> Markdown version of [/jobs/ext/2658614-cybersecurity-engineer](https://www.wearedevelopers.com/jobs/ext/2658614-cybersecurity-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Cybersecurity Engineer - **Company:** Aspis Llc - **Location:** Kansas City Metropolitan Area, United States (Remote available) - **Contract:** Permanent contract - **Skills:** Microsoft Access, Amazon Web Services, Microsoft Azure, Bash Shell, Business Software, Cloud Computing Security, Static Program Analysis, Software Documentation, Code Review, CompTIA Security+, Cyber Security, Continuous Integration, Data Centers, Data Deduplication, Intrusion Detection and Prevention, Python (Programming Language), Key Management, Windows PowerShell, Cloud Services, Data Logging, Cloud Platform System, Gitlab, Cloudformation, Production Code, Terraform, Software Version Control, Devsecops, Security Orchestration, Automation & Response, Vulnerability Analysis - **Published:** August 26, 2026 - **Apply:** https://www.dice.com/job-detail/5d8ea6ed-58a1-4dbf-a06c-f0de75d33ea9 ## About the Role * Demonstrated ability to build and maintain production code or automation in at least one language such as Python, Bash, PowerShell, or Go, with source control, testing, and peer review discipline. * Hands-on cloud security engineering experience in AWS, with working knowledge of Azure, appropriate to experience level. * Experience building CI/CD pipeline security stages using GitLab or comparable tooling, and infrastructure-as-code proficiency such as Terraform or CloudFormation. * Working knowledge of hardening standards and of security frameworks relevant to Federal work (NIST SP 800-53, FISMA, FedRAMP), appropriate to experience level. * Experience building or tuning vulnerability scanning coverage, detection content, or log pipelines. * Strong analytical skills and attention to detail. * Clear, professional written and verbal communication, including design and operational documentation. * Ability to manage multiple assignments and deadlines with limited day-to-day oversight. * Discretion in handling sensitive client, system, and company information. * Ability to obtain and maintain a Federal Public Trust background investigation; must be authorized to work in the United States without sponsorship. * Availability during client core hours with on-call and after-hours support as needed for deployments and incidents. Requirements Skills: * Security automation and tooling development, secure CI/CD pipeline engineering, infrastructure-as-code, platform hardening, detection engineering, and cloud security engineering. * Demonstrated coding or automation ability with source control and peer review discipline. * Strong verbal and written communication skills. Background Check: Public Trust background check required. Degree Required: Associate\'s degree or higher preferred; equivalent experience and/or certifications considered in lieu of a degree. Experience Required: Varies by level (Level 1: 0-2 years; Level 2: 2-5 years; Level 3: 5-10 years; Level 4: 10+ years) of relevant cybersecurity engineering experience. Industry Certifications: Tiered by level - CompTIA Security+ (or equivalent) preferred at entry and required from Level II; advanced cloud and engineering certifications (e.g., AWS Certified Security - Specialty, CCSP, GIAC GCSA, CISSP) expected at senior levels. Must pass reference check and background check. ## Description Aspis is expanding its cybersecurity team and seeking a hands-on Cybersecurity Engineer to build the security capability behind a large Federal civilian cloud platform operations and maintenance program. This is a building role rather than a monitoring role. The environment is hybrid: a FedRAMP-authorized AWS commercial cloud footprint alongside Azure, on-premises data centers, legacy and mainframe-connected applications, and enterprise geospatial platforms supporting hundreds of business applications. You will write and maintain the automation, pipeline security stages, hardened baselines, detection content, and integrations that make security continuous instead of manual. Responsibilities align to the NIST NICE Workforce Framework for Cybersecurity (NIST SP 800-181r1). You will work alongside cloud engineers, DevSecOps engineers, and our compliance and authorization staff, with real ownership on a small, senior team. This is a full-time position. The Kansas City, Missouri metropolitan area is strongly preferred and candidates who reside in and can work from the Kansas City metro will receive preference; however, residency there is not required, and we will consider candidates elsewhere in the United States who are able to travel to client sites as needed. Consistent with Aspis\' telework policy, employees are required to report to an Aspis office on a regular basis but may be allowed to work from home and are required to visit client job sites as applicable. The company reserves the right to change its employment policies at any time without notice. Responsibilities * Design, code, test, and maintain security automation - scripts, modules, services, and integrations - that replace manual security work. * Build and maintain infrastructure-as-code modules that deliver hardened, compliant cloud resources by default. * Build and maintain security stages in CI/CD pipelines, including static analysis, dependency and container image scanning, secrets detection, and policy-as-code gates. * Engineer hardened operating system, container, and cloud service baselines, plus the automation that applies and enforces them. * Build identity, access, encryption, key management, and logging capability into the platform, and engineer secure interfaces between on-premises systems and cloud services. * Build and maintain detection content, correlation rules, and alerting as code, with version control and testing. * Automate vulnerability scanning coverage, finding enrichment, deduplication, ticket creation, and aging escalation so remediation service levels are met without manual tracking. * Build response automation and playbooks-as-code for containment, isolation, evidence capture, and recovery, and participate in the on-call rotation. * Convert incident findings and root cause analysis into durable engineering fixes rather than repeat manual response. * Maintain design documentation, run books, reference architectures, and code documentation, and provide control implementation evidence to compliance and authorization staff. * Mentor junior engineers, perform code review, and support knowledge transfer to client staff. * Other duties as assigned. ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [DevSecOps: Injecting Security into Mobile CI/CD Pipelines](https://www.wearedevelopers.com/videos/273-devsecops-injecting-security-into-mobile-ci-cd-pipelines) - [Infrastructure as Code: The Developer's Secret Weapon](https://www.wearedevelopers.com/videos/1221-infrastructure-as-code-the-developer-s-secret-weapon) - [WeAreDevelopers LIVE - Modern DevOps for IoT Devices and More](https://www.wearedevelopers.com/videos/1805-wearedevelopers-live-modern-devops-for-iot-devices-and-more) - [Enabling automated 1-click customer deployments with built-in quality and security](https://www.wearedevelopers.com/videos/83-enabling-automated-1-click-customer-deployments-with-built-in-quality-and-security) - [DevSecOps culture](https://www.wearedevelopers.com/videos/783-devsecops-culture) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks) - [Best Paying Jobs in Technology](https://www.wearedevelopers.com/magazine/256-best-paying-jobs-in-technology)