<?xml version="1.0" encoding="UTF-8"?>
<source>
  <jobs>
    <job>
      <externalid>38a5c86c-54e</externalid>
      <Title>Senior Compliance Engineer</Title>
      <Description><![CDATA[<p>JOB TITLE: Senior Compliance Engineer LOCATION: Costa Mesa, California, United States DEPARTMENT: Corporate Technology : Information Security : Corporate Assurance</p>
<p>As a Senior Compliance Engineer at Anduril Industries, you will be responsible for driving automation, compliance, and security engineering principles into the design, integration, and operation of Anduril&#39;s internal systems. This is a technically hands-on role that requires a strong DevSecOps background with deep expertise in cloud infrastructure security, embedded systems security, and federal compliance frameworks.</p>
<p><strong>Key Responsibilities</strong></p>
<ul>
<li>Design, develop, and maintain Infrastructure as Code (IaC) and Policy as Code (PaC) that enforce compliance with NIST SP 800-171 and 800-53, CMMC, and other applicable frameworks, enabling developers to deploy CMMC-certified applications using pre-packaged, compliant infrastructure templates.</li>
<li>Architect, build, and deploy robust, scalable security controls across Anduril&#39;s corporate, development, and production cloud environments (AWS, Azure, GCP) and on-premise environments.</li>
<li>Develop and automate IaC pipelines for managing and scaling cloud deployments securely and efficiently, including automated pipelines for deploying infrastructure, applications, and updates.</li>
<li>Build automation for procedural compliance controls, generating compliance and audit artifacts at scale without manual intervention.</li>
<li>Develop security models that integrate Continuous Monitoring (ConMon), DISA STIG scanning, and compliance reporting into a unified, automated workflow.</li>
</ul>
<p><strong>Compliance Engineering &amp; Framework Implementation</strong></p>
<ul>
<li>Analyze, interpret, and operationalize federal and industry cybersecurity regulations, including NIST SP 800-171 and 800-53, CMMC, FedRAMP, and SOC 2, translating regulatory language into actionable engineering guidance and enforceable technical controls.</li>
<li>Evaluate system architectures and configurations to ensure alignment with required security controls for moderate-impact information systems.</li>
<li>Interface directly with infrastructure teams to verify and enforce compliance across existing on-premise and cloud stacks, identifying gaps and driving remediation.</li>
</ul>
<p><strong>Cross-Functional Collaboration &amp; Enablement</strong></p>
<ul>
<li>Partner with engineers, the DevSecOps Team, and the Automation Team to implement and verify security controls in both corporate and product software environments.</li>
<li>Act as a force multiplier by embedding security best practices into the workflows of infrastructure, application, and product teams, particularly for environments holding mission-critical data.</li>
</ul>
<p><strong>Strategic &amp; Advisory</strong></p>
<ul>
<li>Develop strategies and implementation plans for compliance-related matters, advising management on risk posture, regulatory changes, and investment priorities.</li>
<li>Institute best-practice procedures for compliance and risk mitigation across the organization.</li>
</ul>
<p><strong>Required Qualifications</strong></p>
<ul>
<li>3+ years of professional experience in Cloud Security, DevSecOps, Site Reliability Engineering (SRE), or a related security engineering role.</li>
<li>Background in one or more of the following disciplines: Systems Security Engineering, Cybersecurity, Systems Engineering, Software Engineering, Computer Engineering, or Computer Science.</li>
<li>Proven experience building and securing complex cloud environments at scale.</li>
<li>3+ years of hands-on experience working with compliance frameworks such as CMMC, NIST SP 800-171 and/or 800-53, and FedRAMP.</li>
</ul>
<p style="margin-top:24px;font-size:13px;color:#666;">XML job scraping automation by <a href="https://yubhub.co">YubHub</a></p>]]></Description>
      <Jobtype>full-time</Jobtype>
      <Experiencelevel>senior</Experiencelevel>
      <Workarrangement>onsite</Workarrangement>
      <Salaryrange></Salaryrange>
      <Skills>Cloud Security, DevSecOps, Site Reliability Engineering, Systems Security Engineering, Cybersecurity, Systems Engineering, Software Engineering, Computer Engineering, Computer Science, Compliance Frameworks, NIST SP 800-171, NIST SP 800-53, CMMC, FedRAMP</Skills>
      <Category>Engineering</Category>
      <Industry>Technology</Industry>
      <Employername>Anduril Industries</Employername>
      <Employerlogo>https://logos.yubhub.co/anduril.com.png</Employerlogo>
      <Employerdescription>Anduril Industries is a defense technology company that designs, builds, and sells advanced technology systems for the U.S. and allied military.</Employerdescription>
      <Employerwebsite>https://www.anduril.com/</Employerwebsite>
      <Compensationcurrency></Compensationcurrency>
      <Compensationmin></Compensationmin>
      <Compensationmax></Compensationmax>
      <Applyto>https://job-boards.greenhouse.io/andurilindustries/jobs/5087188007</Applyto>
      <Location>Costa Mesa, California, United States</Location>
      <Country></Country>
      <Postedate>2026-04-18</Postedate>
    </job>
    <job>
      <externalid>b5ce114e-dac</externalid>
      <Title>Cloud Engineer – Factory Systems and Operational Technology</Title>
      <Description><![CDATA[<p>Anduril Industries is a defence technology company with a mission to transform U.S. and allied military capabilities with advanced technology. By bringing the expertise, technology and business model of the 21st century&#39;s most innovative companies to the defence industry, Anduril is changing how military systems are designed, built and sold.</p>
<p>The company&#39;s family of systems is powered by Lattice OS, an AI-powered operating system that turns thousands of data streams into a real-time, 3D command and control centre.</p>
<p>As the world enters an era of strategic competition, Anduril is committed to bringing cutting-edge autonomy, AI, computer vision, sensor fusion and networking technology to the military in months, not years.</p>
<p>We are seeking a mission-driven Cloud Infrastructure Engineer to take a leading role in designing and implementing world-class defensive controls. This is a high-impact role with the autonomy to shape security architecture and protect the technology that is changing the future of defence.</p>
<p>Key Responsibilities:</p>
<ul>
<li>Design and Own Security Architecture: Architect, build and deploy robust, scalable security controls for our corporate, development and production cloud environments (AWS, Azure, GCP).</li>
</ul>
<ul>
<li>Automate Everything: Develop and automate infrastructure-as-code (IaC) to manage and scale our cloud deployments securely and efficiently.</li>
</ul>
<ul>
<li>Proactively Defend: Continuously monitor, identify and remediate security weaknesses and configuration drift across our entire cloud footprint.</li>
</ul>
<ul>
<li>Be a Force Multiplier: Partner with infrastructure, application and product teams to embed security best practices into their workflows and secure environments holding mission-critical data.</li>
</ul>
<ul>
<li>Enable Scale and Reliability: Engineer systems and processes that ensure our platforms are highly available, resilient and prepared for rapid growth.</li>
</ul>
<ul>
<li>Serve as a Cloud Security Expert: Act as the go-to subject matter expert for teams across Anduril, providing guidance, mentorship and paved-road solutions for building securely in the cloud.</li>
</ul>
<p>Requirements:</p>
<ul>
<li>Proven experience building and securing complex cloud environments, typically gained through 3+ years in a Cloud Security, DevOps or SRE role.</li>
</ul>
<ul>
<li>Deep proficiency in at least one major cloud provider (AWS, Azure or GCP).</li>
</ul>
<ul>
<li>Strong hands-on experience with Infrastructure as Code (e.g., Terraform, CloudFormation, Bicep).</li>
</ul>
<ul>
<li>Solid programming/scripting ability in one or more languages (e.g., Python, Go, Rust).</li>
</ul>
<ul>
<li>Firm understanding of public cloud networking principles (e.g., VPCs, subnets, routing, security groups).</li>
</ul>
<ul>
<li>Must be a U.S. Person and eligible to obtain and maintain a U.S. Top Secret security clearance.</li>
</ul>
<p>Preferred Qualifications:</p>
<ul>
<li>Experience hardening and monitoring Kubernetes clusters (EKS, GKE, AKS).</li>
</ul>
<ul>
<li>Experience with cloud security posture management (CSPM) or threat detection tooling.</li>
</ul>
<ul>
<li>Familiarity with CI/CD pipelines and securing the software supply chain.</li>
</ul>
<ul>
<li>Knowledge of compliance frameworks such as FedRAMP, MRL, SOC 2 or CMMC.</li>
</ul>
<ul>
<li>On-premises network engineering experience.</li>
</ul>
<p style="margin-top:24px;font-size:13px;color:#666;">XML job scraping automation by <a href="https://yubhub.co">YubHub</a></p>]]></Description>
      <Jobtype>full-time</Jobtype>
      <Experiencelevel>senior</Experiencelevel>
      <Workarrangement>onsite</Workarrangement>
      <Salaryrange>$129,000-$193,000 USD</Salaryrange>
      <Skills>Cloud Security, DevOps, SRE, Infrastructure as Code, Terraform, CloudFormation, Bicep, Python, Go, Rust, Public Cloud Networking, VPCs, Subnets, Routing, Security Groups, Kubernetes, Cloud Security Posture Management, Threat Detection Tooling, CI/CD Pipelines, Software Supply Chain Security, Compliance Frameworks, FedRAMP, MRL, SOC 2, CMMC, On-Premises Network Engineering</Skills>
      <Category>Engineering</Category>
      <Industry>Technology</Industry>
      <Employername>Anduril Industries</Employername>
      <Employerlogo>https://logos.yubhub.co/anduril.com.png</Employerlogo>
      <Employerdescription>Anduril Industries is a defence technology company that designs, builds and sells advanced military systems.</Employerdescription>
      <Employerwebsite>https://www.anduril.com/</Employerwebsite>
      <Compensationcurrency></Compensationcurrency>
      <Compensationmin></Compensationmin>
      <Compensationmax></Compensationmax>
      <Applyto>https://job-boards.greenhouse.io/andurilindustries/jobs/5087348007</Applyto>
      <Location>Costa Mesa, California, United States</Location>
      <Country></Country>
      <Postedate>2026-04-18</Postedate>
    </job>
    <job>
      <externalid>de168cba-02c</externalid>
      <Title>Principal Software Engineer, Platform Security</Title>
      <Description><![CDATA[<p>We&#39;re looking for a principal-level engineer to serve as a technical leader for platform security across Anduril. This role combines deep expertise in cryptography, systems security, and secure architecture with the ability to drive security strategy across business lines and the platform.</p>
<p>As the world enters an era of strategic competition, Anduril is committed to bringing cutting-edge autonomy, AI, computer vision, sensor fusion, and networking technology to the military in months, not years.</p>
<p>Key Responsibilities:</p>
<ul>
<li>Own the technical vision and architecture for platform security across Anduril&#39;s product ecosystem</li>
<li>Design cryptographic systems, protocols, and key management architectures for autonomous and robotic platforms operating in contested and disconnected environments</li>
<li>Lead the design of hardware root-of-trust architectures integrating TPMs, TEEs, HSMs, and secure boot across diverse embedded platforms</li>
<li>Drive the strategy for promoting business-line security implementations into shared, composable platform services</li>
<li>Serve as the senior technical authority for security architecture reviews across the organization, providing definitive guidance on cryptographic design, protocol security, and system hardening</li>
<li>Define security patterns, reference architectures, and engineering standards that enable teams across Anduril to build securely and independently</li>
<li>Mentor and develop senior engineers on the team, raising the bar for security engineering across the organization</li>
<li>Represent Anduril&#39;s security engineering capabilities to customers, partners, and auditors when deep technical credibility is required</li>
<li>Evaluate emerging threats, cryptographic standards, and security technologies, driving adoption where they strengthen the platform</li>
</ul>
<p>Required Qualifications:</p>
<ul>
<li>12+ years of experience in software engineering, with significant depth in systems security and cryptography</li>
<li>Expert-level knowledge of cryptographic protocol design, including key management architectures, certificate systems, and cryptographic agility</li>
<li>Deep experience with hardware security: TPM, TEE, HSM, secure boot, and hardware root-of-trust design across multiple platform types</li>
<li>Proficient in two or more of: C++, Rust, Go</li>
<li>Experience designing security architectures for embedded, real-time, or robotic systems with constrained environments</li>
<li>Track record of leading cross-organizational technical initiatives and driving architectural decisions that span multiple teams</li>
<li>Strong ability to communicate complex security concepts to engineering leadership, product teams, and external stakeholders</li>
<li>Experience performing and leading threat modeling, security architecture reviews, and cryptographic design reviews</li>
<li>Eligible to obtain and maintain active U.S. Secret security clearance</li>
</ul>
<p>Preferred Qualifications:</p>
<ul>
<li>Experience with post-quantum cryptography, distributed key generation (DKG), or threshold cryptographic schemes</li>
<li>Background in defense, aerospace, or autonomous systems with exposure to FIPS 140, Common Criteria, or NSA CSfC requirements</li>
<li>Experience designing secure communication protocols for autonomous platforms or mesh networks</li>
<li>Deep knowledge of Linux kernel security, mandatory access controls (SELinux/AppArmor), and OS hardening at scale</li>
<li>Experience building and evolving platform security services consumed by dozens of teams</li>
<li>Familiarity with compliance frameworks (STIGs, NIST 800-53, CMMC) and translating them into engineering controls that don&#39;t compromise developer velocity</li>
<li>Publications, patents, or recognized contributions in cryptography or systems security</li>
<li>Experience with Nix build systems and reproducible build pipelines for security-critical software</li>
</ul>
<p>US Salary Range: $254,000-$336,000 USD</p>
<p style="margin-top:24px;font-size:13px;color:#666;">XML job scraping automation by <a href="https://yubhub.co">YubHub</a></p>]]></Description>
      <Jobtype>full-time</Jobtype>
      <Experiencelevel>senior</Experiencelevel>
      <Workarrangement>onsite</Workarrangement>
      <Salaryrange>$254,000-$336,000 USD</Salaryrange>
      <Skills>cryptography, systems security, secure architecture, cryptographic protocol design, key management architectures, certificate systems, cryptographic agility, hardware security, TPM, TEE, HSM, secure boot, hardware root-of-trust design, embedded systems, real-time systems, robotic systems, constrained environments, cross-organizational technical initiatives, architectural decisions, complex security concepts, threat modeling, security architecture reviews, cryptographic design reviews, U.S. Secret security clearance, post-quantum cryptography, distributed key generation, threshold cryptographic schemes, defense, aerospace, autonomous systems, FIPS 140, Common Criteria, NSA CSfC requirements, secure communication protocols, mesh networks, Linux kernel security, mandatory access controls, OS hardening, compliance frameworks, STIGs, NIST 800-53, CMMC, publications, patents, recognized contributions, Nix build systems, reproducible build pipelines</Skills>
      <Category>Engineering</Category>
      <Industry>Technology</Industry>
      <Employername>Anduril Industries</Employername>
      <Employerlogo>https://logos.yubhub.co/andurilindustries.com.png</Employerlogo>
      <Employerdescription>Anduril Industries is a defense technology company that transforms U.S. and allied military capabilities with advanced technology.</Employerdescription>
      <Employerwebsite>https://www.andurilindustries.com/</Employerwebsite>
      <Compensationcurrency></Compensationcurrency>
      <Compensationmin></Compensationmin>
      <Compensationmax></Compensationmax>
      <Applyto>https://job-boards.greenhouse.io/andurilindustries/jobs/5087992007</Applyto>
      <Location>Boston, Massachusetts, United States; Costa Mesa, California, United States; Seattle, Washington, United States; Washington, District of Columbia, United States</Location>
      <Country></Country>
      <Postedate>2026-04-18</Postedate>
    </job>
    <job>
      <externalid>269b449a-401</externalid>
      <Title>Staff Engineer, Product Security &amp; Compliance</Title>
      <Description><![CDATA[<p>Shield AI is seeking a senior security professional to lead product security and compliance efforts for our operational autonomous aircraft platforms. This role blends ISSM-level responsibility with hands-on product security and deep collaboration with engineering teams building real, fielded systems.</p>
<p>The ideal candidate brings experience securing aerospace or defense products and approaches compliance as an enabler of mission success. This role emphasizes practical, engineering-driven security decisions that balance regulatory requirements with system performance, autonomy, and operational realities.</p>
<p>Responsibilities:
Serve as the product security lead and ISSM for operational autonomous aircraft platforms.
Own and guide RMF activities, including ATO packages, ongoing authorization, and customer security engagements
Translate security and compliance requirements into product-appropriate, technically sound controls
Partner closely with systems, software, hardware, and platform engineering teams throughout the product lifecycle
Evaluate the security impact and operational tradeoffs of design decisions
Support government and customer audits, assessments, and security reviews
Contribute to the maturation of product security and compliance practices across Shield AI</p>
<p>Required qualifications:
Experience functioning as an Information System Security Manager (ISSM) or senior ISSO for complex systems
Experience securing aerospace and/or defense products
Strong working knowledge of RMF, NIST 800-53, and the ATO process
Enough systems engineering or technical depth to assess the reasonableness and impact of security requirements
Ability to work effectively with engineering teams in fast-paced, product-driven environments
Active U.S. Secret security clearance
Ability to work on-site in Frisco, TX</p>
<p>Preferred qualifications:
Active Top Secret (TS) clearance
Experience with CMMC and ISO 27001 implementation or assessment
Product security experience beyond enterprise IT or GRC-only roles
Commercial technology experience in addition to defense
Familiarity with secure development lifecycles and embedded or autonomous systems</p>
<p>$138,000 - $207,000 a year
Full-time regular employee offer package:
Pay within range listed + Bonus + Benefits + Equity
Temporary employee offer package:
Pay within range listed above + temporary benefits package (applicable after 60 days of employment)</p>
<p style="margin-top:24px;font-size:13px;color:#666;">XML job scraping automation by <a href="https://yubhub.co">YubHub</a></p>]]></Description>
      <Jobtype>full-time</Jobtype>
      <Experiencelevel>senior</Experiencelevel>
      <Workarrangement>onsite</Workarrangement>
      <Salaryrange>$138,000 - $207,000 a year</Salaryrange>
      <Skills>RMF, NIST 800-53, ATO process, Information System Security Manager (ISSM), senior ISSO, systems engineering, technical depth, U.S. Secret security clearance, CMMC, ISO 27001, secure development lifecycles, embedded or autonomous systems</Skills>
      <Category>Engineering</Category>
      <Industry>Technology</Industry>
      <Employername>Shield AI</Employername>
      <Employerlogo>https://logos.yubhub.co/shield.ai.png</Employerlogo>
      <Employerdescription>Shield AI is a venture-backed deep-tech company founded in 2015, developing products such as the V-BAT and X-BAT aircraft, Hivemind Enterprise, and the Hivemind Vision product lines.</Employerdescription>
      <Employerwebsite>https://www.shield.ai</Employerwebsite>
      <Compensationcurrency></Compensationcurrency>
      <Compensationmin></Compensationmin>
      <Compensationmax></Compensationmax>
      <Applyto>https://jobs.lever.co/shieldai/e6434735-b6af-4657-89a5-382a2f9bf366</Applyto>
      <Location>Dallas</Location>
      <Country></Country>
      <Postedate>2026-04-17</Postedate>
    </job>
    <job>
      <externalid>eec951b9-d96</externalid>
      <Title>Security Engineer</Title>
      <Description><![CDATA[<p>We&#39;re seeking a Security Engineer at the senior-level or above to own the product security and authorization lifecycle for Saronic&#39;s autonomous surface vessels. You will serve as the responsible security engineer for one or more vessel programs, owning the security posture from design through production, authorization, and operational deployment.</p>
<p>This is a hands-on security engineering role; not a GRC or project management role. You&#39;ll identify the frameworks that apply, architect the vessel&#39;s security to satisfy them, and drive authorization to completion. Where standards don&#39;t yet exist, you&#39;ll define them.</p>
<p>Key Responsibilities:</p>
<ul>
<li>Own the security posture for one or more vessel programs from architecture through fielding, serving as the responsible security engineer for the product</li>
<li>Drive threat modeling across vessel subsystems including embedded compute, communications, navigation, propulsion controls, sensor fusion, and C2 interfaces and define security architectures, trust boundaries, and segmentation strategies based on findings</li>
<li>Identify and mitigate security risks unique to autonomous maritime platforms, including GPS/GNSS spoofing, RF interference, sensor manipulation, supply chain compromise, and physical access threats</li>
<li>Own the end-to-end authorization lifecycle for vessel programs, from initial security planning through ATO or equivalent customer authorization milestones</li>
<li>Navigate DoD cybersecurity authorization frameworks including RMF, CSRMC, and service-specific requirements across Navy, Coast Guard, Marine Corps, and joint programs</li>
<li>Prepare and maintain authorization artifacts, security documentation, and evidence packages that satisfy Authorizing Officials and program offices</li>
<li>Identify and map applicable compliance frameworks for each vessel and customer segment including NIST SP 800-53, NIST SP 800-171, CMMC 2.0, FedRAMP, IEC 62443, IMO MASS Code, and IACS UR E26/E27 and proactively define Saronic&#39;s compliance posture where standards are still emerging</li>
<li>Engage directly with government program offices, Authorizing Officials, DOT&amp;E evaluators, and classification societies as a credible technical representative of Saronic&#39;s security posture</li>
<li>Support cybersecurity testing and evaluation efforts, including preparation for operational test events, red team assessments, and cooperative vulnerability assessments</li>
<li>Partner with supply chain and manufacturing teams to address hardware provenance, firmware integrity, and anti-tamper requirements for production vessels</li>
<li>Work with Legal and Contracts to ensure security and compliance requirements are accurately reflected in customer agreements, proposals, and contract deliverables</li>
</ul>
<p>Required Qualifications:</p>
<ul>
<li>6+ years of hands-on experience in product security, systems security engineering, authorization engineering, or a closely related security engineering role for defense or high-assurance platforms</li>
<li>Strong understanding of DoD cybersecurity authorization processes (RMF, ATO/IATT, CSRMC, continuous ATO) with experience contributing to or driving systems through authorization</li>
<li>Working knowledge of NIST SP 800-53, NIST SP 800-171, and CMMC 2.0 and their application to weapons systems, autonomous platforms, or similarly complex defense products</li>
<li>Experience with threat modeling, security architecture, or risk assessment for cyber-physical systems, embedded systems, or operational technology environments</li>
<li>Strong technical foundation, able to read architecture diagrams, evaluate security controls at a systems level, and hold credible technical conversations with hardware, software, and cloud engineers</li>
<li>Ability to clearly communicate with both technical and non-technical stakeholders, including production of security documentation and authorization artifacts</li>
<li>Ownership mindset with the ability to operate in ambiguity, define the path forward, and move work to completion across teams</li>
<li>Ability to obtain and maintain a security clearance</li>
</ul>
<p>Preferred Qualifications:</p>
<ul>
<li>Experience as a product security lead, systems security engineer, or authorization lead for a defense platform or program of record</li>
<li>Direct experience engaging with government Authorizing Officials, program offices, or DOT&amp;E as a technical security representative</li>
<li>Experience in defense technology startups, DARPA programs, or organizations that move at speed within the defense acquisition system</li>
<li>Familiarity with maritime-specific frameworks including IMO MASS Code, IACS UR E26/E27, IEC 62443, or classification society autonomous vessel rules</li>
<li>Understanding of autonomous systems security challenges including communications security, electronic warfare hardening, GPS/GNSS resilience, and AI/ML system security</li>
<li>Experience with ITAR/EAR compliance, supply chain security, or manufacturing security for defense products</li>
<li>Familiarity with the defense acquisition lifecycle and how authorization milestones integrate into program schedules</li>
</ul>
<p>Additional Information:</p>
<ul>
<li>Benefits: Medical Insurance, Dental and Vision Insurance, Time Off, Parental Leave, Competitive Salary, Retirement Plan, Stock Options, Life and Disability Insurance, Pet Insurance</li>
<li>This role requires access to export-controlled information or items that require “U.S. Person” status.</li>
</ul>
<p style="margin-top:24px;font-size:13px;color:#666;">XML job scraping automation by <a href="https://yubhub.co">YubHub</a></p>]]></Description>
      <Jobtype>full-time</Jobtype>
      <Experiencelevel>senior</Experiencelevel>
      <Workarrangement>onsite</Workarrangement>
      <Salaryrange></Salaryrange>
      <Skills>product security, systems security engineering, authorization engineering, threat modeling, security architecture, risk assessment, cyber-physical systems, embedded systems, operational technology environments, NIST SP 800-53, NIST SP 800-171, CMMC 2.0, RMF, CSRMC, ATO/IATT, continuous ATO, FedRAMP, IEC 62443, IMO MASS Code, IACS UR E26/E27, product security lead, systems security engineer, authorization lead, defense platform, program of record, government Authorizing Officials, program offices, DOT&amp;E, technical security representative, defense technology startups, DARPA programs, organizations, defense acquisition system, maritime-specific frameworks, ITAR/EAR compliance, supply chain security, manufacturing security</Skills>
      <Category>Engineering</Category>
      <Industry>Technology</Industry>
      <Employername>Saronic Technologies</Employername>
      <Employerlogo>https://logos.yubhub.co/saronictech.com.png</Employerlogo>
      <Employerdescription>Saronic Technologies is a leader in revolutionizing defense autonomy at sea, developing state-of-the-art solutions for the Department of Defense.</Employerdescription>
      <Employerwebsite>https://www.saronictech.com/</Employerwebsite>
      <Compensationcurrency></Compensationcurrency>
      <Compensationmin></Compensationmin>
      <Compensationmax></Compensationmax>
      <Applyto>https://jobs.lever.co/saronic/6e800df8-6173-4f13-863e-b8803017f317</Applyto>
      <Location></Location>
      <Country></Country>
      <Postedate>2026-04-17</Postedate>
    </job>
    <job>
      <externalid>85f1ada0-78d</externalid>
      <Title>Security Engineer</Title>
      <Description><![CDATA[<p>We&#39;re seeking a Security Engineer at the senior-level or above on our Security Operations team with strong detection engineering experience. You&#39;ll design and develop high-fidelity detection content, build and operate the data pipelines that power our security operations, develop automation playbooks that accelerate response, and work across a uniquely diverse telemetry landscape spanning cloud infrastructure, embedded vessel platforms, corporate systems, and operational technology.</p>
<p>This role is heavily weighted toward detection engineering. You should think in terms of adversary behaviour and telemetry coverage, not just alert triage. You&#39;ll own detections end-to-end: from identifying gaps in coverage, through designing and testing detection logic, to tuning and validating in production.</p>
<p>Key Responsibilities:</p>
<ul>
<li><p>Design, build, test, and tune high-fidelity detection rules and analytic queries across endpoint, cloud, network, identity, and DLP telemetry sources</p>
</li>
<li><p>Develop and maintain detection content using detection-as-code practices including version-controlled logic, automated testing, and CI/CD deployment</p>
</li>
<li><p>Map detection coverage to MITRE ATT&amp;CK, identify gaps, and prioritise new detection development based on threat intelligence and business risk</p>
</li>
<li><p>Engineer correlation rules, behavioural analytics, and anomaly-based detections that minimise false positives while surfacing real adversary tradecraft</p>
</li>
<li><p>Own the detection lifecycle from initial development through production tuning, performance monitoring, and retirement</p>
</li>
<li><p>Build and operate pipelines to ingest, normalise, enrich, and manage security telemetry at scale across diverse data sources, using Terraform and infrastructure-as-code practices to deploy and maintain logging and detection infrastructure</p>
</li>
<li><p>Design and maintain log collection, parsing, and enrichment configurations that ensure the right telemetry is available at the right fidelity for detection and investigation</p>
</li>
<li><p>Evaluate and onboard new telemetry sources as Saronic&#39;s infrastructure and threat landscape evolve</p>
</li>
<li><p>Monitor pipeline health, data quality, and ingestion reliability to ensure detections operate on complete and accurate data</p>
</li>
<li><p>Develop and manage automated response playbooks in SOAR platforms to accelerate containment and reduce analyst toil</p>
</li>
<li><p>Build automation that enriches alerts with contextual data, reducing investigation time and improving analyst decision-making</p>
</li>
<li><p>Support incident response efforts and translate lessons learned into improved detections and playbooks</p>
</li>
<li><p>Partner with SOC analysts, Cloud Security, Product Security, and IT teams to close visibility and detection gaps across environments</p>
</li>
<li><p>Collaborate with threat intelligence to ensure detection engineering is informed by current adversary TTPs relevant to defence, maritime, and autonomous systems</p>
</li>
</ul>
<p>Required Qualifications:</p>
<ul>
<li><p>3+ years of hands-on experience in detection engineering, security operations, security automation, or a closely related security engineering role</p>
</li>
<li><p>Demonstrated experience designing, testing, and tuning detection rules and analytic queries across production security telemetry (endpoint, cloud, network, identity, or DLP)</p>
</li>
<li><p>Hands-on experience with SIEM platforms and proficiency with query languages such as SPL, KQL, or equivalent</p>
</li>
<li><p>Experience building and operating security data pipelines, including log ingestion, normalisation, enrichment, and data quality management</p>
</li>
<li><p>Understanding of data engineering concepts including ETL pipelines, data modelling, schema design, and indexing as applied to security telemetry</p>
</li>
<li><p>Hands-on coding experience in Python, PowerShell, Go, or Rust for security automation, detection tooling, or pipeline development, and familiarity with Terraform for managing detection and logging infrastructure as code</p>
</li>
<li><p>Understanding of MITRE ATT&amp;CK framework and its application to detection coverage and gap analysis</p>
</li>
<li><p>Ability to obtain and maintain a security clearance</p>
</li>
</ul>
<p>Preferred Qualifications:</p>
<ul>
<li><p>Experience in defence, aerospace, robotics, autonomy, or other high-assurance environments</p>
</li>
<li><p>Experience with EDR platforms including custom detection rule creation and telemetry analysis</p>
</li>
<li><p>Experience with cloud-native detection in AWS and Microsoft 365/Azure</p>
</li>
<li><p>Experience using Terraform to deploy and manage security monitoring infrastructure, log pipeline components, or cloud-native security service configurations</p>
</li>
<li><p>Hands-on experience with incident response, threat hunting, or adversary emulation</p>
</li>
<li><p>Exposure to embedded Linux, operational technology, or ICS telemetry and detection</p>
</li>
<li><p>Familiarity with NIST SP 800-171, NIST SP 800-53, or CMMC and their logging and monitoring requirements</p>
</li>
<li><p>Relevant certifications such as GCIH, GCIA, GCDA, GSOM, OSDA, or OSCP</p>
</li>
</ul>
<p>Additional Information:</p>
<ul>
<li><p>Benefits: Medical Insurance, Dental and Vision Insurance, Time Off, Parental Leave, Competitive Salary, Retirement Plan, Stock Options, Life and Disability Insurance, Pet Insurance</p>
</li>
<li><p>This role requires access to export-controlled information or items that require &#39;U.S. Person&#39; status.</p>
</li>
</ul>
<p style="margin-top:24px;font-size:13px;color:#666;">XML job scraping automation by <a href="https://yubhub.co">YubHub</a></p>]]></Description>
      <Jobtype>full-time</Jobtype>
      <Experiencelevel>senior</Experiencelevel>
      <Workarrangement>onsite</Workarrangement>
      <Salaryrange></Salaryrange>
      <Skills>detection engineering, security operations, security automation, SIEM platforms, query languages, data engineering, ETL pipelines, data modelling, schema design, indexing, Python, PowerShell, Go, Rust, Terraform, MITRE ATT&amp;CK framework, security clearance, EDR platforms, cloud-native detection, incident response, threat hunting, adversary emulation, embedded Linux, operational technology, ICS telemetry, NIST SP 800-171, NIST SP 800-53, CMMC, GCIH, GCIA, GCDA, GSOM, OSDA, OSCP</Skills>
      <Category>Engineering</Category>
      <Industry>Technology</Industry>
      <Employername>Saronic Technologies</Employername>
      <Employerlogo>https://logos.yubhub.co/saronictechnologies.com.png</Employerlogo>
      <Employerdescription>Saronic Technologies is a leader in revolutionizing defense autonomy at sea, dedicated to developing state-of-the-art solutions that enhance maritime operations for the Department of Defense (DoD) through autonomous and intelligent platforms.</Employerdescription>
      <Employerwebsite>https://www.saronictechnologies.com/</Employerwebsite>
      <Compensationcurrency></Compensationcurrency>
      <Compensationmin></Compensationmin>
      <Compensationmax></Compensationmax>
      <Applyto>https://jobs.lever.co/saronic/79424778-76c1-41c6-8385-cba5f6ddc50e</Applyto>
      <Location>San Francisco</Location>
      <Country></Country>
      <Postedate>2026-04-17</Postedate>
    </job>
    <job>
      <externalid>a2183a2d-c20</externalid>
      <Title>Cyber Security Engineer, Staff Engineer</Title>
      <Description><![CDATA[<p>At Synopsys, we&#39;re seeking a dedicated and detail-oriented Cyber Security Engineer to join our team. As a Cyber Security Engineer, you will play a pivotal role in sustaining long-term CMMC compliance and advancing our cybersecurity maturity. You will own and coordinate CMMC Level 2 documentation, review and validate Standard Operating Procedures (SOPs), and verify implementation and effectiveness of CMMC security controls and practices. You will also support mock audits, readiness reviews, and official CMMC assessments, including evidence preparation and assessor interaction support.</p>
<p>You will collaborate with IT and engineering teams to establish and track patching and remediation priorities, focusing on CMMC scoring impact. You will maintain ownership of all Plans of Action and Milestones (POA&amp;Ms), validating remediation closure evidence, and ensuring alignment with DoD and CMMC requirements. You will also support continuous control monitoring activities for ongoing compliance between assessments.</p>
<p>As a Cyber Security Engineer, you will communicate compliance posture, risks, and remediation status to both technical and non-technical audiences, and support user and stakeholder education. You will also escalate unresolved compliance or remediation risks to cybersecurity and audit leadership as appropriate.</p>
<p>This is an exciting opportunity to join a driven and collaborative Cybersecurity team at Synopsys, working alongside experts in IT, Engineering, and Business Operations. You will report to the Executive Director of Cybersecurity and play a central role in audit readiness, evidence management, and cross-functional collaboration.</p>
<p>To be successful in this role, you will need:</p>
<ul>
<li>Security+ (SEC+) or equivalent industry-recognized cybersecurity certification</li>
<li>4+ years of experience performing Information Assurance, ISSO, ISSE, or equivalent cybersecurity assurance functions</li>
<li>2+ years supporting cybersecurity operations in a DoD or defense-adjacent enterprise environment</li>
<li>Experience supporting NIST SP 800-171, RMF-aligned, or CMMC-related compliance activities</li>
<li>Ability to obtain and maintain a U.S. DoD, FBI, or DHS security clearance</li>
<li>Strong technical understanding of modern hardware, software, and enterprise infrastructure environments</li>
<li>Familiarity with vulnerability management platforms, compliance evidence repositories, and security monitoring outputs</li>
<li>Excellent organizational, prioritization, and time-management skills</li>
<li>Strong analytical and problem-solving abilities with attention to detail</li>
<li>Ability to work effectively across technical and non-technical teams to resolve complex compliance issues</li>
<li>Strong written and verbal communication skills, including the ability to present information to leadership and stakeholder groups</li>
<li>Demonstrated ability to manage multiple competing priorities in a high-assurance environment</li>
</ul>
<p>If you are a collaborative team player who thrives in cross-functional environments, detail-oriented and diligent, proactive and resourceful, clear communicator who can translate technical concepts to non-technical audiences, analytical thinker with strong problem-solving skills, adaptable and resilient, and ethical and trustworthy, committed to maintaining high standards of integrity and confidentiality, then we encourage you to apply for this exciting opportunity.</p>
<p style="margin-top:24px;font-size:13px;color:#666;">XML job scraping automation by <a href="https://yubhub.co">YubHub</a></p>]]></Description>
      <Jobtype>full-time</Jobtype>
      <Experiencelevel>staff</Experiencelevel>
      <Workarrangement>onsite</Workarrangement>
      <Salaryrange>$129000-$193000</Salaryrange>
      <Skills>Security+ (SEC+) or equivalent industry-recognized cybersecurity certification, 4+ years of experience performing Information Assurance, ISSO, ISSE, or equivalent cybersecurity assurance functions, 2+ years supporting cybersecurity operations in a DoD or defense-adjacent enterprise environment, Experience supporting NIST SP 800-171, RMF-aligned, or CMMC-related compliance activities, Ability to obtain and maintain a U.S. DoD, FBI, or DHS security clearance, Strong technical understanding of modern hardware, software, and enterprise infrastructure environments, Familiarity with vulnerability management platforms, compliance evidence repositories, and security monitoring outputs, Excellent organizational, prioritization, and time-management skills, Strong analytical and problem-solving abilities with attention to detail, Ability to work effectively across technical and non-technical teams to resolve complex compliance issues, Strong written and verbal communication skills, including the ability to present information to leadership and stakeholder groups, Demonstrated ability to manage multiple competing priorities in a high-assurance environment</Skills>
      <Category>Engineering</Category>
      <Industry>Technology</Industry>
      <Employername>Synopsys</Employername>
      <Employerlogo>https://logos.yubhub.co/careers.synopsys.com.png</Employerlogo>
      <Employerdescription>Synopsys is a technology company that develops software used in chip design, verification, and manufacturing.</Employerdescription>
      <Employerwebsite>https://careers.synopsys.com</Employerwebsite>
      <Compensationcurrency></Compensationcurrency>
      <Compensationmin></Compensationmin>
      <Compensationmax></Compensationmax>
      <Applyto>https://careers.synopsys.com/job/morrisville/cyber-security-engineer-staff-engineer-15964/44408/93005893632</Applyto>
      <Location>Morrisville</Location>
      <Country></Country>
      <Postedate>2026-04-05</Postedate>
    </job>
    <job>
      <externalid>ce09264c-2d9</externalid>
      <Title>Senior Cybersecurity Engineer</Title>
      <Description><![CDATA[<p>You are a passionate and experienced cybersecurity professional who thrives in fast-paced, global enterprise environments. With over five years of hands-on experience, you bring a deep understanding of enterprise-grade security solutions, including CASB, SSPM, WAF, firewalls, and email security. You have a proven track record in deploying, integrating, and managing network security solutions at scale, with a strong grasp of Zero Trust principles and architectures. Your expertise in CMMC regulations, technical data controls, and export authorization rules enables you to enforce U.S. person–only access restrictions for sensitive systems and datasets.</p>
<p>As a collaborative problem-solver, you are comfortable working across teams—from executives to engineers—to ensure robust security controls and compliance. You excel at conducting security investigations, analyzing complex events and alerts, and developing actionable metrics. Your familiarity with modern security frameworks, such as MITRE ATT&amp;CK and Cyber Kill Chain, empowers you to identify and mitigate threats proactively. You are detail-oriented, organized, and adept at multitasking, thriving in environments that require prioritization and agility.</p>
<p>You are committed to ongoing learning, staying current with emerging security technologies and frameworks. Your experience spans cloud security (AWS, GCP, Azure), offensive security, and incident response. You enjoy participating in audits and assessments, contributing to a culture of continuous improvement. With strong communication skills and an inclusive mindset, you foster trust and collaboration across diverse teams. If you’re ready to make an impact at the forefront of cybersecurity innovation, Synopsys is the place for you.</p>
<p>Design, deploy, and manage enterprise-grade security solutions including CASB, SSPM, WAF, firewalls, and email protection across global environments. Integrate and implement network security solutions, ensuring seamless operation and compliance with Zero Trust security principles. Enforce CMMC regulations, technical data controls, and export authorization rules, including U.S. person-only access restrictions for controlled systems and datasets. Conduct and support external audits, internal reviews, and compliance assessments related to CMMC and other regulatory frameworks. Research, evaluate, pilot, and implement new security solutions at a global enterprise scale, collaborating with vendors and stakeholders. Investigate security events and alerts from multiple log sources, performing end-to-end security investigations, and reporting actionable findings. Develop and manage the collection, reporting, and analysis of security events and metrics to drive continuous improvement. Participate in incident response processes and supporting light on-call pager duty rotations for critical issues.</p>
<p>Strengthen Synopsys’ global security posture by implementing advanced security controls and best practices. Ensure compliance with CMMC and other regulatory frameworks, enabling secure operations for critical projects. Protect sensitive data, intellectual property, and infrastructure against emerging cyber threats. Drive continuous improvement in security operations through data-driven analysis and proactive risk management. Enhance cross-functional collaboration between engineering, compliance, and executive teams to foster a culture of security awareness. Support innovation by enabling secure cloud implementations and supporting offensive security initiatives.</p>
<p>Bachelor’s degree in Computer Science, Cybersecurity, Information Systems, or related field required. 5+ years of hands-on experience with enterprise-grade security solutions (CASB, SSPM, WAF, firewalls, email security). 2+ years of experience installing, integrating, and deploying network security solutions. Solid understanding of Zero Trust security principles and architectures. Deep knowledge of CMMC regulations, technical data controls, and export authorization rules. Experience enforcing U.S. person-only access restrictions for controlled systems and datasets. Experience with external audits, internal reviews, and compliance assessments. Broad experience securing cloud implementations (AWS, GCP, Azure) and offensive security domains. Hands-on experience with Zscaler, Palo Alto Networks, ProofPoint, and other leading security platforms. Relevant certifications (CEH, CISSP, GIAC, OSCP, AWS Certified Advanced Networking, Security+) preferred. US citizenship or Green Card required.</p>
<p style="margin-top:24px;font-size:13px;color:#666;">XML job scraping automation by <a href="https://yubhub.co">YubHub</a></p>]]></Description>
      <Jobtype>full-time</Jobtype>
      <Experiencelevel>senior</Experiencelevel>
      <Workarrangement>onsite</Workarrangement>
      <Salaryrange>$101,000 - $152,000</Salaryrange>
      <Skills>CASB, SSPM, WAF, firewalls, email security, Zero Trust security principles, CMMC regulations, technical data controls, export authorization rules, cloud security, offensive security, incident response, Zscaler, Palo Alto Networks, ProofPoint, AWS, GCP, Azure, CEH, CISSP, GIAC, OSCP, AWS Certified Advanced Networking, Security+</Skills>
      <Category>Engineering</Category>
      <Industry>Technology</Industry>
      <Employername>Synopsys</Employername>
      <Employerlogo>https://logos.yubhub.co/careers.synopsys.com.png</Employerlogo>
      <Employerdescription>Synopsys is a leading provider of electronic design automation (EDA) software and intellectual property (IP) used in chip design, verification, and manufacturing.</Employerdescription>
      <Employerwebsite>https://careers.synopsys.com</Employerwebsite>
      <Compensationcurrency></Compensationcurrency>
      <Compensationmin></Compensationmin>
      <Compensationmax></Compensationmax>
      <Applyto>https://careers.synopsys.com/job/austin/senior-cybersecurity-engineer-15063/44408/91625669280</Applyto>
      <Location>Austin, Texas</Location>
      <Country></Country>
      <Postedate>2026-03-09</Postedate>
    </job>
  </jobs>
</source>