Performance Drone Works Logo

Performance Drone Works

Senior Cybersecurity GRC Engineer

Posted 3 Days Ago
Be an Early Applicant
In-Office
Denver, CO, USA
135K-169K Annually
Senior level
In-Office
Denver, CO, USA
135K-169K Annually
Senior level
Build and mature PDW’s cybersecurity GRC program across enterprise, engineering, manufacturing, and business systems. Translate CMMC, NIST SP 800-171, ISO 27001, ITAR, and customer requirements into controls; manage risk assessments, documentation, evidence, audits, remediation, vulnerability management, and third-party risk. Configure and validate security tools, support incident response, improve endpoint, identity, cloud, network, and monitoring controls, and report security metrics to leadership. The role requires cross-functional collaboration with auditors, customers, vendors, and system owners.
The summary above was generated by AI

Performance Drone Works (PDW) is building the next generation of tactical robotic systems used across defense, national security, and public safety missions. We are building a new center of engineering excellence to design our new category of tactical robotic systems and the industrial capacity to deliver them, bringing decisive airpower into the hands of every operator. We are not here to make promises; we are here to deliver real systems with real capabilities for real missions.  
 
You will join a team of operators, engineers, and builders who solve hard problems with humility and focus. We design and produce multi-mission aerial systems that operators trust to perform in real-world conditions, reliably, repeatedly, and at scale. Our approach is grounded in operator-centered design, rapid iteration from field use, and U.S.-based manufacturing. We operate by a clear set of values: Mission First, Aim Farther, Own It, Win Together. This is how we build advantage and how we help protect our service members, our communities, and our country. 


Now, we’re entering a new phase of growth and are looking for a Senior Cybersecurity GRC Engineer to help build, operate, and mature PDW's cybersecurity and compliance program. This is a hands-on technical role for a cybersecurity practitioner who can translate requirements from CMMC, ISO 27001, ITAR, and customer obligations into practical controls - and personally help implement, validate, and improve those controls across the organization.

 

What You’ll Do

  • Serve as a senior technical contributor to PDW's cybersecurity governance, risk, and compliance program, helping define priorities, technical standards, control requirements, and roadmaps across enterprise IT, engineering, manufacturing, and business systems.
  • Lead and support readiness efforts for applicable compliance frameworks and customer requirements, including CMMC, NIST SP 800-171, ISO 27001, ITAR and export-control obligations, and other defense-industry security requirements.
  • Translate regulatory, contractual, and framework requirements into clear, actionable technical and administrative controls; partner with system owners to implement controls that are effective, sustainable, and appropriate for PDW's operating environment.
  • Own and continuously improve core GRC processes, including risk assessments, control assessments, system security plans, plans of action and milestones, evidence collection, policy and standard development, third-party risk, audit preparation, and remediation tracking.
  • Remain hands-on in cybersecurity operations: configure, administer, tune, and validate security tooling such as endpoint detection and response, identity and access management, email security, logging, security monitoring, and related controls.
  • Ensure standardized vulnerability-management processes are consistently followed across the organization, including asset coverage, scan cadence, remediation tracking, exception management, and evidence collection. Leverage platforms such as Tenable and related security tools to support compliance validation, audit evidence, risk reporting, and verification of remediation activities.
  • Partner with IT and engineering teams to secure endpoints, identity systems, cloud services, networks, collaboration platforms, and business applications through practical configuration, hardening, monitoring, and access-control improvements.
  • Support incident-response preparedness and execution, including developing playbooks, participating in investigations, coordinating technical response activities, documenting lessons learned, and improving controls after incidents.
  • Develop meaningful cybersecurity and compliance metrics for leadership, including risk trends, control maturity, audit readiness, vulnerability remediation, security-tool coverage, and outstanding corrective actions.
  • Work directly with internal stakeholders, external auditors, customers, assessors, and technology vendors to communicate PDW's security posture, answer evidence requests, and drive timely resolution of findings.
  • Build repeatable cybersecurity processes, technical baselines, policies, procedures, and evidence-collection mechanisms that enable PDW to scale while protecting sensitive, controlled, and export-controlled information.

 

Requirements

  • 7+ years of progressive experience in cybersecurity, information security, GRC, security engineering, IT security, or a related technical discipline, including meaningful hands-on experience operating cybersecurity controls and tools.
  • Bachelor's degree in Cybersecurity, Information Technology, Computer Science, Engineering, or a related discipline; equivalent relevant professional experience, technical training, and industry certifications will be considered in lieu of a degree.
  • Demonstrated experience implementing or assessing security programs against CMMC and/or NIST SP 800-171, including familiarity with assessment, evidence, and remediation expectations associated with defense-industry cybersecurity requirements.
  • Working knowledge of ISO 27001 and experience applying its control-based approach to a real-world information security management system.
  • Experience working in an environment subject to ITAR, export controls, controlled unclassified information, defense contracts, or similarly regulated and sensitive data environments.
  • Hands-on experience administering, configuring, or validating security tools such as EDR, endpoint-management tools, identity and access-management systems, SIEM and logging platforms, email-security tools, or cloud-security controls.
  • Familiarity with vulnerability-management platforms such as Tenable, Qualys, or Rapid7, including using scan results and platform reporting to gather compliance evidence, support risk assessments, validate control effectiveness, and track remediation.
  • Demonstrated ability to investigate technical issues, assess security configurations, validate control effectiveness, identify gaps, and work directly with system owners to remediate risk.
  • Experience developing and maintaining cybersecurity documentation, including system security plans, risk registers, policies, procedures, control narratives, audit evidence, and remediation plans.
  • Strong understanding of endpoint security, vulnerability management, identity and access management, least privilege, network security, logging and monitoring, incident response, encryption, asset management, and secure configuration.
  • Ability to independently translate ambiguous compliance or security requirements into pragmatic action plans; prioritize risk; communicate effectively with technical and non-technical stakeholders; and drive work through completion.
  • Must have the ability to obtain and maintain a U.S. Security Clearance. 

 

Preferred

  • Relevant certifications such as CISSP, CISM, CRISC, CISA, Security+, ISO 27001 Lead Implementer or Lead Auditor, Certified CMMC Professional, Certified CMMC Assessor, or similar credentials.
  • Experience supporting a CMMC assessment, ISO 27001 certification audit, NIST SP 800-171 assessment, customer security review, or government-contracting security evaluation.
  • Experience in aerospace, defense, robotics, manufacturing, or another highly technical and regulated environment.
  • Experience with Microsoft 365 and Azure security, Microsoft Defender, CrowdStrike, SentinelOne, Tenable, Jira, ServiceNow, SIEM platforms, or comparable technologies.
  • Experience building cybersecurity programs in a fast-growing organization where controls, systems, and processes are evolving rapidly.

 

Physical Requirements

The physical demands described here are representative of those that must be met to successfully perform the essential functions of the job. Ability to sit, stand, bend, reach, climb, and move about regularly throughout the day and lift / carry up to 25 pounds. Must have manual dexterity to operate standard office or manufacturing equipment. Must be physically capable of occasionally assisting with the setup, movement, and installation of computer, networking, or security-related equipment.

 

Work Environment

PDW will consider remote, hybrid, or on-site work arrangements for the right candidate. This role requires the use of standard office and computing equipment and close cross-departmental collaboration with both independent and team-based responsibilities. Occasional travel between PDW sites, partner locations, industry events, or other business locations may be required. Standard work hours are PDW's core business hours, with availability outside those hours as needed for significant cybersecurity incidents or operational priorities.


Benefits 

PDW values our team, and we offer a compensation package reflective of your experience and capabilities. Benefits include:

  • Comprehensive BCBS medical, dental, and vision coverage; 80% sponsored by the company.
  • Safe Harbor 401(K) with company match.
  • Paid Parental Leave.
  • On-site gym at our Denver, CO & Huntsville, AL locations.
  • Employer provided life insurance.
  • Robust Employee Assistance Program (EAP).
  • A work environment that encourages teamwork and innovation.
  • Competitive salary, generous paid time off (PTO), and flexible leave options.

 

EEO Statement 

PDW is an equal opportunity employer that upholds all federal and state non-discrimination laws. We ensure a fair and unbiased evaluation for employment for all qualified candidates regardless of race, color, religion, age, sex, sexual orientation, gender identity, national origin, marital status, medical condition, disability, genetic information, veteran status, or any other characteristic protected by law. 

Performance Drone Works Denver, Colorado, USA Office

3615 Delgany St, Denver, Colorado, United States, 80216 3996

Similar Jobs

4 Hours Ago
Remote or Hybrid
USA
120K-180K Annually
Senior level
120K-180K Annually
Senior level
Cloud • Computer Vision • Information Technology • Sales • Security • Cybersecurity
Build agentic AI workflows and platforms that automate software development lifecycle activities, including code generation, review, testing, and release. Improve context grounding, model routing, observability, benchmarking, and cost efficiency for LLM-powered engineering tools. Partner with engineering teams to identify workflow friction and promote responsible AI adoption. The role requires backend and platform engineering experience, LLM-agent infrastructure expertise, Kubernetes experience, and proficiency in Go or Python.
Top Skills: A/B TestingAi Coding Agent FrameworksEntity ResolutionEvent PipelinesGoKnowledge GraphsKubernetesLarge Language ModelsLlm Agent InfrastructureObservability ToolingPython
4 Hours Ago
Remote or Hybrid
USA
195K-290K Annually
Expert/Leader
195K-290K Annually
Expert/Leader
Cloud • Computer Vision • Information Technology • Sales • Security • Cybersecurity
Leads the Cloud Detection Platform organization, strategy, architecture, roadmap, and multiple engineering teams. Owns large-scale detection engines, content delivery infrastructure, reliability, latency, cost, SLOs, capacity, and quota management. Drives unified detection architecture, safe content deployment, testing, observability, and cross-functional roadmap execution while managing organizational planning, talent development, and operational excellence.
Top Skills: AICloud ComputingDistributed SystemsQuery EnginesSearch EnginesSIEMStreaming Systems
4 Hours Ago
Remote or Hybrid
USA
95K-140K Annually
Entry level
95K-140K Annually
Entry level
Cloud • Computer Vision • Information Technology • Sales • Security • Cybersecurity
Conduct incident response engagements, threat hunting, intrusion investigations, and host or network forensics across Windows, macOS, and Linux. Analyze network data, malware, and cloud environments; support remediation planning; and prepare reports, presentations, recommendations, and findings for customers, regulators, legal counsel, and internal teams. Consultants collaborate with project leadership and customers while using AI technologies to improve investigative workflows and decision-making.
Top Skills: AWSBro/ZeekGoogle Cloud Platform (Gcp)LinuxmacOSAzureSuricataWindows

What you need to know about the Colorado Tech Scene

With a business-friendly climate and research universities like CU Boulder and Colorado State, Colorado has made a name for itself as a startup ecosystem. The state boasts a skilled workforce and high quality of life thanks to its affordable housing, vibrant cultural scene and unparalleled opportunities for outdoor recreation. Colorado is also home to the National Renewable Energy Laboratory, helping cement its status as a hub for renewable energy innovation.

Key Facts About Colorado Tech

  • Number of Tech Workers: 260,000; 8.5% of overall workforce (2024 CompTIA survey)
  • Major Tech Employers: Lockheed Martin, Century Link, Comcast, BAE Systems, Level 3
  • Key Industries: Software, artificial intelligence, aerospace, e-commerce, fintech, healthtech
  • Funding Landscape: $4.9 billion in VC funding in 2024 (Pitchbook)
  • Notable Investors: Access Venture Partners, Ridgeline Ventures, Techstars, Blackhorn Ventures
  • Research Centers and Universities: Colorado School of Mines, University of Colorado Boulder, University of Denver, Colorado State University, Mesa Laboratory, Space Science Institute, National Center for Atmospheric Research, National Renewable Energy Laboratory, Gottlieb Institute

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account