Cybersecurity Engineer (Assessment and Authorization / Compliance)
- Quinte West, ON
- Sur place
- Publié 2 sept. 2026
- 1 poste
120 000 $ US–155 000 $ US / année
Ouvre un site externe
- Type d’emploi
- Temps plein
- Niveau d’expérience
- Intermédiaire · 4+ ans
- Formation minimale
- Diplôme professionnel
- Langue de l’offre
- anglais
- Heures de travail
- 40 heures par semaine
Résumé du poste
The Cybersecurity Engineer will integrate security evidence collection into CI/CD pipelines to support continuous ATO for containerized applications. They will manage security artifacts, coordinate with government stakeholders, and maintain compliance documentation for DoD systems.
Détails du poste
Zaden Technologies is hiring a Cybersecurity Engineer to bring a DevSecOps mindset to ATO: instead of assembling a security package by hand at the end of a release, you'll wire evidence collection directly into the delivery pipeline so authorization keeps pace with continuous deployment. This is package cyber, not SOC work — you'll own the artifacts that let containerized applications move onto a government system, treating SBOMs, scan results, and compliance evidence as pipeline outputs rather than one-off paperwork. This is a full-time, on-site position in Aurora, CO, with some travel, and an anticipated start of April 2027. Role Responsibilities: Prepare and maintain security packages for containerized deployments, including SSP, ATO artifacts, and supporting RMF documentation Build automated evidence collection into the CI/CD pipeline so SBOMs, scan outputs, and compliance artifacts generate continuously rather than at release time Own static/dynamic analysis tooling (SonarQube or similar) and container image scanning as part of the delivery pipeline Coordinate package submission and remediation with government security stakeholders, keeping pace with an evidence-as-code approach to ATO Partner with the DevSecOps team to treat authorization gates like any other pipeline gate: automated, repeatable, and continuously validated Flex into DevSecOps tasks as workload allows Required Qualifications: Active TS/SCI clearance, or current TS/SCI eligibility, and U.S. citizenship 4+ years in cybersecurity for DoD or federal systems with direct RMF/A&A package experience (SSP, POA&M, ATO artifacts) DoD 8140/8570 baseline certification (Security+ CE or equivalent minimum) Working knowledge of container security: image scanning, SBOMs, and static/dynamic analysis tooling Comfort working inside a CI/CD pipeline and automating evidence generation rather than assembling it manually Preferred Qualifications: Hands-on DevSecOps skills (pipelines, Kubernetes, scripting) to serve as a cross-certified cyber/DevOps resource Experience with continuous-ATO or evidence-as-code approaches on DoD software factory programs eMASS or equivalent authorization-tracking system experience Experience supporting space or missile warning ground systems What we offer: Robust startup environment with a variety of projects to work on Growth paths and endless opportunities to learn and develop Paid holidays and flexible paid time off Employer contributions toward 401k 50% coverage of health insurance for employees and their dependents
Ce que vous ferez
The Cybersecurity Engineer will integrate security evidence collection into CI/CD pipelines to support continuous ATO for containerized applications. They will manage security artifacts, coordinate with government stakeholders, and maintain compliance documentation for DoD systems.
Exigences
Candidates must possess an active TS/SCI clearance and at least 4 years of experience in cybersecurity for federal systems with RMF/A&A expertise. A DoD 8140/8570 baseline certification, such as Security+ CE, is required along with proficiency in container security and pipeline automation.
Avantages
• Paid holidays • Flexible paid time off • 401k • Health insurance
Compétences indiquées
- Kubernetes · Souhaitée
- CI/CD · Souhaitée
Autres compétences pertinentes
Relevées dans la description du poste. Confirmez les exigences importantes ci-dessus.
- Cybersecurity
- RMF
- A&A
- DevSecOps
- CI/CD
- Container security
- SBOM
- SonarQube
- Kubernetes
- Scripting
- eMASS
- Security+ CE
- DoD compliance
- Static analysis
- Dynamic analysis
- Plan Of Action And Milestones (POA&M)
- CompTIA Security+ CE
- Pipelines
- Enterprise Mission Assurance Support Service (eMASS)
- Container Security
- Cyber Engineering
- Time Off Management
- Evidence Collection
- Continuous Deployment
- Containerized Application
- Automation
- Cyber Security
- DevOps
- Dynamic Program Analysis
- Software Factory
- Tooling
- Authorization (Computing)
- Top Secret-Sensitive Compartmented Information (TS/SCI Clearance)
- Delivery Pipelines
Domaines d’emploi
- Technology
- Security & Safety
- Software
- Engineering
- Government & Public Sector
- Cybersecurity Engineer
- Cyber Security Engineer
- Database and Network Professionals Not Elsewhere Classified
- Information Security Engineers
- Computer Occupations, All Other
D’autres postes auxquels postuler directement
Des possibilités semblables publiées par des employeurs qui recrutent sur Jobs.ca, sans formulaire externe.
Desjardins
Administrateur ou administratrice de plateforme TI - Senior
Employeur directCandidature simplifiée- Hybride
- Montréal, QC
- Publié 17 sept. 2026
Connectability Inc.
Technical Sales Specialist
Employeur directCandidature simplifiée- Hybride
- Publié 5 sept. 2026
Government of Ontario
Infirmier autorisé
CommanditéEmployeur directCandidature simplifiée- Sur place
- Lindsay, ON
- Publié 17 sept. 2026