Back to jobs
New

Principal DevSecOps Architect

Remote, USA

Principal DevSecOps Architect

About Us:

BlackSky is a real-time intelligence company. We own and operate the world's most advanced space-based intelligence platform and provide customers satellite imagery, automated analytics and high-frequency monitoring of strategic locations, economic assets and events from around the globe. BlackSky is trusted by the most demanding allied military and intelligence organizations and commercial companies to deliver foresight into critical matters that affect national security and the economy. BlackSky's data enables governments and businesses to see, understand and anticipate change as it happens, giving them the ultimate strategic advantage so they can act quickly. Our global team works with cutting-edge technology to make a difference around the world and prides itself on being people-first, customer-focused and fun.

BlackSky is looking for a talented DevSecOps architect, in support of the Chief Technology Office to help shape and drive the cybersecurity of BlackSky software systems and satellite ground segment deployments. This role will play an instrumental part in future innovation and supporting BlackSky’s position as a leader in secure real-time geospatial intelligence and satellite missions. BlackSky is looking for multi-faceted individual with a cybersecurity and infrastructure (DevSecOps) background who can work across diverse stakeholder sets to plan and execute infrastructure security architectural solutions to achieve cybersecurity standards compliance. This is a hands-on role and you will be working across teams to evolve our current systems and technologies to align with current and future BlackSky security requirements, compliance, and strategic direction. 

This role reports to the VP, Product Architecture and while we would strongly prefer candidates near our Herndon, VA office we may also consider remote candidates in certain states.

Responsibilities:

  • Drive alignment between the Information Security Office and the Chief Technology Office by developing and decomposing requirements and solutions to achieve security compliance of engineering deployments.
  • Develop robust architectural blueprints and plans for software, network, and infrastructure deployment security for systems hosted within cloud and on-premises environments ensuring adherence to industry best practices and regulatory compliance.
  • Develop a robust cybersecurity roadmap in coordination with the Information Security Office and Engineering and work to implement security frameworks for cloud and on-premises infrastructure.
  • Support the Engineering organization by assessing vulnerabilities and security risks through security and architectural reviews.
  • Partner with the DevOps teams to integrate automated security controls directly into Infrastructure-as-Code (IAC) templates like Terraform and Helm.
  • Establish engineering wide security practices, standards, and access guidelines based on interpreting regulatory and security compliance rulesets.
  • Communicate with internal and external stakeholders and translate security requirements into engineering specifications within the BlackSky architecture.
  • Understand the interactions between systems, applications, and services within the architecture and evaluate the impact of implementing security controls to include cyber security risk, staffing resource, and schedule implications.
  • Ensure the accuracy and completeness of engineering security documentation.
  • Coordinate development and execution of security controls across security, software development teams, infrastructure, systems engineering, and program and product teams to develop execution plans for implementing security controls or addressing vulnerabilities.
  • Organize and track projects, proactively manage risks, manage project escalations, prioritize tasks, and meet specific business objectives.
  • Collaborate with managers and technical groups to address important customer issues and find innovative solutions to difficult problems
  • Develop models and analyze data to evaluate tradeoffs and support the decision-making process.
  • Other job-related duties as assigned.

Required Qualifications:

  • A minimum of 12 years of related work experience with at least five (5) years focused on leading projects in DevSecOps or infrastructure security architecture .
  • Bachelor’s degree in an engineering field.
  • Experience in architecting complex software systems and deployments for cybersecurity compliance.
  • Intimate knowledge of software security standards including NIST 800-171, NIST 800-53, NIST 800-207, FIPS 140-2, FedRAMP, and ISO/IEC 27001:2022.
  • Experience building security architecture roadmaps for businesses.
  • Familiarity with software engineering best practices and process including agile development, enterprise design patterns, and coding standards.
  • Experience with Kubernetes and on-premises deployments of software systems
  • Experience with the software engineering life cycle from product concept through operations and maintenance and toolchains used to manage this process (JIRA, Git, etc.).
  • Versed in Systems Engineering best practices and tools including communicating, managing, and documenting system architectures, documenting interfaces, documenting and validation of functional and non-functional requirements.
  • Effective communication skills to represent security, architectural, and engineering concepts and decisions across varied stakeholders including Engineering, Sales, Customers, Product Management.
  • Proficient in DevSecOps tooling, technologies, and environments.
  • Must be eligible to obtain and maintain a US Security Clearance (this requires US Citizenship).

Preferred Qualifications:

  • Active ISC2 Information Systems Security Architecture Professional (ISSAP) or Certified Information Systems Security Professional (CISSP) certification.
  • A minimum of 15 years of related work experience with at least five (5) years in focused on leading projects in DevSecOps or infrastructure security architecture .
  • Experience upgrading software systems and guiding engineering teams to achieve NIST 800-171, ISO/IEC 27001:2022, or FedRAMP Compliance.
  • Experience securing software systems for on-premises air-gapped environments.
  • Former software engineering and software architecture experience for production systems, especially for space or defense applications.
  • Hands on experience with DevOps and Kubernetes infrastructure and deployments.
  • Master’s degree in engineering.

Life at BlackSky for full-time US benefits eligible employees includes:

  • Medical, dental, vision, disability, group term life and AD&D, voluntary life and AD&D insurance
    • BlackSky pays 100% of employee-only premiums for medical, dental and vision and contributes $100/month for out-of-pocket expenses!
  • 15 days of PTO, 11 Company holidays, four Floating Holidays (pro-rated based on hire date), one day of paid volunteerism leave per year, parental leave and more
  • 401(k) pre-tax and Roth deferral options with employer match
  • Flexible Spending Accounts
  • Employee Stock Purchase Program
  • Employee Assistance and Travel Assistance Programs
  • Employer matching donations
  • Professional development
  • Mac or PC? Your choice!
  • Awesome swag

The anticipated salary range for candidates in Seattle, WA is $190,000 - $215,000 per year. The final compensation package offered to a successful candidate will be dependent on specific background and education. BlackSky is a multi-state employer and this pay scale may not reflect salary ranges in other states or locations outside of Seattle, WA.

BlackSky is committed to hiring and retaining a diverse workforce. We are proud to be an Equal Opportunity Employer All Qualified applicants will receive consideration for employment without regard to race, color, religion, sex, age, national origin, sexual orientation, gender identity, disability, protected veteran status or any other characteristic protected by law.

To conform to U.S. Government space technology export regulations, including the International Traffic in Arms Regulations (ITAR) you must be a U.S. citizen, lawful permanent resident of the U.S., protected individual as defined by 8 U.S.C. 1324b(a)(3), or eligible to obtain the required authorizations from the U.S. Department of State. #LI-Remote

EEO/Pay Transparency Statements:

https://www.dol.gov/ofccp/regs/compliance/posters/pdf/eeopost.pdf

https://www.dol.gov/ofccp/regs/compliance/posters/pdf/OFCCP_EEO_Supplement_Final_JRF_QA_508c.pdf

Create a Job Alert

Interested in building your career at BlackSky? Get future opportunities sent straight to your email.

Apply for this job

*

indicates a required field

Phone
Resume/CV*

Accepted file types: pdf, doc, docx, txt, rtf

Cover Letter

Accepted file types: pdf, doc, docx, txt, rtf


Select...
Select...
Which of the following languages are you proficient in? *
Select...
Select...
Select...
Select...

Voluntary Self-Identification

For government reporting purposes, we ask candidates to respond to the below self-identification survey. Completion of the form is entirely voluntary. Whatever your decision, it will not be considered in the hiring process or thereafter. Any information that you do provide will be recorded and maintained in a confidential file.

As set forth in BlackSky’s Equal Employment Opportunity policy, we do not discriminate on the basis of any protected group status under any applicable law.

Select...
Select...
Race & Ethnicity Definitions

If you believe you belong to any of the categories of protected veterans listed below, please indicate by making the appropriate selection. As a government contractor subject to the Vietnam Era Veterans Readjustment Assistance Act (VEVRAA), we request this information in order to measure the effectiveness of the outreach and positive recruitment efforts we undertake pursuant to VEVRAA. Classification of protected categories is as follows:

A "disabled veteran" is one of the following: a veteran of the U.S. military, ground, naval or air service who is entitled to compensation (or who but for the receipt of military retired pay would be entitled to compensation) under laws administered by the Secretary of Veterans Affairs; or a person who was discharged or released from active duty because of a service-connected disability.

A "recently separated veteran" means any veteran during the three-year period beginning on the date of such veteran's discharge or release from active duty in the U.S. military, ground, naval, or air service.

An "active duty wartime or campaign badge veteran" means a veteran who served on active duty in the U.S. military, ground, naval or air service during a war, or in a campaign or expedition for which a campaign badge has been authorized under the laws administered by the Department of Defense.

An "Armed forces service medal veteran" means a veteran who, while serving on active duty in the U.S. military, ground, naval or air service, participated in a United States military operation for which an Armed Forces service medal was awarded pursuant to Executive Order 12985.

Select...