Information Systems Security Engineer (ISSE) - DoW Skillbridge

HTX Labs, Inc.
United States
7 days ago
Apply on startup.jobs
Prepare application

Role details

Contract type
Internship / Graduate position
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
5 years minimum
Working hours
Regular working hours
Job source

Tech stack

Kubernetes Security Artificial Intelligence Microsoft Azure Bash Shell Cloud Computing Security Cloud Engineering Configuration Management Cyber Security Continuous Integration Information Leak Prevention Identity and Access Management IT Management
+21 more
Python (Programming Language) Linux System Administration Network Segmentation Open Web Application Security Windows PowerShell Role-Based Access Control Zero Trust Network Access Software Engineering Systems Integration Software Vulnerability Management YAML Scripting Large Language Models Azure Powershell Generative AI Infrastructure as Code (IaC) Kubernetes Infrastructure Automation Frameworks Terraform Devsecops Plan of Action and Milestones

Job description

HTX Labs is seeking a hands-on Information Systems Security Engineer (ISSE) to design, implement, automate, and maintain secure cloud and edge infrastructure supporting Department of War (DoW) systems. This position partners daily with the DevSecOps Engineer to build and operate secure Microsoft Azure Government and disconnected/on-premise deployments while translating RMF, CMMC Level 2, and DoW security requirements into technical implementations. Approximately 15% of this role focuses on AI Security Engineering, ensuring AI-enabled capabilities are deployed securely and governed in accordance with NIST AI RMF, DoW guidance, and industry best practices., * Harden and maintain secure cloud and edge infrastructure supporting DoW workloads.

  • Partner with the DevSecOps Engineer to build secure CI/CD pipelines using modern software delivery and Infrastructure as Code (IaC) practices.
  • Implement Zero Trust principles including RBAC, workload identity, network segmentation, private networking, and least privilege.
  • Engineer and maintain security controls for cloud IAM, WAF, container security, runtime protection, and Kubernetes policy enforcement.
  • Automate security validation, compliance monitoring, evidence collection, vulnerability remediation, and configuration management using PowerShell, Python, Bash, Azure CLI, and YAML.
  • Implement and maintain NIST SP 800-53 Rev. 5, RMF, CMMC Level 2, STIG, and DISA security controls through technical implementations.
  • Support ATO packages, Cybersecurity Impact Analyses (CIAs), SSP updates, POA&M remediation, security assessments, and continuous monitoring.
  • Collaborate with engineering teams to secure software supply chains through SBOM generation, image signing, container security, and secure CI/CD.

AI Security Engineering (Approximately 15% of Role)

  • Design and implement security controls for AI-enabled applications, LLMs, Retrieval-Augmented Generation (RAG), AI agents, and Model Context Protocol (MCP) integrations.
  • Evaluate AI technologies for security, privacy, compliance, and supply chain risks before deployment.
  • Mitigate AI-specific threats including prompt injection, model poisoning, jailbreak attacks, insecure tool usage, and data leakage.
  • Integrate AI security testing and policy validation into CI/CD pipelines.
  • Perform AI threat modeling and architecture reviews using the NIST AI Risk Management Framework (AI RMF) and OWASP Top 10 for LLM Applications.
  • Support secure deployment of AI workloads in Azure Government and disconnected Edge environments.

Requirements

  • U.S. Citizen.
  • 5+ years of experience in cybersecurity, cloud engineering, DevSecOps, or information systems security engineering.
  • Experience with Azure or Azure Government, Kubernetes, Linux administration, networking, scripting, and Infrastructure as Code.
  • Experience implementing RMF, CMMC, STIGs, or other government cybersecurity frameworks.
  • Strong troubleshooting and communication skills., * Experience supporting DoW IL4/IL5 environments and Authority to Operate (ATO) efforts.
  • Experience with managed/self-managed Kubernetes.
  • Experience with CI/CD platforms, GitOps deployment solutions, IaC tools, Kubernetes policy enforcement, container runtime security, cloud IAM, and WAF technologies.
  • Experience securing AI-enabled applications, Azure AI Foundry, Azure OpenAI, RAG architectures, or MCP integrations.
  • Knowledge of NIST AI RMF, OWASP Top 10 for LLM Applications, secure AI software supply chains, and AI governance.
  • Preferred certifications include Security+, CASP+, CKA, CKS, Azure Security Engineer Associate, Azure Administrator Associate, Terraform Associate, or RHCSA., * Hands-on security engineer focused on building secure cloud-native platforms.
  • Collaborates across software engineering, DevSecOps, cybersecurity, AI engineering, and program management.
  • Passionate about automation, Zero Trust, AI Security Engineering, and continuous improvement.

Technologies

  • Cloud-native architectures
  • Managed and self-managed Kubernetes
  • Containers and container orchestration
  • CI/CD platforms
  • GitOps deployment solutions
  • Infrastructure as Code (IaC)
  • Kubernetes policy enforcement

Benefits & conditions

Pay: This internship is not paid through HTX Labs - you will be paid through the DoW as per your Skillbridge Agreement upon approval. Speak to your CO if you have questions.

We’re constantly working towards making HTX Labs the best place to work, for everyone. We believe deeply that bringing together diversity of thoughts, perspectives and expression is key for building the best product for our equally diverse community. We celebrate uniqueness and whatever makes you, you and encourage everyone who wants to help us transform the way the world learns, to join us on our journey. We value all types of experiences. If you don’t think you quite meet every qualification, we’d still love to hear from you. We are interested in qualified candidates who are eligible to work in the United States. We are not able to sponsor work visas at this time.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on startup.jobs
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

3:22 min

Transitioning from software engineering to security roles

Anna Oliveira · Coffee With Developers

1:35 min

Centralizing configuration logic with native YAML block references

Matthieu Vincent Matthieu Vincent · Europe 2026 Virtual

1:15 min

Key lessons learned from implementing automated mobile DevSecOps

Moataz Nabil Moataz Nabil · LIVE

1:34 min

Essential commands for running and testing Terraform configurations

Hennie Francis · LIVE

1:45 min

Transitioning from software development to security roles

Stefania Chaplin · World Congress 2022

2:00 min

Introduction to YAML syntax and basic formatting

Chris Ayers · LIVE

Videos

See all

Related articles

See all