
Senior Engineer
Raft Company Website7 hours ago
Remote, United States or San Antonio, TX, USASenior
Base Salary
$140k - $160k/yr
Responsibilities
- Embed DoD information assurance and cybersecurity requirements into pipeline tooling, configurations, workflows, and software delivery processes.
- Design, implement, configure, and maintain automated security controls and security gates in GitLab CI/CD pipelines.
- Integrate security tools for application security, container scanning, secrets detection, dependency scanning, software composition analysis, and vulnerability management.
- Support software supply-chain security through artifact integrity, SBOM generation, signing, provenance, attestations, and vulnerability scanning.
- Review Kubernetes, container, GitLab Runner, infrastructure-as-code, and pipeline configurations for vulnerabilities and weaknesses.
- Triage and remediate software, container, infrastructure, and configuration vulnerabilities with engineering teams.
- Develop security-as-code and policy-as-code approaches and automate security evidence for authorization and continuous monitoring.
- Support DoD DevSecOps, NIST RMF, NIST 800-53, cATO, and continuous delivery requirements.
- Create security documentation, implementation guidance, configuration standards, and engineering best practices.
- Participate in architecture reviews, troubleshooting, security assessments, and technical discussions with engineering and government stakeholders.
Requirements
- At least 3 years of experience in cybersecurity engineering, DevSecOps, platform engineering, cloud security, application security, or a related technical discipline.
- Hands-on experience implementing security capabilities in CI/CD pipelines, preferably GitLab CI/CD.
- Experience with application or container security tools such as Fortify, SonarQube, Trivy, Twistlock/Prisma Cloud, NeuVector, or equivalent technologies.
- Experience with containerized environments and Kubernetes security concepts.
- Experience identifying, assessing, and remediating software, container, infrastructure, or configuration vulnerabilities.
- Working knowledge of DoD RMF, NIST SP 800-53, and DoD cybersecurity or information assurance requirements.
- Experience with Git and infrastructure or configuration-as-code technologies such as Terraform, Ansible, or Helm.
- Understanding of software supply-chain security, including SBOMs, artifact signing, provenance, vulnerability scanning, and attestations.
- Ability to translate cybersecurity requirements into practical technical controls and communicate with cybersecurity and engineering stakeholders.
- Preferred experience with GitLab, GitLab Runners, Argo CD, Kubernetes, Helm, SOPS, AWS/GovCloud, Platform One, DoD software factories, DoD cATO environments, Cosign/Sigstore, container registries, package managers, Kubernetes admission controls, policy-as-code, and automated compliance evidence collection.
- Experience supporting software delivery in IL4, IL5, or IL6 DoD environments and working with ISSMs, ISSOs, security control assessors, authorizing officials, or government cybersecurity organizations is preferred.
- A DoD 8140/8570-compliant cybersecurity certification such as Security+, CySA+, CASP+/SecurityX, CISSP, or equivalent is preferred; Kubernetes, cloud security, or AWS certifications are desirable.
- Minimum active Secret clearance is required to start.
- U.S. citizenship is required for employment eligibility.
Benefits
- Remote work with a preference for candidates based in San Antonio, Texas.
- Up to 35% travel to customer sites.
- Fully covered healthcare, dental, and vision coverage.
- 401(k) with company match.
- Take-as-needed paid time off and 11 paid holidays.
- Education and training benefits.
- Generous referral bonuses.
Tech Stack
Categories
About Raft Company Website
Raft is a defense technology company that builds AI/ML, autonomous data fusion, and cloud-native software platforms for U.S. military and government agencies. It develops distributed data systems, DevSecOps/GitOps platforms, and applications to operate at scale in secure environments. Headquartered in McLean, Virginia, the privately held firm is backed by Washington Harbour Partners, which invested $60M in private equity funding in 2024.