Jobs · Information Technology · Colorado

Senior DevSecOps Cybersecurity Engineer

KBR Careers · Colorado Springs, CO · Yesterday
Information Technology$149k–$186k/yrFull-time

About the Role

KBR is seeking a motivated and experienced Senior DevSecOps Cybersecurity Engineer to join our team. The primary work locations are El Segundo, CA and Colorado Spring, CO, but work-from-home flexibility is available. This role serves as a senior cybersecurity practitioner embedded within Agile and DevSecOps development teams responsible for delivering capabilities into government-owned production environments operating at IL5 and IL6. The Cybersecurity Engineer will work closely with software developers, cloud engineers, mission owners, systems engineers, Information System Security Managers (ISSMs), Authorizing Officials (AOs), and government cybersecurity personnel to ensure software releases meet security, compliance, and operational requirements.

Responsibilities

  • Cybersecurity Engineering: Serve as the primary cybersecurity engineering lead supporting DevSecOps software delivery efforts. Provide cybersecurity guidance throughout the software development lifecycle from design through production deployment. Evaluate system architectures, software components, and deployment pipelines for compliance with DoD and Department of the Air Force cybersecurity requirements. Partner with development, platform, cloud, and infrastructure teams to ensure security is integrated into all phases of delivery.
  • CVE Analysis & Remediation: Assess Common Vulnerabilities and Exposures (CVEs) identified through automated scanning, security testing, and cybersecurity reviews. Analyze operational impact, exploitability, mission risk, and remediation options for vulnerabilities affecting mission systems. Develop mitigation strategies and Plans of Action and Milestones (POA&M) recommendations when immediate remediation is not feasible. Provide technical justification and risk-based explanations to government stakeholders regarding vulnerability disposition decisions. Support vulnerability review boards and release decisions for software entering production environments.
  • RMF & Compliance Support: Risk Management Framework (RMF) activities across development, test, staging, and production environments. Assist with implementation and maintenance of NIST 800-53 security controls. Develop and maintain cybersecurity artifacts required to support system authorization and continuous monitoring activities. Prepare material supporting cybersecurity assessments, authorization reviews, and package updates. Assist with security control assessments and remediation activities associated with authorization findings.
  • Secure Deployment & Operations: Support secure software release processes into IL5 and IL6 production environments. Collaborate with DevSecOps teams to establish compliant deployment methodologies and release procedures. Validate cybersecurity readiness prior to production deployments and major software releases. Review security impacts of infrastructure, software, and configuration changes. Ensure application, container, platform, and infrastructure security requirements are met prior to deployment.
  • Security Documentation & Readiness Activities: Support development and maintenance of cybersecurity documentation including Cybersecurity Strategies (CSS), System Security Plans (SSPs), authorization package artifacts, and supporting cybersecurity documentation. Participate in Cyber Vulnerability Identification (CVI) events, cybersecurity assessments, security audits, and remediation activities. Support Continuity of Operations (COOP) planning, tabletop exercises, incident response activities, and operational readiness events. Assist mission teams in preparing for cybersecurity inspections, compliance reviews, and authorization activities. Coordinate with government cybersecurity organizations to ensure documentation remains current and audit-ready.
  • Stakeholder Collaboration: Interface directly with government cybersecurity personnel, ISSMs, ISSOs, Authorizing Officials, mission owners, and engineering teams. Communicate cybersecurity risks, mitigation options, and deployment recommendations to leadership and operational stakeholders. Support Agile ceremonies, release planning events, architecture reviews, and technical working groups. Provide cybersecurity guidance to software teams on secure coding, vulnerability remediation, and release readiness.

Requirements

  • Able to obtain and maintain a DoD Secret clearance
  • Bachelor's degree in engineering, computer science, information systems, cybersecurity or related technical field
  • 7+ years of cybersecurity, information assurance, DevSecOps, system security engineering, or related defense experience
  • Extensive experience implementing and supporting the Risk Management Framework (RMF)
  • Strong understanding of NIST 800-53 security controls and DoD cybersecurity policies
  • Demonstrated experience evaluating, explaining, mitigating, and remediating Common Vulnerabilities and Exposures (CVEs)
  • Experience supporting software deployments within accredited government production environments
  • Strong understanding of IL5 and IL6 cloud environments and associated cybersecurity requirements
  • Experience supporting ATO and continuous monitoring activities
  • Experience working directly with government cybersecurity organizations and mission stakeholders
  • Ability to communicate technical cybersecurity issues to both technical and executive audiences
  • Strong written communication skills supporting cybersecurity documentation, risk acceptance packages, and authorization artifacts

Preferred Qualifications

  • Active DoD Secret clearance or higher
  • Master's degree in engineering, computer science, information systems, cybersecurity or related technical field
  • Experience supporting Space Systems Command (SSC), Space Operations Command (SpOC), U.S. Space Force, or other DoD space organizations
  • Experience supporting operational systems accredited under RMF within classified environments
  • Familiarity with Platform One, Cloud One, Kubernetes, Iron Bank, Big Bang, and related DoD DevSecOps ecosystems
  • Experience supporting Authority to Operate (ATO) and Continuous Authorization to Operate (cATO) initiatives
  • Knowledge of Secure Software Development Framework (SSDF) and modern DevSecOps pipelines
  • Experience supporting Cybersecurity Strategies (CSS), Cyber Vulnerability Identification (CVI) events, cybersecurity inspections, and COOP tabletop exercises
  • Experience with STIG implementation, SCAP compliance, ACAS, Nessus, Fortify, SonarQube, Snyk, Prisma Cloud, Twistlock, or similar security tooling
  • Security certifications such as CISSP, CASP+, Security+, CISM, CCSP, or GIAC certifications
  • Experience supporting mission-critical systems deployed in classified cloud environments
  • Experience supporting software modernization efforts within U.S. Space Force programs
  • Familiarity with SATCOM, space operations, command and control systems, mission planning systems, or enterprise management platforms
  • Experience implementing Zero Trust architectures within DoD environments
  • Experience balancing mission delivery timelines with cybersecurity compliance requirements in operational production systems
  • Experience supporting large-scale software factories or government-managed production environments
  • Certifications such as CISSP, CompTIA Security+
  • Certifications such as INCOSE CSEP or ESEP

Compensation

$149,000-$186,000 in El Segundo, CA. The offered rate will be based on the selected candidate's knowledge, skills, abilities and/or experience and in consideration of internal parity.

Benefits

  • 401K plan with company match
  • Medical, dental, vision, life insurance, AD&D
  • Flexible spending account
  • Disability insurance
  • Paid time off
  • Flexible work schedule
  • Professional training and development

Similar jobs