Cybersecurity Engineer - DevOps

Sphera Solutions, Inc.

Northern (KY)

Hybrid

USD 112,000 - 178,000

Full time

3 days ago
Be an early applicant
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Benefits offered by this job

Medical Insurance
Dental Insurance
Vision Insurance
401(k) Retirement Plan with Company匹s

Job summary

Sphera Solutions, Inc. is seeking a Cybersecurity Engineer - DevOps to lead security in federal and DoD environments. You will own RMF/ATO lifecycle, implement STIGs, and drive vulnerability remediation within DevOps pipelines.

The role emphasizes FedRAMP/FISMA compliance, SAST/DAST/SCA scanning, and integration of security controls into CI/CD processes. U.S. citizenship and active clearance are required.

Qualifications

  • Experience supporting RMF/ATO lifecycle for federal or DoD systems.
  • Proficiency applying STIGs using DISA-approved tools.
  • Strong understanding of FedRAMP Moderate and FISMA controls.

Responsibilities

  • Lead cybersecurity for software in federal and DoD environments ensuring compliance.
  • Execute RMF activities and document ATO for federal/DoD systems.
  • Integrate security tooling into CI/CD pipelines and automate checks.

Skills

RMF/ATO lifecycle
STIGs implementation
Vulnerability management
DevSecOps integration
SAST/DAST/SCA scanning
CI/CD security
NIST SP 800-53 Rev.5
FedRAMP/FISMA
PKI CAC/PIV
DoD/government environments

Education

Bachelor’s degree in CS/IS/Cv
DoD 8570/8140 IAT Level II+ Certification

Tools

Tenable.sc
Nessus
ACAS
SCC/STIG Viewer

Job description

## Cybersecurity Engineer - DevOpsApply: US Remote: Full time: Posted Today: R106099Sphera is a leading global provider of enterprise software and services that enables companies to manage and optimize their environmental, health, safety and sustainability. Our mission is to create a safer, more sustainable and productive world.Sphera is a portfolio company of Blackstone, a U.S.-based alternative asset investment company that focuses on private equity, technology and innovation, and more. Blackstone businesses succeed through strong partnerships, a personalized approach and a commitment to exceptional performance with uncompromising integrity. Sphera and Blackstone are leaders in the Environmental, Social and Governance (ESG) space.We are guided by our core values of Customer Centricity, Accountability, Bias to Action, Innovation, and Collaboration. These values help us recruit the right talent to join our rapidly expanding team around the globe. It is important to us that each and every Spherion is not only eager to challenge themselves and knows how to get work done but is an awesome addition to our company culture.## POSITION SUMMARYThis role will be pivotal in advancing the company's mission of delivering secure, reliable, and innovative software solutions for U.S. government and DoD clients. The Cybersecurity Engineer serves as the resident security subject-matter expert embedded within the DevOps squad, owning the security compliance posture for software deployed in federal, DoD, and other highly regulated secure environments. The ideal candidate brings direct, hands-on experience operating within secure federal technology environments and a strong working knowledge of the security frameworks, tooling, and authorization processes that govern government-hosted systems. This individual will drive RMF/ATO lifecycle management, STIG implementation, vulnerability remediation, and DevSecOps integration across Sphera's product lines, ensuring that all systems maintain continuous compliance and readiness for deployment in secure government operating environments.**KEY RESPONSIBILITIES*** Lead cybersecurity for software deployed in secure federal and DoD environments, ensuring compliance with applicable government security policies, access requirements, and accreditation expectations.* Execute RMF activities, including system categorization, security control selection, implementation, assessment, and ATO documentation for federal or DoD-hosted systems.* Implement, configure, and validate STIGs across layers using DISA-approved or equivalent government security tooling.* Mitigate OWASP Top 10 and application-layer vulnerabilities across services.* Monitor security controls, scan vulnerabilities, and audit systems, producing reports and coordinating remediation with development and DevOps.* Manage POA&Ms, coordinating with government security stakeholders, ISSMs, and internal teams to track and resolve open findings.* Support FedRAMP and FISMA compliance, aligning controls with NIST SP 800-53 Rev. 5.* Integrate security tooling and automated checks into CI/CD pipelines, advancing DevSecOps maturity.* Collaborate with engineers and the Principal Solutions Architect to conduct threat modeling, security design reviews, and application-level security assessments.* Maintain System Security Plans (SSPs), security architectures, and supporting ATO documentation packages in alignment with federal and DoD requirements.* Lead incident response activities for security events affecting systems deployed in secure government environments, coordinating with customer cybersecurity personnel and internal stakeholders.* Monitor SIEM alerts, analyze logs, and investigate anomalous activity.* Evaluate the security posture of third-party integrations, vendor tools, and emerging technologies for adoption in secure federal or DoD environments.* Embed security requirements into sprint planning, feature development, and release processes with the TPM, engineering squads, and product owners.* Stay informed on evolving federal, DoD, DISA, and agency-specific security policies, DISA guidance updates, and emerging threats, and proactively communicate their impact to the engineering organization.## QUALIFICATIONS & EXPERIENCE* U.S. citizen required; active DoD security clearance or ability to obtain and maintain one due to secure federal enclave access.* Minimum 3-5 years of hands-on cybersecurity experience in a federal, DoD or similarly regulated secure environments.* Strong working knowledge of secure federal or DoD environments, including segmented networks, access control, approved software baselines, and applicable security requirements.* Experience supporting or leading RMF processes, including ATO package preparation and submission for federal or DoD systems.* Proficiency in applying STIGs using DISA-approved tools (SCC, STIG Viewer, Nessus/ACAS) or comparable vulnerability and compliance platforms.* Solid understanding of FedRAMP Moderate and FISMA compliance, with ability to map security controls to NIST SP 800-53 Rev. 5.* Experience with vulnerability management tools (e.g., Tenable.sc, Nessus, ACAS) in federal or DoD environments.* Familiarity with enterprise security tools including SIEM, IDS/IPS, and network security controls.* DevSecOps experience, including integrating SAST, DAST, and SCA scanning into CI/CD pipelines using Azure DevOps, Jenkins, or equivalent tools.* Familiarity with PKI, CAC/PIV authentication, and certificate management in federal or DoD environments.* Strong written and verbal communication skills to translate complex security findings into actionable guidance for engineering teams and brief government stakeholders.* DoD 8570/8140 compliant certification at IAT Level II or higher (e.g., CompTIA Security+, CISSP, CEH, CAP, or equivalent).* Bachelor’s degree in Computer Science, Information Security, Cybersecurity, or a related field, or equivalent practical experience.* Experience working in segmented networks with an understanding of federal, DoD, or similarly regulated infrastructure and security requirements.**PROFESSIONAL SKILLS*** Proven time management, organizational and follow-up skills to meet deadlines.* Work effectively, independently, and in a dynamic team environment.* Excellent interpersonal skills.* Must be willing to learn new technologies and processes as needed.## KEY COMPETENCIES**Secure Federal Environment Expertise**Strong working knowledge of secure federal, DoD, or similarly regulated operating environments, including security requirements, approval workflows, access constraints, and operational expectations — enabling the team to navigate complex government security landscapes with confidence and minimal disruption to delivery.**RMF and Compliance Execution**End-to-end ownership of RMF activities, from control implementation through ATO documentation, ensuring systems remain authorized and compliant throughout their lifecycle.**DevSecOps Integration**Embeds security as a continuous, automated discipline within engineering pipelines, reducing friction and shifting security left in the development lifecycle to maximize engineering velocity without sacrificing compliance.**Exceptional Stakeholder Communication and Collaboration**Foster strong partnerships by maintaining open, transparent, and effective communication with all stakeholders — including government program offices, ISSMs, and internal engineering teams — to ensure alignment and rapid resolution of security findings.**Incident Response and Threat Management**Rapid identification, escalation, and resolution of security events affecting systems deployed in secure government environments, with established protocols for coordinating with customer cybersecurity personnel.**Passion for Secure Innovation**Champion a security-first engineering culture that treats compliance not as a constraint but as a foundation for building reliable, mission-ready software for the DoD.**Pay:**$112,000.00 - $178,000.00 + Eligible for Variable Compensation PlanCommensurate with relevant qualifications and experience**Benefits:*** Medical, Dental, and Vision Insurance* Health Savings Account* Flexible Spending Account* 401(k) Retirement Plan with Company Match* Life and Disability Insurance* Critical Illness Insurance* Accident Insurance* Hospital Indemnity Insurance* Paid Time Off and Holidays* Flexible Working Schedule
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Remote DoD DevSecOps Cybersecurity Engineer
Remote DoD DevSecOps Cybersecurity Engineer

Sphera Solutions, Inc. • Northern (KY)

Hybrid
USD 112,000 - 178,000
Medical Insurance
Dental Insurance
Vision Insurance
+1
Technical Consultant- Cyber Security Engineering
Technical Consultant- Cyber Security Engineering

NextGenEnergyJobs • Vienna (VA), Northern (KY)

Hybrid
USD 110,000 - 160,000
System Engineer- Cyber Security Engineering Focus
System Engineer- Cyber Security Engineering Focus

NextGenEnergyJobs • Vienna (VA), Northern (KY)

Hybrid
USD 120,000 - 170,000
Health benefits
401(k) plan
Profit sharing
+1
Cybersecurity Engineer (FedRAMP) (US Remote)
Cybersecurity Engineer (FedRAMP) (US Remote)

Motorola Solutions • Northern (KY)

Hybrid
USD 90,000 - 100,000
Remote work
Principal Systems Security Engineer / Senior ISSM
Principal Systems Security Engineer / Senior ISSM

Sierra Nevada Corporation • Lone Tree (CO)

On-site
USD 165,000 - 227,000
Medical, dental, and vision plans
401(k) with 150% match up to 6%
3 weeks paid time off
+1
ME00672-Lead Information Security Officer (ISSO)
ME00672-Lead Information Security Officer (ISSO)

Momentum Engineering, Inc. • Washington

On-site
USD 150,000 - 210,000
11 paid holidays
3 weeks PTO (min)
Medical plan
+4
ME00672-Lead Information Security Officer (ISSO)
ME00672-Lead Information Security Officer (ISSO)

Momentum Engineering, Inc • Washington, Northern (KY)

Hybrid
USD 140,000 - 220,000
Paid holidays
PTO
Group medical plan
+4
DevSecOps Engineer
DevSecOps Engineer

Integrated Solutions for Systems, Inc. • City of Auburn (NY)

On-site
USD 110,000 - 150,000
Health benefits
Employee ownership
401(k) retirement plan
+2
Security Engineer
Security Engineer

The Squires Group • Washington

Hybrid
USD 96,000 - 138,000
PTO
Medical coverage
Dental coverage
+4
Cybersecurity Lead - Information System Security Manager (ISSM)
Cybersecurity Lead - Information System Security Manager (ISSM)

Sphinx Defense • Colorado Springs (CO)

On-site
USD 160,000 - 218,000
Competitive salary
Equity ownership
Profit sharing
+2