Spin.AI is a global SaaS cybersecurity company that protects mission-critical data across Google Workspace, Microsoft 365, Salesforce, Slack & more. Our product — SpinOne — unifies SSPM, ransomware protection, DLP, backup & recovery in one platform trusted by enterprise customers worldwide.
We are looking for a Junior/Middle UI/UX Designer to help us design clear, scalable, and trustworthy user experiences for our cybersecurity SaaS platform and AI-powered product features.
This role is a great fit for someone who is curious, proactive, comfortable using AI tools, and interested in complex B2B products. For Middle-level candidates, experience with cybersecurity, enterprise SaaS, or security-related products will be a strong advantage.
You will work closely with Product, Engineering, and other stakeholders to turn complex product logic into simple, intuitive, and visually consistent user experiences.
You’ll design web application interfaces, dashboards, user flows, prototypes, and reusable components while supporting and evolving our design system.
This role is based in our Malaga office in a hybrid format. If you are not currently in Malaga, we are open to remote work during the trial period, with relocation to Lisbon afterward.
🧰 Day-to-Day Responsibilities
Design UX/UI solutions for a complex cybersecurity SaaS product
Create wireframes, user flows, prototypes, and high-fidelity UI designs
Work with AI-powered product features and enterprise workflows
Maintain and scale reusable components and design system patterns
Collaborate with Product and Engineering to clarify requirements and improve UX
Use AI tools such as Claude, Figma AI, or similar to support design workflows
Ensure consistency, usability, responsive behavior, and visual quality across the product
📌 Requirements
1+ year of experience in UX/UI Design, Product Design, or similar
Experience designing web applications, SaaS products, dashboards, or complex interfaces
Experience working with design systems and component-based design
Strong proficiency in Figma
Hands-on experience using AI tools in design workflows
Ability to create wireframes, user flows, prototypes, and high-fidelity UI designs
Good understanding of UX principles, interaction design, visual hierarchy, and user-centered design
Understanding of responsive design and modern web application patterns
Familiarity with design systems and component-based design
Basic understanding of usability testing and iterative design process
English: Intermediate+
Nice-to-have
Experience with cybersecurity, security products, or enterprise SaaS
Experience designing AI-powered product features
Understanding of trust-centered design for AI-powered or security-related products
Experience with complex data, dashboards, admin panels, permissions, alerts, or monitoring systems
Interest in AI, cybersecurity, SaaS, or enterprise software
🌍 Why Spin.AI
Work in a fast-moving, high-impact cybersecurity company recognized by Gartner, Forrester, and G2.
Work on a real product with real users and visible business impact
Work on an interesting and large-scale product
Solve complex, non-trivial security and engineering challenges
Opportunity to influence technical and product decisions
Trust from management and autonomy in day-to-day work
Strong, professional team with deep expertise
🎁 What we offer
Annual performance-based salary review
Annual performance-based bonus
Referral bonuses
Educational budget
Sport & hobby compensation
Medical insurance compensation
Company presents (birthdays, anniversaries, weddings, etc.)
The Information System Security Officer (ISSO) provides senior-level cybersecurity engineering and compliance support to the Defense Information Systems Agency (DISA) Internet Enterprise (IE) under the CTAS Task Order. This role is responsible for ensuring mission systems achieve and sustain Authorization to Operate (ATO) through implementation of the Risk Management Framework (RMF) and transition from legacy DIACAP requirements. The ISSO – Level 3 acts as both a technical and compliance leader, bridging vulnerability management, STIG/SRG application, and documentation development to create complete and accurate accreditation packages. This position serves as a senior-level resource, providing mentorship to mid-level and junior ISSOs, while interfacing with Government stakeholders, Information System Security Managers (ISSMs), and Authorizing Officials (AOs).
Key Responsibilities:
The ISSO is expected to perform duties that span both hands-on technical tasks and high-level compliance oversight. Core responsibilities include:
Leading the development, maintenance, and validation of RMF and A&A artifacts, including System Security Plans (SSPs), Security Assessment Reports (SARs), Plans of Action and Milestones (POA&Ms), configuration management records, and testing documentation.
Implementing and validating compliance with DISA Security Technical Implementation Guides (STIGs) and Security Requirements Guides (SRGs) to maintain technical baselines across supported systems.
Managing and analyzing results from vulnerability scanning and compliance tools such as ACAS, HBSS, and CMRS, and ensuring timely remediation of findings in accordance with IAVM directives.
Preparing and submitting comprehensive accreditation packages in eMASS, ensuring accuracy, completeness, and timeliness of submissions to meet contract and PWS requirements.
Conducting and documenting Security Test and Evaluation (ST&E) activities, ensuring objective assessment of control implementation and risk posture.
Supporting and preparing for Command Cyber Readiness Inspections (CCRI), Security Assessment Visits (SAV), and Cooperative Vulnerability Penetration Assessments (CVPA) by creating corrective action plans, briefing results, and tracking closure of findings.
Providing mentorship and guidance to junior ISSOs, ensuring proper interpretation of DoD cybersecurity policy and consistent application of standards across the team.
Contributing to recurring deliverables such as Policy Compliance Reports, Risk Assessment Reports, and Directorate-level cybersecurity briefings, ensuring all outputs meet QASP Acceptable Quality Levels (AQLs).
Required Qualifications:
Bachelor’s degree in Cybersecurity, Information Technology, or related field.
Must hold and maintain an appropriate DoD 8140.03 / 8570.01-M certification baseline for this labor category (e.g., Security+, CISSP, CISM, or equivalent as required).
At least 7 years of experience in cybersecurity engineering, RMF/DIACAP accreditation, and compliance documentation in DoD environments.
Expertise in the application of DISA STIGs/SRGs, ACAS/HBSS vulnerability analysis, and eMASS package preparation.
Strong written and verbal communication skills, with demonstrated experience producing accreditation documentation and presenting risk findings to senior stakeholders.
Desired Qualifications:
Master’s degree in Cybersecurity or related discipline.
Experience supporting DISA programs and preparing for CCRI inspections.
Advanced certifications such as CISSP-ISSAP or CISM.
As a Forescout Cyber Security Engineer at Cinteot, you will play a critical role in safeguarding our information technology infrastructure. Your expertise will be essential in managing cybersecurity controls and enhancing our detection capabilities within a collaborative team environment.
Key Responsibilities:
Develop relationships quickly and easily with other teams, communicating the complexities of security with a wide variety of audiences, including senior management.
Manage infrastructure and cybersecurity controls, including enhanced detection and vulnerability capabilities and improved event correlation in large enterprises.
Contribute to risk and vulnerability assessments in network, system, and application areas, leveraging big data analytics to identify advanced threats or indicators of compromise.
Required Qualifications:
5+ years of experience performing systems administration for Windows or Linux, including troubleshooting, installation, configuration, and security upgrades.
Experience architecting and designing IP networks, with the ability to develop and document network topologies.
Knowledge of multi-domain architectures, including data center, WAN, and LAN in virtualized environments.
TS/SCI clearance with the ability to obtain a counterintelligence (CI) polygraph.
Associate’s degree with 5+ years of experience, Bachelor’s degree with 3+ years, or Master’s degree with 1+ year of experience supporting IT projects. Experience may be accepted in lieu of a degree.
DoD 8570 IAT Level II Certification, including Security+ CE, CCNA-Security, GSEC, SSCP, CySA+, GICSP, or CND Certification.
Ability to obtain a DoD 8570 Cybersecurity Service Provider - Infrastructure Support Certification (CSSP-IS) prior to the start date.
Additional Qualifications:
Experience with deployment or daily maintenance of Forescout CounterACT appliances.
Knowledge of federal information security policies, standards, and risk management processes for enterprise systems.
Ability to install and deploy Forescout in customer environments.
Ability to integrate Cybersecurity data using enterprise or custom data aggregation and analysis tools, including Splunk.
Ability to provide support in a Tier II IT operations and maintenance role.
Self-starter with excellent verbal and written communication skills.
Company Culture:
At Cinteot, we foster a culture of collaboration, innovation, and continuous learning. We believe in empowering our employees to grow both personally and professionally in a supportive environment.
As an Information Systems Security Engineer (ISSE), you'll:
-Facilitate sub-projects as they go through the Risk Management Framework (RMF) accreditation life cycle. -Support the periodic system security scans as required by policy and the RMF. -Validate and verify system security requirement definitions and analyze system security designs. -Perform technical security assessments of computing environments to identify points of vulnerability, and then recommend mitigation strategies for those that do not comply with established Information Assurance (IA) standards. -Experience manually reviewing network diagrams, network device configurations, termination points for VPNs, and a working knowledge of software TLS security. -Able to maintain a flexible and non-traditional RMF review of secure networks to assess and prescribe countermeasures for secure communications e.g. analog radio, mobile cellular, remote kits, software/hardware-based VPN solutions and VDI technologies. -Familiar with applying different standards and security frameworks to include CIS benchmarks, FIPS 140-2, DISA Stigs, CNSA cryptographic suite compliance, etc. -Participated as a security engineering representative on engineering teams for the design, development, implementation and/or integration of secure networking, computing, and enclave environments. -Participated as a security engineering representative on engineering teams for the design, development, implementation and/or integration of IA architectures, systems, or system components. -Supported the Government in the enforcement of the design and implementation of trusted relationships among external systems and architectures. -Applied knowledge of IA policy, procedures, and workforce structure to design, develop, and implement secure networking, computing, and enclave environments -Supported security planning, assessment, risk analysis, and risk management. -Identified overall security requirements for the proper handling of Government data.
Required Qualifications -Bachelor’s degree in Cybersecurity, Information Technology, or related field. -Must hold and maintain an appropriate DoD 8140.03 / 8570.01-M certification baseline for this labor category (e.g., Security+, CISSP, CISM, or equivalent as required). -At least 7 years of experience in cybersecurity engineering, RMF/DIACAP accreditation, and compliance documentation in DoD environments. -Expertise in the application of DISA STIGs/SRGs, ACAS/HBSS vulnerability analysis, and eMASS package preparation. -Strong written and verbal communication skills, with demonstrated experience producing accreditation documentation and presenting risk findings to senior stakeholders.
Desired Qualifications -Master’s degree in Cybersecurity or related discipline. -Experience supporting DISA programs and preparing for CCRI inspections. -Advanced certifications such as CISSP-ISSAP or CISM.
Clearance Requirement -Active Top Secret clearance
Satellite Communications System Security Engineer, Sr
Cinteot
Fort Meade, MD, United States
2 months ago
The Opportunity:
Are you seeking an opportunity to enhance your expertise in satellite communications systems, including devices, implementing security systems, and identifying tools, that will support our country and safeguard our nation? As a Satellite Communications Systems Security Engineer, you will identify the necessary tools, security systems, devices, and applications required to assess vulnerabilities and recommend optimal solutions and security strategies. Your experience is needed to develop and implement security solutions that protect our military and infrastructure.
Join a team of communications and systems engineers supporting engineering, sustainment, and management of communications systems. You’ll perform ongoing system analyst activities for programs, perform risk assessments of systems and equipment, assist engineers with identifying solutions for vulnerabilities, create and map Security Technical Implementation Guides (STIGs), submit change requests for system components, develop a Plan of Action and Milestones (POA&M), create documentation supporting Risk Management Framework (RMF) accreditations, perform vulnerability management using automated systems, and create and submit RMF packages. You’ll brief the technical security posture to client leadership, prepare brief slides and summaries of vulnerabilities, and advise on how to prevent and mitigate future security threats.
In this role, you’ll closely impact a national security level communications system that provides vital information to strategic and tactical users of the DoD Teleport communications systems. With mentoring, challenging hands-on problem-solving, and opportunities to learn new tools and skills, we focus on growing as a team to make the best solutions for our customers.
What You’ll Work On:
Develop relationships quickly and easily with other teams, communicating the complexities of security with a wide variety of audiences, including senior management.
Implement infrastructure and cybersecurity controls, including enhanced detection and vulnerability capabilities and improved event correlation in large enterprises.
Perform risk and vulnerability assessments in network, system, and application areas and leverage big data analytics and traditional security event types to identify advanced threats or indicators of compromise.
Participate in the development of test strategies and conduct of testing, validating, and implementing applicable STIG requirements for current or new systems.
Conduct periodic self-assessments of systems to ensure STIG compliance and create STIG checklists to support periodic self-assessments.
Perform Information Assurance Vulnerability Management (IAVM) activities such as IA vulnerability alerts, bulletins, and tasking orders and develop a systematic approach for responses to IAVM related issues to maintain system compliance.
You Have:
7+ years of experience implementing, testing, and validating STIGs, performing system self‑assessments, and creating STIG checklists
7+ years of experience executing IAVM actions, such as IAVA alerts, bulletins, or tasking orders, and developing compliant engineering responses
7+ years of experience deploying and validating ESS, ACAS, and CMRS, analyzing ACAS scans, developing remediation strategies, and implementing patches and upgrades
7+ years of experience reviewing cybersecurity and engineering change requests to ensure operational availability and compliance
Knowledge of RMF and its application to networks and IT systems, such as Cisco routers, switches, Active Directory, or access control
Ability to manage users in Windows or Linux and administer VMs in VMware or Hyper‑V
Ability to accredit and secure DoD systems using RMF, perform IAVA analysis, document POA&Ms, and prepare security assessment artifacts
Secret clearance
HS diploma or GED
Security+ Certification
Nice If You Have:
Possession of excellent verbal and written communication skills
Top Secret Clearance
Cybersecurity Certification, such as CISSP or Certified Ethical Hacker Certification, or Networking Certification, such as Network+ or Cisco Certification
OverviewSilverEdge is a premier provider of innovative cyber, software, and intelligence solutions, addressing mission-critical challenges for the Department of Defense (DoD), Intelligence Community (IC), and beyond. We are dedicated to delivering impactful results to meet mission goals through cutting-edge technology and expertise. We are seeking a Cybersecurity Assessor to join our dynamic team. This individual will play a pivotal role in developing innovative and effective solutions for our DoD customers within the IC sector.Role Overview: The Cybersecurity Assessor will be responsible for evaluating the security controls within network systems to identify vulnerabilities and recommend corrective actions. This role involves ensuring the safety of information systems assets and protecting systems from intentional or inadvertent access or destruction. The assessor will work either independently or as part of a team to perform comprehensive security assessments.Primary Duties:Conduct comprehensive security assessments of information systems to ensure compliance with DoD and IC security standards.Identify vulnerabilities within network systems and recommend effective remediation strategies.Develop and maintain security assessment documentation, including security assessment plans, reports, and risk assessments.Collaborate with system owners and stakeholders to ensure the implementation of effective security controls.Stay current with emerging security threats and technologies to provide informed recommendations.Required QualificationsActive TS/SCI w/Polygraph clearance.Bachelor's degree in Computer Science, Information Security, or a related field.Minimum of 5 years of experience in cybersecurity assessment or a related field.In-depth knowledge of DoD and IC security standards and protocols.Strong analytical and problem-solving skills.Excellent written and verbal communication skills.Desired QualificationsMaster's degree in a related field.Experience with security assessment tools and methodologies.Familiarity with cloud security practices.Relevant cybersecurity certifications (e.g., CISSP, CISM).Certifications:Certified Information Systems Security Professional (CISSP) or equivalent certification preferred.About SilverEdgeSilverEdge Government Solutions was founded on the belief that nurturing talent and collaborating closely with our customers enables us to think big and deliver the best for our country. Our mission is to bring top technology talent together to solve the world's most challenging problems while protecting the United States and our allies. SilverEdge Government Solutions, LLC is an Equal Opportunity Employer and applicants receive lawful consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability, or protected veteran status.
DivIHN (pronounced divine) is a CMMI ML3-certified Technology and Talent solutions firm. Driven by a unique Purpose, Culture, and Value Delivery Model, we enable meaningful connections between talented professionals and forward-thinking organizations. Since our formation in 2002, organizations across commercial and public sectors have been trusting us to help build their teams with exceptional temporary and permanent talent. Visit us at https://divihn.com/find-a-job/ to learn more and view our open positions. Please apply or call one of us to learn more For further inquiries regarding the following opportunity, please contact our Talent Specialist, Lavanya at (224) 369-0873 Title:Cybersecurity Specialist Duration:6 Months with a strong possibility of extension or full-time Location:St. Paul, MN or Abbott Park (North Chicago) Travel:Very limited, possibly 1 2 times during the 6 month period, likely none. Work Schedule:8 hours/day, 5 days/week Only W2 candidates are eligible for this position. Third-party or C2C candidates will not be considered Role Overview The role has a strong focus on medical devices, IoT/sensor-based products, mobile applications, and backend systems, including building security standards, guidance, dashboards, and validating the effectiveness of cybersecurity controls. Description:As a Senior Cyber Specialist Digital Enablement, you will play an important role in ensuring that Client product technologies leveraged by healthcare providers and consumers are secure-by-design. These technologies range from regulated medical devices to e-commerce and customer loyalty solutions. You will evaluate the cybersecurity posture of new and existing product technologies, identify risks, recommend mitigation strategies, and ensure timely remediation and closure. You will bring deep expertise in security risks, controls, mitigations, and global cybersecurity standards to Client product teams. This role is expert-driven and guidance-focused, requiring strong technical depth, excellent communication skills, and a proven ability to navigate a large, global environment. You will partner closely with internal product owners, developers, engineers, security architects, and external collaborators to evaluate solutions, strengthen governance, and guide secure product development. Your work will directly contribute to the delivery of scalable, compliant, and secure product technologies, cloud services, and connected applications. The role focuses on consultative responsibilities rather than hands on development or cybersecurity operations. Primary Responsibilities Develop and maintain security guidance documentation, including standards and frameworks Conduct full-stack architecture reviews of products and platforms, including consumer identity platforms Perform cybersecurity threat modeling and prepare outputs for review by internal and external stakeholders Establish, document, and monitor compliance with risk based and regulatory-informed cybersecurity requirements for individual products Collaborate with product designers and developers to ensure security considerations are integrated early into product design discussions Validate the security of product software supply chains and product deployment pipelines Develop risk mitigation strategies and recommend appropriate security controls Assess and prioritize product security risks through detailed evaluation of vulnerability assessments and penetration testing results Evaluate the effectiveness of product cybersecurity controls Identify and effectively communicate cyber risk trends Ensure risk management plans are clearly documented, actionable, and accurately reflect the organization's risk tolerance Track and ensure product compliance with defined vulnerability remediation SLAs. Participate in governance forums, architecture reviews, and technical discussions as a representative of Product Cybersecurity Required:At least 5 years of experience but typically 7 plus years of experience is required. Possess expertise in valuing and implementing industry standards such as the ISO 27001/2, SOC 2, HITRUST and FedRAMP Information Security standard and the ISO 22301 Business Continuity Standard. Experience with implementation and operational use of GRC toolsets (Governance Risk and Compliance). Possess CISSP certification (or similar) and be knowledge of national and international regulatory compliances and frameworks such as ISO, SOX, BASEL II, EU DPD, HIPAA, and PCI DSS. Ability to influence policy/standards for emerging tech (AI, quantum, cloud). About You 7 years of experience in cybersecurity or technology architecture, assessment, or consulting with a focus on the development of secure digital product technologies Experience conducting risk assessments, control assessments, and governance reporting Ability to clearly articulate cybersecurity risks and recommended mitigations to product development teams Strong understanding of modern technology stacks, including cloud native architectures and API-driven services Understanding of core concepts related to identity and access management, secure software development, network security, and cryptography Familiar with device to device, service to service, and consumer identity and access management practices Familiarity with modern phishing-resistant authentication technologies, including WebAuthn and Passkeys Understanding of cybersecurity risks associated with emerging technologies, including quantum computing and artificial intelligence Knowledge of global medical device regulatory frameworks Excellent analytical, problem-solving, and communication skills Working knowledge of security frameworks and standards (e.g., NIST, ISO/IEC 27001, PCI DSS) Strong collaboration and influencing skills, with the ability to work effectively across technical and business teams Exceptional written and verbal communication skills, with the ability to tailor complex information for diverse audiences Strong analytical and problem solving skills, with the ability to work independently and manage multiple priorities Bachelor's degree in Cybersecurity, Computer Science, Information Systems, Information Assurance, Software Engineering, or a related field but not mandatory if experience is strong Preferred Qualifications Strong preference for candidates with cybersecurity experience across e commerce, mobile apps, IoT, or medical devices. Preferred certifications include CISSP, HCISPP, CISM, CCSP, SABSA Foundation, CISA, or similar industry-recognized certifications Background in application security, product security, and secure development practices. Experience supporting mobile applications, sensors, and backend operational systems. Ability to draft, influence, and operationalize cybersecurity policies and standards. Reading Static Application Security Testing (SAST)/Dynamic Application Security Testing (DAST) outputs, pen test results; collaborating with teams; no major required internal tools. Top 3 required skills:Cybersecurity consulting w/ development teams (software/hardware). Ability to influence policy/standards for emerging tech (AI, quantum, cloud). Ability to evaluate the effectiveness of cybersecurity controls. Top 3 preferred skills:Medical device or IoT cybersecurity; development background; broader product security experience. Certifications:Not required; experience is prioritized over certs. Industry Experience:Medical device preferred; e commerce, IoT, cloud, and mobile app security also acceptable. Systems used daily:Reading Static Application Security Testing (SAST)/Dynamic Application Security Testing (DAST) outputs, pen test results; collaborating with teams; no major required internal tools. Personality traits:Curious, detail oriented, collaborative, strong communication, relationship builder. Interview Process:One Teams Video interview About us:DivIHN, the 'IT Asset Performance Services' organization, provides Professional Consulting, Custom Projects, and Professional Resource Augmentation services to clients in the Mid-West and beyond. The strategic characteristics of the organization are Standardization, Specialization, and Collaboration. DivIHN is an equal opportunity employer. DivIHN does not and shall not discriminate against any employee or qualified applicant on the basis of race, color, religion (creed), gender, gender expression, age, national origin (ancestry), disability, marital status, sexual orientation, or military status. SOX, ISO, HIPAA, HITRUST, SOC 2, ISO 27001/2, BASEL II, EU DPD
Amentum is seeking a Cybersecurity Analyst to join our team and support our McLean, VA customer.We are looking for team members who are passionate about making a difference by working on critical efforts we manage as a premier government contractor.Here at Amentum, we are purpose-driven with a fierce commitment to deliver on our promises.We create trailblazing solutions, have unwavering integrity, and embrace inclusion and collaboration.Our team is excited to help customers solve todays and tomorrow's problems, giving confidence and reassurance that together we'll accomplish mission success. Must possess and maintain a TS/SCI with Polygraph government security clearance.Note:U.S.citizenship is required to maintain a TS/SCI with Polygraph clearance. Purpose / Scope: The Cybersecurity Analyst will perform assessment and authorization (A&A) efforts under the NIST Risk Management Framework (RMF) on behalf of a federal civilian agency as a contractor.The role will conduct cybersecurity analysis in preparation for A&A reviewing and validation of all associated cybersecurity documentation and technical controls.The role will work within a team that conducts A&A activities.This individual will develop System Security Plans (SSP), Contingency Plans, Business Impact Analyses (BIA), Plan of Action and Milestones (POA&Ms), Security Assessment Report (SARs), Security Assessment Plan (SAPs), and other RMF documentation.This position covers all cybersecurity aspects including, but not limited to, identifying risks, validating the mitigation of plans of action, analyzing system designs, and assisting with A&A issues that may prevent a system from receiving authorization.It supports the implementation of RMF by developing documentation and updating policies, procedures, and processes as assigned.The Cybersecurity Analyst will assess and mitigates system security threats/risks throughout the program life cycle.Contribute to the security planning, assessment, risk analysis, risk management, certification and awareness activities for system and networking operations.Create and review A&A Body of Evidence documentation, providing feedback on completeness and compliance of its content.Develop and execute Security Test Plan (STP) in close cooperation with team members.Manage and ensure Continuous Monitoring (CONMON) to maintain system authorization. Essential Responsibilities: Identify key stakeholders in A&A efforts and ensure system documentation reflects current system security configurations to include hardware and software components, data flow, interconnections, and ports, protocols, and services, etc. Identify potential risks associated with system configurations and advise on mitigation strategies Participate in A&A status meetings and facilitate moving systems toward a successful A&A effort Assist to estimate Level of Effort (LOE) involved in performing A&A activities Assist customer program offices in interpreting and applying mitigation strategies Conduct thorough reviews of all vulnerabilities, architecture, and defense in depth strategies and report findings in POA&Ms document Document residual risks and provide the cybersecurity risk analysis and mitigation determination results Maintain cybersecurity policy and processes as assigned Able to analyze, interpret, and apply Federal cybersecurity guidance to customer needs Communicate the security posture of systems through designated reporting mechanism Collaborate with other team members in cybersecurity Minimum Requirements: 5years of experience in the following areas:Cybersecurity policy, procedures, and processes, including RMF and NIST 800-53 and A&A's Experience developing A&A documentation from scratch and performing assessments; RMF step 1 through 4 Familiar with NIST publications, specifically RMF and NIST controls One or more of the following certifications preferred (Security+, CAP, CISSP, CISM, GSEC, GCIH, or GSLC) Minimum DoD 8570 Information Assurance Management Technology (IAM) level II Familiar with dealing with defense-in-depth, and other information security and assurance principles and associated supporting technologies Hands on experience and detailed familiarity with the A&A processes Experience working in Xacta, Greenlight/Roadrunner Excellent customer service and organization skills Must demonstrate proficiency in the following areas:multi-tasking, critical thinking; and the ability to work quickly, efficiently and accurately in a dynamic and fluid environment Must be able to read, speak, write, and understand the English language Must possess and maintain a TS/SCI with Polygraph government security clearance.Note:U.S.citizenship is required to maintain a TS/SCI with Polygraph clearance. Preferred Qualifications: BA/BS Degree Excellent oral and written communication skills Ability to interact and relay security technical requirements at all levels of leadership and work force Ability to work both independently and as a member of a team Work Environment, Physical Demands, and Mental Demands: Typical office environment with no unusual hazards, occasional lifting to 20 pounds, constant sitting while using the computer terminal, constant use of sight abilities while reviewing documents, constant use of speech/hearing abilities for communication, constant mental alertness, must possess planning/organizing skills, and must be able to work under deadlines. Other Responsibilities: Safety - Amentum enforces a safety culture whereby all employees have the responsibility for continuously developing and maintaining a safe work environment.As appropriate, each employee is responsible for completing all training requirements and fulfilling all self-aid/buddy aid responsibilities, participating in emergency response tasks and serving on safety committees and teams.Quality - Quality is the foundation for the management of our business and the keystone to our goal of customer satisfaction.It is our policy to consistently provide services that meet customer expectations.Accordingly, each employee must conform to the Amentum Quality Policy and carry out job activities in compliance with applicable Amentum Quality System documents and customer contracts.Each employee must read and understand his/her Quality Management and Customer Satisfaction responsibilities Procedure Compliance - Each employee must read, understand and implement the general and specific operational, safety, quality and environmental requirements of all plans, procedures and policies pertaining to his/her job.#INDTECH Pay:$140,000.00 - $160,000.00 per year Benefits: 401(k) 401(k) matching Dental insurance Employee discount Health insurance Health savings account Life insurance Paid time off Parental leave Referral program Retirement plan Tuition reimbursement Vision insurance Experience: Cybersecurity:5 years (Required) License/Certification: TS/SCI clearance with Polygraph (Required) Work Location:In person.
Role: Cybersecurity ResearcherLocation: South Bay Area (On-site or Remote flexibility)Compensation: $175K - $225K 0.1% equityVisa: Sponsorship available for all visa typesCompanyAn early-stage cybersecurity startup (founded 2024) operating in stealth mode. The company has raised $25M in funding and currently employs about 20 people. Backed by top-tier investors, the startup is building advanced security solutions at the intersection of applied research and product development.Role OverviewThis role sits at the cutting edge of cybersecurity R&D. As a Cybersecurity Researcher, you'll combine deep research expertise with hands-on engineering skills to design and implement novel approaches to securing systems and infrastructure. The position blends applied research with practical engineering, giving you a direct impact on shaping new security technologies.Tech EnvironmentPrimary Language: PythonFocus Areas: Applied research, threat detection, system security, and vulnerability analysisRole Types: Research Scientist & Applied Research, Security EngineerCulture & WorkstyleSmall, highly technical team ( 20 employees)Flexible work policy (on-site South Bay or fully remote)High-impact environment with direct contributions to product direction and security innovationBenefits & PerksCompetitive base salaryEquity ( 0.1%)Visa sponsorship availableOpportunity to own projects end-to-end in a fast-growing startupFast FactsFounded: 2024Funding: $25MTeam Size: 20Industry: CybersecurityStage: Stealth, early growth with strong investor backing
COMPANY OVERVIEWThe Cybersecurity Community Champion is a technical, customer-facing role designed for an experienced cybersecurity professional who enjoys engaging with the community, sharing knowledge, and helping others solve real security problems. This role represents ThreatLocker in public forums, online communities, social platforms, and industry discussions, leading with expertise, advocacy for Zero Trust, and practical guidance.The goal is to be a trusted voice in the cybersecurity community:helpful, credible, and authentic while appropriately introducing ThreatLocker solutions when they genuinely add value.The role will be based in Orlando, FL and is an in-office position.JOB SCOPE:Actively engage with cybersecurity practitioners across online communities (forums, social platforms, comment threads, Discord/Slack groups, etc.).Provide thoughtful, technically accurate responses to real-world security questions and challenges.Advocate for Zero Trust principles, helping the community understand prevention-first security approaches.Represent ThreatLocker as a knowledgeable, approachable expert.Identify opportunities where ThreatLocker solutions are relevant and introduce them naturally and ethically.Monitor community sentiment, emerging topics, and common pain points to inform marketing, product, and leadership teams.Collaborate with marketing, product, and threat intelligence teams to ensure messaging is accurate and aligned.Participate in industry conversations, live events, AMAs, and community initiatives as needed.Help build long-term trust and brand credibility within the cybersecurity ecosystem.REQUIRED Qualifications:Strong background in cybersecurity engineering, security operations, or IT security.Hands-on experience with modern security challenges (malware, ransomware, lateral movement, endpoint protection, Zero Trust concepts).Deep understanding of Zero Trust architecture and philosophy.Comfortable explaining complex technical concepts clearly and respectfully.Strong written communication skills; able to engage thoughtfully in public forums.Ability to balance being helpful and educational with appropriate product advocacy.High integrity and strong judgment when engaging publicly on behalf of the brand.Preferred QualificationsExperience participating in cybersecurity communities (Reddit, X, LinkedIn, Discord, industry forums, etc.).Familiarity with endpoint protection, application control, and network security solutions.Experience representing a company publicly or acting as a technical evangelist.Passion for community-building and knowledge-sharing.WHY THIS ROLE MATTERSThis role helps shape how the cybersecurity community perceives ThreatLocker,through authentic expertise and trust. It's about showing up where practitioners are, helping first, and leading the conversation on Zero Trust.WORKING CONDITIONSThe duties described below are representative of those encountered while performing the essential functions of this position. If necessary, reasonable accommodation may be requested and will be evaluated for its relationship to the essential functions that must be performed.Job will generally be performed in an office environment but may require travel to visit company offices and/or property locations.While performing duties of this job, would occasionally require to stand, walk, sit, reach with hands and arms, climb or balance, stoop or kneel, talk and hear, and use fingers and hands to feel objects and tools.Must occasionally lift and/or move up to 50 pounds.Specific vision abilities required include close vision, distance vision, depth perceptions, and the ability to adjust focus.A background check and drug/substance screening are required after a conditional offer. Employment will proceed only upon receiving clear results from both.ThreatLocker also conducts randomized drug and substance testing approximately every 60 days, in line with the same screening standards.