Constellis Logo

Constellis

Sr Cyber Security Engineer

Posted 18 Days Ago
Be an Early Applicant
Remote
Hiring Remotely in USA
Senior level
Remote
Hiring Remotely in USA
Senior level
Lead and own the end-to-end cybersecurity program: achieve and maintain DoD ATO (RMF), embed security automation into CI/CD, run vulnerability scanning and remediation, harden microservices and containers, produce eMASS artifacts, and report risk and progress to leadership.
The summary above was generated by AI
Job Summary & Responsibilities

Position Overview

The Senior Cyber Security Engineer will bridge the gap between "Compliance" and "Engineering." You will not just audit the system, you will help build it securely and own the cybersecurity workstream end-to-end. This role is responsible for achieving Authority to Operate (ATO) under DoD Risk Management Framework (RMF) standards among other federal certifications while embedding security automation directly into our CI/CD pipelines, and reporting program status and risk directly to LEXSO leadership. You will work side-by-side with backend and frontend engineers to harden the microservices architecture against evolving threats, and you will independently identify security gaps, drive architectural design decisions and shepherd remediation to completion..

 

Responsibilities

  • Own the LEXSO cybersecurity program end-to-end – from gap identification through architectural design to implementation tracking
  • Report cyber risk posture and remediation progress; translate technical findings into terms leadership can act on
  • Define and maintain the cybersecurity requirements backlog and progress-tracking cadence
  • Lead the technical execution of the RMF process to achieve and maintain Authority to Operate (ATO) for the LEXSO platform
  • Implement security controls in accordance with NIST SP 800-53 and DoD SRG/STIGs
  • Generate and maintain artifacts required for eMASS, including SSPs, POAMs, and SARs
  • Conduct self-assessments using ACAS (Nessus) and SCAP Compliance Checker (SCC) to identify vulnerabilities
  • Integrate automated security testing (SAST/DAST) tools (e.g., SonarQube, OWASP ZAP) into the GitLab/GitHub CI/CD pipeline
  • Develop scripts (Python, Bash, Ansible) to automate patching and configuration management for Linux (RHEL/Ubuntu) servers
  • Implement Container Security scanning for Docker/Kubernetes environments to detect vulnerabilities before deployment
  • Enforce "Security as Code" principles using Terraform or Helm charts
  • Analyze vulnerability scan results and write the code/scripts to remediate findings (e.g., fixing SSH configurations, patching libraries, hardening NGINX)
  • Harden APIs and microservices by implementing secure authentication (OAuth2/JWT/mTLS) and encryption standards (FIPS 140-2)
  • Respond to zero-day threats and CVEs by rapidly deploying hotfixes to the production environment
  • Conduct threat modeling sessions with the engineering team to identify attack vectors in the multi-sensor architecture
  • Design and implement secure logging and auditing pipelines (ELK Stack/Splunk) to meet audit requirements
  • Advise on the secure architecture for integrating third-party sensors (LiDAR, Radar) and IoT devices
  • Work is typically based in a remote working environment and subject to frequent interruptions. Business work hours are Monday-Friday from 8:00 am to 5:00 pm, however some extended or weekend hours may be required.
  • Other duties as assigned

 

Qualifications

  • 8+ years of experience in Cyber Security Engineering or DevSecOps.
  • Proven track record of achieving ATO (Authority to Operate) for a software system in a DoD/Federal environment
  • Hands-on experience with RMF, NIST 800-53, and DISA STIGs
  • Proficiency in scripting languages (Python, Bash) for automation
  • Experience with vulnerability scanning tools (ACAS/Nessus, SonarQube, Burp Suite)
  • Strong knowledge of Linux Security (SELinux, iptables, hardening)
  • Experience with CI/CD tools (GitLab CI, Jenkins) and Container Security (Docker/K8s)
  • Demonstrated ability to work autonomously — identify security gaps, drive architectural design decisions, and track implementation through to completion
  • Experience communicating technical findings and program status to executive leadership; able to translate risk and remediation into terms leadership can act on
  • Track record of ownership over requirements definition and progress reporting for cybersecurity workstreams
  • CISSP, CASP+, or Security+ CE (Required)
  • Active Secret Security Clearance
  • Bachelor’s degree in Computer Science, Cyber Security, or related technical discipline.
  • Preferred Experience:
    • Experience securing cloud environments (AWS GovCloud / Azure Government)
    • Experience with FedRAMP authorization processes
    • Familiarity with "Zero Trust" architecture principles
    • Previous experience as a Software Developer before moving into Security
    • Prior experience as a technical lead or senior individual contributor with direct exposure to stakeholders

BENEFITS

 

Constellis offers a comprehensive, total rewards package that includes competitive compensation and a flexible benefits package that reflect its commitment to creating a diverse and supportive workplace.

Similar Jobs

15 Days Ago
Remote or Hybrid
Senior level
Senior level
Fintech • Legal Tech • Software • Financial Services • Cybersecurity • Data Privacy
Lead design, deployment, and optimization of Cortex XSIAM detections and analytics. Develop XQL detections and threat hunts, build automated response playbooks, integrate security telemetry (endpoint, network, cloud, identity), collaborate with SOC and incident responders, mentor staff, and improve detection fidelity and MTTR at enterprise scale.
Top Skills: Active DirectoryAWSAzureAzure AdCortex XdrCrowdstrikeEdrGCPIamKqlMicrosoft DefenderPalo Alto Cortex XsiamPythonSIEMSoarSplXdrXqlXsoar
A Minute Ago
Remote or Hybrid
OH, USA
Mid level
Mid level
Financial Services
Develop and support secure, scalable full-stack applications using Java, Spring Boot, microservices, REST APIs, React, and AWS. Design architecture, write production code, troubleshoot systems, and collaborate across front-end, back-end, cloud, and platform teams. Apply agile SDLC practices, CI/CD, resiliency, security, and enterprise-approved AI-assisted development tools. Analyze data and system patterns to improve application quality, architecture, and engineering practices.
Top Skills: Amazon Ec2Amazon EksAmazon RdsAmazon S3AngularAWSAws LambdaCi/CdDockerJavaJavaScriptKafkaKubernetesMicroservicesReactRest ApisSpring BootSQL
10 Minutes Ago
Remote
California, USA
17-17 Hourly
Mid level
17-17 Hourly
Mid level
Fintech • Real Estate • Sales • Financial Services
Originates mortgage loans, builds referral relationships, develops a book of business, and represents Rocket Mortgage in the community. The role consults with clients, evaluates credit and financial documents, recommends appropriate loan products, educates borrowers, and supports applications through closing. Responsibilities also include resolving client concerns, generating leads, and maintaining knowledge of mortgage products and qualification requirements.
Top Skills: Mortgage OriginationNmls

What you need to know about the Austin Tech Scene

Austin has a diverse and thriving tech ecosystem thanks to home-grown companies like Dell and major campuses for IBM, AMD and Apple. The state’s flagship university, the University of Texas at Austin, is known for its engineering school, and the city is known for its annual South by Southwest tech and media conference. Austin’s tech scene spans many verticals, but it’s particularly known for hardware, including semiconductors, as well as AI, biotechnology and cloud computing. And its food and music scene, low taxes and favorable climate has made the city a destination for tech workers from across the country.

Key Facts About Austin Tech

  • Number of Tech Workers: 180,500; 13.7% of overall workforce (2024 CompTIA survey)
  • Major Tech Employers: Dell, IBM, AMD, Apple, Alphabet
  • Key Industries: Artificial intelligence, hardware, cloud computing, software, healthtech
  • Funding Landscape: $4.5 billion in VC funding in 2024 (Pitchbook)
  • Notable Investors: Live Oak Ventures, Austin Ventures, Hinge Capital, Gigafund, KdT Ventures, Next Coast Ventures, Silverton Partners
  • Research Centers and Universities: University of Texas, Southwestern University, Texas State University, Center for Complex Quantum Systems, Oden Institute for Computational Engineering and Sciences, Texas Advanced Computing Center

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account