Job Closed
This listing is no longer active.
Connecting people, systems and data from space to operator for data superiority
Cybersecurity Lead Engineer
Location
United States
Posted
10 days ago
Salary
$135K - $145K / year
Seniority
Senior
Job Description
Cybersecurity Lead Engineer
Sigma Defense Systems LLC
• Support DevSecOps and Software Engineers in developing secure platforms and effectively communicating regarding the risk posture of the platforms. • Support of full RMF lifecycle for authorization and re-authorization of existing and novel capabilities including regular communication with stakeholders and authorizing personnel. • Identification and reduction of system vulnerabilities to achieve compliance objectives. • Mentorship and proliferation of cybersecurity culture within team.
Job Requirements
- 8-10 years of Cybersecurity experience.
- Experience with DoW RMF policy.
- Experience maintaining cybersecurity on an enterprise DevSecOps platform.
- Registered DoW RMF Practitioner (RDRP) is preferred.
- Must be a U.S. citizen.
- Mandatory Certifications:**
- CISSP
- Personnel Clearance Level:**
- Candidate must possess or have the ability to obtain an active Secret security clearance or higher.
- Clearance may be sponsored for the right candidate.*
- Education Requirements:**
- Bachelor's degree from an accredited college or university in an Cyber Security, Information Technology, Information Systems, Computer Science, Computer Engineering, Mathematics, or related field of study.
- Degree may be substituted for comparable additional industry experience and/or industry accepted training and certification.*
Benefits
- Dental and Vision Insurance
- Medical Insurance to Include HSA, FSA, and DFSA Plans
- Life and AD&D coverage
- Employee Assistance Program (EAP)
- 401(k) Plan with Company Matching Contributions
- 160 Hours of Paid Time Off (PTO)
- 12 (Floating) Holidays
- Educational Assistance
- Highly Competitive Salary
Related Guides
Related Categories
Related Job Pages
More Security Engineer Jobs
• Design, build, and maintain secure CI/CD pipelines with security gates that catch issues before they reach production. • Systematically, consistently and automatically capture the risk exposure of Chainguards products. • Implement and enforce software supply chain security controls: signed artifacts, SBOMs, provenance attestation (SLSA, Sigstore / Cosign). • Proactively identify emerging customer security needs, and build solutions to meet these. • Lead security architecture reviews and threat models for Kubernetes-based workloads running on GCP and AWS. • Harden container images, Kubernetes cluster configurations, and cloud IAM postures – minimising attack surface across our product stack. • Define and drive adoption of baseline security standards: pod security standards, network policies, workload identity, secrets management. • Evaluate and operationalise CNAPP / CSPM tooling to maintain continuous visibility into cloud-native risk.
• Own the product security research agenda for Chainguard scanning the broader ecosystem, identifying emerging attack patterns, and translating them into clear risks and opportunities for Chainguard and our customers. • Shape security direction across products and platforms, partnering closely with Product, Engineering, and Security leadership to embed your findings into roadmaps, architecture decisions, and long-term plans. • Operate as someone who sees the whole ecosystem, spots issues early, and helps others navigate with confidence (and just enough healthy paranoia). • Research emerging threats & trends in software supply chain and product security, and analyze their impact on Chainguard’s products and customers. • Design creative mitigations across people, process, and technology not just proof-of-concept demos, but pragmatic defenses that actually get adopted. • Lead large-scale, multi-quarter initiatives that materially reduce risk or improve our security maturity across multiple product lines and platforms. • Partner with executive and senior engineering leadership to drive org-level security strategy, influence key roadmap decisions, and secure buy-in for big, complex changes. • Identify systematic weaknesses (in systems, structures, and sometimes habits) and develop plans that fix root causes in ways that persist long after you’ve moved on to the next hard problem. • Mentor and uplevel others across Product Security and Engineering by helping teams think more strategically about threats, risk, and long-term security posture. • Represent Chainguard externally through talks, conferences, and thought leadership, sharing what we’re learning and helping move the industry forward.
Senior Security Engineer
HopperHopper is an accredited, mobile-only travel agency using big data to analyze and predict airfare and accommodations. A fully remote employer, Hopper strives to
• Own and evolve our vulnerability management program with a focus on application security — container images, dependencies, code scanning, and runtime detection • Build and maintain security tooling that integrates directly into CI/CD pipelines and developer workflows, so security happens automatically rather than as a gate • Use AI extensively to write code faster, automate analyses that would otherwise require manual review, and build intelligent tooling that scales beyond what a small team could achieve manually • Assess and improve how we leverage available telemetry across our systems • Work directly with engineering teams to influence secure development practices — not by writing standards and documents, but by shipping tools and defaults that make the secure path the easy path • Investigate and respond to security findings when needed, but spend more of your time building systems that prevent and detect issues than manually chasing them • Adapt quickly as priorities shift — our team is agile and tomorrow's challenge may look different from today's
Senior Security Engineer
HopperHopper is an accredited, mobile-only travel agency using big data to analyze and predict airfare and accommodations. A fully remote employer, Hopper strives to
• Own and evolve our vulnerability management program with a focus on application security — container images, dependencies, code scanning, and runtime detection • Build and maintain security tooling that integrates directly into CI/CD pipelines and developer workflows, so security happens automatically rather than as a gate • Use AI extensively to write code faster, automate analyses that would otherwise require manual review, and build intelligent tooling that scales beyond what a small team could achieve manually • Assess and improve how we leverage available telemetry across our systems • Work directly with engineering teams to influence secure development practices — not by writing standards and documents, but by shipping tools and defaults that make the secure path the easy path • Investigate and respond to security findings when needed, but spend more of your time building systems that prevent and detect issues than manually chasing them • Adapt quickly as priorities shift — our team is agile and tomorrow's challenge may look different from todays


