Senior Engineer

Posted 2 Days Ago
Be an Early Applicant
Hiring Remotely in San Antonio, TX, USA
In-Office or Remote
140K-160K Annually
Senior level
Artificial Intelligence • Big Data • Cloud • Cybersecurity • Defense
The Role
The Senior Cybersecurity Engineer embeds DoD cybersecurity, Information Assurance, RMF, and DevSecOps controls into CI/CD pipelines and software delivery processes. Responsibilities include integrating security scanning and compliance tools, enforcing GitLab security gates, securing Kubernetes and container environments, supporting software supply chain integrity, triaging vulnerabilities, automating authorization evidence, and enabling continuous Authority to Operate. The role collaborates with engineering and government stakeholders and develops security documentation, standards, and security-as-code practices.
Summary Generated by Built In

This is a U.S. based position. All of the programs we support require U.S. citizenship to be eligible for employment. All work must be conducted within the continental U.S.

Who we are:

Raft (https://TeamRaft.com) is a customer-obsessed non-traditional defense tech company dedicated to empowering U.S. military and government agencies with cutting-edge AI/ML and data solutions. We are a leader in autonomous data fusion and Agentic AI, with a purposeful focus on Distributed Data Systems, Platforms at Scale, and Complex Application Development. With headquarters in McLean, VA, our range of clients includes innovative federal and public agencies leveraging design thinking, cutting-edge tech stack, and cloud-native ecosystem. We build digital solutions that impact the lives of millions of Americans.

About the role:

The SeniorCybersecurity Engineer supports a DoW program by ensuring Information Assurance (IA), cybersecurity, and security engineering requirements are incorporated directly into the platform’s DevSecOps pipelines, tooling, configurations, and software delivery processes.
 
This role works closely with the Pipeline Architect, Software Engineering SMEs, infrastructure/platform engineers, and government stakeholders to ensure required DoD cybersecurity thresholds are met without creating unnecessary friction in the software delivery lifecycle. The Senior Cybersecurity Engineer helps translate security and compliance requirements into technical controls that can be automated, validated, and continuously enforced within the pipeline.
 
Key Responsibilities
  • Work with the Pipeline Architect and Software Engineering SMEs to ensure DoD IA and cybersecurity thresholds are met and built directly into pipeline tooling, configurations, and workflows.
  • Translate DoD cybersecurity, RMF, and DevSecOps requirements into actionable technical requirements for engineering teams.
  • Design, implement, configure, and maintain automated security controls within CI/CD pipelines.
  • Integrate and maintain security tooling for SAST, DAST, software composition analysis (SCA), container scanning, secrets detection, dependency scanning, and vulnerability management.
  • Establish and enforce security gates and thresholds within GitLab CI/CD pipelines to prevent noncompliant or vulnerable software artifacts from progressing through the delivery lifecycle.
  • Support secure software supply chain practices, including artifact integrity, SBOM generation, vulnerability scanning, signing, provenance, and software attestations.
  • Work with engineering teams to integrate tools such as Fortify, SonarQube, Trivy, Twistlock/Prisma Cloud, NeuVector, Cosign/Sigstore, and similar security capabilities into automated workflows.
  • Review Kubernetes, container, GitLab Runner, infrastructure-as-code, and pipeline configurations for security vulnerabilities and configuration weaknesses.
  • Support vulnerability triage and remediation by working directly with software and platform engineering teams to determine severity, operational impact, remediation approaches, and acceptable mitigation strategies.
  • Develop and maintain security-as-code and policy-as-code approaches that allow cybersecurity requirements to be consistently enforced across environments.
  • Support compliance with the DoD DevSecOps Reference Design, NIST Risk Management Framework (RMF), NIST 800-53 controls, and applicable DoD cybersecurity requirements.
  • Support the collection and automation of security evidence required for authorization and continuous monitoring activities.
  • Partner with platform and application teams to ensure cybersecurity requirements support the UP continuous Authority to Operate (cATO) approach and Continuous Delivery/Continuous Deployment processes.
  • Identify cybersecurity risks associated with changes to pipeline architecture, platform baselines, infrastructure, and application delivery processes and recommend technical mitigations.
  • Develop security documentation, technical implementation guidance, configuration standards, and engineering best practices.
  • Participate in architecture reviews, technical discussions, troubleshooting sessions, and security assessments.

What we are looking for: 

  • 3+ years of experience in Cybersecurity Engineering, DevSecOps, Platform Engineering, Cloud Security, Application Security, or a related technical discipline.
  • Hands-on experience implementing security capabilities within CI/CD pipelines, preferably GitLab CI/CD.
  • Experience with one or more application or container security technologies such as Fortify, SonarQube, Trivy, Twistlock/Prisma Cloud, NeuVector, or equivalent tools.
  • Experience with containerized environments and Kubernetes security concepts.
  • Experience identifying, assessing, and remediating software, container, infrastructure, or configuration vulnerabilities.
     
  • Working knowledge of DoD RMF, NIST SP 800-53, and DoD cybersecurity/Information Assurance requirements.
     
  • Understanding of DevSecOps principles and the integration of security controls throughout the software development lifecycle.
     
  • Experience working with Git and infrastructure/configuration-as-code technologies such as Terraform, Ansible, Helm, or equivalent technologies.
     
  • Understanding of software supply chain security concepts, including SBOMs, artifact signing, provenance, vulnerability scanning, and attestations.
     
  • Ability to translate cybersecurity requirements into practical technical controls and communicate effectively with both cybersecurity and engineering stakeholders.

Highly preferred:

  • Experience with GitLab, GitLab Runners, Argo CD, Kubernetes, Helm, SOPS, AWS/GovCloud, Platform One or other DoD software factories, and DoD cATO environments is preferred. Familiarity with Cosign/Sigstore, container registries, package managers, microservices architectures, Kubernetes admission controls, policy-as-code, and automated compliance evidence collection is also highly desirable.
     
  • Experience supporting software delivery within IL4/IL5/IL6 DoD environments and working directly with ISSMs, ISSOs, security control assessors, Authorizing Officials, or government cybersecurity organizations is a plus.
    Certifications
     
  • DoD 8140/8570-compliant cybersecurity certification appropriate to the position is preferred (e.g., Security+, CySA+, CASP+/SecurityX, CISSP, or equivalent).
     
  •  Kubernetes, cloud security, or AWS certifications are desirable.

Clearance Requirements:

  • Minimum active Secret Clearance required to start

Salary Range: $140,000.00 - $160,000.00

Work Type:

  • Remote with a preference for candidates based in San Antonio, TX
  • Travel up to 35% to customer sites

What we will offer you: 

  • Highly competitive salary
  • Fully covered healthcare, dental, and vision coverage
  • 401(k) and company match
  • Take as you need PTO + 11 paid holidays
  • Education & training benefits
  • Generous Referral Bonuses
  • And More!

Our Vision Statement: 

We bridge the gap between humans and data through radical transparency and our obsession with the mission. 

Our Customer Obsession: 

We will approach every deliverable like it's a product. We will adopt a customer-obsessed mentality. As we grow, and our footprint becomes larger, teams and employees will treat each other not only as teammates but customers. We must live the customer-obsessed mindset, always. This will help us scale and it will translate to the interactions that our Rafters have with their clients and other product teams that they integrate with. Our culture will enable our success and set us apart from other companies.

How do we get there? 

Public-sector modernization is critical for us to live in a better world. We, at Raft, want to innovate and solve complex problems. And, if we are successful, our generation and the ones that follow us will live in a delightful, efficient, and accessible world where out-of-box thinking, and collaboration is a norm. 

Raft’s core philosophy is Ubuntu: I Am, Because We are. We support our “nadi” by elevating the other Rafters. We work as a hyper collaborative team where each team member brings a unique perspective, adding value that did not exist before. People make Raft special. We celebrate each other and our cognitive and cultural diversity. We are devoted to our practice of innovation and collaboration. 

We’re an equal opportunity employer. All applicants will be considered for employment without attention to race, color, religion, sex, sexual orientation, gender identity, national origin, veteran or disability status.

Skills Required

  • 3+ years of experience in cybersecurity engineering, DevSecOps, platform engineering, cloud security, application security, or a related technical discipline
  • Hands-on experience implementing security capabilities within CI/CD pipelines, preferably GitLab CI/CD
  • Experience with application or container security technologies such as Fortify, SonarQube, Trivy, Twistlock/Prisma Cloud, NeuVector, or equivalent
  • Experience with containerized environments and Kubernetes security concepts
  • Experience identifying, assessing, and remediating software, container, infrastructure, or configuration vulnerabilities
  • Working knowledge of DoD RMF, NIST SP 800-53, and DoD cybersecurity or Information Assurance requirements
  • Understanding of DevSecOps principles and integration of security controls throughout the software development lifecycle
  • Experience working with Git and infrastructure or configuration-as-code technologies such as Terraform, Ansible, Helm, or equivalent
  • Understanding of software supply chain security, including SBOMs, artifact signing, provenance, vulnerability scanning, and attestations
  • Ability to translate cybersecurity requirements into practical technical controls and communicate effectively with cybersecurity and engineering stakeholders
  • Experience with GitLab, GitLab Runners, Argo CD, Kubernetes, Helm, SOPS, AWS/GovCloud, Platform One, or DoD software factories
  • Familiarity with Cosign/Sigstore, container registries, package managers, microservices architectures, Kubernetes admission controls, policy-as-code, and automated compliance evidence collection
  • Experience supporting software delivery within IL4, IL5, or IL6 DoD environments and working with ISSMs, ISSOs, security control assessors, Authorizing Officials, or government cybersecurity organizations
  • DoD 8140/8570-compliant cybersecurity certification such as Security+, CySA+, CASP+/SecurityX, CISSP, or equivalent
  • Kubernetes, cloud security, or AWS certification
  • U.S. citizenship
  • Active Secret clearance
Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
HQ: Reston, VA
200 Employees
Year Founded: 2018

What We Do

Raft is a digital consulting firm with niche expertise in the rapid delivery of modern, user-first, scalable, and data-intensive digital solutions. We accelerate the missions of our federal partners through human-centered design (HCD) and agile development practices, bringing deep technical expertise in DevSecOps, Kubernetes management, cloud-native microservice architectures, and secure, open source delivery. We put our people and our culture first. We work with some of the smartest, hardest working experts in their field. We owe it to them to make sure our team is free of meaningless restrictions and internal politics so they can focus on what they love, finding innovative solutions. We build off the Open-Source and resist vendor lock in. That way you’re not paying us to reinvent the wheel, our solutions play nice with others and are always adaptable. We know digital innovation doesn’t always operate during bank hours, so neither do we. (It's also why we don’t dress like bankers.) We aren’t afraid to go the extra mile or put in the extra time to find a solution. We get it right the first time; we won’t waste our time (and your money) trying to fix something that’s fundamentally broken. It’s kind of like making an exceptional cup of coffee, if the beans are roasted wrong, it doesn’t matter how much pumpkin spice you dump in your cup, it’s still not going to taste great. And above all else we’re up for a challenge; it’s in our DNA. Ask us about something that’s never been done, or better yet something that can’t be done, and we’ll find a way to do it. It’s just who we are. If you need a partner that’s looking toward the future and not the past, don’t go traditional, go Raft.

Why Work With Us

Raft partners with public agencies to solve hard complex problems that impact the lives of millions of Americans. We work hard to make it easy for humans to connect with data.

Gallery

Gallery

Similar Jobs

NetBox Labs Logo NetBox Labs

Senior Engineer

Cloud • Software
Remote
US
125 Employees
180K-195K Annually

CDW Logo CDW

Senior Engineer

Information Technology
Remote or Hybrid
US
15100 Employees
107K-150K Annually

Engine Logo Engine

Senior GTM Engineer

Consumer Web • Software • Travel
Easy Apply
Remote
United States
1000 Employees
135K-187K Annually

AlertMedia Logo AlertMedia

Senior Software Engineer

Artificial Intelligence • Cloud • Information Technology • Security • Social Impact • Software
Easy Apply
Remote or Hybrid
2 Locations
450 Employees

Similar Companies Hiring

Kepler  Thumbnail
Artificial Intelligence • Fintech • Software
New York, New York
9 Employees
Onshore Thumbnail
Artificial Intelligence • Fintech • Software • Financial Services
New York, New York
60 Employees
Blee Thumbnail
Artificial Intelligence • Marketing Tech • Software
New York, New York
30 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account