Cybersecurity Engineer - DevOps

Posted 4 Hours Ago
Hiring Remotely in US
Remote
112K-178K Annually
Mid level
Cloud • Information Technology • Software
Make a Difference. Spherions do it every day by helping companies create a safer, more sustainable and productive world
The Role
Lead cybersecurity for software deployed in federal and DoD environments. Manage RMF and ATO activities, STIG implementation, vulnerability remediation, FedRAMP and FISMA compliance, POA&Ms, SSPs, incident response, SIEM monitoring, and threat modeling. Integrate security testing into CI/CD pipelines, coordinate with government security stakeholders, and guide engineering teams on secure design, compliance, and remediation requirements.
Summary Generated by Built In

Sphera is a leading global provider of enterprise software and services that enables companies to manage and optimize their environmental, health, safety and sustainability. Our mission is to create a safer, more sustainable and productive world.

Sphera is a portfolio company of Blackstone, a U.S.-based alternative asset investment company that focuses on private equity, technology and innovation, and more. Blackstone businesses succeed through strong partnerships, a personalized approach and a commitment to exceptional performance with uncompromising integrity. Sphera and Blackstone are leaders in the Environmental, Social and Governance (ESG) space.

We are guided by our core values of Customer Centricity, Accountability, Bias to Action, Innovation, and Collaboration. These values help us recruit the right talent to join our rapidly expanding team around the globe. It is important to us that each and every Spherion is not only eager to challenge themselves and knows how to get work done but is an awesome addition to our company culture.

POSITION SUMMARY

This role will be pivotal in advancing the company's mission of delivering secure, reliable, and innovative software solutions for U.S. government and DoD clients. The Cybersecurity Engineer serves as the resident security subject-matter expert embedded within the DevOps squad, owning the security compliance posture for software deployed in federal, DoD, and other highly regulated secure environments. The ideal candidate brings direct, hands-on experience operating within secure federal technology environments and a strong working knowledge of the security frameworks, tooling, and authorization processes that govern government-hosted systems. This individual will drive RMF/ATO lifecycle management, STIG implementation, vulnerability remediation, and DevSecOps integration across Sphera's product lines, ensuring that all systems maintain continuous compliance and readiness for deployment in secure government operating environments.

KEY RESPONSIBILITIES

  • Lead cybersecurity for software deployed in secure federal and DoD environments, ensuring compliance with applicable government security policies, access requirements, and accreditation expectations.
  • Execute RMF activities, including system categorization, security control selection, implementation, assessment, and ATO documentation for federal or DoD-hosted systems.
  • Implement, configure, and validate STIGs across layers using DISA-approved or equivalent government security tooling.
  • Mitigate OWASP Top 10 and application-layer vulnerabilities across services.
  • Monitor security controls, scan vulnerabilities, and audit systems, producing reports and coordinating remediation with development and DevOps.
  • Manage POA&Ms, coordinating with government security stakeholders, ISSMs, and internal teams to track and resolve open findings.
  • Support FedRAMP and FISMA compliance, aligning controls with NIST SP 800-53 Rev. 5.
  • Integrate security tooling and automated checks into CI/CD pipelines, advancing DevSecOps maturity.
  • Collaborate with engineers and the Principal Solutions Architect to conduct threat modeling, security design reviews, and application-level security assessments.
  • Maintain System Security Plans (SSPs), security architectures, and supporting ATO documentation packages in alignment with federal and DoD requirements.
  • Lead incident response activities for security events affecting systems deployed in secure government environments, coordinating with customer cybersecurity personnel and internal stakeholders.
  • Monitor SIEM alerts, analyze logs, and investigate anomalous activity.
  • Evaluate the security posture of third-party integrations, vendor tools, and emerging technologies for adoption in secure federal or DoD environments.
  • Embed security requirements into sprint planning, feature development, and release processes with the TPM, engineering squads, and product owners.
  • Stay informed on evolving federal, DoD, DISA, and agency-specific security policies, DISA guidance updates, and emerging threats, and proactively communicate their impact to the engineering organization.
QUALIFICATIONS & EXPERIENCE
  • U.S. citizen required; active DoD security clearance or ability to obtain and maintain one due to secure federal enclave access.
  • Minimum 3-5 years of hands-on cybersecurity experience in a federal, DoD or similarly regulated secure environments.
  • Strong working knowledge of secure federal or DoD environments, including segmented networks, access control, approved software baselines, and applicable security requirements.
  •  Experience supporting or leading RMF processes, including ATO package preparation and submission for federal or DoD systems.
  • Proficiency in applying STIGs using DISA-approved tools (SCC, STIG Viewer, Nessus/ACAS) or comparable vulnerability and compliance platforms.
  • Solid understanding of FedRAMP Moderate and FISMA compliance, with ability to map security controls to NIST SP 800-53 Rev. 5.
  • Experience with vulnerability management tools (e.g., Tenable.sc, Nessus, ACAS) in federal or DoD environments.
  • Familiarity with enterprise security tools including SIEM, IDS/IPS, and network security controls.
  • DevSecOps experience, including integrating SAST, DAST, and SCA scanning into CI/CD pipelines using Azure DevOps, Jenkins, or equivalent tools.
  • Familiarity with PKI, CAC/PIV authentication, and certificate management in federal or DoD environments.
  • Strong written and verbal communication skills to translate complex security findings into actionable guidance for engineering teams and brief government stakeholders.
  • DoD 8570/8140 compliant certification at IAT Level II or higher (e.g., CompTIA Security+, CISSP, CEH, CAP, or equivalent).
  • Bachelors degree in Computer Science, Information Security, Cybersecurity, or a related field, or equivalent practical experience.
  • Experience working in segmented networks with an understanding of federal, DoD, or similarly regulated infrastructure and security requirements.

PROFESSIONAL SKILLS

  • Proven time management, organizational and follow-up skills to meet deadlines.
  • Work effectively, independently, and in a dynamic team environment. 
  • Excellent interpersonal skills.
  • Must be willing to learn new technologies and processes as needed.
KEY COMPETENCIES

Secure Federal Environment Expertise

Strong working knowledge of secure federal, DoD, or similarly regulated operating environments, including security requirements, approval workflows, access constraints, and operational expectations — enabling the team to navigate complex government security landscapes with confidence and minimal disruption to delivery.

RMF and Compliance Execution

End-to-end ownership of RMF activities, from control implementation through ATO documentation, ensuring systems remain authorized and compliant throughout their lifecycle.

DevSecOps Integration

Embeds security as a continuous, automated discipline within engineering pipelines, reducing friction and shifting security left in the development lifecycle to maximize engineering velocity without sacrificing compliance.

Exceptional Stakeholder Communication and Collaboration

Foster strong partnerships by maintaining open, transparent, and effective communication with all stakeholders — including government program offices, ISSMs, and internal engineering teams — to ensure alignment and rapid resolution of security findings.

Incident Response and Threat Management

Rapid identification, escalation, and resolution of security events affecting systems deployed in secure government environments, with established protocols for coordinating with customer cybersecurity personnel.

Passion for Secure Innovation

Champion a security-first engineering culture that treats compliance not as a constraint but as a foundation for building reliable, mission-ready software for the DoD.

Pay:

$112,000.00 - $178,000.00 + Eligible for Variable Compensation Plan

Commensurate with relevant qualifications and experience

Benefits:

  • Medical, Dental, and Vision Insurance

  • Health Savings Account

  • Flexible Spending Account

  • 401(k) Retirement Plan with Company Match

  • Life and Disability Insurance

  • Critical Illness Insurance

  • Accident Insurance

  • Hospital Indemnity Insurance

  • Paid Time Off and Holidays

  • Flexible Working Schedule

Sphera is proud to be an Equal Opportunity Employer. We celebrate diversity and are committed to creating an inclusive environment for all colleagues. We provide equal employment opportunities to all individuals regardless of race, color, religion, sex, sexual orientation, gender identity or expression, national origin, disability, age, veteran status, marital status, or any other legally protected status.

If you require a reasonable accommodation for a disability during the application or recruiting process, please email us at [email protected] to make your request. To help us best respond, please include your name and the position you are applying for in your message.

This job description is intended to convey information essential to understanding the scope of the job and the general nature and level of work performed by job holders within this job. This job description is not intended to be an exhaustive list of qualifications, skills, efforts, duties, responsibilities or working conditions associated with the position.

Skills Required

  • U.S. citizenship
  • Active DoD security clearance or ability to obtain and maintain one
  • 3-5 years of hands-on cybersecurity experience in federal, DoD, or similarly regulated secure environments
  • Experience with secure federal or DoD environments, segmented networks, access controls, approved software baselines, and security requirements
  • Experience supporting or leading RMF processes, including ATO package preparation and submission
  • Proficiency applying STIGs using DISA-approved tools such as SCC, STIG Viewer, Nessus, or ACAS
  • Understanding of FedRAMP Moderate and FISMA compliance and mapping controls to NIST SP 800-53 Rev. 5
  • Experience with vulnerability management tools such as Tenable.sc, Nessus, or ACAS
  • Familiarity with SIEM, IDS/IPS, and network security controls
  • DevSecOps experience integrating SAST, DAST, and SCA scanning into CI/CD pipelines using Azure DevOps, Jenkins, or equivalent
  • Familiarity with PKI, CAC/PIV authentication, and certificate management
  • Strong written and verbal communication skills
  • DoD 8570/8140-compliant certification at IAT Level II or higher, such as CompTIA Security+, CISSP, CEH, or CAP
  • Bachelor's degree in Computer Science, Information Security, Cybersecurity, or related field, or equivalent practical experience
  • Time management, organizational, follow-up, interpersonal, and teamwork skills

Sphera Compensation & Benefits Highlights

The following summarizes recurring compensation and benefits themes identified from responses generated by popular LLMs to common candidate questions about Sphera and has not been reviewed or approved by Sphera.

  • Strong & Reliable Incentives Sales on‑target earnings can be competitive for certain roles, with healthy ranges and high OTE potential for Solution/Account Executives. Feedback suggests on‑plan earnings compare well against many B2B software peers.
  • Healthcare Strength Medical, dental and vision coverage are characterized as good, with low deductibles and a significant employer share of premiums. Feedback suggests core health insurance quality is a relative strength.
  • Retirement Support A 401(k) with employer match is consistently referenced, with a clear structure that enables a meaningful company contribution when employees contribute. Feedback suggests retirement offerings are straightforward and valued.

Sphera Insights

Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
HQ: Chicago, IL
1,300 Employees
Year Founded: 2016

What We Do

Sphera is the leading provider of integrated sustainability and operational risk management software, data and consulting services focusing on Environment, Health, Safety & Sustainability (EHS&S), Process Safety, Product Stewardship and Supply Chain Transparency. For more than 30 years, we have served 8,500 customers and a million-plus users in 100 countries to help companies keep their people safe, their products sustainable and their operations productive. We help enterprises build sustainable businesses while keeping people and the planet safe. Our solutions provide critical visibility and alignment across safety, risk, and supply chains -- empowering organizations to create lasting, sustainable impact. Our Mission: To create a safer, more sustainable and productive world by advancing operational excellence. Sphera's many internal initiatives, such as its annual Mentoring Program, running for its sixth year in 2025, supports staff in feeling and achieving their best.  The goal of the Mentoring Program is to help participants achieve career development, personal growth, and create opportunities to partner with others from across the organization.

Why Work With Us

At Sphera we are solving some of the most important challenges facing the world today. Our staff, some of the world’s leading safety and sustainability experts, are meeting this challenge. Sphera is a hybrid company, with Chicago team attending SpheraIn days. We are always looking for talented people who want to make a difference.

Gallery

Gallery

Similar Jobs

BAE Systems, Inc. Logo BAE Systems, Inc.

Information Technology Project Manager

Aerospace • Hardware • Information Technology • Security • Software • Cybersecurity • Defense
Remote or Hybrid
Falls Church, VA, USA
40000 Employees
133K-226K Annually

Cloudflare Logo Cloudflare

Account Executive

Cloud • Information Technology • Security • Software • Cybersecurity
Remote or Hybrid
United States
4400 Employees

TransUnion Logo TransUnion

Financial Services Industry Executive - Consumer Lending & Card

Big Data • Fintech • Information Technology • Business Intelligence • Financial Services • Cybersecurity • Big Data Analytics
Remote or Hybrid
6 Locations
13000 Employees
92K-154K Annually

Runpod Logo Runpod

Head of Analytics and Business Intelligence

Artificial Intelligence • Cloud • Software • Infrastructure as a Service (IaaS)
Remote
USA
120 Employees
200K-280K Annually

Similar Companies Hiring

Onshore Thumbnail
Artificial Intelligence • Fintech • Software • Financial Services
New York, New York
60 Employees
Revel.io Thumbnail
Aerospace • Hardware • Robotics • Software
US
50 Employees
Blee Thumbnail
Artificial Intelligence • Marketing Tech • Software
New York, New York
30 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account