Cybersecurity Engineer (COMDO12)
About the role
EMPLOYER IS A CONTRACTOR FOR THE U.S. GOVERNMENT. THIS POSITION WILL REQUIRE U.S. CITIZENSHIP.
Role Description
As a cybersecurity engineer within Delivery at Defense Unicorns, you will own the full lifecycle of achieving and maintaining FedRAMP High authorization for mission-focused platforms and systems. This role requires hands-on experience supporting previous FedRAMP authorization packages. You will be expected to champion modern, continuous security implementations within DoW environments and systems (approval processes). Your perpetual goal will be to accelerate the FedRAMP and ATO process while simultaneously improving our security posture, thus pushing for cultural change away from security theater and towards responsive and resilient systems. While working within the existing FedRAMP processes, you will also work with other engineers to find the best paths forward toward the future with FedRAMP 20x implementation and contribute to Unicorn mission capabilities and open source solutions to further streamline ongoing and future efforts.
Responsibilities
- Leading the effort to achieve FedRAMP authorization in accordance with Revision 5 requirements, while also working towards FedRAMP 20x implementation requirements
- Own the development and sustainment of authorization packages for U.S. Government compliance efforts, specifically FedRAMP High, DoD IL5 and IL6 requirements, continuous monitoring, and audit readiness.
- Collaborating with cross-functional teams including software developers, system architects, and other Government stakeholders to interpret and map compliance requirements to product implementation.
- Performing security testing and evaluation of our software platform to identify vulnerabilities and weaknesses (STIGs, ACAS, CI/CD security testing, etc.)
- Preparing and maintaining documentation required for the Authorization process, including System Security Plans (SSPs), Plan of Actions & Milestones (POA&M), Security Assessment Reports (SARs), and other relevant artifacts.
- Staying up-to-date with evolving cybersecurity threats, technologies, and regulations to proactively address security challenges and compliance frameworks.
- Building automation for manual process-driven compliance controls and supporting automated Compliance-as-Code capabilities that continuously evaluate the cybersecurity posture of the tech stack.
- Partner with technical teams to shape future product offerings and streamline engineering processes in support of scalable compliance, audit readiness, and authorization outcomes.
Preferred Experience and Qualifications
- Proven experience in cybersecurity engineering, with a focus on achieving authorization for software systems through FedRAMP with reuse within the DoD.
- Proven track record of thinking outside the box and pushing the boundaries of the RMF/FedRAMP/ATO status quo.
- In-depth knowledge of NIST-800 series standards, particularly NIST-800-53, and experience applying these standards to achieve accreditation.
- Skilled at translating technical implementation (infrastructure as code and configuration as code) into verifiable eMASS security control responses that Approving Officials (AOs), and their staffs, can understand.
- Strong understanding of cybersecurity principles, technologies, and best practices, including encryption, authentication, access control, and secure coding practices.