HOME Cybersecurity & Info Security Cybersecurity Engineer (Assessment and Authorization / Compliance)
Zaden Tech VERIFIED EMPLOYER

Cybersecurity Engineer (Assessment and Authorization / Compliance).

Cybersecurity & Info Security Full-Time

Cybersecurity Engineer (Assessment and Authorization / Compliance): our view in 3 lines...

  • The Role:This role is for a cybersecurity engineer focused on Assessment and Authorization and compliance for containerized applications on government systems.
  • The Person:The person will prepare and maintain security packages, automate evidence collection in the CI/CD pipeline, own static and dynamic analysis tooling and container scanning, and coordinate submission and remediation with government security stakeholders.
  • Requirements:The ideal candidate has active TS/SCI clearance or TS/SCI eligibility, U.S. citizenship, 4+ years in cybersecurity for DoD or federal systems, DoD 8140/8570 baseline certification, and experience with RMF, A&A, container security, and CI/CD.

About the role

Zaden Technologies is hiring a Cybersecurity Engineer to bring a DevSecOps mindset to ATO: instead of assembling a security package by hand at the end of a release, you'll wire evidence collection directly into the delivery pipeline so authorization keeps pace with continuous deployment. This is package cyber, not SOC work — you'll own the artifacts that let containerized applications move onto a government system, treating SBOMs, scan results, and compliance evidence as pipeline outputs rather than one-off paperwork. This is a full-time, on-site position in Aurora, CO, with some travel, and an anticipated start of April 2027.

Role Responsibilities:

  • Prepare and maintain security packages for containerized deployments, including SSP, ATO artifacts, and supporting RMF documentation
  • Build automated evidence collection into the CI/CD pipeline so SBOMs, scan outputs, and compliance artifacts generate continuously rather than at release time
  • Own static/dynamic analysis tooling (SonarQube or similar) and container image scanning as part of the delivery pipeline
  • Coordinate package submission and remediation with government security stakeholders, keeping pace with an evidence-as-code approach to ATO
  • Partner with the DevSecOps team to treat authorization gates like any other pipeline gate: automated, repeatable, and continuously validated
  • Flex into DevSecOps tasks as workload allows

Required Qualifications:

  • Active TS/SCI clearance, or current TS/SCI eligibility, and U.S. citizenship
  • 4+ years in cybersecurity for DoD or federal systems with direct RMF/A&A package experience (SSP, POA&M, ATO artifacts)
  • DoD 8140/8570 baseline certification (Security+ CE or equivalent minimum)
  • Working knowledge of container security: image scanning, SBOMs, and static/dynamic analysis tooling
  • Comfort working inside a CI/CD pipeline and automating evidence generation rather than assembling it manually

Preferred Qualifications:

  • Hands-on DevSecOps skills (pipelines, Kubernetes, scripting) to serve as a cross-certified cyber/DevOps resource
  • Experience with continuous-ATO or evidence-as-code approaches on DoD software factory programs
  • eMASS or equivalent authorization-tracking system experience
  • Experience supporting space or missile warning ground systems

What we offer:

  • Robust startup environment with a variety of projects to work on
  • Growth paths and endless opportunities to learn and develop
  • Paid holidays and flexible paid time off
  • Employer contributions toward 401k
  • 50% coverage of health insurance for employees and their dependents

Published September 2, 2026
Location Denver, Canada
Job Type Full-Time