> Markdown version of [/jobs/ext/1507268-sr-cyber-security-engineer](https://www.wearedevelopers.com/jobs/ext/1507268-sr-cyber-security-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Sr Cyber Security Engineer - **Company:** LEXSO LLC - **Location:** United States (Remote available) - **Experience:** Expert - **Contract:** Permanent contract - **Skills:** Kubernetes Security, Application Programming Interfaces (APIs), Amazon Web Services, Microsoft Azure, Bash Shell, Burp Suite, Ubuntu (Operating System), Configuration Management, Cyber Security, Continuous Integration, Linux, Federal Information Processing Standards (FIPS), Github, Python (Programming Language), Nginx, OAuth, Red Hat Enterprise Linux, Ansible, Zero Trust Network Access, Software Requirements Analysis, SonarQube, Data Logging, Scripting, SARS Software Products, Cloud Platform System, Kubernetes Helm Charts, Backend, Gitlab, Gitlab-ci, Selinux, Kubernetes, Information Technology, Iptables, Nessus, Front End Software Development, Terraform, Splunk, Scap Compliance Checker, Lidar, Devsecops, Docker, Elk Stack, Jenkins, Static Application Security Testing, Vulnerability Analysis, Microservices, Dynamic Application Security Testing - **Published:** July 30, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=2252bec892e52943 ## About the Role * 8+ years of experience in Cyber Security Engineering or DevSecOps. * Proven track record of achieving ATO (Authority to Operate) for a software system in a DoD/Federal environment * Hands-on experience with RMF, NIST 800-53, and DISA STIGs * Proficiency in scripting languages (Python, Bash) for automation * Experience with vulnerability scanning tools (ACAS/Nessus, SonarQube, Burp Suite) * Strong knowledge of Linux Security (SELinux, iptables, hardening) * Experience with CI/CD tools (GitLab CI, Jenkins) and Container Security (Docker/K8s) * Demonstrated ability to work autonomously - identify security gaps, drive architectural design decisions, and track implementation through to completion * Experience communicating technical findings and program status to executive leadership; able to translate risk and remediation into terms leadership can act on * Track record of ownership over requirements definition and progress reporting for cybersecurity workstreams * CISSP, CASP+, or Security+ CE (Required) * Active Secret Security Clearance * Bachelor's degree in Computer Science, Cyber Security, or related technical discipline. * Preferred Experience: + Experience securing cloud environments (AWS GovCloud / Azure Government) + Experience with FedRAMP authorization processes + Familiarity with "Zero Trust" architecture principles + Previous experience as a Software Developer before moving into Security + Prior experience as a technical lead or senior individual contributor with direct exposure to stakeholders ## Description The Senior Cyber Security Engineer will bridge the gap between "Compliance" and "Engineering." You will not just audit the system, you will help build it securely and own the cybersecurity workstream end-to-end. This role is responsible for achieving Authority to Operate (ATO) under DoD Risk Management Framework (RMF) standards among other federal certifications while embedding security automation directly into our CI/CD pipelines, and reporting program status and risk directly to LEXSO leadership. You will work side-by-side with backend and frontend engineers to harden the microservices architecture against evolving threats, and you will independently identify security gaps, drive architectural design decisions and shepherd remediation to completion.., * Own the LEXSO cybersecurity program end-to-end - from gap identification through architectural design to implementation tracking * Report cyber risk posture and remediation progress; translate technical findings into terms leadership can act on * Define and maintain the cybersecurity requirements backlog and progress-tracking cadence * Lead the technical execution of the RMF process to achieve and maintain Authority to Operate (ATO) for the LEXSO platform * Implement security controls in accordance with NIST SP 800-53 and DoD SRG/STIGs * Generate and maintain artifacts required for eMASS, including SSPs, POAMs, and SARs * Conduct self-assessments using ACAS (Nessus) and SCAP Compliance Checker (SCC) to identify vulnerabilities * Integrate automated security testing (SAST/DAST) tools (e.g., SonarQube, OWASP ZAP) into the GitLab/GitHub CI/CD pipeline * Develop scripts (Python, Bash, Ansible) to automate patching and configuration management for Linux (RHEL/Ubuntu) servers * Implement Container Security scanning for Docker/Kubernetes environments to detect vulnerabilities before deployment * Enforce "Security as Code" principles using Terraform or Helm charts * Analyze vulnerability scan results and write the code/scripts to remediate findings (e.g., fixing SSH configurations, patching libraries, hardening NGINX) * Harden APIs and microservices by implementing secure authentication (OAuth2/JWT/mTLS) and encryption standards (FIPS 140-2) * Respond to zero-day threats and CVEs by rapidly deploying hotfixes to the production environment * Conduct threat modeling sessions with the engineering team to identify attack vectors in the multi-sensor architecture * Design and implement secure logging and auditing pipelines (ELK Stack/Splunk) to meet audit requirements * Advise on the secure architecture for integrating third-party sensors (LiDAR, Radar) and IoT devices * Work is typically based in a remote working environment and subject to frequent interruptions. Business work hours are Monday-Friday from 8:00 am to 5:00 pm, however some extended or weekend hours may be required. * Other duties as assigned ## Related Videos - [How to develop an autonomous car end-to-end: Robotic Drive and the mobility revolution](https://www.wearedevelopers.com/videos/22-how-to-develop-an-autonomous-car-end-to-end-robotic-drive-and-the-mobility-revolution) - [Keeping applications secure by evolving OAuth 2.0 and OpenID Connect](https://www.wearedevelopers.com/videos/100152-keeping-applications-secure-by-evolving-oauth-2-0-and-openid-connect) - [Post-Quantum Cryptography: Preparing for Q-Day](https://www.wearedevelopers.com/videos/100179-post-quantum-cryptography-preparing-for-q-day) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Remote Driving on Plant Grounds with State-of-the-Art Cloud Technologies](https://www.wearedevelopers.com/videos/251-remote-driving-on-plant-grounds-with-state-of-the-art-cloud-technologies) - [You can’t hack what you can’t see](https://www.wearedevelopers.com/videos/41-you-can-t-hack-what-you-can-t-see) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks) - [Fully Remote Software Engineer Jobs](https://www.wearedevelopers.com/magazine/447-fully-remote-software-engineer-jobs) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Is Software Engineering Over-Saturated?](https://www.wearedevelopers.com/magazine/418-is-software-engineering-over-saturated)