10 Sep
|
Zaden Tech
|
Picton
Zaden Technologies is hiring a Cybersecurity Engineer to bring a DevSecOps mindset to ATO: instead of assembling a security package by hand at the end of a release, you'll wire evidence collection directly into the delivery pipeline so authorization keeps pace with continuous deployment. This is package cyber, not SOC work — you'll own the artifacts that let containerized applications move onto a government system, treating SBOMs, scan results, and compliance evidence as pipeline outputs rather than one-off paperwork. This is a full-time, on-site position in Aurora, CO, with some travel, and an anticipated start of April 2027.
Role Responsibilities
Prepare and maintain security packages for containerized deployments, including SSP, ATO artifacts, and supporting RMF documentation
Build automated evidence collection into the CI/CD pipeline so SBOMs, scan outputs, and compliance artifacts generate continuously rather than at release time
Own static/dynamic analysis tooling (SonarQube or similar) and container image scanning as part of the delivery pipeline
Coordinate package submission and remediation with government security stakeholders, keeping pace with an evidence-as-code approach to ATO
Partner with the DevSecOps team to treat authorization gates like any other pipeline gate: automated, repeatable,
and continuously validated
Flex into DevSecOps tasks as workload allows
Required Qualifications
Active TS/SCI clearance, or current TS/SCI eligibility, and U.S. citizenship
4+ years in cybersecurity for DoD or federal systems with direct RMF/A&A; package experience (SSP, POA&M;, ATO artifacts)
DoD 8140/8570 baseline certification (Security+ CE or equivalent minimum)
Working knowledge of container security: image scanning, SBOMs, and static/agile analysis tooling
Comfort working inside a CI/CD pipeline and automating evidence generation rather than assembling it manually
Preferred Qualifications
Hands-on DevSecOps skills (pipelines, Kubernetes, scripting) to serve as a cross-certified cyber/DevOps resource
Experience with continuous-ATO or evidence-as-code approaches on DoD software factory programs eMASS or equivalent authorization-tracking system experience
Experience supporting space or missile warning ground systems
What we offer
Robust startup environment with a variety of projects to work on
Growth paths and endless opportunities to learn and develop
Paid holidays and flexible paid time off
Employer contributions toward 401k
50% coverage of health insurance for employees and their dependents
📌 Cybersecurity Engineer (Assessment and Authorization / Compliance) (Picton)
🏢 Zaden Tech
📍 Picton