Slingshot Aerospace Logo

Slingshot Aerospace

Application Security Engineer

Reposted 5 Hours Ago
Remote or Hybrid
Hiring Remotely in United States
Senior level
Remote or Hybrid
Hiring Remotely in United States
Senior level
As a Security Engineer, you'll design and harden systems in classified environments, deploy secure enclaves, and ensure compliance. You'll handle secure CI/CD processes, threat modeling, and vulnerability management while automating compliance enforcement and supporting incident response.
The summary above was generated by AI

Mission 

As Security Engineer you will design, integrate, and harden Slingshot’s software and infrastructure in classified government environments. You will deploy secure enclaves, enforce DevSecOps practices, and ensure systems are hardened, resilient, and compliant. This role is mission critical. If systems are not hardened and compliant, the SME cannot secure the ATO and mission progress halts. Success requires a hands on engineer who thrives in complexity, moves fast under pressure, and brings a mission first can do mindset to cleared programs. 

What You Will Do 

  • Engineer hardened Linux based and containerized systems for air gapped and enclave deployments 
  • Build and maintain secure CI/CD pipelines, enclave build processes, and hardened OS images 
  • Perform secure code reviews, threat modeling, and integrate AppSec scanning including SAST, DAST, IaC, and SBOM validation 
  • Deploy hybrid and on prem IAM solutions including RBAC, MFA, PAM, and directory services for classified enclaves 
  • Apply CIA triad principles to strengthen system security and reliability 
  • Execute vulnerability management, CVE remediation, and produce Software Assurance Reports 
  • Draft system architecture and boundary diagrams supporting ATO and audit packages 
  • Apply DISA STIGs, CIS Benchmarks, and DoD hardening standards to enclave deployments 
  • Work with primes, subcontractors, and government ISSMs to ensure systems are hardened and auditable 
  • Automate compliance enforcement to reduce manual overhead in secure builds 
  • Support incident detection and response in classified environments
  • Secure internal SaaS, productivity tools, and collaboration platforms
  • Manage vulnerabilities, harden corporate applications, and assist with audit-driven remediation
  • Support best DevOps practices across company products and services as well as internal tools

Required Qualifications 

  • Active TS/SCI clearance (polygraph if applicable) 
  • U.S. Citizenship (no duals) 
  • 7 plus years in security engineering or systems engineering for cleared government programs 
  • Direct experience in enclave or air gapped deployments supporting ATO accreditation 
  • Strong coding and scripting ability including Python, Go, Bash, YAML 
  • Knowledge of NIST 800 171, CMMC 2.0, DoD RMF, FedRAMP, and CNSSI 1253 
  • Experience implementing DISA STIGs, CIS Benchmarks, and enclave hardening standards 
  • Certifications such as CISSP, Security+, and OSCP or equivalent 

Preferred Qualifications 

  • 10 plus years of experience in security engineering or systems engineering supporting cleared DoD or IC programs 
  • Direct experience implementing and validating DISA STIGs, CIS Benchmarks, and DoD Secure Configuration Guidance in classified environments 
  • Hands on experience with cross domain solutions and enclave to enclave data flow protections 
  • Expertise integrating DevSecOps practices in air gapped CI/CD pipelines with automated compliance checks 
  • Experience deploying and securing AI and ML workloads in classified settings including GPU isolation, model artifact protection, and sensitive data boundary enforcement 
  • Familiarity with advanced FedRAMP and DoD approved stacks including M365 GCC High, Okta FedRAMP, CrowdStrike GovCloud, and Zscaler for Government 
  • Deep knowledge of cryptography, PKI, key management, enclave networking, and secure hybrid cloud integration 
  • Experience drafting technical documentation and presenting to customer design reviews, TRBs, and accreditation boards 
  • Container and Kubernetes security experience including hardened builds and cluster defense in classified environments 
  • Infrastructure as Code (IaC) security expertise with Terraform, Ansible, or similar tooling 
  • Reverse engineering and exploit mitigation skills in enclave settings 
  • Cross platform expertise across Linux, Windows, and hybrid operating systems in air gapped environments 
  • Network segmentation and microsegmentation design for high side environments 
  • Zero Trust architecture implementation in hybrid and enclave deployments 
  • Red team and penetration testing support to validate enclave hardening 
  • Experience supporting IT and cyber operations inside SCIFs or other secure facilities 
  • Advanced certifications strongly preferred including OSCE, CISSP ISSEP, GIAC GSE, or equivalent 

Why This Role 

This role is hands on and mission critical. If systems are not secured to the highest standards, the SME cannot deliver an ATO and the program will not move forward. You will be the engineer who ensures Slingshot’s technology is trusted and deployable in the most sensitive environments, enabling programs to succeed and missions to be accomplished. 

Location: US based Remote with onsite travel to secure customer environments

Clearance Required: Active TS/SCI (polygraph if applicable) 

Employment Type: Full Time 

Reports To: Senior Director of Information Security and IT 

Location: Remote

Travel: 15% - 35%

Salary: $100,000 - $155,000


US-based Candidates: we are currently only able to hire residents of the following U.S. states: AZ, CA, CO, DC, FL, GA, HI, IL, IN, KS, MD, MA, MI, MN, MO, MT, NV, NJ, NM, NY, NC, OR, RI, TN, TX, UT, VT, VA, WA, WV, and WI. We are unable to consider candidates residing in other U.S. states at this time.

Internationally-based Candidates: we are currently only able to hire residents of the following locations: United Kingdom. We are unable to consider candidates residing in other countries at this time.

Equity, Diversity & Inclusion are key to our success. We are an Equal Opportunity Employer and our employees are people with different strengths, experiences, and backgrounds, who share a passion for creating a safer, more connected world. Diversity not only includes race and gender identity, but also national origin, citizenship, sex, color, veteran status, disability, genetic information, or any other protected characteristic that is part of one’s identity. All of our employees’ points of view are key to our success, and we embrace individuality.

Top Skills

Ansible
Bash
Ci/Cd
Cis Benchmarks
Devsecops
Disa Stigs
Go
Hybrid Iam Solutions
Iac
Linux
Python
Terraform
Yaml

Similar Jobs

2 Days Ago
Remote or Hybrid
5 Locations
175K-175K Annually
Mid level
175K-175K Annually
Mid level
eCommerce • Legal Tech • Professional Services • Software • Data Privacy
The Security Engineer role involves identifying vulnerabilities, automating tasks in penetration testing, and creating security reports for various audiences.
Top Skills: Ruby On RailsVue
17 Days Ago
In-Office or Remote
2 Locations
156K-183K
Senior level
156K-183K
Senior level
Healthtech • Other • Social Impact • Software • Telehealth
As a Senior Application Security Engineer, you'll enhance security practices, manage vulnerabilities, and collaborate with teams on patient data protection.
Top Skills: DastJavaScriptNode.jsOwasp Top 10ReactSastTypescript
24 Days Ago
In-Office or Remote
2 Locations
Senior level
Senior level
Artificial Intelligence • Enterprise Web • Machine Learning • Natural Language Processing • Software • Conversational AI • Automation
Kustomer seeks a Senior Application Security Engineer to enhance security practices, perform audits, and collaborate across teams to protect applications and customer data, particularly in AI and automation.
Top Skills: AppsecAWSCi/CdDastGCPSast

What you need to know about the Los Angeles Tech Scene

Los Angeles is a global leader in entertainment, so it’s no surprise that many of the biggest players in streaming, digital media and game development call the city home. But the city boasts plenty of non-entertainment innovation as well, with tech companies spanning verticals like AI, fintech, e-commerce and biotech. With major universities like Caltech, UCLA, USC and the nearby UC Irvine, the city has a steady supply of top-flight tech and engineering talent — not counting the graduates flocking to Los Angeles from across the world to enjoy its beaches, culture and year-round temperate climate.

Key Facts About Los Angeles Tech

  • Number of Tech Workers: 375,800; 5.5% of overall workforce (2024 CompTIA survey)
  • Major Tech Employers: Snap, Netflix, SpaceX, Disney, Google
  • Key Industries: Artificial intelligence, adtech, media, software, game development
  • Funding Landscape: $11.6 billion in venture capital funding in 2024 (Pitchbook)
  • Notable Investors: Strong Ventures, Fifth Wall, Upfront Ventures, Mucker Capital, Kittyhawk Ventures
  • Research Centers and Universities: California Institute of Technology, UCLA, University of Southern California, UC Irvine, Pepperdine, California Institute for Immunology and Immunotherapy, Center for Quantum Science and Engineering

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account