Senior Cybersecurity Engineer (Secret Clearance)
Job Description
Your Dream. Our Team.
About Rise8
Rise8 builds custom, secure software for government organizations, measuring success by impact: lives saved, time returned, and missions advanced.
We think big, start small, and scale fast with elite teams across product, design, and engineering to drive continuous delivery for critical missions.
We believe customer experience starts with employee experience, so we take care of our employees. Rise8 is where you’ll do the best work of your career—supported by a culture you won’t find anywhere else. We offer competitive pay and benefits, but what sets us apart is our commitment to autonomy, growth, and a culture rooted in kindness, candor, and continuous learning.
Certified as a Great Place to Work®, with 100% of employees saying they love working here, Rise8 is where bold ideas become real capabilities. Where mission meets meaning. And where fewer bad things happen because of bad software.
About You
- Are you a Senior Cybersecurity Engineer with expertise across multiple domains, including cloud security, containerization, secure software supply chain and compliance? Do you thrive in dynamic environments where collaboration, innovation, and secure delivery are top priorities? At Rise8, we’re looking for someone like you to lead the charge in securing complex systems, while ensuring client satisfaction across projects.
As a Senior Cybersecurity Engineer at Rise8, you will:
- Secure cloud-based environments by designing and implementing native security solutions using services.
- Drive Continuous RMF practices, automating control implementation and reporting through modern methodologies like Continuous Authorization to Operate.
- Automate provisioning and configuration of IT environments
- Implement and manage security measures like firewalls, IDS/IPS, vulnerability scanning, encryption, and ICAM solutions.
- Secure containerized and large-scale cloud production systems while responding effectively to security incidents.
- Apply advanced security concepts to protect systems, including threats, vulnerabilities, encryption, boundary defense, and risk management.
- Establish and manage identity and access management policies, ensuring least-privilege access and cross-account role adherence.
- Create and maintain engineering artifacts, such as network diagrams, data flow diagrams, installation procedures, and operational manuals.
- Enforce cloud-native security best practices, leveraging frameworks like AWS’s Well-Architected Security Pillar
- Collaborate with cross-functional teams to integrate Zero Trust principles into the broader security posture, aligning with DoD policies such as the Risk Management Framework (RMF)
- Apply and operationalize RMF, FedRAMP, and DISA CC SRG controls, ensuring compliance with DoD Impact Levels.
- Collaborate with cross-functional teams to integrate lean and agile practices into secure development lifecycles.
- Contribute to the continuous improvement of DevSecOps practices, ensuring systems are secure, scalable, and compliant.
- Work in a dynamic, collaborative environment that supports your professional development.
Qualifications
- A background of 6-10 years of experience in cloud/platform operations or related roles, with a focus on implementing and maintaining secure and compliant systems in diverse environments.
- Must have experience securing CI/CD pipelines using various commercially available tools (i.e. Gitlab)
- Experience with dependency analysis across various software components
- Familiar with SLSA (Supply-chain Levels for Software Artifacts)
- Strong proficiency in securing AWS GovCloud and Azure GCC High environments, including applying security controls, conducting vulnerability scans, and ensuring compliance with DoD standards.
- Expertise in container orchestration, specifically Kubernetes, with a focus on implementing security best practices, ensuring container runtime protection, and automating vulnerability scanning.
- Expertise with monitoring and observability platforms, including integrating security monitoring tools and automating anomaly detection workflows.
- Proven experience in incident management and troubleshooting large-scale distributed systems, with a focus on mitigating security incidents and performing root cause analysis for vulnerabilities.
- Strong proficiency in Infrastructure as Code (IaC) tools, such as Terraform, including automating the implementation of security policies and controls within IaC pipelines.
- Subject Matter Expertise in Linux Operating Systems administration, with a focus on hardening techniques, patch automation, compliance enforcement and bash scripting languages (Python, Bash, PowerShell)
- Strong understanding of networking concepts and practical experience with securing technologies like Load Balancers, DNS, SSL, Firewalls, NAT, and NTP, including applying network-level security policies.
- Excellent communication skills to articulate security risks, advoc...
Is this company safe?
Ask Hyrizon AI to scan this company for potential red flags.
Safety First
- Never pay for a job application.
- Do not share sensitive bank info.
- Verify the client before starting work.