> Markdown version of [/jobs/ext/2702926-senior-cybersecurity-engineer](https://www.wearedevelopers.com/jobs/ext/2702926-senior-cybersecurity-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Senior Cybersecurity Engineer - **Company:** DSD Laboratories, Inc. - **Location:** United States (Remote available) - **Experience:** Expert - **Contract:** Permanent contract - **Skills:** Microsoft Windows, Microsoft Azure, Cloud Computing, Cyber Security, Continuous Integration, Information Security Management, Intrusion Detection and Prevention, Key Management, Log Analysis, Kusto Query Language, Software Vulnerability Management, Information Security Management System, Gitlab, SC Clearance, Plan of Action and Milestones - **Published:** September 4, 2026 - **Apply:** https://www.clearancejobs.com/jobs/9144511/senior-cybersecurity-engineer ## About the Role Security Clearance Requirement: An active Secret clearance is preferred; at minimum, candidates must be able to obtain and maintain a Secret clearance., * Seven or more years in cybersecurity engineering or a closely related discipline, including at least three in a regulated or government-adjacent environment. * Hands-on administration and security engineering in Microsoft 365 and Azure - Entra ID, conditional access, Defender, and log analytics. * Demonstrated experience implementing or evidencing a formal control framework such as NIST SP 800-171 or 800-53. * Direct experience responding to security incidents in a production environment, including the judgement calls made under time pressure. * Active U.S. Government Secret clearance preferred; at minimum, must be eligible to obtain and maintain a Secret clearance. Preferred Qualifications * Microsoft Government cloud experience specifically - GCC High or Azure Government - as distinct from commercial tenancy. * CMMC experience from either side of an assessment. * FedRAMP, DoD Cloud Computing SRG, or Impact Level 4 and 5 authorization package experience. * Prior designation as an ISSM or ISSO. * Detection engineering, KQL, and log pipeline design. * Infrastructure as code, CI/CD security, SBOM generation, and dependency scanning. * Certifications aligned to the role - CISSP, CISM, CCSP, AZ-500, SC-200, or equivalent. ## Description DSD Laboratories is hiring its first dedicated Senior Cybersecurity Engineer to own the security engineering, assurance, and continuity of an environment that supports Department of Defense work - a Microsoft Government-cloud estate, a set of internal business platforms, and a product suite heading toward a formal authorization. Much of what you will own does not exist yet; you will be defining it. This role was approved and funded following an independent 2026 review of DSD's technology function, with managed detection and response, retained incident response, and external assessment funded alongside it. Your mandate is to make DSD's security posture demonstrable - to customers, assessors, and auditors - and to build the operational depth that lets this environment run and recover without depending on any one person. What You Will Do * Serve as the named alternate administrator for the Microsoft 365 and Azure Government tenant, HAL, GitLab, and the corporate wiki. * Hold escrowed break-glass credentials under dual control, and demonstrate recovery competence through restore tests you personally perform. * Own the control register, System Security Plan, and plan of action and milestones. * Support the NIST SP 800-53 Rev 5 policy programme and the authorization package for the DSD Forge product suite. * Own daily triage and disposition of alerts from the managed detection service and internal automation. * Own vulnerability management end to end, and manage the managed detection vendor relationship. * Serve on the incident command roster as a deputy commander, and hold a DoD-approved medium assurance certificate for regulatory incident reporting. * Own evidence preservation configuration, retention verification, and chain of custody. * Administer privileged access management, conditional access policy, and secrets management across the estate. * Embed secrets scanning, dependency analysis, and software bill of materials generation into product pipelines. * Respond to customer and prime contractor security questionnaires and supply chain due diligence. ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [WeAreDevelopers LIVE - Modern DevOps for IoT Devices and More](https://www.wearedevelopers.com/videos/1805-wearedevelopers-live-modern-devops-for-iot-devices-and-more) - [Progressive Delivery in Kubernetes](https://www.wearedevelopers.com/videos/949-progressive-delivery-in-kubernetes) - [Enabling automated 1-click customer deployments with built-in quality and security](https://www.wearedevelopers.com/videos/83-enabling-automated-1-click-customer-deployments-with-built-in-quality-and-security) - [What makes Cybersecurity different for critical infrastructure?](https://www.wearedevelopers.com/videos/571-what-makes-cybersecurity-different-for-critical-infrastructure) - [Leveraging Large Language Models for Legacy Code Translation: Challenges and Solutions](https://www.wearedevelopers.com/videos/1157-leveraging-large-language-models-for-legacy-code-translation-challenges-and-solutions) ## Related Articles - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again](https://www.wearedevelopers.com/magazine/751-how-we-built-a-worry-free-system-that-runs-for-10-years-and-what-we-d-do-again)