Back to Jobs
Raft LLC
Development 1d ago

Senior Cybersecurity Engineer

Raft LLC
San AntonioSan Antonio
Remote with travel
$140,000.00 - $160,000.00
Senior-Level

Job Description

Key Skills Required

Master these to land this role

DevOps1h 38mFree Trial ✨
Start 10-Day Free Trial
GitLab CI/CDCybersecurityKubernetesSecurity-as-Code

Want to know if you're a match for this job?

Calculate My Match Score

Raft, a customer-obsessed non-traditional defense tech company, is seeking a Senior Cybersecurity Engineer to support a Department of War (DoW) program. The role focuses on ensuring Information Assurance (IA), cybersecurity, and security engineering requirements are integrated into platform DevSecOps pipelines, tooling, configurations, and software delivery processes.

The Senior Cybersecurity Engineer collaborates closely with the Pipeline Architect, Software Engineering Subject Matter Experts (SMEs), infrastructure/platform engineers, and government stakeholders to meet DoD cybersecurity thresholds without disrupting the software delivery lifecycle. This role involves translating security and compliance requirements into technical controls that can be automated, validated, and continuously enforced within the pipeline.

Key Responsibilities:

  • Ensure DoD IA and cybersecurity thresholds are met and incorporated into pipeline tooling, configurations, and workflows.
  • Translate DoD cybersecurity, RMF, and DevSecOps requirements into actionable technical requirements for engineering teams.
  • Design, implement, configure, and maintain automated security controls within CI/CD pipelines.
  • Integrate and maintain security tooling for SAST, DAST, software composition analysis (SCA), container scanning, secrets detection, dependency scanning, and vulnerability management.
  • Establish and enforce security gates and thresholds within GitLab CI/CD pipelines to prevent noncompliant or vulnerable software artifacts from progressing.
  • Support secure software supply chain practices, including artifact integrity, SBOM generation, vulnerability scanning, signing, provenance, and software attestations.
  • Integrate tools such as Fortify, SonarQube, Trivy, Twistlock/Prisma Cloud, NeuVector, Cosign/Sigstore, and similar security capabilities into automated workflows.
  • Review Kubernetes, container, GitLab Runner, infrastructure-as-code, and pipeline configurations for security vulnerabilities and configuration weaknesses.
  • Support vulnerability triage and remediation by working directly with software and platform engineering teams to determine severity, operational impact, remediation approaches, and acceptable mitigation strategies.
  • Develop and maintain security-as-code and policy-as-code approaches for consistent enforcement across environments.
  • Support compliance with the DoD DevSecOps Reference Design, NIST Risk Management Framework (RMF), NIST 800-53 controls, and applicable DoD cybersecurity requirements.
  • Support the collection and automation of security evidence required for authorization and continuous monitoring activities.
  • Partner with platform and application teams to ensure cybersecurity requirements support the UP continuous Authority to Operate (cATO) approach and Continuous Delivery/Continuous Deployment processes.
  • Identify cybersecurity risks associated with changes to pipeline architecture, platform baselines, infrastructure, and application delivery processes and recommend technical mitigations.
  • Develop security documentation, technical implementation guidance, configuration standards, and engineering best practices.
  • Participate in architecture reviews, technical discussions, troubleshooting sessions, and security assessments.

What We Are Looking For:

  • 3+ years of experience in Cybersecurity Engineering, DevSecOps, Platform Engineering, Cloud Security, Application Security, or a related technical discipline.
  • Hands-on experience implementing security capabilities within CI/CD pipelines, preferably GitLab CI/CD.
  • Experience with one or more application or container security technologies such as Fortify, SonarQube, Trivy, Twistlock/Prisma Cloud, NeuVector, or equivalent tools.
  • Experience with containerized environments and Kubernetes security concepts.
  • Experience identifying, assessing, and remediating software, container, infrastructure, or configuration vulnerabilities.
  • Working knowledge of DoD RMF, NIST SP 800-53, and DoD cybersecurity/Information Assurance requirements.
  • Understanding of DevSecOps principles and integration of security controls throughout the software development lifecycle.
  • Experience working with Git and infrastructure/configuration-as-code technologies such as Terraform, Ansible, Helm, or equivalent technologies.
  • Understanding of software supply chain security concepts, including SBOMs, artifact signing, provenance, vulnerability scanning, and attestations.
  • Ability to translate cybersecurity requirements into practical technical controls and communicate effectively with both cybersecurity and engineering stakeholders.

Highly Preferred:

  • Experience with GitLab, GitLab Runners, Argo CD, Kubernetes, Helm, SOPS, AWS/GovCloud, Platform One, or other DoD software factories, and DoD cATO environments.
  • Familiarity with Cosign/Sigstore, container registries, package managers, microservices architectures, Kubernetes admission controls, policy-as-code, and automated compliance evidence collection.
  • Experience supporting software delivery within IL4/IL5/IL6 DoD environments and working directly with ISSMs, ISSOs, security control assessors, Authorizing Officials, or government cybersecurity organizations.
  • DoD 8140/8570-compliant cybersecurity certification (e.g., Security+, CySA+, CASP+/SecurityX, CISSP, or equivalent).
  • Kubernetes, cloud security, or AWS certifications.

How would you rate this job post?

See what other professionals think about this role.

banner

Raft (operating at teamraft.com) is a technology platform engineered for mission clarity and operational success. Founded by Shubhi Mishra, Col (R) Frederick “Trey” Coleman, Dawn Pinto, and Danielle McCoy, Raft is a leading defense technology company dedicated to empowering the U.S. military and government agencies with cutting-edge AI/ML and data solutions. Under the hood, Raft delivers scalable AI, data integration, and resilience. This allows mission-focused enterprises to streamline their operations and achieve operational success. Backed by a $60 million strategic growth investment.

Safety First

  • Never pay for a job application.
  • Do not share sensitive bank info.
  • Verify the client before starting work.
Learn More