For Employers
Apply Now

Please mention DailyRemote when applying

?/100
Resume Match Score

Match your resume skills with our AI powered skill match!

Get professional review

Create a cover letter for this job

Upload your resume and we draft a letter for this exact role, tailored to what it asks for.

  • Tailored to this role
  • Based on your resume
  • Fully editable
AI Summary

Integrate cybersecurity and Information Assurance requirements directly into DevSecOps pipelines and software delivery processes. Design and maintain automated security controls and tooling to ensure DoD compliance without hindering the delivery lifecycle.

This is a U.S. based position. All of the programs we support require U.S. citizenship to be eligible for employment. All work must be conducted within the continental U.S.

Who we are:

Raft (https://TeamRaft.com) is a customer-obsessed non-traditional defense tech company dedicated to empowering U.S. military and government agencies with cutting-edge AI/ML and data solutions. We are a leader in autonomous data fusion and Agentic AI, with a purposeful focus on Distributed Data Systems, Platforms at Scale, and Complex Application Development. With headquarters in McLean, VA, our range of clients includes innovative federal and public agencies leveraging design thinking, cutting-edge tech stack, and cloud-native ecosystem. We build digital solutions that impact the lives of millions of Americans.

About the role:

The SeniorCybersecurity Engineer supports a DoW program by ensuring Information Assurance (IA), cybersecurity, and security engineering requirements are incorporated directly into the platform’s DevSecOps pipelines, tooling, configurations, and software delivery processes.
 
This role works closely with the Pipeline Architect, Software Engineering SMEs, infrastructure/platform engineers, and government stakeholders to ensure required DoD cybersecurity thresholds are met without creating unnecessary friction in the software delivery lifecycle. The Senior Cybersecurity Engineer helps translate security and compliance requirements into technical controls that can be automated, validated, and continuously enforced within the pipeline.
 
Key Responsibilities
  • Work with the Pipeline Architect and Software Engineering SMEs to ensure DoD IA and cybersecurity thresholds are met and built directly into pipeline tooling, configurations, and workflows.
  • Translate DoD cybersecurity, RMF, and DevSecOps requirements into actionable technical requirements for engineering teams.
  • Design, implement, configure, and maintain automated security controls within CI/CD pipelines.
  • Integrate and maintain security tooling for SAST, DAST, software composition analysis (SCA), container scanning, secrets detection, dependency scanning, and vulnerability management.
  • Establish and enforce security gates and thresholds within GitLab CI/CD pipelines to prevent noncompliant or vulnerable software artifacts from progressing through the delivery lifecycle.
  • Support secure software supply chain practices, including artifact integrity, SBOM generation, vulnerability scanning, signing, provenance, and software attestations.
  • Work with engineering teams to integrate tools such as Fortify, SonarQube, Trivy, Twistlock/Prisma Cloud, NeuVector, Cosign/Sigstore, and similar security capabilities into automated workflows.
  • Review Kubernetes, container, GitLab Runner, infrastructure-as-code, and pipeline configurations for security vulnerabilities and configuration weaknesses.
  • Support vulnerability triage and remediation by working directly with software and platform engineering teams to determine severity, operational impact, remediation approaches, and acceptable mitigation strategies.
  • Develop and maintain security-as-code and policy-as-code approaches that allow cybersecurity requirements to be consistently enforced across environments.
  • Support compliance with the DoD DevSecOps Reference Design, NIST Risk Management Framework (RMF), NIST 800-53 controls, and applicable DoD cybersecurity requirements.
  • Support the collection and automation of security evidence required for authorization and continuous monitoring activities.
  • Partner with platform and application teams to ensure cybersecurity requirements support the UP continuous Authority to Operate (cATO) approach and Continuous Delivery/Continuous Deployment processes.
  • Identify cybersecurity risks associated with changes to pipeline architecture, platform baselines, infrastructure, and application delivery processes and recommend technical mitigations.
  • Develop security documentation, technical implementation guidance, configuration standards, and engineering best practices.
  • Participate in architecture reviews, technical discussions, troubleshooting sessions, and security assessments.

What we are looking for: 

  • 3+ years of experience in Cybersecurity Engineering, DevSecOps, Platform Engineering, Cloud Security, Application Security, or a related technical discipline.
  • Hands-on experience implementing security capabilities within CI/CD pipelines, preferably GitLab CI/CD.
  • Experience with one or more application or container security technologies such as Fortify, SonarQube, Trivy, Twistlock/Prisma Cloud, NeuVector, or equivalent tools.
  • Experience with containerized environments and Kubernetes security concepts.
  • Experience identifying, assessing, and remediating software, container, infrastructure, or configuration vulnerabilities.
     
  • Working knowledge of DoD RMF, NIST SP 800-53, and DoD cybersecurity/Information Assurance requirements.
     
  • Understanding of DevSecOps principles and the integration of security controls throughout the software development lifecycle.
     
  • Experience working with Git and infrastructure/configuration-as-code technologies such as Terraform, Ansible, Helm, or equivalent technologies.
     
  • Understanding of software supply chain security concepts, including SBOMs, artifact signing, provenance, vulnerability scanning, and attestations.
     
  • Ability to translate cybersecurity requirements into practical technical controls and communicate effectively with both cybersecurity and engineering stakeholders.

Highly preferred:

  • Experience with GitLab, GitLab Runners, Argo CD, Kubernetes, Helm, SOPS, AWS/GovCloud, Platform One or other DoD software factories, and DoD cATO environments is preferred. Familiarity with Cosign/Sigstore, container registries, package managers, microservices architectures, Kubernetes admission controls, policy-as-code, and automated compliance evidence collection is also highly desirable.
     
  • Experience supporting software delivery within IL4/IL5/IL6 DoD environments and working directly with ISSMs, ISSOs, security control assessors, Authorizing Officials, or government cybersecurity organizations is a plus.
    Certifications
     
  • DoD 8140/8570-compliant cybersecurity certification appropriate to the position is preferred (e.g., Security+, CySA+, CASP+/SecurityX, CISSP, or equivalent).
     
  •  Kubernetes, cloud security, or AWS certifications are desirable.

Clearance Requirements:

  • Minimum active Secret Clearance required to start

Salary Range: $140,000.00 - $160,000.00

Work Type:

  • Remote with a preference for candidates based in San Antonio, TX
  • Travel up to 35% to customer sites

What we will offer you: 

  • Highly competitive salary
  • Fully covered healthcare, dental, and vision coverage
  • 401(k) and company match
  • Take as you need PTO + 11 paid holidays
  • Education & training benefits
  • Generous Referral Bonuses
  • And More!

Our Vision Statement: 

We bridge the gap between humans and data through radical transparency and our obsession with the mission. 

Our Customer Obsession: 

We will approach every deliverable like it's a product. We will adopt a customer-obsessed mentality. As we grow, and our footprint becomes larger, teams and employees will treat each other not only as teammates but customers. We must live the customer-obsessed mindset, always. This will help us scale and it will translate to the interactions that our Rafters have with their clients and other product teams that they integrate with. Our culture will enable our success and set us apart from other companies.

How do we get there? 

Public-sector modernization is critical for us to live in a better world. We, at Raft, want to innovate and solve complex problems. And, if we are successful, our generation and the ones that follow us will live in a delightful, efficient, and accessible world where out-of-box thinking, and collaboration is a norm. 

Raft’s core philosophy is Ubuntu: I Am, Because We are. We support our “nadi” by elevating the other Rafters. We work as a hyper collaborative team where each team member brings a unique perspective, adding value that did not exist before. People make Raft special. We celebrate each other and our cognitive and cultural diversity. We are devoted to our practice of innovation and collaboration. 

We’re an equal opportunity employer. All applicants will be considered for employment without attention to race, color, religion, sex, sexual orientation, gender identity, national origin, veteran or disability status.

Automatically Apply to the Best Remote Jobs

Stop the endless job search. Our AI finds and applies to the best jobs for you.

Try it Now
Keep looking

Similar Jobs

See all Remote Software Development jobs →

Principal Software Engineer - FDE

Full Time United States $142K - $274K per year Software Development

Experienced Programmer Analyst

Full Time United States $90900 - $129K per year Software Development

Principal Deployment Engineer - AI Project Controls

Full Time United States $110K - $140K per year Software Development

Senior Data Analyst - Fraud

Full Time Spain Software Development

SAP Solution Architect, SD

Full Time Mexico Software Development

Senior Software Engineer

Full Time Poland Software Development
Apply Now

Personalize your Remote Job Search in 3 Easy Steps!

Featuring 215,372+ Jobs in Software Development

Answer easy questions

Answer easy questions

215,372+ jobs across 15+ categories

Get your best job matches

Get your best job matches

Only hand-screened, legit jobs

Find a remote job faster

Find a remote job faster

No ads, scams, or junk

I was the first applicant for a remote marketing position that got listed on the company website the same day I applied. Had an interview within 48 hours!”

Sarah J. — Sarah J. · Marketing Manager ★★★★★ Verified