Sphera

Cybersecurity Engineer - DevOps

Sphera
Apply
23 hours ago
Remote, United StatesMid Level / Senior

Base Salary

$112k - $178k/yr

Responsibilities

  • Lead cybersecurity and compliance for software deployed in secure federal and DoD environments.
  • Execute RMF activities, including system categorization, control selection, implementation, assessment, and ATO documentation.
  • Implement and validate DISA-approved STIGs, scan vulnerabilities, audit systems, and coordinate remediation.
  • Manage POA&Ms and maintain SSPs, security architectures, and ATO documentation packages.
  • Support FedRAMP and FISMA compliance and map controls to NIST SP 800-53 Rev. 5.
  • Integrate SAST, DAST, and SCA security checks into CI/CD pipelines to advance DevSecOps maturity.
  • Conduct threat modeling, security design reviews, and application-level security assessments.
  • Lead incident response, monitor SIEM alerts, analyze logs, and investigate anomalous activity.
  • Evaluate the security posture of third-party integrations, vendor tools, and emerging technologies.
  • Embed security requirements into sprint planning, feature development, and release processes.
  • Communicate security findings and policy impacts to engineering teams, government stakeholders, and cybersecurity personnel.

Requirements

  • U.S. citizenship and an active DoD security clearance or ability to obtain and maintain one are required.
  • A minimum of 3–5 years of hands-on cybersecurity experience in federal, DoD, or similarly regulated secure environments is required.
  • Experience supporting or leading RMF processes and preparing ATO packages for federal or DoD systems is required.
  • Proficiency applying STIGs with DISA-approved tools such as SCC, STIG Viewer, Nessus, or ACAS is required.
  • Knowledge of FedRAMP Moderate, FISMA, and NIST SP 800-53 Rev. 5 is required.
  • Experience with vulnerability management tools such as Tenable.sc, Nessus, or ACAS is required.
  • Familiarity with SIEM, IDS/IPS, network security controls, segmented networks, PKI, CAC/PIV authentication, and certificate management is required.
  • DevSecOps experience integrating SAST, DAST, and SCA scanning into CI/CD pipelines using Azure DevOps, Jenkins, or equivalent tools is required.
  • A DoD 8570/8140-compliant IAT Level II or higher certification is required, such as CompTIA Security+, CISSP, CEH, or CAP.
  • A bachelor’s degree in Computer Science, Information Security, Cybersecurity, or a related field, or equivalent practical experience, is required.
  • Strong written, verbal, organizational, interpersonal, independent-work, and collaboration skills are required.

Benefits

  • Medical, dental, and vision insurance.
  • Health Savings Account and Flexible Spending Account.
  • 401(k) retirement plan with company match.
  • Life and disability insurance.
  • Critical illness, accident, and hospital indemnity insurance.
  • Paid time off and holidays.
  • Flexible working schedule.
  • Eligible for a variable compensation plan in addition to the stated base salary.

Tech Stack

Jenkins

Categories

Sphera

About Sphera

1,001-5,000 employees

Sphera builds enterprise software and data solutions for EHS, sustainability, operational risk, and product stewardship, delivered via its SpheraCloud SaaS platform and consulting services. Its tools help companies manage compliance, safety, emissions, and supply‑chain impacts across operations and products. Founded in 2016, headquartered in Chicago, and owned by Blackstone, it serves customers across energy, manufacturing, chemicals, and other regulated industries.

Contact me