Defense Unicorns
Cybersecurity Engineer (COMDO12)
About this role
A remote cybersecurity engineering role supporting a U.S. government contractor, requiring U.S. citizenship. You'll lead the accreditation process for defense software systems, implementing FedRamp and DoD compliance standards while advancing modern, continuous security practices.
What you'll do
- Lead accreditation efforts following NIST-800 series requirements and manage RMF processes
- Develop and implement cybersecurity policies and controls for FedRamp and DoD standards
- Conduct risk assessments, vulnerability analyses, and security testing across platforms
- Collaborate with developers and architects to integrate security into the software development lifecycle
- Prepare and maintain accreditation documentation including SSPs and SARs
- Support automated compliance-as-code capabilities for continuous security posture evaluation
What they're looking for
- NIST-800 standards (particularly 800-53)
- FedRamp and RMF/ATO accreditation processes
- Vulnerability scanning and security assessment tools
- DevSecOps and Agile methodologies
- OSCAL (Open Security Controls Assessment Language)
- Infrastructure and configuration-as-code translation
- DoD security clearance eligibility
- Technical communication with non-technical stakeholders
Opens the application — the Jobs AI extension fills it for you. Set up autofill
Opens the official application on the employer’s site. No login required.
Defense Unicorns
Defense Unicorns builds software platforms and infrastructure services for defense and government customers, including containerized applications, package management systems, and Kubernetes-based deployment environments for disconnected or hybrid cloud settings. The company is hiring software engineers, platform engineers, technical writers, and military SkillBridge interns to develop, deploy, and support these mission-critical systems.
- Website
- defenseunicorns.com
Likely interview questions
- Walk us through your experience leading an RMF accreditation effort. What was your biggest challenge in meeting NIST-800-53 requirements, and how did you overcome it?
- Describe your experience translating infrastructure-as-code and configuration-as-code into eMASS security control responses that non-technical stakeholders can understand.