Senior Cybersecurity GRC Engineer

Posted 3 Days Ago
Be an Early Applicant
Denver, CO, USA
In-Office
135K-169K Annually
Senior level
Artificial Intelligence • Hardware • Internet of Things • Robotics • Defense • Manufacturing
Airpower at the edge: Multi-mission aerial robotic systems built to deliver capability at scale
The Role
Build and mature PDW’s cybersecurity GRC program across enterprise, engineering, manufacturing, and business systems. Translate CMMC, NIST SP 800-171, ISO 27001, ITAR, and customer requirements into controls; manage risk assessments, documentation, evidence, audits, remediation, vulnerability management, and third-party risk. Configure and validate security tools, support incident response, improve endpoint, identity, cloud, network, and monitoring controls, and report security metrics to leadership. The role requires cross-functional collaboration with auditors, customers, vendors, and system owners.
Summary Generated by Built In

Performance Drone Works (PDW) is building the next generation of tactical robotic systems used across defense, national security, and public safety missions. We are building a new center of engineering excellence to design our new category of tactical robotic systems and the industrial capacity to deliver them, bringing decisive airpower into the hands of every operator. We are not here to make promises; we are here to deliver real systems with real capabilities for real missions.  
 
You will join a team of operators, engineers, and builders who solve hard problems with humility and focus. We design and produce multi-mission aerial systems that operators trust to perform in real-world conditions, reliably, repeatedly, and at scale. Our approach is grounded in operator-centered design, rapid iteration from field use, and U.S.-based manufacturing. We operate by a clear set of values: Mission First, Aim Farther, Own It, Win Together. This is how we build advantage and how we help protect our service members, our communities, and our country. 


Now, we’re entering a new phase of growth and are looking for a Senior Cybersecurity GRC Engineer to help build, operate, and mature PDW's cybersecurity and compliance program. This is a hands-on technical role for a cybersecurity practitioner who can translate requirements from CMMC, ISO 27001, ITAR, and customer obligations into practical controls - and personally help implement, validate, and improve those controls across the organization.

 

What You’ll Do

  • Serve as a senior technical contributor to PDW's cybersecurity governance, risk, and compliance program, helping define priorities, technical standards, control requirements, and roadmaps across enterprise IT, engineering, manufacturing, and business systems.
  • Lead and support readiness efforts for applicable compliance frameworks and customer requirements, including CMMC, NIST SP 800-171, ISO 27001, ITAR and export-control obligations, and other defense-industry security requirements.
  • Translate regulatory, contractual, and framework requirements into clear, actionable technical and administrative controls; partner with system owners to implement controls that are effective, sustainable, and appropriate for PDW's operating environment.
  • Own and continuously improve core GRC processes, including risk assessments, control assessments, system security plans, plans of action and milestones, evidence collection, policy and standard development, third-party risk, audit preparation, and remediation tracking.
  • Remain hands-on in cybersecurity operations: configure, administer, tune, and validate security tooling such as endpoint detection and response, identity and access management, email security, logging, security monitoring, and related controls.
  • Ensure standardized vulnerability-management processes are consistently followed across the organization, including asset coverage, scan cadence, remediation tracking, exception management, and evidence collection. Leverage platforms such as Tenable and related security tools to support compliance validation, audit evidence, risk reporting, and verification of remediation activities.
  • Partner with IT and engineering teams to secure endpoints, identity systems, cloud services, networks, collaboration platforms, and business applications through practical configuration, hardening, monitoring, and access-control improvements.
  • Support incident-response preparedness and execution, including developing playbooks, participating in investigations, coordinating technical response activities, documenting lessons learned, and improving controls after incidents.
  • Develop meaningful cybersecurity and compliance metrics for leadership, including risk trends, control maturity, audit readiness, vulnerability remediation, security-tool coverage, and outstanding corrective actions.
  • Work directly with internal stakeholders, external auditors, customers, assessors, and technology vendors to communicate PDW's security posture, answer evidence requests, and drive timely resolution of findings.
  • Build repeatable cybersecurity processes, technical baselines, policies, procedures, and evidence-collection mechanisms that enable PDW to scale while protecting sensitive, controlled, and export-controlled information.

 

Requirements

  • 7+ years of progressive experience in cybersecurity, information security, GRC, security engineering, IT security, or a related technical discipline, including meaningful hands-on experience operating cybersecurity controls and tools.
  • Bachelor's degree in Cybersecurity, Information Technology, Computer Science, Engineering, or a related discipline; equivalent relevant professional experience, technical training, and industry certifications will be considered in lieu of a degree.
  • Demonstrated experience implementing or assessing security programs against CMMC and/or NIST SP 800-171, including familiarity with assessment, evidence, and remediation expectations associated with defense-industry cybersecurity requirements.
  • Working knowledge of ISO 27001 and experience applying its control-based approach to a real-world information security management system.
  • Experience working in an environment subject to ITAR, export controls, controlled unclassified information, defense contracts, or similarly regulated and sensitive data environments.
  • Hands-on experience administering, configuring, or validating security tools such as EDR, endpoint-management tools, identity and access-management systems, SIEM and logging platforms, email-security tools, or cloud-security controls.
  • Familiarity with vulnerability-management platforms such as Tenable, Qualys, or Rapid7, including using scan results and platform reporting to gather compliance evidence, support risk assessments, validate control effectiveness, and track remediation.
  • Demonstrated ability to investigate technical issues, assess security configurations, validate control effectiveness, identify gaps, and work directly with system owners to remediate risk.
  • Experience developing and maintaining cybersecurity documentation, including system security plans, risk registers, policies, procedures, control narratives, audit evidence, and remediation plans.
  • Strong understanding of endpoint security, vulnerability management, identity and access management, least privilege, network security, logging and monitoring, incident response, encryption, asset management, and secure configuration.
  • Ability to independently translate ambiguous compliance or security requirements into pragmatic action plans; prioritize risk; communicate effectively with technical and non-technical stakeholders; and drive work through completion.
  • Must have the ability to obtain and maintain a U.S. Security Clearance. 

 

Preferred

  • Relevant certifications such as CISSP, CISM, CRISC, CISA, Security+, ISO 27001 Lead Implementer or Lead Auditor, Certified CMMC Professional, Certified CMMC Assessor, or similar credentials.
  • Experience supporting a CMMC assessment, ISO 27001 certification audit, NIST SP 800-171 assessment, customer security review, or government-contracting security evaluation.
  • Experience in aerospace, defense, robotics, manufacturing, or another highly technical and regulated environment.
  • Experience with Microsoft 365 and Azure security, Microsoft Defender, CrowdStrike, SentinelOne, Tenable, Jira, ServiceNow, SIEM platforms, or comparable technologies.
  • Experience building cybersecurity programs in a fast-growing organization where controls, systems, and processes are evolving rapidly.

 

Physical Requirements

The physical demands described here are representative of those that must be met to successfully perform the essential functions of the job. Ability to sit, stand, bend, reach, climb, and move about regularly throughout the day and lift / carry up to 25 pounds. Must have manual dexterity to operate standard office or manufacturing equipment. Must be physically capable of occasionally assisting with the setup, movement, and installation of computer, networking, or security-related equipment.

 

Work Environment

PDW will consider remote, hybrid, or on-site work arrangements for the right candidate. This role requires the use of standard office and computing equipment and close cross-departmental collaboration with both independent and team-based responsibilities. Occasional travel between PDW sites, partner locations, industry events, or other business locations may be required. Standard work hours are PDW's core business hours, with availability outside those hours as needed for significant cybersecurity incidents or operational priorities.


Benefits 

PDW values our team, and we offer a compensation package reflective of your experience and capabilities. Benefits include:

  • Comprehensive BCBS medical, dental, and vision coverage; 80% sponsored by the company.
  • Safe Harbor 401(K) with company match.
  • Paid Parental Leave.
  • On-site gym at our Denver, CO & Huntsville, AL locations.
  • Employer provided life insurance.
  • Robust Employee Assistance Program (EAP).
  • A work environment that encourages teamwork and innovation.
  • Competitive salary, generous paid time off (PTO), and flexible leave options.

 

EEO Statement 

PDW is an equal opportunity employer that upholds all federal and state non-discrimination laws. We ensure a fair and unbiased evaluation for employment for all qualified candidates regardless of race, color, religion, age, sex, sexual orientation, gender identity, national origin, marital status, medical condition, disability, genetic information, veteran status, or any other characteristic protected by law. 

Skills Required

  • 7+ years of progressive experience in cybersecurity, information security, GRC, security engineering, IT security, or a related technical discipline
  • Hands-on experience operating cybersecurity controls and tools
  • Bachelor's degree in Cybersecurity, Information Technology, Computer Science, Engineering, or a related discipline, or equivalent professional experience, training, and certifications
  • Experience implementing or assessing security programs against CMMC and/or NIST SP 800-171
  • Working knowledge of ISO 27001 and experience applying its control-based approach to an information security management system
  • Experience with ITAR, export controls, controlled unclassified information, defense contracts, or similarly regulated sensitive data
  • Hands-on experience administering, configuring, or validating EDR, endpoint-management, IAM, SIEM, logging, email-security, or cloud-security tools
  • Familiarity with vulnerability-management platforms such as Tenable, Qualys, or Rapid7
  • Ability to investigate technical issues, assess security configurations, validate control effectiveness, identify gaps, and remediate risk
  • Experience developing cybersecurity documentation including system security plans, risk registers, policies, procedures, control narratives, audit evidence, and remediation plans
  • Strong understanding of endpoint security, vulnerability management, IAM, least privilege, network security, logging and monitoring, incident response, encryption, asset management, and secure configuration
  • Ability to translate ambiguous requirements into action plans, prioritize risk, communicate with technical and non-technical stakeholders, and drive completion
  • Ability to obtain and maintain a U.S. Security Clearance
  • CISSP, CISM, CRISC, CISA, Security+, ISO 27001 Lead Implementer or Lead Auditor, Certified CMMC Professional, Certified CMMC Assessor, or similar certification
  • Experience supporting a CMMC assessment, ISO 27001 certification audit, NIST SP 800-171 assessment, customer security review, or government-contracting security evaluation
  • Experience in aerospace, defense, robotics, manufacturing, or another highly technical and regulated environment
  • Experience with Microsoft 365, Azure security, Microsoft Defender, CrowdStrike, SentinelOne, Tenable, Jira, ServiceNow, SIEM platforms, or comparable technologies
  • Experience building cybersecurity programs in a fast-growing organization
Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
HQ: Huntsville, Alabama
350 Employees
Year Founded: 2017

What We Do

The fight has changed. Capability that once depended on large, centralized systems is moving closer to the operator. Performance Drone Works (PDW) is a defense technology company building multi-mission aerial robotic systems for that reality. We are creating a new category of tactical robotic systems designed to bridge the gap between low-capability drones and high-end platforms. Just as important, we are building the industrial capacity to produce those systems at scale in the United States. Everything starts with the operator. We learn from real-world use, move quickly, and build systems designed to perform when the mission depends on them. Our mission is simple: put decisive airpower in the hands of every operator.

Why Work With Us

At PDW, you’ll build technology that matters. We’re a proven, mission-driven team of veterans, engineers and problem-solvers moving at startup speed to put decisive capabilities in the hands of those who serve. Ideas win, impact matters and your best work can make a difference from day one.

Gallery

Gallery

Similar Jobs

Chewy Logo Chewy

Client Concierge

eCommerce • Healthtech • Pet • Retail • Pharmaceutical
Hybrid
Fort Collins, CO, USA
17800 Employees
14-21 Hourly

Tapestry - Coach and Kate Spade Logo Tapestry - Coach and Kate Spade

Temporary Associate

eCommerce • Fashion • Retail • Sales • Wearables • Design
Hybrid
Thornton, CO, USA
16000 Employees
15-20 Hourly
Remote or Hybrid
US
15100 Employees
127K-177K Annually

Micron Technology Logo Micron Technology

Solutions Architect

Artificial Intelligence • Hardware • Information Technology • Machine Learning
In-Office
3 Locations
45000 Employees
148K-308K Annually

Similar Companies Hiring

Revel Thumbnail
Aerospace • Hardware • Robotics • Software
Marina Del Rey, California
60 Employees
Blee Thumbnail
Artificial Intelligence • Marketing Tech • Software
New York, New York
30 Employees
Vega Thumbnail
Artificial Intelligence • Automotive • Insurance • Transportation
US
43 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account