Sr Cyber Security Engineer

Posted Yesterday
Be an Early Applicant
Hiring Remotely in USA
Remote
Senior level
Information Technology • Professional Services • Security • Defense
The Role
Lead and own the end-to-end cybersecurity program: achieve and maintain DoD ATO (RMF), embed security automation into CI/CD, run vulnerability scanning and remediation, harden microservices and containers, produce eMASS artifacts, and report risk and progress to leadership.
Summary Generated by Built In
Job Summary & Responsibilities

Position Overview

The Senior Cyber Security Engineer will bridge the gap between "Compliance" and "Engineering." You will not just audit the system, you will help build it securely and own the cybersecurity workstream end-to-end. This role is responsible for achieving Authority to Operate (ATO) under DoD Risk Management Framework (RMF) standards among other federal certifications while embedding security automation directly into our CI/CD pipelines, and reporting program status and risk directly to LEXSO leadership. You will work side-by-side with backend and frontend engineers to harden the microservices architecture against evolving threats, and you will independently identify security gaps, drive architectural design decisions and shepherd remediation to completion..

 

Responsibilities

  • Own the LEXSO cybersecurity program end-to-end – from gap identification through architectural design to implementation tracking
  • Report cyber risk posture and remediation progress; translate technical findings into terms leadership can act on
  • Define and maintain the cybersecurity requirements backlog and progress-tracking cadence
  • Lead the technical execution of the RMF process to achieve and maintain Authority to Operate (ATO) for the LEXSO platform
  • Implement security controls in accordance with NIST SP 800-53 and DoD SRG/STIGs
  • Generate and maintain artifacts required for eMASS, including SSPs, POAMs, and SARs
  • Conduct self-assessments using ACAS (Nessus) and SCAP Compliance Checker (SCC) to identify vulnerabilities
  • Integrate automated security testing (SAST/DAST) tools (e.g., SonarQube, OWASP ZAP) into the GitLab/GitHub CI/CD pipeline
  • Develop scripts (Python, Bash, Ansible) to automate patching and configuration management for Linux (RHEL/Ubuntu) servers
  • Implement Container Security scanning for Docker/Kubernetes environments to detect vulnerabilities before deployment
  • Enforce "Security as Code" principles using Terraform or Helm charts
  • Analyze vulnerability scan results and write the code/scripts to remediate findings (e.g., fixing SSH configurations, patching libraries, hardening NGINX)
  • Harden APIs and microservices by implementing secure authentication (OAuth2/JWT/mTLS) and encryption standards (FIPS 140-2)
  • Respond to zero-day threats and CVEs by rapidly deploying hotfixes to the production environment
  • Conduct threat modeling sessions with the engineering team to identify attack vectors in the multi-sensor architecture
  • Design and implement secure logging and auditing pipelines (ELK Stack/Splunk) to meet audit requirements
  • Advise on the secure architecture for integrating third-party sensors (LiDAR, Radar) and IoT devices
  • Work is typically based in a remote working environment and subject to frequent interruptions. Business work hours are Monday-Friday from 8:00 am to 5:00 pm, however some extended or weekend hours may be required.
  • Other duties as assigned

 

Qualifications

  • 8+ years of experience in Cyber Security Engineering or DevSecOps.
  • Proven track record of achieving ATO (Authority to Operate) for a software system in a DoD/Federal environment
  • Hands-on experience with RMF, NIST 800-53, and DISA STIGs
  • Proficiency in scripting languages (Python, Bash) for automation
  • Experience with vulnerability scanning tools (ACAS/Nessus, SonarQube, Burp Suite)
  • Strong knowledge of Linux Security (SELinux, iptables, hardening)
  • Experience with CI/CD tools (GitLab CI, Jenkins) and Container Security (Docker/K8s)
  • Demonstrated ability to work autonomously — identify security gaps, drive architectural design decisions, and track implementation through to completion
  • Experience communicating technical findings and program status to executive leadership; able to translate risk and remediation into terms leadership can act on
  • Track record of ownership over requirements definition and progress reporting for cybersecurity workstreams
  • CISSP, CASP+, or Security+ CE (Required)
  • Active Secret Security Clearance
  • Bachelor’s degree in Computer Science, Cyber Security, or related technical discipline.
  • Preferred Experience:
    • Experience securing cloud environments (AWS GovCloud / Azure Government)
    • Experience with FedRAMP authorization processes
    • Familiarity with "Zero Trust" architecture principles
    • Previous experience as a Software Developer before moving into Security
    • Prior experience as a technical lead or senior individual contributor with direct exposure to stakeholders

BENEFITS

 

Constellis offers a comprehensive, total rewards package that includes competitive compensation and a flexible benefits package that reflect its commitment to creating a diverse and supportive workplace.

Skills Required

  • 8+ years of experience in Cyber Security Engineering or DevSecOps
  • Proven track record of achieving ATO for a software system in a DoD/Federal environment
  • Hands-on experience with RMF, NIST SP 800-53, and DISA STIGs
  • Proficiency in scripting languages: Python and Bash
  • Experience with vulnerability scanning tools (ACAS/Nessus, SonarQube, Burp Suite)
  • Strong knowledge of Linux security (SELinux, iptables) and hardening for RHEL/Ubuntu
  • Experience with CI/CD tools and pipelines (GitLab CI, GitLab/GitHub, Jenkins)
  • Experience with Container Security (Docker, Kubernetes)
  • Experience generating and maintaining eMASS artifacts (SSP, POAM, SAR)
  • Ability to integrate automated security testing (SAST/DAST) into CI/CD (e.g., SonarQube, OWASP ZAP)
  • Experience implementing security controls per FIPS 140-2 and secure authentication (OAuth2, JWT, mTLS)
  • Demonstrated ability to work autonomously and drive remediation to completion
  • Experience communicating technical findings and program status to executive leadership
  • Ownership over requirements definition and progress reporting for cybersecurity workstreams
  • CISSP, CASP+, or Security+ CE certification
  • Active Secret Security Clearance
  • Bachelor's degree in Computer Science, Cyber Security, or related technical discipline
  • Develop scripts and automation for patching/configuration management (Ansible, Python, Bash)
  • Implement container security scanning and 'Security as Code' (Terraform or Helm)
  • Analyze vulnerability scan results and remediate findings (e.g., SSH config, patching libraries, hardening NGINX)
  • Preferred: Experience securing cloud environments (AWS GovCloud / Azure Government)
  • Preferred: Experience with FedRAMP authorization processes
  • Preferred: Familiarity with Zero Trust architecture principles
  • Preferred: Previous experience as a Software Developer
  • Preferred: Prior experience as a technical lead or senior individual contributor

Constellis Compensation & Benefits Highlights

The following summarizes recurring compensation and benefits themes identified from responses generated by popular LLMs to common candidate questions about Constellis and has not been reviewed or approved by Constellis.

  • Leave & Time Off Breadth Structured PTO starting around 15 days per year, increasing with tenure, plus 12 company holidays establishes a predictable time-off baseline. This design provides clear accrual growth with tenure.
  • Retirement Support A 401(k) is available at hire for eligible employees with contributions adjustable at any time. This offers accessible retirement saving even as terms may differ under collective bargaining agreements.
  • Career-Linked Recognition & Rewards Programs include short-term incentive pay, SPOT awards, and an annual Employee Excellence Award of $5,000. These mechanisms add cash recognition beyond base pay when available.

Constellis Insights

Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
HQ: Herndon, VA
7,000 Employees
Year Founded: 2010

What We Do

Constellis is the largest and most diverse non-financial risk management company in the United States, providing operational support and risk management services to safeguard people and infrastructure globally.

Similar Jobs

Federal Reserve Bank of Boston Logo Federal Reserve Bank of Boston

Security Engineer

Fintech • Information Technology • Payments • Sharing Economy • Financial Services • Cryptocurrency
Remote
USA
1200 Employees
150K-224K Annually

CSC Logo CSC

Security Engineer

Fintech • Legal Tech • Software • Financial Services • Cybersecurity • Data Privacy
Remote or Hybrid
Wilmington, DE, USA
8500 Employees

OIP Insurtech Logo OIP Insurtech

Business Analyst

Artificial Intelligence • Information Technology • Insurance
Remote
United States
1200 Employees
90K-110K Annually

ServiceNow Logo ServiceNow

Technical Readiness & Communities Director

Artificial Intelligence • Cloud • HR Tech • Information Technology • Productivity • Software • Automation
Remote or Hybrid
Phoenix, AZ, USA
29000 Employees

Similar Companies Hiring

NODA AI Thumbnail
Artificial Intelligence • Information Technology • Software • Cybersecurity
Sydney, AU
54 Employees
Golden Pet Brands Thumbnail
Digital Media • eCommerce • Information Technology • Marketing Tech • Pet • Retail • Social Media
El Segundo, California
178 Employees
Outpost Space Thumbnail
Aerospace • Defense
US
24 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account