The future of aerospace and defense starts here.
Ursa Major was founded to revolutionize how America and its allies access and apply high-performance propulsion, from hypersonics to solid rocket motors, satellite maneuvering and launch. We design and deliver propulsion and defense systems that solve the most urgent and critical national security demands.
We are bringing a new model to space access: one in which every link in an enormous value chain isn’t limited by those around it. We design rocket engines and propulsion solutions.
Our products and technologies require an extraordinary team—one that will ensure the security of tomorrow’s technologies while deploying today’s best. We are an intrinsically motivated team with a passion for solving problems and empowering each other every day.
As a Senior Cybersecurity Engineer (Level 3) within our Digital Operations team, you won’t just be monitoring alerts or checking compliance boxes. You will be a hands-on problem solver and trusted advisor who helps our hardware, software, and manufacturing engineers navigate complex security environments—including Controlled Unclassified Information (CUI)—without slowing down the pace of innovation.
Reporting up through Digital Operations, you will sit at the intersection of DevOps, Digital Manufacturing, Software Engineering, Zero-Trust Networking, and IT. As Ursa Major scales from 380 to 500+ employees by EOY 2026, you will play a central role in evolving our CMMC Level 2 posture—leading the strategic transition from a cloud-only enclave to a high-performing hybrid enclave that integrates on-premise hardware, lab equipment, and manufacturing environments smoothly and securely.
Responsibilities:
- Stakeholder Enablement & Creative Risk Mitigation
- Partner directly with non-cyber employees (program managers, manufacturing engineers, test stand operators) to understand their workflows and help them safely manage CUI and new tools without fear or unnecessary friction.
- Approach security challenges with nuance rather than black-and-white rules. Find pragmatically secure pathways that satisfy federal requirements while keeping physical hardware engineering and CAD/CAM development moving forward.
- Design controls around engineering workflows to eliminate latency and operational bottlenecks, ensuring compliance feels like an accelerator rather than a roadblock.
- Hybrid CMMC L2 Expansion & Security Engineering
- Lead the technical implementation to strategically expand our CMMC Level 2 boundary beyond our cloud-only enclave—safely integrating on-premise infrastructure, physical testing equipment, and shop floor operations without expanding CMMC scope to the entire enterprise network.
- Manage and optimize technical security controls (SIEM, firewalls, zero-trust network access, identity platforms, vulnerability management) across both cloud and physical network environments.
- Evolve key compliance artifacts—including System Security Plans (SSPs), Risk Assessment Reports (RARs), and POA&Ms—ensuring physical site boundaries and hybrid hardware data flows are accurately documented.
- Leadership & Technical Ownership (Level 3)
- Act as a subject matter expert who tackles ambiguous, high-complexity security and network segmentation challenges with minimal supervision, taking full ownership from diagnosis to resolution.
- Work side-by-side with Zero-Trust Networking, DevOps, and IT to embed micro-segmentation and physical device controls directly into manufacturing environments and automated pipelines.
- Provide technical guidance and mentorship to junior staff and IT team members, translating complex federal regulations into clear, actionable advice for non-cyber stakeholders.
Minimum Qualifications:
- 4+ years of dedicated cybersecurity engineering experience in regulated or high-rigor environments.
- Bachelor’s degree in Cybersecurity, Information Technology, Computer Science, or equivalent practical experience.
- Deep familiarity with government contracting regulations, specifically NIST SP 800-171 and CMMC Level 2 framework requirements.
- Demonstrated experience implementing security controls in hybrid IT/OT or cloud-and-physical hardware environments (e.g., site-to-site VPNs, micro-segmentation, local device controls).
- Proven track record of working constructively with engineering and business stakeholders—focusing on trust-building, communication, and enabling business outcomes rather than simple ticket-taking.
Preferred Qualifications:
- Master’s degree in a technical field; active CISSP, CISM, CISA, or CRISC certifications.
- Direct experience participating in or maintaining a C3PAO CMMC assessment environment.
- Ability to obtain and maintain a U.S. Government Security Clearance.
Colorado law requires us to tell you the base compensation range of this role, which is $130,000 - $162,000, determined by your education, experience, knowledge, skills, and abilities. The salary range for this role is intentionally wide as we are evaluating individuals based on their unique experience and abilities to fit our needs. Most importantly, we are excited to meet you and see if you are a great fit for our team. What we can’t quantify for you are the exciting challenges, supportive team, and amazing culture we enjoy.
Classification: Full-Time, Exempt
Benefits Include: (Please note, Interns are not eligible for benefits)
- Unlimited PTO - Vacation, Sick, Personal, and Bereavement
- Paid Parental and Adoptive Leave
- Medical, Dental and Vision Insurance
- Tax Advantage Accounts (HSA/FSA)
- Employer Paid Short and Long Term Disability, Basic Life, AD&D
- Additional Benefit Options Including Voluntary Life and Emergency Medical Transport
- EAP Program
- Retirement Savings Plan - 401k with Company Match
- Equity Grants in the Company
How To Apply:
Interested candidates are encouraged to apply by filling out the application below and clicking "Submit Application". This position will be posted for a minimum of 3 days and will remain open until filled or adjusted based on the volume of applicants.
Skills Required
- 4+ years of dedicated cybersecurity engineering experience in regulated or high-rigor environments
- Bachelor's degree in Cybersecurity, Information Technology, Computer Science, or equivalent practical experience
- Deep familiarity with NIST SP 800-171 and CMMC Level 2 framework requirements
- Experience implementing security controls in hybrid IT/OT or cloud-and-physical hardware environments (e.g., site-to-site VPNs, micro-segmentation, local device controls)
- Proven track record of working constructively with engineering and business stakeholders to enable secure workflows
- Must be a U.S. Person (U.S. Citizen or Permanent Resident)
- Eligibility to obtain and maintain a U.S. Security Clearance
- Master's degree in a technical field
- Active CISSP, CISM, CISA, or CRISC certification
- Direct experience participating in or maintaining a C3PAO CMMC assessment environment
What We Do
Ursa Major was founded to address a critical shortfall in the U.S. industrial base and bring a new model to aerospace and defense systems: we design and manufacture the world’s leading propulsion systems for space, hypersonic applications, and missile systems. Our products and technologies require an extraordinary team – a team that will mold tomorrow’s technologies while deploying today’s best. We are an intrinsically motivated team that has a passion for solving problems and empowering each other every day to develop our skills, knowing that there is always room for growth.
Why Work With Us
We believe that each unique team member fuels the creativity necessary to build the world’s best propulsion systems. This is realized as a deeply held commitment to celebrating individuality, hiring talent across all backgrounds and experiences, building a culture of inclusion, and constantly challenging ourselves to improve.
Gallery
Ursa Major Offices
OnSite Workspace
Most employees work on-site with some positions allowing hybrid and/or remote work.





