Cybersecurity Engineer, Product Security

CHAOS Industries

Washington (District of Columbia)

On-site

USD 110,000 - 190,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Medical, dental, and vision benefits 100% paid for by the company
401k (+ 50% company match up to 6% of pay)
Free daily lunch
Unlimited PTO

Job summary

CHAOS Industries is seeking a Cybersecurity Engineer focused on Product Security in Washington, D.C. to design and secure next-generation sensor platforms and software ecosystems. This role emphasizes collaboration with engineering teams to integrate security throughout the product lifecycle.

The ideal candidate has 5+ years of experience in cybersecurity, strong analytical skills, and the ability to operate in a fast-paced environment. The position offers a competitive salary range of $110,000 to $190,000, along with extensive health benefits and perks.

Qualifications

  • 5+ years of experience in cybersecurity engineering, product security, application security, or related engineering roles.
  • Experience with software security design and secure system architecture principles.
  • Hands-on experience conducting threat modeling and cybersecurity risk assessments.

Responsibilities

  • Design and implement secure software and hardware system architectures.
  • Conduct architecture reviews to identify security risks.
  • Support cybersecurity compliance initiatives and product authorization efforts.

Skills

Cybersecurity engineering
Secure system architecture
Threat modeling
Cybersecurity risk assessments
Analytical skills
Technical communication

Education

5+ years of experience in relevant roles

Tools

RMF
NIST 800-53
Python
PowerShell
Bash

Job description

Cybersecurity Engineer, Product Security

Washington, District of Columbia, United States

Role Overview: We are seeking a Cybersecurity Engineer focused on Product Security to help design, assess, and secure our next-generation sensor platforms and supporting software ecosystems. This role will work closely with Software Engineering, Embedded Systems, Hardware Engineering, Infrastructure, and Program teams to ensure security is integrated throughout the product lifecycle — from architecture and development through deployment and operational support.

The ideal candidate has experience securing complex software and hardware systems within defense, aerospace, or other highly regulated environments. This individual will lead software security architecture efforts, perform threat modeling and risk assessments, support compliance initiatives, and help establish secure engineering standards across the organization.

This is a highly collaborative and hands‑on role with direct impact on the security and resiliency of mission‑critical technologies deployed in operational environments.

Responsibilities
  • Product Security Engineering
    • Design and implement secure software and hardware system architectures for mission‑critical platforms and supporting infrastructure
    • Partner with engineering teams to integrate security requirements throughout the software development lifecycle (SDLC)
    • Conduct architecture reviews and identify security risks across software, embedded, cloud, and hardware systems
    • Develop secure design standards, engineering guidance, and product security best practices
    • Support secure development initiatives including code review, dependency management, secrets management, and vulnerability remediation
  • Lead threat modeling exercises for software, embedded systems, hardware platforms, and supporting infrastructure
  • Conduct cybersecurity risk assessments for products, systems, and operational environments
  • Identify attack surfaces, trust boundaries, and potential exploitation paths
  • Work with engineering teams to prioritize and remediate identified security risks
  • Develop mitigation strategies for cybersecurity threats impacting deployed systems and sensitive technologies
  • Compliance & Security Authorization
    • Support cybersecurity compliance initiatives and product authorization efforts including:
    • RMF (Risk Management Framework)
    • ATO (Authority to Operate)
    • Export control and regulated data handling requirements
    • Assist with development of system security documentation, security controls, SSPs, and assessment artifacts
    • Support internal and external security audits, assessments, and accreditation activities
    • Collaborate with government, customer, and program stakeholders on security requirements and authorization activities
  • Security Testing & Validation
    • Assist with security testing activities including vulnerability assessments, penetration testing coordination, and validation of remediation efforts
    • Support secure configuration and hardening efforts across software, operating systems, and embedded environments
    • Review software and system telemetry to identify potential security weaknesses or anomalous behavior
    • Collaborate with Security Operations and Infrastructure teams to improve enterprise and product security visibility
  • Cross‑Functional Collaboration
    • Work closely with Software, Embedded, Hardware, DevOps, and Infrastructure teams to balance security, performance, and operational requirements
    • Contribute to the development of scalable product security processes and governance
    • Support customer and internal security reviews related to deployed technologies and operational environments
    • Mentor engineering teams on secure development and security‑by‑design principles
Qualifications
  • 5+ years of experience in cybersecurity engineering, product security, application security, or related engineering roles
  • Experience with software security design and secure system architecture principles
  • Hands‑on experience conducting threat modeling and cybersecurity risk assessments
  • Knowledge of secure software development lifecycle (SSDLC) practices and application security concepts
  • Familiarity with cybersecurity frameworks and compliance standards including RMF, NIST 800‑53, NIST 800‑171, CMMC, DFARS
  • Experience supporting security authorization activities such as ATO processes and security documentation development, and eMASS
  • Understanding of cloud, endpoint, network, and identity security concepts
  • Strong analytical, troubleshooting, and technical communication skills
  • Ability to operate effectively in a fast‑paced startup environment
  • Must be a U.S. Citizen eligible for government facilities and sensitive information
  • Ability to obtain additional security clearances as required by contract
Preferred Requirements
  • Active Security Clearance
  • Experience supporting defense, aerospace, government contracting, or regulated technology environments
  • Experience securing embedded systems, sensor platforms, or edge computing technologies
  • Familiarity with export control requirements including ITAR and EAR
  • Experience with secure DevSecOps pipelines and automation practices
  • Experience with Microsoft GCC High environments and regulated cloud architectures
  • BIOS/UEFI security or development experience
  • Hardware security design experience
  • Trusted Platform Module (TPM), secure boot, cryptographic hardware, or supply chain security knowledge
  • Experience with scripting or automation using Python, PowerShell, or Bash
  • Security certifications such as CISSP, CSSLP, GSEC, Security+, or equivalent
Benefits
  • Health Benefits: Medical, dental, and vision benefits 100% paid for by the company
  • Additional benefits: 401k (+ 50% company match up to 6% of pay), FSA, HSA, life insurance, and more
  • Our Perks: Free daily lunch, ‘No meeting Fridays’, unlimited PTO, casual dress code
  • Compensation Components: Competitive base salaries, generous pre‑IPO stock option grants, relocation assistance, and (coming soon!) annual bonuses
  • Team Growth: 250 employees and counting across 5 global offices

Salary Range: $110,000 – $190,000

The stated compensation range reflects only the targeted base compensation range and excludes additional earnings such as bonus, equity, and benefits. If your compensation requirements fall outside of the range, we still encourage you to apply. The salary range for this role is an estimate based on a range of compensation factors, inclusive of base salary only. Actual salary offer may vary based on (but not limited to) work experience, education and/or training, critical skills, and/or business considerations.

As set forth in CHAOS Industries’s Equal Employment Opportunity policy, we do not discriminate on the basis of any protected group status under any applicable law.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Cybersecurity Engineer (Product Security)
Cybersecurity Engineer (Product Security)

CHAOS Industries • El Segundo (CA)

On-site
USD 110,000 - 190,000
Health benefits (100% paid)
401(k) with company match
Free daily lunch
+2
Cybersecurity Engineer, Product Security
Cybersecurity Engineer, Product Security

CHAOS Industries • San Francisco (CA)

On-site
USD 110,000 - 190,000
Free daily lunch
Unlimited PTO
401k with company match
Cybersecurity SOC Analyst II
Cybersecurity SOC Analyst II

CHAOS Industries • El Segundo (CA)

On-site
USD 110,000 - 160,000
Health benefits 100% covered
401k with company match
Free daily lunch
+2
Cybersecurity SOC Analyst II
Cybersecurity SOC Analyst II

CHAOS Industries • San Francisco (CA)

On-site
USD 110,000 - 160,000
Medical, dental, and vision benefits 100% paid by the company
401k with 50% company match
Free daily lunch
+2
Cloud Cybersecurity Engineer
Cloud Cybersecurity Engineer

CHAOS Industries • El Segundo (CA)

Hybrid
USD 130,000 - 180,000
Health Benefits
401k with company match
Free daily lunch
+1
DevSecOps Engineer
DevSecOps Engineer

CHAOS Industries • El Segundo (CA)

On-site
USD 110,000 - 160,000
Health benefits 100% paid
Free daily lunch
Unlimited PTO
DevSecOps - Software Engineer
DevSecOps - Software Engineer

CHAOS Industries • El Segundo (CA)

On-site
USD 140,000 - 220,000
Health benefits fully covered
401k with company match
Free daily lunch
+1
Cybersecurity Administrator, Data Loss Prevention
Cybersecurity Administrator, Data Loss Prevention

CHAOS Industries • El Segundo (CA)

On-site
USD 110,000 - 190,000
Health insurance
401k with company match
Free daily lunch
+2
Cloud DevSecOps Engineer - (Software Engineering Focused)
Cloud DevSecOps Engineer - (Software Engineering Focused)

3M HEALTHCARE • Hawthorne (CA)

On-site
USD 140,000 - 220,000
Health benefits 100% paid
401k with company match
Free daily lunch
+1
Staff Software Engineer
Staff Software Engineer

Chaos, Inc. • San Francisco (CA)

On-site
USD 190,000 - 260,000
Health benefits
401k with company match
Free daily lunch
+3