ISSM / Security Automation Engineer

Posted 12 Hours Ago
Be an Early Applicant
Hiring Remotely in US
Remote
175K-190K Annually
Entry level
Artificial Intelligence • Cybersecurity • Quantum Computing • Defense
The Role
Leads NIST RMF, security authorization, continuous monitoring, and cybersecurity risk activities while engineering automation for compliance, vulnerability management, evidence collection, and remediation. Develops integrations, dashboards, policy validation, and Compliance as Code using cloud platforms, APIs, CI/CD, Infrastructure as Code, containers, and scripting languages. Partners with engineering and security teams to embed controls into cloud and DevSecOps workflows.
Summary Generated by Built In
Description

Quantum Sky is searching for a highly technical Information System Security Manager (ISSM) / Security Automation Engineer to lead cybersecurity risk management and security authorization activities while designing and developing automation that enables continuous security and compliance.


This is a hands-on engineering role for an individual who can operate effectively across cybersecurity governance, cloud security, DevSecOps, software automation, and NIST Risk Management Framework (RMF) environments. The successful candidate will own traditional ISSM responsibilities while also developing scripts, integrations, and automated workflows that reduce manual compliance activities and provide continuous visibility into system security posture.


The ideal candidate has previous software development or automation engineering experience and is comfortable working directly with source code, APIs, cloud services, CI/CD pipelines, Infrastructure as Code, security tooling, and machine-readable compliance data.The objective of this position is to move security programs away from periodic, document-driven compliance toward automated, continuous security assurance and Compliance as Code.


Responsibilities:

  • Lead RMF, Security Authorization & Continuous Assurance — Own NIST RMF implementation, system authorization and ongoing authorization activities, including SSPs, control implementation documentation, risk assessments, continuous monitoring artifacts, and coordination with system owners, assessors, ISSOs, engineers, and Authorizing Officials.
  • Engineer Security & Compliance Automation — Design, develop, and maintain production-quality automation using Python, PowerShell, Bash, APIs, and cloud-native technologies to automate control validation, evidence collection, compliance reporting, security assessments, and remediation workflows.
  • Implement Compliance as Code & Continuous Control Monitoring — Translate NIST SP 800-53 controls and organizational requirements into measurable technical requirements, machine-readable policies, automated validation procedures, and continuous control monitoring capabilities.
  • Embed Security into Cloud & DevSecOps Workflows — Partner with engineering and platform teams to integrate security into cloud architectures, Infrastructure as Code, CI/CD pipelines, containers, Kubernetes, and software delivery processes, including automated testing, policy validation, and security gates.
  • Integrate Security Platforms, Data & Tooling — Build integrations and reusable services connecting cloud platforms, vulnerability scanners, security tools, GRC platforms, ticketing systems, source-code repositories, and CI/CD systems using APIs and structured data such as JSON and YAML.
  • Manage Vulnerabilities, Findings & Cybersecurity Risk — Automate vulnerability and configuration finding ingestion, correlation, prioritization, assignment, tracking, and reporting; manage POA&Ms, exceptions, and remediation through closure; and evaluate system architectures and changes for cybersecurity risk.
  • Deliver Continuous Security Visibility & Improvement — Develop dashboards, metrics, and automated reporting that provide actionable visibility into vulnerabilities, configuration compliance, control status, POA&Ms, and organizational risk while identifying opportunities to replace manual security reviews with automated technical validation.
Qualifications

Required:

  • Bachelor’s degree in Cybersecurity, Computer Science, Information Technology, Software Engineering, or a related field, or equivalent professional experience.
  • Demonstrated experience as an ISSM, ISSO, Security Engineer, Cloud Security Engineer, DevSecOps Engineer, or similar technical cybersecurity professional.
  • Strong knowledge of NIST SP 800-53, NIST SP 800-37, RMF, security authorization, security control assessment, and continuous monitoring.
  • Demonstrated hands-on experience developing production-quality automation, scripts, integrations, or software.
  • Strong programming or scripting experience with Python and experience with one or more additional languages or scripting environments such as PowerShell, Bash, JavaScript, or Go.
  • Experience working with JSON and YAML.
  • Experience automating cybersecurity, infrastructure, compliance, or operational processes.
  • Experience with vulnerability scanning and vulnerability management technologies.
  • Experience with cloud platforms such as AWS, Azure or GCP.
  • Ability to understand cloud and enterprise system architectures and evaluate their security implications.
  • Ability to translate regulatory and cybersecurity requirements into technical engineering requirements.

Desired:

  • Experience developing automation against AWS, Azure or GCP API/SDKs
  • Experience with Infrastructure as Code technologies such as Terraform.
  • Experience with configuration management and automation technologies such as Ansible.
  • Experience with CI/CD platforms such as GitHub Actions, GitLab CI/CD, Jenkins, or Azure DevOps.
  • Experience with container and orchestration technologies such as Docker and Kubernetes.
  • Experience integrating vulnerability scanners, SIEM platforms, CSPM/CNAPP solutions, GRC platforms, and ticketing systems.
  • Experience developing security dashboards and data pipelines.
  • Experience with automated testing frameworks and software engineering practices.
  • Experience with serverless architectures and event-driven automation.
  • Experience transforming NIST controls and security documentation into structured, machine-readable data.
  • Experience with Compliance as Code and Policy as Code technologies such as Open Policy Agent (OPA).
  • Experience implementing automated security evidence collection and continuous control validation.

Desired Federal Cybersecurity Experience:

  • Experience supporting FISMA, FedRAMP, DoD RMF, CMMC, or other federal cybersecurity programs.
  • Experience supporting systems through initial authorization and ongoing authorization processes.
  • Experience working with Security Control Assessors (SCAs), Third Party Assessment Organizations (3PAOs), or government Authorizing Officials.
  • Experience developing or maintaining SSPs, POA&Ms, Security Assessment Reports, continuous monitoring documentation, and supporting authorization artifacts.
  • Familiarity with federal security baselines, implementation guidance, and security assessment procedures.

Desired Certifications:

  • One or more of the following is preferred:
  • CISSP, CGRC, CISM, CCSP, Security+
  • AWS Solution Architect or Security Specialty
  • GCP Cloud Architect or Security Engineer
  • Certified Kubernetes Security Specialist (CKS)
About Quantum Sky

Compensation:

  • Compensation is unique to each candidate and relative to the skills and experience they bring to the position. The salary range for this position is typically between $175,000-$190,000. This does not guarantee a specific salary as compensation is based upon multiple factors such as education, experience, certifications, and other requirements, and may fall outside of the above-stated range.

Benefits:

  • Highlights of our benefits include Health/Dental/Vision, 401(k) match, Paid Time Off, STD/LTD/Life Insurance, Referral Bonuses, professional development reimbursement, and parental leave.

The world the mission operates in is going post-quantum, contested, and machine-speed. Quantum Sky engineers the advantage across cyber, networks, software, and quantum because the mission demands dominance, not parity. We don't follow the map. We draw it. 


At Quantum Sky, we believe that success starts with our people. We foster a collaborative, innovative, and mission-driven environment where every team member plays a critical role in shaping the future of technology. Are you ready to join #TeamQuantumSky? 


Quantum Sky Engineering LLC is an Equal Opportunity Employer; all qualified applicants will receive consideration for employment without regard to race, color, religion, sex, [sexual orientation, gender identity,] national origin, disability, status as a protected veteran, or any characteristic protected by applicable law.


Skills Required

  • Bachelor’s degree in Cybersecurity, Computer Science, Information Technology, Software Engineering, or a related field, or equivalent professional experience.
  • Experience as an ISSM, ISSO, Security Engineer, Cloud Security Engineer, DevSecOps Engineer, or similar technical cybersecurity professional.
  • Knowledge of NIST SP 800-53, NIST SP 800-37, RMF, security authorization, security control assessment, and continuous monitoring.
  • Hands-on experience developing production-quality automation, scripts, integrations, or software.
  • Strong Python programming or scripting experience and experience with PowerShell, Bash, JavaScript, or Go.
  • Experience working with JSON and YAML.
  • Experience automating cybersecurity, infrastructure, compliance, or operational processes.
  • Experience with vulnerability scanning and vulnerability management technologies.
  • Experience with AWS, Azure, or GCP.
  • Ability to understand cloud and enterprise system architectures and evaluate security implications.
  • Ability to translate regulatory and cybersecurity requirements into technical engineering requirements.
  • Experience developing automation against AWS, Azure, or GCP APIs or SDKs.
  • Experience with Terraform or other Infrastructure as Code technologies.
  • Experience with Ansible or similar configuration management and automation technologies.
  • Experience with GitHub Actions, GitLab CI/CD, Jenkins, or Azure DevOps.
  • Experience with Docker and Kubernetes.
  • Experience integrating vulnerability scanners, SIEM, CSPM/CNAPP, GRC, and ticketing platforms.
  • Experience developing security dashboards and data pipelines.
  • Experience with automated testing frameworks and software engineering practices.
  • Experience with serverless architectures and event-driven automation.
  • Experience transforming NIST controls and security documentation into structured, machine-readable data.
  • Experience with Compliance as Code and Policy as Code technologies such as Open Policy Agent.
  • Experience implementing automated security evidence collection and continuous control validation.
  • Experience supporting FISMA, FedRAMP, DoD RMF, CMMC, or other federal cybersecurity programs.
  • Experience supporting initial and ongoing authorization processes.
  • Experience working with Security Control Assessors, Third Party Assessment Organizations, or government Authorizing Officials.
  • Experience developing or maintaining SSPs, POA&Ms, Security Assessment Reports, continuous monitoring documentation, and authorization artifacts.
  • Familiarity with federal security baselines, implementation guidance, and security assessment procedures.
  • CISSP, CGRC, CISM, CCSP, Security+, AWS Solution Architect or Security Specialty, GCP Cloud Architect or Security Engineer, or Certified Kubernetes Security Specialist certification.
Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
969 Employees
Year Founded: 2018

What We Do

Quantum Sky is a Reston, Virginia-based mission technology company, formerly Tyto Athene, that delivers secure, AI-enabled and quantum-ready capabilities to defense, intelligence, and federal civilian agencies. Its work spans enterprise IT, network engineering, cybersecurity, cloud, software, post-quantum cryptography, and applied quantum technologies, helping customers modernize critical systems, protect mission data, and achieve faster, more resilient decision-making across complex, high-consequence missions.

Similar Jobs

ServiceNow Logo ServiceNow

Global Partner Manager – Autonomous Workforce/IT, Deloitte

Artificial Intelligence • Cloud • HR Tech • Information Technology • Productivity • Software • Automation
Remote or Hybrid
Waltham, MA, USA
29000 Employees
126K-208K Annually

ServiceNow Logo ServiceNow

Global Partner Management - Global SI

Artificial Intelligence • Cloud • HR Tech • Information Technology • Productivity • Software • Automation
Remote or Hybrid
Waltham, MA, USA
29000 Employees
146K-241K Annually

GC AI Logo GC AI

Counsel

Artificial Intelligence • Legal Tech
In-Office or Remote
San Mateo, CA, USA
130 Employees
170K-225K Annually

Dynatrace Logo Dynatrace

Inside Sales Representative

Artificial Intelligence • Big Data • Cloud • Information Technology • Software • Big Data Analytics • Automation
Remote or Hybrid
Denver, CO, USA
5600 Employees
82K-100K Annually

Similar Companies Hiring

Kepler  Thumbnail
Artificial Intelligence • Fintech • Software
New York, New York
9 Employees
Onshore Thumbnail
Artificial Intelligence • Fintech • Software • Financial Services
New York, New York
60 Employees
Blee Thumbnail
Artificial Intelligence • Marketing Tech • Software • Productivity
US
15 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account