it job board logo
  • Home
  • Find IT Jobs
  • Register CV
  • Register as Employer
  • Contact us
  • Career Advice
  • Recruiting? Post a job
  • Sign in
  • Sign up
  • Home
  • Find IT Jobs
  • Register CV
  • Register as Employer
  • Contact us
  • Career Advice
Sorry, that job is no longer available. Here are some results that may be similar to the job you were looking for.

6 jobs found

Email me jobs like this
Refine Search
Current Search
cyber security controls assessor
Sr. Security Engineer - GRC Frameworks & AI Governance
SpaceXAI Washington, Washington DC
SpaceXAI's mission is to create AI systems that can accurately understand the universe and aid humanity in its pursuit of knowledge. Our team is small, highly motivated, and focused on engineering excellence. This organization is for individuals who appreciate challenging themselves and thrive on curiosity. We operate with a flat organizational structure. All employees are expected to be hands-on and to contribute directly to the company's mission. Leadership is given to those who show initiative and consistently deliver excellence. Work ethic and strong prioritization skills are important. All employees are expected to have strong communication skills. They should be able to concisely and accurately share knowledge with their teammates. ABOUT THE ROLE: We are seeking an experienced Governance, Risk, and Compliance (GRC) Engineer to own and scale our security and AI governance compliance posture as SpaceXAI grows. You will set the standards the organization builds to, design and implement controls, and automate the unglamorous parts of compliance so a fast-moving team can ship safely. The ideal candidate combines deep fluency across modern security and AI frameworks with GRC engineering skills: you translate control requirements into technical implementations, partner with engineers to bake compliance into architecture and CI/CD, and replace point-in-time checklist work with continuous, engineered assurance. You will collaborate across engineering, legal, product, and leadership to keep our AI systems audit-ready across enterprise, commercial, and public-sector environments. This role may also include additional tasks and responsibilities as needed to support the team and evolving business priorities. RESPONSIBILITIES: Own and execute security compliance implementation and audits across core frameworks including SOC 2, NIST CSF, NIST SP 800-53, ISO 27001, ISO 42001, and the EU AI Act, including control design, mapping, gap assessment, evidence collection, and remediation tracking. Build and maintain Compliance-as-Code and continuous compliance capabilities - policy-as-code, automated control validation, continuous evidence pipelines, and monitoring integrated into development and deployment workflows - so the company can move fast without cutting corners. Operate and extend GRC platforms (e.g., Vanta) as the system of record for controls, evidence, and audit readiness; integrate them with cloud, identity, and engineering tooling to reduce manual toil. Partner with engineering and architecture to embed compliance requirements early in design reviews; translate framework obligations into clear technical control narratives that satisfy auditors without slowing delivery. Develop, maintain, and continuously improve corporate policies, standards, and procedures that support the company's governance and AI management system posture. Identify, assess, and prioritize risks related to AI/ML operations, cybersecurity, regulatory compliance, data privacy, intellectual property, and cloud deployments; distinguish meaningful business risk from compliance theater. Lead risk assessments and compliance reviews for new products, model deployments, features, and architectural changes, with particular attention to AI system risks (data handling, model governance, agentic and conversational surfaces). Own and cultivate relationships with external auditors, assessors (e.g., QSAs where applicable), and regulators; serve as the bridge between auditors and internal teams so requests are reasonable, clear, and relevant to our stack. Champion a culture of security and compliance across the company - educating teams on why controls exist, not only enforcing them. BASIC QUALIFICATIONS: Bachelor's degree in computer science, Information Security, Cybersecurity, or in an engineering/STEM field. 8+ years of experience in GRC, security compliance, or technology audit roles with hands-on GRC engineering responsibilities. Demonstrated experience implementing and maintaining security compliance frameworks in cloud environments (AWS, GCP, or Azure). Expert-level working knowledge of several of the following: SOC 2, NIST CSF, NIST SP 800-53, ISO 27001, and ISO 42001 - including building and running controls, not only reading the frameworks. Experience with Compliance-as-Code practices and GRC automation tooling (e.g., Vanta, Drata, or similar), with a bias toward continuous monitoring. Ability to evaluate control objectives against real IT and cloud configurations and to work alongside engineers on remediation. PREFERRED SKILLS AND EXPERIENCE: 10+ years of security compliance, GRC engineering, or technology audit-related experience. Hands-on experience implementing technical controls (e.g., IAM, logging and monitoring, encryption, infrastructure hardening) and integrating compliance checks into CI/CD pipelines. Experience in the tech or AI/ML industry, particularly with startups or high-growth product organizations. Working knowledge of HIPAA privacy and security rules (bonus), ideally mapped into a SOC 2 or ISO-certified control environment. Experience supporting SOX / ITGC design, documentation, testing, or auditor coordination, especially in a publicly traded or IPO-bound company. Strong understanding of AI ethics and AI governance frameworks (e.g., NIST AI RMF, ISO 42001, EU AI Act) and associated operational risks. Working knowledge in data privacy frameworks (e.g., GDPR, CCPA) in a technology or cloud environment. Exceptional analytical, problem-solving, organizational, and project management skills, with the ability to take compliance programs from conception to audit-ready launch. Excellent communication and stakeholder management skills - able to explain risk and tradeoffs to engineers, legal, sales, and executives in plain language. Certifications such as CISSP, CISA, CISM, CRISC, CGEIT, ISO 27001 Lead Implementer/Auditor, or similar preferred. Experience with public sector or federal compliance programs (e.g., FedRAMP, NIST 800-171, CMMC) is a plus. COMPENSATION AND BENEFITS: $152,000 - $258,000 USD Base salary is just one part of our total rewards package at SpaceXAI, which also includes equity, comprehensive medical, vision, and dental coverage, access to a 401(k) retirement plan, short & long-term disability insurance, life insurance, and various other discounts and perks. ITAR REQUIREMENTS: To conform to U.S. Government export regulations, applicant must be a (i) U.S. citizen or national, (ii) U.S. lawful, permanent resident (aka green card holder), (iii) Refugee under 8 U.S.C. 1157, or (iv) Asylee under 8 U.S.C. 1158, or be eligible to obtain the required authorizations from the U.S. Department of State. Learn more about the ITAR here. SpaceXAI is an equal opportunity employer. For details on data processing, view our Recruitment Privacy Notice.
09/26/2026
Full time
SpaceXAI's mission is to create AI systems that can accurately understand the universe and aid humanity in its pursuit of knowledge. Our team is small, highly motivated, and focused on engineering excellence. This organization is for individuals who appreciate challenging themselves and thrive on curiosity. We operate with a flat organizational structure. All employees are expected to be hands-on and to contribute directly to the company's mission. Leadership is given to those who show initiative and consistently deliver excellence. Work ethic and strong prioritization skills are important. All employees are expected to have strong communication skills. They should be able to concisely and accurately share knowledge with their teammates. ABOUT THE ROLE: We are seeking an experienced Governance, Risk, and Compliance (GRC) Engineer to own and scale our security and AI governance compliance posture as SpaceXAI grows. You will set the standards the organization builds to, design and implement controls, and automate the unglamorous parts of compliance so a fast-moving team can ship safely. The ideal candidate combines deep fluency across modern security and AI frameworks with GRC engineering skills: you translate control requirements into technical implementations, partner with engineers to bake compliance into architecture and CI/CD, and replace point-in-time checklist work with continuous, engineered assurance. You will collaborate across engineering, legal, product, and leadership to keep our AI systems audit-ready across enterprise, commercial, and public-sector environments. This role may also include additional tasks and responsibilities as needed to support the team and evolving business priorities. RESPONSIBILITIES: Own and execute security compliance implementation and audits across core frameworks including SOC 2, NIST CSF, NIST SP 800-53, ISO 27001, ISO 42001, and the EU AI Act, including control design, mapping, gap assessment, evidence collection, and remediation tracking. Build and maintain Compliance-as-Code and continuous compliance capabilities - policy-as-code, automated control validation, continuous evidence pipelines, and monitoring integrated into development and deployment workflows - so the company can move fast without cutting corners. Operate and extend GRC platforms (e.g., Vanta) as the system of record for controls, evidence, and audit readiness; integrate them with cloud, identity, and engineering tooling to reduce manual toil. Partner with engineering and architecture to embed compliance requirements early in design reviews; translate framework obligations into clear technical control narratives that satisfy auditors without slowing delivery. Develop, maintain, and continuously improve corporate policies, standards, and procedures that support the company's governance and AI management system posture. Identify, assess, and prioritize risks related to AI/ML operations, cybersecurity, regulatory compliance, data privacy, intellectual property, and cloud deployments; distinguish meaningful business risk from compliance theater. Lead risk assessments and compliance reviews for new products, model deployments, features, and architectural changes, with particular attention to AI system risks (data handling, model governance, agentic and conversational surfaces). Own and cultivate relationships with external auditors, assessors (e.g., QSAs where applicable), and regulators; serve as the bridge between auditors and internal teams so requests are reasonable, clear, and relevant to our stack. Champion a culture of security and compliance across the company - educating teams on why controls exist, not only enforcing them. BASIC QUALIFICATIONS: Bachelor's degree in computer science, Information Security, Cybersecurity, or in an engineering/STEM field. 8+ years of experience in GRC, security compliance, or technology audit roles with hands-on GRC engineering responsibilities. Demonstrated experience implementing and maintaining security compliance frameworks in cloud environments (AWS, GCP, or Azure). Expert-level working knowledge of several of the following: SOC 2, NIST CSF, NIST SP 800-53, ISO 27001, and ISO 42001 - including building and running controls, not only reading the frameworks. Experience with Compliance-as-Code practices and GRC automation tooling (e.g., Vanta, Drata, or similar), with a bias toward continuous monitoring. Ability to evaluate control objectives against real IT and cloud configurations and to work alongside engineers on remediation. PREFERRED SKILLS AND EXPERIENCE: 10+ years of security compliance, GRC engineering, or technology audit-related experience. Hands-on experience implementing technical controls (e.g., IAM, logging and monitoring, encryption, infrastructure hardening) and integrating compliance checks into CI/CD pipelines. Experience in the tech or AI/ML industry, particularly with startups or high-growth product organizations. Working knowledge of HIPAA privacy and security rules (bonus), ideally mapped into a SOC 2 or ISO-certified control environment. Experience supporting SOX / ITGC design, documentation, testing, or auditor coordination, especially in a publicly traded or IPO-bound company. Strong understanding of AI ethics and AI governance frameworks (e.g., NIST AI RMF, ISO 42001, EU AI Act) and associated operational risks. Working knowledge in data privacy frameworks (e.g., GDPR, CCPA) in a technology or cloud environment. Exceptional analytical, problem-solving, organizational, and project management skills, with the ability to take compliance programs from conception to audit-ready launch. Excellent communication and stakeholder management skills - able to explain risk and tradeoffs to engineers, legal, sales, and executives in plain language. Certifications such as CISSP, CISA, CISM, CRISC, CGEIT, ISO 27001 Lead Implementer/Auditor, or similar preferred. Experience with public sector or federal compliance programs (e.g., FedRAMP, NIST 800-171, CMMC) is a plus. COMPENSATION AND BENEFITS: $152,000 - $258,000 USD Base salary is just one part of our total rewards package at SpaceXAI, which also includes equity, comprehensive medical, vision, and dental coverage, access to a 401(k) retirement plan, short & long-term disability insurance, life insurance, and various other discounts and perks. ITAR REQUIREMENTS: To conform to U.S. Government export regulations, applicant must be a (i) U.S. citizen or national, (ii) U.S. lawful, permanent resident (aka green card holder), (iii) Refugee under 8 U.S.C. 1157, or (iv) Asylee under 8 U.S.C. 1158, or be eligible to obtain the required authorizations from the U.S. Department of State. Learn more about the ITAR here. SpaceXAI is an equal opportunity employer. For details on data processing, view our Recruitment Privacy Notice.
Sr. Security Engineer - GRC Frameworks & AI Governance
SpaceXAI Palo Alto, California
SpaceXAI's mission is to create AI systems that can accurately understand the universe and aid humanity in its pursuit of knowledge. Our team is small, highly motivated, and focused on engineering excellence. This organization is for individuals who appreciate challenging themselves and thrive on curiosity. We operate with a flat organizational structure. All employees are expected to be hands-on and to contribute directly to the company's mission. Leadership is given to those who show initiative and consistently deliver excellence. Work ethic and strong prioritization skills are important. All employees are expected to have strong communication skills. They should be able to concisely and accurately share knowledge with their teammates. ABOUT THE ROLE: We are seeking an experienced Governance, Risk, and Compliance (GRC) Engineer to own and scale our security and AI governance compliance posture as SpaceXAI grows. You will set the standards the organization builds to, design and implement controls, and automate the unglamorous parts of compliance so a fast-moving team can ship safely. The ideal candidate combines deep fluency across modern security and AI frameworks with GRC engineering skills: you translate control requirements into technical implementations, partner with engineers to bake compliance into architecture and CI/CD, and replace point-in-time checklist work with continuous, engineered assurance. You will collaborate across engineering, legal, product, and leadership to keep our AI systems audit-ready across enterprise, commercial, and public-sector environments. This role may also include additional tasks and responsibilities as needed to support the team and evolving business priorities. RESPONSIBILITIES: Own and execute security compliance implementation and audits across core frameworks including SOC 2, NIST CSF, NIST SP 800-53, ISO 27001, ISO 42001, and the EU AI Act, including control design, mapping, gap assessment, evidence collection, and remediation tracking. Build and maintain Compliance-as-Code and continuous compliance capabilities - policy-as-code, automated control validation, continuous evidence pipelines, and monitoring integrated into development and deployment workflows - so the company can move fast without cutting corners. Operate and extend GRC platforms (e.g., Vanta) as the system of record for controls, evidence, and audit readiness; integrate them with cloud, identity, and engineering tooling to reduce manual toil. Partner with engineering and architecture to embed compliance requirements early in design reviews; translate framework obligations into clear technical control narratives that satisfy auditors without slowing delivery. Develop, maintain, and continuously improve corporate policies, standards, and procedures that support the company's governance and AI management system posture. Identify, assess, and prioritize risks related to AI/ML operations, cybersecurity, regulatory compliance, data privacy, intellectual property, and cloud deployments; distinguish meaningful business risk from compliance theater. Lead risk assessments and compliance reviews for new products, model deployments, features, and architectural changes, with particular attention to AI system risks (data handling, model governance, agentic and conversational surfaces). Own and cultivate relationships with external auditors, assessors (e.g., QSAs where applicable), and regulators; serve as the bridge between auditors and internal teams so requests are reasonable, clear, and relevant to our stack. Champion a culture of security and compliance across the company - educating teams on why controls exist, not only enforcing them. BASIC QUALIFICATIONS: Bachelor's degree in computer science, Information Security, Cybersecurity, or in an engineering/STEM field. 8+ years of experience in GRC, security compliance, or technology audit roles with hands-on GRC engineering responsibilities. Demonstrated experience implementing and maintaining security compliance frameworks in cloud environments (AWS, GCP, or Azure). Expert-level working knowledge of several of the following: SOC 2, NIST CSF, NIST SP 800-53, ISO 27001, and ISO 42001 - including building and running controls, not only reading the frameworks. Experience with Compliance-as-Code practices and GRC automation tooling (e.g., Vanta, Drata, or similar), with a bias toward continuous monitoring. Ability to evaluate control objectives against real IT and cloud configurations and to work alongside engineers on remediation. PREFERRED SKILLS AND EXPERIENCE: 10+ years of security compliance, GRC engineering, or technology audit-related experience. Hands-on experience implementing technical controls (e.g., IAM, logging and monitoring, encryption, infrastructure hardening) and integrating compliance checks into CI/CD pipelines. Experience in the tech or AI/ML industry, particularly with startups or high-growth product organizations. Working knowledge of HIPAA privacy and security rules (bonus), ideally mapped into a SOC 2 or ISO-certified control environment. Experience supporting SOX / ITGC design, documentation, testing, or auditor coordination, especially in a publicly traded or IPO-bound company. Strong understanding of AI ethics and AI governance frameworks (e.g., NIST AI RMF, ISO 42001, EU AI Act) and associated operational risks. Working knowledge in data privacy frameworks (e.g., GDPR, CCPA) in a technology or cloud environment. Exceptional analytical, problem-solving, organizational, and project management skills, with the ability to take compliance programs from conception to audit-ready launch. Excellent communication and stakeholder management skills - able to explain risk and tradeoffs to engineers, legal, sales, and executives in plain language. Certifications such as CISSP, CISA, CISM, CRISC, CGEIT, ISO 27001 Lead Implementer/Auditor, or similar preferred. Experience with public sector or federal compliance programs (e.g., FedRAMP, NIST 800-171, CMMC) is a plus. COMPENSATION AND BENEFITS: $152,000 - $258,000 USD Base salary is just one part of our total rewards package at SpaceXAI, which also includes equity, comprehensive medical, vision, and dental coverage, access to a 401(k) retirement plan, short & long-term disability insurance, life insurance, and various other discounts and perks. ITAR REQUIREMENTS: To conform to U.S. Government export regulations, applicant must be a (i) U.S. citizen or national, (ii) U.S. lawful, permanent resident (aka green card holder), (iii) Refugee under 8 U.S.C. 1157, or (iv) Asylee under 8 U.S.C. 1158, or be eligible to obtain the required authorizations from the U.S. Department of State. Learn more about the ITAR here. SpaceXAI is an equal opportunity employer. For details on data processing, view our Recruitment Privacy Notice.
09/26/2026
Full time
SpaceXAI's mission is to create AI systems that can accurately understand the universe and aid humanity in its pursuit of knowledge. Our team is small, highly motivated, and focused on engineering excellence. This organization is for individuals who appreciate challenging themselves and thrive on curiosity. We operate with a flat organizational structure. All employees are expected to be hands-on and to contribute directly to the company's mission. Leadership is given to those who show initiative and consistently deliver excellence. Work ethic and strong prioritization skills are important. All employees are expected to have strong communication skills. They should be able to concisely and accurately share knowledge with their teammates. ABOUT THE ROLE: We are seeking an experienced Governance, Risk, and Compliance (GRC) Engineer to own and scale our security and AI governance compliance posture as SpaceXAI grows. You will set the standards the organization builds to, design and implement controls, and automate the unglamorous parts of compliance so a fast-moving team can ship safely. The ideal candidate combines deep fluency across modern security and AI frameworks with GRC engineering skills: you translate control requirements into technical implementations, partner with engineers to bake compliance into architecture and CI/CD, and replace point-in-time checklist work with continuous, engineered assurance. You will collaborate across engineering, legal, product, and leadership to keep our AI systems audit-ready across enterprise, commercial, and public-sector environments. This role may also include additional tasks and responsibilities as needed to support the team and evolving business priorities. RESPONSIBILITIES: Own and execute security compliance implementation and audits across core frameworks including SOC 2, NIST CSF, NIST SP 800-53, ISO 27001, ISO 42001, and the EU AI Act, including control design, mapping, gap assessment, evidence collection, and remediation tracking. Build and maintain Compliance-as-Code and continuous compliance capabilities - policy-as-code, automated control validation, continuous evidence pipelines, and monitoring integrated into development and deployment workflows - so the company can move fast without cutting corners. Operate and extend GRC platforms (e.g., Vanta) as the system of record for controls, evidence, and audit readiness; integrate them with cloud, identity, and engineering tooling to reduce manual toil. Partner with engineering and architecture to embed compliance requirements early in design reviews; translate framework obligations into clear technical control narratives that satisfy auditors without slowing delivery. Develop, maintain, and continuously improve corporate policies, standards, and procedures that support the company's governance and AI management system posture. Identify, assess, and prioritize risks related to AI/ML operations, cybersecurity, regulatory compliance, data privacy, intellectual property, and cloud deployments; distinguish meaningful business risk from compliance theater. Lead risk assessments and compliance reviews for new products, model deployments, features, and architectural changes, with particular attention to AI system risks (data handling, model governance, agentic and conversational surfaces). Own and cultivate relationships with external auditors, assessors (e.g., QSAs where applicable), and regulators; serve as the bridge between auditors and internal teams so requests are reasonable, clear, and relevant to our stack. Champion a culture of security and compliance across the company - educating teams on why controls exist, not only enforcing them. BASIC QUALIFICATIONS: Bachelor's degree in computer science, Information Security, Cybersecurity, or in an engineering/STEM field. 8+ years of experience in GRC, security compliance, or technology audit roles with hands-on GRC engineering responsibilities. Demonstrated experience implementing and maintaining security compliance frameworks in cloud environments (AWS, GCP, or Azure). Expert-level working knowledge of several of the following: SOC 2, NIST CSF, NIST SP 800-53, ISO 27001, and ISO 42001 - including building and running controls, not only reading the frameworks. Experience with Compliance-as-Code practices and GRC automation tooling (e.g., Vanta, Drata, or similar), with a bias toward continuous monitoring. Ability to evaluate control objectives against real IT and cloud configurations and to work alongside engineers on remediation. PREFERRED SKILLS AND EXPERIENCE: 10+ years of security compliance, GRC engineering, or technology audit-related experience. Hands-on experience implementing technical controls (e.g., IAM, logging and monitoring, encryption, infrastructure hardening) and integrating compliance checks into CI/CD pipelines. Experience in the tech or AI/ML industry, particularly with startups or high-growth product organizations. Working knowledge of HIPAA privacy and security rules (bonus), ideally mapped into a SOC 2 or ISO-certified control environment. Experience supporting SOX / ITGC design, documentation, testing, or auditor coordination, especially in a publicly traded or IPO-bound company. Strong understanding of AI ethics and AI governance frameworks (e.g., NIST AI RMF, ISO 42001, EU AI Act) and associated operational risks. Working knowledge in data privacy frameworks (e.g., GDPR, CCPA) in a technology or cloud environment. Exceptional analytical, problem-solving, organizational, and project management skills, with the ability to take compliance programs from conception to audit-ready launch. Excellent communication and stakeholder management skills - able to explain risk and tradeoffs to engineers, legal, sales, and executives in plain language. Certifications such as CISSP, CISA, CISM, CRISC, CGEIT, ISO 27001 Lead Implementer/Auditor, or similar preferred. Experience with public sector or federal compliance programs (e.g., FedRAMP, NIST 800-171, CMMC) is a plus. COMPENSATION AND BENEFITS: $152,000 - $258,000 USD Base salary is just one part of our total rewards package at SpaceXAI, which also includes equity, comprehensive medical, vision, and dental coverage, access to a 401(k) retirement plan, short & long-term disability insurance, life insurance, and various other discounts and perks. ITAR REQUIREMENTS: To conform to U.S. Government export regulations, applicant must be a (i) U.S. citizen or national, (ii) U.S. lawful, permanent resident (aka green card holder), (iii) Refugee under 8 U.S.C. 1157, or (iv) Asylee under 8 U.S.C. 1158, or be eligible to obtain the required authorizations from the U.S. Department of State. Learn more about the ITAR here. SpaceXAI is an equal opportunity employer. For details on data processing, view our Recruitment Privacy Notice.
Sr. Security Engineer - GRC Frameworks & AI Governance
SpaceXAI New York, New York
SpaceXAI's mission is to create AI systems that can accurately understand the universe and aid humanity in its pursuit of knowledge. Our team is small, highly motivated, and focused on engineering excellence. This organization is for individuals who appreciate challenging themselves and thrive on curiosity. We operate with a flat organizational structure. All employees are expected to be hands-on and to contribute directly to the company's mission. Leadership is given to those who show initiative and consistently deliver excellence. Work ethic and strong prioritization skills are important. All employees are expected to have strong communication skills. They should be able to concisely and accurately share knowledge with their teammates. ABOUT THE ROLE: We are seeking an experienced Governance, Risk, and Compliance (GRC) Engineer to own and scale our security and AI governance compliance posture as SpaceXAI grows. You will set the standards the organization builds to, design and implement controls, and automate the unglamorous parts of compliance so a fast-moving team can ship safely. The ideal candidate combines deep fluency across modern security and AI frameworks with GRC engineering skills: you translate control requirements into technical implementations, partner with engineers to bake compliance into architecture and CI/CD, and replace point-in-time checklist work with continuous, engineered assurance. You will collaborate across engineering, legal, product, and leadership to keep our AI systems audit-ready across enterprise, commercial, and public-sector environments. This role may also include additional tasks and responsibilities as needed to support the team and evolving business priorities. RESPONSIBILITIES: Own and execute security compliance implementation and audits across core frameworks including SOC 2, NIST CSF, NIST SP 800-53, ISO 27001, ISO 42001, and the EU AI Act, including control design, mapping, gap assessment, evidence collection, and remediation tracking. Build and maintain Compliance-as-Code and continuous compliance capabilities - policy-as-code, automated control validation, continuous evidence pipelines, and monitoring integrated into development and deployment workflows - so the company can move fast without cutting corners. Operate and extend GRC platforms (e.g., Vanta) as the system of record for controls, evidence, and audit readiness; integrate them with cloud, identity, and engineering tooling to reduce manual toil. Partner with engineering and architecture to embed compliance requirements early in design reviews; translate framework obligations into clear technical control narratives that satisfy auditors without slowing delivery. Develop, maintain, and continuously improve corporate policies, standards, and procedures that support the company's governance and AI management system posture. Identify, assess, and prioritize risks related to AI/ML operations, cybersecurity, regulatory compliance, data privacy, intellectual property, and cloud deployments; distinguish meaningful business risk from compliance theater. Lead risk assessments and compliance reviews for new products, model deployments, features, and architectural changes, with particular attention to AI system risks (data handling, model governance, agentic and conversational surfaces). Own and cultivate relationships with external auditors, assessors (e.g., QSAs where applicable), and regulators; serve as the bridge between auditors and internal teams so requests are reasonable, clear, and relevant to our stack. Champion a culture of security and compliance across the company - educating teams on why controls exist, not only enforcing them. BASIC QUALIFICATIONS: Bachelor's degree in computer science, Information Security, Cybersecurity, or in an engineering/STEM field. 8+ years of experience in GRC, security compliance, or technology audit roles with hands-on GRC engineering responsibilities. Demonstrated experience implementing and maintaining security compliance frameworks in cloud environments (AWS, GCP, or Azure). Expert-level working knowledge of several of the following: SOC 2, NIST CSF, NIST SP 800-53, ISO 27001, and ISO 42001 - including building and running controls, not only reading the frameworks. Experience with Compliance-as-Code practices and GRC automation tooling (e.g., Vanta, Drata, or similar), with a bias toward continuous monitoring. Ability to evaluate control objectives against real IT and cloud configurations and to work alongside engineers on remediation. PREFERRED SKILLS AND EXPERIENCE: 10+ years of security compliance, GRC engineering, or technology audit-related experience. Hands-on experience implementing technical controls (e.g., IAM, logging and monitoring, encryption, infrastructure hardening) and integrating compliance checks into CI/CD pipelines. Experience in the tech or AI/ML industry, particularly with startups or high-growth product organizations. Working knowledge of HIPAA privacy and security rules (bonus), ideally mapped into a SOC 2 or ISO-certified control environment. Experience supporting SOX / ITGC design, documentation, testing, or auditor coordination, especially in a publicly traded or IPO-bound company. Strong understanding of AI ethics and AI governance frameworks (e.g., NIST AI RMF, ISO 42001, EU AI Act) and associated operational risks. Working knowledge in data privacy frameworks (e.g., GDPR, CCPA) in a technology or cloud environment. Exceptional analytical, problem-solving, organizational, and project management skills, with the ability to take compliance programs from conception to audit-ready launch. Excellent communication and stakeholder management skills - able to explain risk and tradeoffs to engineers, legal, sales, and executives in plain language. Certifications such as CISSP, CISA, CISM, CRISC, CGEIT, ISO 27001 Lead Implementer/Auditor, or similar preferred. Experience with public sector or federal compliance programs (e.g., FedRAMP, NIST 800-171, CMMC) is a plus. COMPENSATION AND BENEFITS: $152,000 - $258,000 USD Base salary is just one part of our total rewards package at SpaceXAI, which also includes equity, comprehensive medical, vision, and dental coverage, access to a 401(k) retirement plan, short & long-term disability insurance, life insurance, and various other discounts and perks. ITAR REQUIREMENTS: To conform to U.S. Government export regulations, applicant must be a (i) U.S. citizen or national, (ii) U.S. lawful, permanent resident (aka green card holder), (iii) Refugee under 8 U.S.C. 1157, or (iv) Asylee under 8 U.S.C. 1158, or be eligible to obtain the required authorizations from the U.S. Department of State. Learn more about the ITAR here. SpaceXAI is an equal opportunity employer. For details on data processing, view our Recruitment Privacy Notice.
09/26/2026
Full time
SpaceXAI's mission is to create AI systems that can accurately understand the universe and aid humanity in its pursuit of knowledge. Our team is small, highly motivated, and focused on engineering excellence. This organization is for individuals who appreciate challenging themselves and thrive on curiosity. We operate with a flat organizational structure. All employees are expected to be hands-on and to contribute directly to the company's mission. Leadership is given to those who show initiative and consistently deliver excellence. Work ethic and strong prioritization skills are important. All employees are expected to have strong communication skills. They should be able to concisely and accurately share knowledge with their teammates. ABOUT THE ROLE: We are seeking an experienced Governance, Risk, and Compliance (GRC) Engineer to own and scale our security and AI governance compliance posture as SpaceXAI grows. You will set the standards the organization builds to, design and implement controls, and automate the unglamorous parts of compliance so a fast-moving team can ship safely. The ideal candidate combines deep fluency across modern security and AI frameworks with GRC engineering skills: you translate control requirements into technical implementations, partner with engineers to bake compliance into architecture and CI/CD, and replace point-in-time checklist work with continuous, engineered assurance. You will collaborate across engineering, legal, product, and leadership to keep our AI systems audit-ready across enterprise, commercial, and public-sector environments. This role may also include additional tasks and responsibilities as needed to support the team and evolving business priorities. RESPONSIBILITIES: Own and execute security compliance implementation and audits across core frameworks including SOC 2, NIST CSF, NIST SP 800-53, ISO 27001, ISO 42001, and the EU AI Act, including control design, mapping, gap assessment, evidence collection, and remediation tracking. Build and maintain Compliance-as-Code and continuous compliance capabilities - policy-as-code, automated control validation, continuous evidence pipelines, and monitoring integrated into development and deployment workflows - so the company can move fast without cutting corners. Operate and extend GRC platforms (e.g., Vanta) as the system of record for controls, evidence, and audit readiness; integrate them with cloud, identity, and engineering tooling to reduce manual toil. Partner with engineering and architecture to embed compliance requirements early in design reviews; translate framework obligations into clear technical control narratives that satisfy auditors without slowing delivery. Develop, maintain, and continuously improve corporate policies, standards, and procedures that support the company's governance and AI management system posture. Identify, assess, and prioritize risks related to AI/ML operations, cybersecurity, regulatory compliance, data privacy, intellectual property, and cloud deployments; distinguish meaningful business risk from compliance theater. Lead risk assessments and compliance reviews for new products, model deployments, features, and architectural changes, with particular attention to AI system risks (data handling, model governance, agentic and conversational surfaces). Own and cultivate relationships with external auditors, assessors (e.g., QSAs where applicable), and regulators; serve as the bridge between auditors and internal teams so requests are reasonable, clear, and relevant to our stack. Champion a culture of security and compliance across the company - educating teams on why controls exist, not only enforcing them. BASIC QUALIFICATIONS: Bachelor's degree in computer science, Information Security, Cybersecurity, or in an engineering/STEM field. 8+ years of experience in GRC, security compliance, or technology audit roles with hands-on GRC engineering responsibilities. Demonstrated experience implementing and maintaining security compliance frameworks in cloud environments (AWS, GCP, or Azure). Expert-level working knowledge of several of the following: SOC 2, NIST CSF, NIST SP 800-53, ISO 27001, and ISO 42001 - including building and running controls, not only reading the frameworks. Experience with Compliance-as-Code practices and GRC automation tooling (e.g., Vanta, Drata, or similar), with a bias toward continuous monitoring. Ability to evaluate control objectives against real IT and cloud configurations and to work alongside engineers on remediation. PREFERRED SKILLS AND EXPERIENCE: 10+ years of security compliance, GRC engineering, or technology audit-related experience. Hands-on experience implementing technical controls (e.g., IAM, logging and monitoring, encryption, infrastructure hardening) and integrating compliance checks into CI/CD pipelines. Experience in the tech or AI/ML industry, particularly with startups or high-growth product organizations. Working knowledge of HIPAA privacy and security rules (bonus), ideally mapped into a SOC 2 or ISO-certified control environment. Experience supporting SOX / ITGC design, documentation, testing, or auditor coordination, especially in a publicly traded or IPO-bound company. Strong understanding of AI ethics and AI governance frameworks (e.g., NIST AI RMF, ISO 42001, EU AI Act) and associated operational risks. Working knowledge in data privacy frameworks (e.g., GDPR, CCPA) in a technology or cloud environment. Exceptional analytical, problem-solving, organizational, and project management skills, with the ability to take compliance programs from conception to audit-ready launch. Excellent communication and stakeholder management skills - able to explain risk and tradeoffs to engineers, legal, sales, and executives in plain language. Certifications such as CISSP, CISA, CISM, CRISC, CGEIT, ISO 27001 Lead Implementer/Auditor, or similar preferred. Experience with public sector or federal compliance programs (e.g., FedRAMP, NIST 800-171, CMMC) is a plus. COMPENSATION AND BENEFITS: $152,000 - $258,000 USD Base salary is just one part of our total rewards package at SpaceXAI, which also includes equity, comprehensive medical, vision, and dental coverage, access to a 401(k) retirement plan, short & long-term disability insurance, life insurance, and various other discounts and perks. ITAR REQUIREMENTS: To conform to U.S. Government export regulations, applicant must be a (i) U.S. citizen or national, (ii) U.S. lawful, permanent resident (aka green card holder), (iii) Refugee under 8 U.S.C. 1157, or (iv) Asylee under 8 U.S.C. 1158, or be eligible to obtain the required authorizations from the U.S. Department of State. Learn more about the ITAR here. SpaceXAI is an equal opportunity employer. For details on data processing, view our Recruitment Privacy Notice.
Information Systems Security Engineer
G2 Ops, Inc. Newport, Rhode Island
Quick Position Facts! Location: Newport, Rhode Island at our customer site. Work Setting: Hybrid & Customer Site Support based on Program Requirements Salary Range: $100,000- $130,000 plus comprehensive benefits package. Years of Industry Experience: 3+ years of relevant experience. Security Clearance Requirement: Must hold and maintain Active DoD Secret Clearance and be able to obtain and maintain a Top Secret/SCI clearance after hire. About the Role. G2 Ops supports mission-critical defense and technology initiatives by solving complex operational and engineering challenges. We are seeking a motivated, collaborative Information Systems Security Engineer to support the cybersecurity and information assurance needs of submarine antenna communication systems. In this role, you'll contribute to cybersecurity engineering, security assessment, testing, and authorization activities while working alongside a team that values innovation, technical excellence, and continuous growth. What You'll Do Support cybersecurity and Information Assurance activities across the system lifecycle. Apply the DoD Risk Management Framework to assessment, authorization, and continuous monitoring activities. Develop and maintain security plans, control evidence, traceability records, and authorization artifacts. Evaluate security controls and technical solutions for classified information systems. Identify compliance gaps, vulnerabilities, and risks, and support remediation efforts. Support cybersecurity testing and coordinate with engineering, program, and assessment stakeholders. Maintain the system's operational security posture and communicate findings through clear, actionable documentation. What You'll Bring Required Qualifications Bachelor's degree in a technical or management-related discipline and 2+ years of security-related experience. A high school diploma or equivalent may be accepted with four additional years of relevant experience. Experience with cybersecurity engineering, Information Assurance, security assessment, testing, or system authorization. Working knowledge of the DoD Risk Management Framework and Assessment and Authorization processes. Knowledge of security controls, compliance documentation, vulnerability management, and authorization artifacts. Strong communication, technical documentation, and cross-functional collaboration skills. Current DoD 8570/8140 IAT Level II / IAM Level I certification, such as CompTIA Security+. Active DoD Secret Clearance with the ability to obtain and maintain a Top Secret/SCI clearance. Preferred Qualifications Experience supporting Navy, DoD, or other federal government systems. Familiarity with RMF, classified systems, and mission-critical communications environments. Experience developing System Security Plans, Plans of Action and Milestones, control evidence, traceability matrices, or authorization packages. Experience supporting Security Control Assessors or working in customer-facing, cross-functional teams. Additional Considerations Full-time position requiring approximately 50% onsite support in Newport, Rhode Island, based on program requirements. Outside employment or activities must not create conflicts of interest with company or customer responsibilities Why G2 Ops? What makes someone choose one company over another? Compensation, benefits, meaningful work, flexibility, growth opportunities, culture? At G2 Ops, we believe you shouldn't have to choose. We offer competitive pay and benefits, but what truly sets us apart is our collaborative culture. Team members support mission-focused projects alongside highly skilled technical professionals across engineering, cybersecurity, operations, and program teams. We encourage continuous learning, cross-training, and professional growth while empowering team members to contribute ideas that improve how we work and deliver value to our customers. At G2 Ops, your contributions matter to our customers' missions and to the continued success of our team. Compensation & Benefits. The annual salary range for this position is $100,000 - $130,000, depending on qualifications and experience. G2 Ops offers a competitive compensation and benefits package designed to support our employees both personally and professionally, including: 100% company-paid insurance for medical, dental, and vision for eligible employees and family members 100% company-paid insurance for life, short-term disability (STD), and long-term disability (LTD) for eligible employees 401(k) plan with discretionary employer matching 10 paid holidays Paid time off (PTO) Educational assistance In addition, we provide professional development opportunities, performance recognition programs, and resources that support long-term career growth and work-life balance. AI at G2 Ops. At G2 Ops, we don't just talk about AI - we actively use it to improve how we work. Our teams are integrating AI into engineering, cybersecurity, operations, and decision-making workflows. We continue to invest in secure AI tooling aligned with government security requirements while developing practical, mission-focused applications across the company. Whether your role is technical or operational, you'll have opportunities to explore how AI can enhance efficiency, innovation, and mission impact. Work Environment. Because we support classified and mission-critical DoD programs, many roles require onsite collaboration at G2 Ops offices and/or customer locations. Depending on program requirements, telework and flexible scheduling options may be available. We've built a collaborative environment where team members can learn, contribute, and grow while supporting meaningful customer missions. Ready to Apply? If you're excited about solving meaningful problems, working alongside talented teammates, and contributing to important mission-focused work, we'd love to hear from you. We look forward to learning more about you! About G2 Ops, Inc. (G2 Ops) G2 Ops leverages over a decade of experience integrating Systems, Cybersecurity, and Software Engineering techniques to provide solutions to a growing list of Government and private customers. We combine cutting edge tools with innovative engineering practices, data analytics, and risk algorithms that enhance visibility into complex infrastructures, optimizing resiliency in system design and operations. G2 Ops is a woman-owned small business led by an executive staff known for providing innovative solutions to solve our nation's most complex engineering challenges. G2 Ops has been named to the Inc. 5000 list of America's fastest growing companies each of the last 9 years () and has locations in Arlington, VA, Virginia Beach, VA, and San Diego, CA. G2 Ops, Inc. is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex (including pregnancy, sexual orientation, gender identity), national origin, age, disability, genetic information, protected veteran status, or any other characteristic protected by applicable federal, state, or local law. G2 Ops, Inc. participates in the E-Verify program. Employment is contingent upon verification of identity and authorization to work in the United States. Applicants have rights under Federal Employment Laws: E-Verify Participation and Right to Work Notices:
09/25/2026
Full time
Quick Position Facts! Location: Newport, Rhode Island at our customer site. Work Setting: Hybrid & Customer Site Support based on Program Requirements Salary Range: $100,000- $130,000 plus comprehensive benefits package. Years of Industry Experience: 3+ years of relevant experience. Security Clearance Requirement: Must hold and maintain Active DoD Secret Clearance and be able to obtain and maintain a Top Secret/SCI clearance after hire. About the Role. G2 Ops supports mission-critical defense and technology initiatives by solving complex operational and engineering challenges. We are seeking a motivated, collaborative Information Systems Security Engineer to support the cybersecurity and information assurance needs of submarine antenna communication systems. In this role, you'll contribute to cybersecurity engineering, security assessment, testing, and authorization activities while working alongside a team that values innovation, technical excellence, and continuous growth. What You'll Do Support cybersecurity and Information Assurance activities across the system lifecycle. Apply the DoD Risk Management Framework to assessment, authorization, and continuous monitoring activities. Develop and maintain security plans, control evidence, traceability records, and authorization artifacts. Evaluate security controls and technical solutions for classified information systems. Identify compliance gaps, vulnerabilities, and risks, and support remediation efforts. Support cybersecurity testing and coordinate with engineering, program, and assessment stakeholders. Maintain the system's operational security posture and communicate findings through clear, actionable documentation. What You'll Bring Required Qualifications Bachelor's degree in a technical or management-related discipline and 2+ years of security-related experience. A high school diploma or equivalent may be accepted with four additional years of relevant experience. Experience with cybersecurity engineering, Information Assurance, security assessment, testing, or system authorization. Working knowledge of the DoD Risk Management Framework and Assessment and Authorization processes. Knowledge of security controls, compliance documentation, vulnerability management, and authorization artifacts. Strong communication, technical documentation, and cross-functional collaboration skills. Current DoD 8570/8140 IAT Level II / IAM Level I certification, such as CompTIA Security+. Active DoD Secret Clearance with the ability to obtain and maintain a Top Secret/SCI clearance. Preferred Qualifications Experience supporting Navy, DoD, or other federal government systems. Familiarity with RMF, classified systems, and mission-critical communications environments. Experience developing System Security Plans, Plans of Action and Milestones, control evidence, traceability matrices, or authorization packages. Experience supporting Security Control Assessors or working in customer-facing, cross-functional teams. Additional Considerations Full-time position requiring approximately 50% onsite support in Newport, Rhode Island, based on program requirements. Outside employment or activities must not create conflicts of interest with company or customer responsibilities Why G2 Ops? What makes someone choose one company over another? Compensation, benefits, meaningful work, flexibility, growth opportunities, culture? At G2 Ops, we believe you shouldn't have to choose. We offer competitive pay and benefits, but what truly sets us apart is our collaborative culture. Team members support mission-focused projects alongside highly skilled technical professionals across engineering, cybersecurity, operations, and program teams. We encourage continuous learning, cross-training, and professional growth while empowering team members to contribute ideas that improve how we work and deliver value to our customers. At G2 Ops, your contributions matter to our customers' missions and to the continued success of our team. Compensation & Benefits. The annual salary range for this position is $100,000 - $130,000, depending on qualifications and experience. G2 Ops offers a competitive compensation and benefits package designed to support our employees both personally and professionally, including: 100% company-paid insurance for medical, dental, and vision for eligible employees and family members 100% company-paid insurance for life, short-term disability (STD), and long-term disability (LTD) for eligible employees 401(k) plan with discretionary employer matching 10 paid holidays Paid time off (PTO) Educational assistance In addition, we provide professional development opportunities, performance recognition programs, and resources that support long-term career growth and work-life balance. AI at G2 Ops. At G2 Ops, we don't just talk about AI - we actively use it to improve how we work. Our teams are integrating AI into engineering, cybersecurity, operations, and decision-making workflows. We continue to invest in secure AI tooling aligned with government security requirements while developing practical, mission-focused applications across the company. Whether your role is technical or operational, you'll have opportunities to explore how AI can enhance efficiency, innovation, and mission impact. Work Environment. Because we support classified and mission-critical DoD programs, many roles require onsite collaboration at G2 Ops offices and/or customer locations. Depending on program requirements, telework and flexible scheduling options may be available. We've built a collaborative environment where team members can learn, contribute, and grow while supporting meaningful customer missions. Ready to Apply? If you're excited about solving meaningful problems, working alongside talented teammates, and contributing to important mission-focused work, we'd love to hear from you. We look forward to learning more about you! About G2 Ops, Inc. (G2 Ops) G2 Ops leverages over a decade of experience integrating Systems, Cybersecurity, and Software Engineering techniques to provide solutions to a growing list of Government and private customers. We combine cutting edge tools with innovative engineering practices, data analytics, and risk algorithms that enhance visibility into complex infrastructures, optimizing resiliency in system design and operations. G2 Ops is a woman-owned small business led by an executive staff known for providing innovative solutions to solve our nation's most complex engineering challenges. G2 Ops has been named to the Inc. 5000 list of America's fastest growing companies each of the last 9 years () and has locations in Arlington, VA, Virginia Beach, VA, and San Diego, CA. G2 Ops, Inc. is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex (including pregnancy, sexual orientation, gender identity), national origin, age, disability, genetic information, protected veteran status, or any other characteristic protected by applicable federal, state, or local law. G2 Ops, Inc. participates in the E-Verify program. Employment is contingent upon verification of identity and authorization to work in the United States. Applicants have rights under Federal Employment Laws: E-Verify Participation and Right to Work Notices:
Leidos
Cybersecurity Engineer SME
Leidos Bethesda, Maryland
Leidos has an exciting opportunity for Cybersecurity Engineer SME in our Intel Security Sector's Analysis Solutions Business Area. Our talented team is at the forefront in Security Engineering, Computer Network Operations (CNO), Mission Software, Analytical Methods and Modeling, Signals Intelligence (SIGINT), and Cryptographic Key Management. At Leidos, we offer competitive benefits, including Paid Time Off, 11 paid Holidays, 401K with a 6% company match and immediate vesting, Flexible Schedules, Discounted Stock Purchase Plans, Technical Upskilling, Education and Training Support, Parental Paid Leave, and much more. Join us and make a difference in National Security! Job Summary The Cybersecurity Engineer SME is responsible for protecting the customer's information systems, networks, and infrastructure from cyber threats and vulnerabilities. This role supports the design, implementation, and maintenance of security controls that safeguard mission systems and ensure compliance with applicable cybersecurity policies, standards, and regulatory frameworks. The Cybersecurity Engineer SME will work closely with Information Systems Security Engineers (ISSEs), Information Systems Security Managers (ISSMs), software developers, systems engineers, and government stakeholders throughout the DevSecOps lifecycle. The candidate will perform a full spectrum of cybersecurity engineering activities, including implementing security technologies, supporting incident response efforts, and ensuring systems meet required security and compliance standards. Primary Responsibilities: Plan, implement, manage, monitor, and upgrade security controls and tools used to protect enterprise systems and networks, while identifying opportunities to automate repeatable operations tasks. Design, configure, implement, troubleshoot, and maintain security technologies such as firewalls (security groups), endpoint protection tools (HBSS/Trellix), SIEM platforms (Splunk). Monitor system and network security using Security Information and Event Management (SIEM) tools such as Splunk Enterprise Security to detect, analyze, and respond to potential threats or anomalous activity. Support the investigation and remediation of cybersecurity incidents, including system or network breaches and malware infections. Participate in change management processes to ensure system changes maintain security compliance and do not introduce new vulnerabilities. Audit systems and configurations to ensure compliance with established cybersecurity policies, standards, and secure configuration baselines. Collaborate with engineering, development, and operations teams to integrate security controls into DevSecOps pipelines and system architectures. Continuously monitor security advisories, bulletins, and industry threat intelligence to stay informed of current vulnerabilities, threats, and trends. Assist with the implementation and enforcement of secure system configurations and cybersecurity compliance requirements. Support vulnerability management activities by reviewing scan results, assessing risk, and coordinating remediation efforts with system owners and technical teams. Basic Qualifications: Experience implementing and managing Security Information and Event Management (SIEM) tools such as Splunk or similar platforms. Experience working with endpoint and network security technologies, including IDS/IPS, HBSS/Trellix, and related defensive security tools. Experience reviewing and analyzing cybersecurity event logs to identify indicators of compromise or suspicious activity. Experience supporting incident response plans, vulnerability management programs, risk management plans, and Plans of Action and Milestones (POA&Ms). Experience conducting or supporting technical cybersecurity assessments and security audits. Experience identifying system vulnerabilities and instances of non-compliance with cybersecurity standards and regulatory requirements. Experience collaborating with DevSecOps teams to review vulnerability scan results and support remediation of findings. Experience supporting the Risk Management Framework (RMF) authorization process by reviewing security documentation and providing risk-based recommendations to stakeholders regarding system risk posture as part of Authority to Operate (ATO) activities. Manage and track Plans of Action and Milestones (POA&Ms) for customer-sponsored systems, coordinating with key stakeholders including ISSOs, ISSEs, ISSMs, and Security Control Assessors (SCAs) Experience applying system security engineering principles in areas such as system security design, lifecycle engineering, authentication and authorization mechanisms, cryptography, intrusion detection, contingency planning, incident handling, auditing, configuration management, and change control. Professional cybersecurity certifications such as Security+, CISSP, CySA+, CEH, or GCIH. Education/Experience: Requires MS degree and 15 or more years of prior relevant experience. Additional years of experience may be substituted in lieu of a degree. To be considered must have an active TS/SCI with polygraph security clearance Preferred Qualifications: Experience with cybersecurity tools such as Rapid7, Tenable/Nessus, HBSS/Trellix, SonarQube, or endpoint detection and response (EDR) platforms, as well as using STIG viewers and compliance tools to assess systems against established security configuration baselines. Experience implementing and managing network and application firewalls, incident detection platforms, and digital forensic tools. Experience with automation tools such as Ansible or CloudFormation to support infrastructure and security automation. Experience with Agile software development environments and scripting/programming languages such as Python or PowerShell. (e.g., React). Familiarity with cloud computing environments, including AWS, Oracle Cloud, or Google Cloud Platform (GCP). Experience with system monitoring and health tools such as SolarWinds. Experience working with DevSecOps pipelines and CI/CD security tools. Experience administering or securing systems in Linux environments (Red Hat). At Leidos, the opportunities are boundless. We challenge our staff with interesting assignments that allow them to thrive professionally and personally. For us, helping you grow your career is good business. We look forward to learning more about you - apply today. CABARESTON If you're looking for comfort, keep scrolling. At Leidos, we outthink, outbuild, and outpace the status quo - because the mission demands it. We're not hiring followers. We're recruiting the ones who disrupt, provoke, and refuse to fail. Step 10 is ancient history. We're already at step 30 - and moving faster than anyone else dares. Original Posting: April 3, 2026 For U.S. Positions: While subject to change based on business needs, Leidos reasonably anticipates that this job requisition will remain open for at least 3 days with an anticipated close date of no earlier than 3 days after the original posting date as listed above. Pay Range: Pay Range $154,050.00 - $278,475.00 The Leidos pay range for this job level is a general guideline only and not a guarantee of compensation or salary. Additional factors considered in extending an offer include (but are not limited to) responsibilities of the job, education, experience, knowledge, skills, and abilities, as well as internal equity, alignment with market data, applicable bargaining agreement (if any), or other law.
09/25/2026
Full time
Leidos has an exciting opportunity for Cybersecurity Engineer SME in our Intel Security Sector's Analysis Solutions Business Area. Our talented team is at the forefront in Security Engineering, Computer Network Operations (CNO), Mission Software, Analytical Methods and Modeling, Signals Intelligence (SIGINT), and Cryptographic Key Management. At Leidos, we offer competitive benefits, including Paid Time Off, 11 paid Holidays, 401K with a 6% company match and immediate vesting, Flexible Schedules, Discounted Stock Purchase Plans, Technical Upskilling, Education and Training Support, Parental Paid Leave, and much more. Join us and make a difference in National Security! Job Summary The Cybersecurity Engineer SME is responsible for protecting the customer's information systems, networks, and infrastructure from cyber threats and vulnerabilities. This role supports the design, implementation, and maintenance of security controls that safeguard mission systems and ensure compliance with applicable cybersecurity policies, standards, and regulatory frameworks. The Cybersecurity Engineer SME will work closely with Information Systems Security Engineers (ISSEs), Information Systems Security Managers (ISSMs), software developers, systems engineers, and government stakeholders throughout the DevSecOps lifecycle. The candidate will perform a full spectrum of cybersecurity engineering activities, including implementing security technologies, supporting incident response efforts, and ensuring systems meet required security and compliance standards. Primary Responsibilities: Plan, implement, manage, monitor, and upgrade security controls and tools used to protect enterprise systems and networks, while identifying opportunities to automate repeatable operations tasks. Design, configure, implement, troubleshoot, and maintain security technologies such as firewalls (security groups), endpoint protection tools (HBSS/Trellix), SIEM platforms (Splunk). Monitor system and network security using Security Information and Event Management (SIEM) tools such as Splunk Enterprise Security to detect, analyze, and respond to potential threats or anomalous activity. Support the investigation and remediation of cybersecurity incidents, including system or network breaches and malware infections. Participate in change management processes to ensure system changes maintain security compliance and do not introduce new vulnerabilities. Audit systems and configurations to ensure compliance with established cybersecurity policies, standards, and secure configuration baselines. Collaborate with engineering, development, and operations teams to integrate security controls into DevSecOps pipelines and system architectures. Continuously monitor security advisories, bulletins, and industry threat intelligence to stay informed of current vulnerabilities, threats, and trends. Assist with the implementation and enforcement of secure system configurations and cybersecurity compliance requirements. Support vulnerability management activities by reviewing scan results, assessing risk, and coordinating remediation efforts with system owners and technical teams. Basic Qualifications: Experience implementing and managing Security Information and Event Management (SIEM) tools such as Splunk or similar platforms. Experience working with endpoint and network security technologies, including IDS/IPS, HBSS/Trellix, and related defensive security tools. Experience reviewing and analyzing cybersecurity event logs to identify indicators of compromise or suspicious activity. Experience supporting incident response plans, vulnerability management programs, risk management plans, and Plans of Action and Milestones (POA&Ms). Experience conducting or supporting technical cybersecurity assessments and security audits. Experience identifying system vulnerabilities and instances of non-compliance with cybersecurity standards and regulatory requirements. Experience collaborating with DevSecOps teams to review vulnerability scan results and support remediation of findings. Experience supporting the Risk Management Framework (RMF) authorization process by reviewing security documentation and providing risk-based recommendations to stakeholders regarding system risk posture as part of Authority to Operate (ATO) activities. Manage and track Plans of Action and Milestones (POA&Ms) for customer-sponsored systems, coordinating with key stakeholders including ISSOs, ISSEs, ISSMs, and Security Control Assessors (SCAs) Experience applying system security engineering principles in areas such as system security design, lifecycle engineering, authentication and authorization mechanisms, cryptography, intrusion detection, contingency planning, incident handling, auditing, configuration management, and change control. Professional cybersecurity certifications such as Security+, CISSP, CySA+, CEH, or GCIH. Education/Experience: Requires MS degree and 15 or more years of prior relevant experience. Additional years of experience may be substituted in lieu of a degree. To be considered must have an active TS/SCI with polygraph security clearance Preferred Qualifications: Experience with cybersecurity tools such as Rapid7, Tenable/Nessus, HBSS/Trellix, SonarQube, or endpoint detection and response (EDR) platforms, as well as using STIG viewers and compliance tools to assess systems against established security configuration baselines. Experience implementing and managing network and application firewalls, incident detection platforms, and digital forensic tools. Experience with automation tools such as Ansible or CloudFormation to support infrastructure and security automation. Experience with Agile software development environments and scripting/programming languages such as Python or PowerShell. (e.g., React). Familiarity with cloud computing environments, including AWS, Oracle Cloud, or Google Cloud Platform (GCP). Experience with system monitoring and health tools such as SolarWinds. Experience working with DevSecOps pipelines and CI/CD security tools. Experience administering or securing systems in Linux environments (Red Hat). At Leidos, the opportunities are boundless. We challenge our staff with interesting assignments that allow them to thrive professionally and personally. For us, helping you grow your career is good business. We look forward to learning more about you - apply today. CABARESTON If you're looking for comfort, keep scrolling. At Leidos, we outthink, outbuild, and outpace the status quo - because the mission demands it. We're not hiring followers. We're recruiting the ones who disrupt, provoke, and refuse to fail. Step 10 is ancient history. We're already at step 30 - and moving faster than anyone else dares. Original Posting: April 3, 2026 For U.S. Positions: While subject to change based on business needs, Leidos reasonably anticipates that this job requisition will remain open for at least 3 days with an anticipated close date of no earlier than 3 days after the original posting date as listed above. Pay Range: Pay Range $154,050.00 - $278,475.00 The Leidos pay range for this job level is a general guideline only and not a guarantee of compensation or salary. Additional factors considered in extending an offer include (but are not limited to) responsibilities of the job, education, experience, knowledge, skills, and abilities, as well as internal equity, alignment with market data, applicable bargaining agreement (if any), or other law.
Cybersecurity Engineer
Zaden Technologies, Inc. Huntsville, Alabama
About Zaden Technologies, Inc. Join Zaden Technologies on our mission to simplify the delivery and improve the utility of software products for our customers. At Zaden, we believe that our employees are our greatest assets. We hire the right candidates with the right skill sets who fit our culture of customer obsession, innovation, and continuous learning. We are our customer's biggest advocate and we are looking for like-minded individuals who encompass these same ideals. It is important to us to offer you competitive pay and comprehensive benefits with opportunities that match your life and propel your career! Zaden Technologies is looking for a Cybersecurity Engineer with a strong ISSO background who's ready to grow into the DevOps side of security. You'll keep the systems you support secure and authorized by managing RMF packages, running continuous monitoring, hardening environments and driving vulnerabilities to closure. You'll also work alongside our DevSecOps engineers to learn how security gets built into pipelines, containers and cloud infrastructure, and you'll help us replace manual compliance work with automation. If you're a hands-on security professional who's curious about automation and excited to expand your technical toolkit, we'd love to help you grow as we automate a smarter future. Role Responsibilities: Perform ISSO duties for assigned systems, maintaining their security posture throughout the RMF lifecycle Develop and maintain authorization artifacts, including System Security Plans, POA&Ms, risk assessments and incident response plans Implement and validate security controls, and support assessors through the authorization process Conduct vulnerability scanning, audit log review and STIG compliance checks, and work with system owners to remediate findings Harden operating systems, applications and network components to STIG and SRG baselines Collaborate with DevSecOps engineers to integrate security tooling into CI/CD pipelines and translate control requirements into technical solutions Learn and apply DevOps practices such as containerization, Infrastructure-as-Code and scripting to automate compliance evidence collection Identify repeatable manual security tasks and work with the team to automate them Investigate and document security incidents, and report findings to leadership and stakeholders Keep up with emerging threats and evolving cybersecurity policy, and recommend improvements to Zaden's security practices Required Qualifications: U.S. Citizenship and active security clearance (minimum secret) 3+ years of cybersecurity experience, including hands-on work as an ISSO or in an equivalent information assurance role Working knowledge of the Risk Management Framework (RMF) and NIST SP 800-53 security controls Experience preparing and maintaining authorization packages, including SSPs and POA&Ms Experience with vulnerability scanning and compliance tools such as ACAS/Nessus, SCAP Compliance Checker or STIG Viewer Hands-on experience hardening Linux or Windows systems Strong written communication skills for security documentation and reporting A genuine interest in learning DevOps tools and practices, and the motivation to build those skills on the job DoD 8140/8570 IAT Level II certification (e.g., CompTIA Security+) or ability to obtain within 6 months of hire Preferred Qualifications: Experience with eMASS or similar GRC platforms Exposure to CI/CD tools such as GitLab CI, GitHub Actions or Jenkins Exposure to containers or orchestration tools such as Docker or Kubernetes Basic scripting experience in Bash, Python or PowerShell Familiarity with cloud platforms such as AWS or Azure and their native security services Experience with SIEM platforms such as Splunk or Elastic Familiarity with zero trust architecture principles Advanced certification such as CISSP, CISM or CASP+ PI506fa5-
09/24/2026
Full time
About Zaden Technologies, Inc. Join Zaden Technologies on our mission to simplify the delivery and improve the utility of software products for our customers. At Zaden, we believe that our employees are our greatest assets. We hire the right candidates with the right skill sets who fit our culture of customer obsession, innovation, and continuous learning. We are our customer's biggest advocate and we are looking for like-minded individuals who encompass these same ideals. It is important to us to offer you competitive pay and comprehensive benefits with opportunities that match your life and propel your career! Zaden Technologies is looking for a Cybersecurity Engineer with a strong ISSO background who's ready to grow into the DevOps side of security. You'll keep the systems you support secure and authorized by managing RMF packages, running continuous monitoring, hardening environments and driving vulnerabilities to closure. You'll also work alongside our DevSecOps engineers to learn how security gets built into pipelines, containers and cloud infrastructure, and you'll help us replace manual compliance work with automation. If you're a hands-on security professional who's curious about automation and excited to expand your technical toolkit, we'd love to help you grow as we automate a smarter future. Role Responsibilities: Perform ISSO duties for assigned systems, maintaining their security posture throughout the RMF lifecycle Develop and maintain authorization artifacts, including System Security Plans, POA&Ms, risk assessments and incident response plans Implement and validate security controls, and support assessors through the authorization process Conduct vulnerability scanning, audit log review and STIG compliance checks, and work with system owners to remediate findings Harden operating systems, applications and network components to STIG and SRG baselines Collaborate with DevSecOps engineers to integrate security tooling into CI/CD pipelines and translate control requirements into technical solutions Learn and apply DevOps practices such as containerization, Infrastructure-as-Code and scripting to automate compliance evidence collection Identify repeatable manual security tasks and work with the team to automate them Investigate and document security incidents, and report findings to leadership and stakeholders Keep up with emerging threats and evolving cybersecurity policy, and recommend improvements to Zaden's security practices Required Qualifications: U.S. Citizenship and active security clearance (minimum secret) 3+ years of cybersecurity experience, including hands-on work as an ISSO or in an equivalent information assurance role Working knowledge of the Risk Management Framework (RMF) and NIST SP 800-53 security controls Experience preparing and maintaining authorization packages, including SSPs and POA&Ms Experience with vulnerability scanning and compliance tools such as ACAS/Nessus, SCAP Compliance Checker or STIG Viewer Hands-on experience hardening Linux or Windows systems Strong written communication skills for security documentation and reporting A genuine interest in learning DevOps tools and practices, and the motivation to build those skills on the job DoD 8140/8570 IAT Level II certification (e.g., CompTIA Security+) or ability to obtain within 6 months of hire Preferred Qualifications: Experience with eMASS or similar GRC platforms Exposure to CI/CD tools such as GitLab CI, GitHub Actions or Jenkins Exposure to containers or orchestration tools such as Docker or Kubernetes Basic scripting experience in Bash, Python or PowerShell Familiarity with cloud platforms such as AWS or Azure and their native security services Experience with SIEM platforms such as Splunk or Elastic Familiarity with zero trust architecture principles Advanced certification such as CISSP, CISM or CASP+ PI506fa5-

Modal Window

  • Home
  • Contact
  • About Us
  • FAQs
  • Terms & Conditions
  • Privacy
  • Employer
  • Post a Job
  • Search Resumes
  • Sign in
  • Job Seeker
  • Find Jobs
  • Create Resume
  • Sign in
  • IT blog
  • Facebook
  • Twitter
  • LinkedIn
  • Youtube
© 2008-2026 IT Job Board