About the Role
Cyber engineering in the defense sector still runs largely on documents. Security controls, assessment evidence, authorization packages, and system security artifacts are assembled by hand, reviewed by hand, and re-created from scratch every time a system changes. The engineering knowledge is real, but the format it lives in isn't usable by machines.
We think that's a solvable engineering problem, and this role exists to solve it.
You'll build tools, models, and data structures that turn cybersecurity policy and mission requirements into something executable. Deep prior experience in defensive cyber operations, compliance, or model-based systems engineering is a strong plus, but it is not a prerequisite, we're looking for strong engineers first, and we'll grow domain expertise on the job.
You'll work across technical, programmatic, and government stakeholders, and you'll adapt as our programs evolve. We need engineers who can context switch, learn fast, and stay mission focused.
What You'll Work On
Digitizing Cyber Artifacts
- Tools and automated workflows that support cyber assessment and authorization activities, including artifact generation
- Structured, machine readable representations of security requirements, controls, and compliance evidence
- Reducing the manual burden of Risk Management Framework activities without cutting corners on rigor
Cyber Data Schemas and Interoperability
- Defining and integrating cyber relevant data schemas that let tools, models, and environments exchange information cleanly
- Integration with existing systems, services, and repositories through approved APIs and interface protocols
- Making cyber data portable across the digital engineering toolchain instead of trapped in individual applications
Modeling and Simulation
- MBSE and digital twin models, where applicable, built in industry standard modeling languages
- Integration of models with simulation environments to evaluate cyber resiliency and compliance
- Architecture and design recommendations for model enhancements and new cyber engineering capabilities
Secure Delivery
- CI/CD pipeline work: build and test automation, quality gates, secure and repeatable deployments
- Static and dynamic application security testing, peer code review, and vulnerability mitigation
- Deployment into production ready environments using established DevSecOps practices
What You'll Do
- Design and build software solutions and tooling in support of cyber and digital engineering activities
- Define, use, and integrate data schemas that enable interoperability across digital engineering tooling and environments
- Gather functional, technical, and operational requirements through interviews, workshops, and working sessions with stakeholders
- Identify security risks in proposed designs, including data exposure, interface vulnerabilities, and architectural dependencies, and document mitigation recommendations
- Perform unit, integration, functional, regression, and system testing across delivered capabilities
- Participate in working groups, integrated product teams, and technical review meetings to keep technical work aligned with mission, policy, and cybersecurity objectives
- Write implementation documentation, configuration instructions, user guides, and training materials that drive adoption
- Provide post deployment support including fixes, updates, configuration assistance, and incremental improvements based on user feedback
What We're Looking For
Must Haves
- Bachelor's degree in a STEM discipline (Computer Science, Engineering, Mathematics, or related field); advanced degree a plus
- 8+ years of professional software engineering experience
- Strong programming ability in one or more modern languages
- Experience with Git workflows and CI/CD fundamentals
- US Citizenship required; active Secret clearance preferred, must be able to obtain
Preferred
- Working knowledge of cybersecurity policy and the Risk Management Framework (NIST SP 800-37), including authorization and accreditation processes
- Familiarity with MBSE tooling, digital twin development, runelite, and simulation based analysis
- Active CompTIA Security+ certification (or equivalent DoD 8140 cert), or willingness to obtain shortly after hire
- Experience with containerization (Docker/Podman)
- Experience supporting cybersecurity functional teams on DoD programs of record
- Hands-on work with SysML/UML and modeling tools such as Cameo Systems Modeler or MagicDraw
- Familiarity with automated compliance evidence generation, STIGs, or control as code approaches
- Experience with SAST/DAST tooling and secure code review at scale