Cybersecurity Engineer (Assessment and Authorization / Compliance)
Zaden Technologies is hiring a Cybersecurity Engineer to bring a DevSecOps mindset to ATO: instead of assembling a security package by hand at the end of a release, you'll wire evidence collection directly into the delivery pipeline so authorization keeps pace with continuous deployment. This is package cyber, not SOC work — you'll own the artifacts that let containerized applications move onto a government system, treating SBOMs, scan results, and compliance evidence as pipeline outputs rather than one-off paperwork. This is a full-time, on-site position in Aurora, CO, with some travel, and an anticipated start of April 2027.
Role Responsibilities:
- Prepare and maintain security packages for containerized deployments, including SSP, ATO artifacts, and supporting RMF documentation
- Build automated evidence collection into the CI/CD pipeline so SBOMs, scan outputs, and compliance artifacts generate continuously rather than at release time
- Own static/dynamic analysis tooling (SonarQube or similar) and container image scanning as part of the delivery pipeline
- Coordinate package submission and remediation with government security stakeholders, keeping pace with an evidence-as-code approach to ATO
- Partner with the DevSecOps team to treat authorization gates like any other pipeline gate: automated, repeatable, and continuously validated
- Flex into DevSecOps tasks as workload allows
Required Qualifications:
- Active TS/SCI clearance, or current TS/SCI eligibility, and U.S. citizenship
- 4+ years in cybersecurity for DoD or federal systems with direct RMF/A&A package experience (SSP, POA&M, ATO artifacts)
- DoD 8140/8570 baseline certification (Security+ CE or equivalent minimum)
- Working knowledge of container security: image scanning, SBOMs, and static/dynamic analysis tooling
- Comfort working inside a CI/CD pipeline and automating evidence generation rather than assembling it manually
Preferred Qualifications:
- Hands-on DevSecOps skills (pipelines, Kubernetes, scripting) to serve as a cross-certified cyber/DevOps resource
- Experience with continuous-ATO or evidence-as-code approaches on DoD software factory programs
- eMASS or equivalent authorization-tracking system experience
- Experience supporting space or missile warning ground systems
What we offer:
- Robust startup environment with a variety of projects to work on
- Growth paths and endless opportunities to learn and develop
- Paid holidays and flexible paid time off
- Employer contributions toward 401k
- 50% coverage of health insurance for employees and their dependents