Summary
What you’ll impact
Our organization is seeking a Senior Security Engineer to design, implement, and operate secure systems across commercial and DoD environments, ensuring compliance with FedRAMP and DoD Impact Level requirements. The role involves hands‑on security engineering, incident response, security integration into the SDLC, and protecting AI‑driven flight safety technology.
Responsibilities
What you'll do
- Design and implement secure architectures across applications, cloud infrastructure, backend services, and in-cockpit edge systems, including environments built to FedRAMP Moderate baseline and DoD IL4/IL5 environments.
- Protect sensitive data through strong controls for access management, encryption, and secure data handling, consistent with NIST 800-53 and NIST 800-171 requirements.
- Identify, assess, and mitigate security risks through vulnerability assessments, penetration testing, and security reviews.
- Lead incident response efforts, including detection, containment, remediation, and follow-up analysis.
- Integrate security into the SDLC by partnering with software teams on threat modeling, secure code review, and automated security checks in CI/CD and infrastructure-as-code.
- Implement and operate security monitoring and logging to detect and respond to threats in real time.
- Support authorization and compliance efforts (ATO packages, SSPs, POA&Ms) for FedRAMP and DoD accreditation processes.
- Help maintain CMMC 2.0 readiness and alignment with DFARS cybersecurity clauses across the environment.
- Secure our AI systems, including LLM and retrieval-based features, against risks like prompt injection, data leakage, and model misuse.
Requirements
What you’ll bring
- 5+ years of hands-on experience in security engineering roles securing complex systems and data, including production cloud environments (AWS or AWS GovCloud strongly preferred)
- Strong knowledge of security principles, threat modeling, and defensive security practices.
- Experience with common security tools and technologies (e.g., SIEM, IDS/IPS, vulnerability scanning, encryption).
- Familiarity with security and compliance frameworks such as NIST 800-53/800-171, ISO 27001, and CMMC.
- Direct experience with FedRAMP authorization processes (ATO, SSP, POA&M) and/or DoD Impact Level (IL4/IL5) environments.
- Comfort being an early security owner: setting priorities, building from scratch, and balancing risk against a fast-moving product roadmap.
- Proven ability to collaborate effectively with software engineers on secure system design.
- Hands-on mindset with strong analytical and problem-solving skills.
- Must be a U.S. Person (U.S. citizen, Green Card holder, lawful permanent resident, or individual granted asylum or refugee status); no visa sponsorship or transfers are available; all work must be performed in the United States.
- Hybrid work location in San Carlos, CA, with at least 3 days per week onsite.