

Desired Experience: 

  • Experience building and supporting continuous authority to operate (cATO) packages within the DoD 
  • Experience with Open Security Controls Assessment Language (OSCAL)
  • Ability to use OSCAL to manage control implementation and statements as “compliance as code” 
  • Understand how products and deployments affect the OSCAL lifecycle from upstream to operations 
  • Familiarity with Department of the Air Force (DAF) security approval processes to include AFI 17-101 
  • Familiarity with DAF Gov Cloud offerings and inherited controls in Gov Cloud environments 
  • Familiarity with the Cloud Computing Security Requirements Guide (CC SRG)
  • Experience working in a remote team or asynchronous work environment where focus, discipline, and comfort navigating/leveraging various communication forms and frequencies to disseminate and prioritize information and keep stakeholders informed 

Full compensation packages are based on candidate experience. Compensation ranges are established using national benchmarking data and apply across all geographic locations within the United States. 

Remote - USA
$123,250$166,750 USD
Who We Are

Defense Unicorns delivers mission value by streamlining software delivery so our customers can focus on the most important challenges. We share a vision of freedom and security for the advancement of progress and innovation. Our commitment to this vision, and to our mission-driven customers, means a commitment to speed, user experience and optionality, without compromising security. Our team is composed of innovators, software engineers, and veterans with decades of experience delivering technology programs across the federal market.

What We Do

We create and deliver secure solutions for continuous software integration and delivery. Defense Unicorns consolidates the best practices for security pipelines, testing, and deployment automation in order to meet the high security requirements valued by mission owners. Our solutions are agnostic by design and we believe that growing a robust ecosystem of secure, cloud-native software solutions can help enterprise customers inside and outside the federal market buy and integrate software more easily.

Who We Serve

Defense Unicorns’ customers are mission-focused leaders across public and private enterprises. We proudly support defense and civil agencies across the U.S. government and we work closely with the creators of leading-edge software solutions to deliver value to the mission-owner by improving the security and consumability of commercial software products.

What We Work On
  • Kubernetes
  • Cloud Environments (AWS/GCP and Azure)
  • Infrastructure-as-code (like Terraform/Pulumi)
  • Continuous Delivery and automation tooling
  • GitOps
  • Containers
  • CNCF projects and open source products and packages
  • Helm/Kustomize-Value Stream Mapping
  • Building and improving security delivery
  • Building Kubernetes and cloud native applications
Benefits Our Unicorns EnjoyHealth:
  • Medical/Dental/Vision
  • Premiums are 100% Company Paid
  • Health Reimbursement Account
  • Life Insurance
  • Disability Insurance
Financial:
  • 401k Retirement Plan
  • Company Stock Options
  • Home Office Budget
Leave:
  • We offer all full-time Unicorns Flexible Time Off (FTO) plus all Federal Holidays, one week for Thanksgiving, and two weeks for Christmas and New Year’s
  • Paid Parental Leave
Learning:
  • Reimbursement for approved trainings/subscriptions
  • Conferences (travel, lodging, and fees)

Don’t have all the preferred experience or qualifications? Studies show that underrepresented groups like women and people of color are less likely to apply to jobs if they don't meet every requirement listed. 

At Defense Unicorns, we're committed to diversity. If you're enthusiastic about the role but don't match every criteria, we encourage you to apply. You could be the perfect fit for this or another role! Defense Unicorns is an equal opportunity employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, disability, sex, sexual orientation, gender identity or expression, age, national origin, veteran status, genetic information, union status and/or beliefs, or any other characteristic protected by federal, state, or local law.

CCPA DISCLOSURE

Top Skills

Acas
AWS
Azure
Ci/Cd
Configuration As Code
GCP
Gitops
Helm
Infrastructure As Code
Kubernetes
Kustomize
Nist-800 Series
Rmf
Security Assessment Tools
Stigs
Terraform
Vulnerability Scanning
HQ

Defense Unicorns Colorado Springs, Colorado, USA Office

555 E Pikes Peak Ave, Colorado Springs, CO, United States, 80903

Similar Jobs

17 Days Ago
Remote or Hybrid
Illinois, USA
90K-100K Annually
Mid level
90K-100K Annually
Mid level
Artificial Intelligence • Hardware • Information Technology • Security • Software • Cybersecurity • Big Data Analytics
As a Cybersecurity Engineer, lead security assessments for client systems, ensure compliance with FedRAMP, FISMA, and NIST RMF, and mentor team members in secure cloud architecture.
Top Skills: AcasDb ProtectDisa Stigs/Stig ViewerNessusNmapWebinspect
5 Days Ago
Remote
United States
100K-120K Annually
Senior level
100K-120K Annually
Senior level
Information Technology • Consulting • Cybersecurity
The Cybersecurity Engineer protects clients by managing security monitoring solutions, vulnerability management, and compliance in cloud and on-premises environments.
Top Skills: Application ControlCloud InfrastructureEdrGovcloudMdmMdrMicrosoft Gcc HighNacNsmUemVulnerability ManagementXdr
8 Days Ago
Remote
USA
106K-115K Annually
Mid level
106K-115K Annually
Mid level
Information Technology • Consulting
The Cybersecurity Engineer will design and manage security solutions, assess vulnerabilities, develop incident response plans, monitor security alerts, and document procedures to safeguard digital assets.
Top Skills: EncryptionEndpoint ProtectionFedrampFirewallsFismaIcd 503Intrusion DetectionNist Sp 800-53Rmf

What you need to know about the Colorado Tech Scene

With a business-friendly climate and research universities like CU Boulder and Colorado State, Colorado has made a name for itself as a startup ecosystem. The state boasts a skilled workforce and high quality of life thanks to its affordable housing, vibrant cultural scene and unparalleled opportunities for outdoor recreation. Colorado is also home to the National Renewable Energy Laboratory, helping cement its status as a hub for renewable energy innovation.

Key Facts About Colorado Tech

  • Number of Tech Workers: 260,000; 8.5% of overall workforce (2024 CompTIA survey)
  • Major Tech Employers: Lockheed Martin, Century Link, Comcast, BAE Systems, Level 3
  • Key Industries: Software, artificial intelligence, aerospace, e-commerce, fintech, healthtech
  • Funding Landscape: $4.9 billion in VC funding in 2024 (Pitchbook)
  • Notable Investors: Access Venture Partners, Ridgeline Ventures, Techstars, Blackhorn Ventures
  • Research Centers and Universities: Colorado School of Mines, University of Colorado Boulder, University of Denver, Colorado State University, Mesa Laboratory, Space Science Institute, National Center for Atmospheric Research, National Renewable Energy Laboratory, Gottlieb Institute

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account