Sr Cyber Security Engineer

constelliscareers

United States

Remote

USD 140,000 - 190,000

Full time

11 days ago
Application generator

Stand out for this role — generate a tailored resume and cover letter in about a minute.

Get past ATS filters

Benefits offered by this job

Comprehensive benefits package
Flexible remote work environment
Professional development opportunities

Job summary

Constellis is seeking a Senior Cyber Security Engineer to bridge compliance and engineering, own the security workstream end-to-end, and embed automation into CI/CD pipelines for the LEXSO platform.

You will work with backend and frontend engineers to harden microservices, drive risk remediation, and report status to leadership while maintaining security controls per RMF/NIST standards.

Qualifications

  • 8+ years of experience in Cyber Security Engineering or DevSecOps.
  • Proven track record of achieving ATO for a software system in a DoD/Federal environment.
  • Hands-on RMF, NIST 800-53, and DISA STIGs experience.
  • Scripting proficiency (Python, Bash) for automation.
  • Experience with vulnerability scanning tools (ACAS/Nessus, SonarQube, Burp Suite).
  • Strong Linux security knowledge (SELinux, iptables, hardening).
  • CI/CD and Container Security experience (GitLab CI, Jenkins, Docker/K8s).
  • Ability to own security workstreams end-to-end and report to leadership.

Responsibilities

  • Own the LEXSO cybersecurity program end-to-end from gap identification to implementation tracking.
  • Report cyber risk posture and remediation progress to leadership in actionable terms.
  • Define and maintain the cybersecurity requirements backlog and progress cadence.
  • Lead RMF execution to achieve and maintain ATO for the LEXSO platform.
  • Implement security controls per NIST SP 800-53 and DoD SRG/STIGs.
  • Generate artifacts for eMASS (SSPs, POAMs, SARs) and maintain them.
  • Conduct vulnerability assessments using ACAS and SCC for gaps.
  • Integrate SAST/DAST security testing into GitLab/GitHub CI/CD pipelines.
  • Develop scripts (Python/Bash/Ansible) to automate patching on Linux servers.
  • Implement container security scans for Docker/Kubernetes environments.

Skills

Cyber Security Engineering
DevSecOps
RMF
NIST 800-53
Bash/Python scripting
CI/CD
Container Security
DoD/Federal environments

Education

Bachelor's degree in Computer Science or related field

Tools

ACAS/Nessus
SonarQube
Burp Suite
GitLab CI
Jenkins
Kubernetes
Docker

Job description

Position Overview

The Senior Cyber Security Engineer will bridge the gap between \"Compliance\" and \"Engineering.\" You will not just audit the system, you will help build it securely and own the cybersecurity workstream end-to-end. This role is responsible for achieving Authority to Operate (ATO) under DoD Risk Management Framework (RMF) standards among other federal certifications while embedding security automation directly into our CI/CD pipelines, and reporting program status and risk directly to LEXSO leadership. You will work side-by-side with backend and frontend engineers to harden the microservices architecture against evolving threats, and you will independently identify security gaps, drive architectural design decisions and shepherd remediation to completion..


Responsibilities


  • Own the LEXSO cybersecurity program end-to-end – from gap identification through architectural design to implementation tracking

  • Report cyber risk posture and remediation progress; translate technical findings into terms leadership can act on

  • Define and maintain the cybersecurity requirements backlog and progress-tracking cadence

  • Lead the technical execution of the RMF process to achieve and maintain Authority to Operate (ATO) for the LEXSO platform

  • Implement security controls in accordance with NIST SP 800-53 and DoD SRG/STIGs

  • Generate and maintain artifacts required for eMASS, including SSPs, POAMs, and SARs

  • Conduct self-assessments using ACAS (Nessus) and SCAP Compliance Checker (SCC) to identify vulnerabilities

  • Integrate automated security testing (SAST/DAST) tools (e.g., SonarQube, OWASP ZAP) into the GitLab/GitHub CI/CD pipeline

  • Develop scripts (Python, Bash, Ansible) to automate patching and configuration management for Linux (RHEL/Ubuntu) servers

  • Implement Container Security scanning for Docker/Kubernetes environments to detect vulnerabilities before deployment

  • Enforce \"Security as Code\" principles using Terraform or Helm charts

  • Analyze vulnerability scan results and write the code/scripts to remediate findings (e.g., fixing SSH configurations, patching libraries, hardening NGINX)

  • Harden APIs and microservices by implementing secure authentication (OAuth2/JWT/mTLS) and encryption standards (FIPS 140-2)

  • Respond to zero-day threats and CVEs by rapidly deploying hotfixes to the production environment

  • Conduct threat modeling sessions with the engineering team to identify attack vectors in the multi-sensor architecture

  • Design and implement secure logging and auditing pipelines (ELK Stack/Splunk) to meet audit requirements

  • Advise on the secure architecture for integrating third‑party sensors (LiDAR, Radar) and IoT devices

  • Work is typically based in a remote working environment and subject to frequent interruptions. Business work hours are Monday‑Friday from 8:00 am to 5:00 pm, however some extended or weekend hours may be required.

  • Other duties as assigned


Qualifications


  • 8+ years of experience in Cyber Security Engineering or DevSecOps.

  • Proven track record of achieving ATO (Authority to Operate) for a software system in a DoD/Federal environment

  • Hands‑on experience with RMF, NIST 800-53, and DISA STIGs

  • Proficiency in scripting languages (Python, Bash) for automation

  • Experience with vulnerability scanning tools (ACAS/Nessus, SonarQube, Burp Suite)

  • Strong knowledge of Linux Security (SELinux, iptables, hardening)

  • Experience with CI/CD tools (GitLab CI, Jenkins) and Container Security (Docker/K8s)

  • Demonstrated ability to work autonomously — identify security gaps, drive architectural design decisions, and track implementation through to completion

  • Experience communicating technical findings and program status to executive leadership; able to translate risk and remediation into terms leadership can act on

  • Track record of ownership over requirements definition and progress reporting for cybersecurity workstreams

  • CISSP, CASP+, or Security+ CE (Required)

  • Active Secret Security Clearance

  • Bachelor’s degree in Computer Science, Cyber Security, or related technical discipline.

  • Preferred Experience:

    • Experience securing cloud environments (AWS GovCloud / Azure Government)

    • Experience with FedRAMP authorization processes

    • Familiarity with \"Zero Trust\" architecture principles

    • Previous experience as a Software Developer before moving into Security

    • Prior experience as a technical lead or senior individual contributor with direct exposure to stakeholders



BENEFITS

Constellis offers a comprehensive, total rewards package that includes competitive compensation and a flexible benefits package that reflect its commitment to creating a diverse and supportive workplace.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Full Stack Developer
Full Stack Developer

constelliscareers • Town of Florida (NY)

Remote
USD 120,000 - 160,000
Competitive pay
Flexible benefits
Diversity-friendly workplace
Cyber Technical Engineer
Cyber Technical Engineer

Technomics, Inc. • Arlington (VA)

On-site
USD 80,000 - 100,000
Cyber Systems Security Engineering Asc Mgr - L4
Cyber Systems Security Engineering Asc Mgr - L4

Lockheed Martin • King of Prussia (PA)

On-site
USD 136,000 - 252,000
Medical Insurance
Dental Insurance
Vision Insurance
+9
Senior Cyber Security Engineer — RMF/ATO Leader (Remote)
Senior Cyber Security Engineer — RMF/ATO Leader (Remote)

constelliscareers • United States

Remote
USD 140,000 - 190,000
Comprehensive benefits package
Flexible remote work environment
Professional development opportunities
Cyber Software Eng Stf - E4
Cyber Software Eng Stf - E4

Lockheed Martin • King of Prussia (PA)

On-site
USD 136,000 - 252,000
Medical
Dental
Vision
+2
Cyber Systems Security Engineering Sr Stf - E5
Cyber Systems Security Engineering Sr Stf - E5

Lockheed Martin • Maryland

On-site
USD 167,000 - 310,000
401(k) match
Paid time off
Flexible work arrangements
ME00672-Lead Information Security Officer (ISSO)
ME00672-Lead Information Security Officer (ISSO)

Momentum Engineering, Inc • Washington, Northern (KY)

On-site
USD 140,000 - 220,000
Paid holidays
PTO
Group medical plan
+4
ME00672-Lead Information Security Officer (ISSO)
ME00672-Lead Information Security Officer (ISSO)

Momentum Engineering, Inc. • Washington

On-site
USD 150,000 - 210,000
11 paid holidays
3 weeks PTO (min)
Medical plan
+4
Cybersecurity Engineer 3
Cybersecurity Engineer 3

Base-2 Solutions • Reston (VA)

On-site
USD 150,000 - 190,000
Salary & bonuses
Company-paid benefits
401(k) retirement plan
+2
Lead Cybersecurity Engineer
Lead Cybersecurity Engineer

Accelint • San Diego (CA)

On-site
USD 130,000 - 165,000
Paid Time Off
Paid Company Holidays
Optional HSA and FSA
+4