Senior Cybersecurity Engineer

Colorado Springs

Why This Role Matters
The Senior Cybersecurity Engineer at Bluestaq owns the defensive posture of software systems that underpin national security decisions — space domain awareness, satellite command and control, and the infrastructure behind them. This is not a scan-and-report seat. You close vulnerabilities, build detection logic that catches real threats, and lead incident response when things get loud. No playbook required. If you need to be told what to look for, this isn't the right level. 

What You Own 

  • Own the full vulnerability lifecycle — scanning with vulnerability management tools, triage by mission risk, remediation tracking, and verified closure across the fleet. 
  • Build and tune detection rules in SIEM tools (Splunk, Elastic, ArcSight, Sentinel, etc.) mapped to MITRE ATT&CK tactics relevant to Bluestaq's threat model. 
  • Serve as an incident responder for security events — contain, help scope, and provide clear status to the IR lead/leadership. 
  • Deliver written post-mortems with root cause, timeline, and tracked action items following incident closure. 
  • Maintain endpoint antivirus coverage across the fleet — configure policies, ensure definition currency, and coordinate remediation of flagged systems. 
  • Apply DISA STIGs to operating systems (Linux, Windows, etc.); document deviations and manage compliance artifacts (POA&Ms) in compliance management platforms (eMASS, Xacta, or equivalent RMF tools). 
  • Assist in CI/CD pipeline security — provide guidance as far left as possible in the development cycle to ensure developers are generating clean, secure code and catching vulnerabilities before they reach production. 
  • Review threat intelligence and peer-organization incident disclosures; translate findings into deployed detection logic within a sprint cycle. 

What You Bring

Must-Haves 

  • Production experience across the vulnerability lifecycle — scanning, risk-based triage, and driving findings to verified closure. 
  • Hands-on SIEM detection engineering — building and tuning rules, mapped to MITRE ATT&CK, beyond running queries. 
  • Real incident response reps — containment, scoping, and writing clear post-mortems with root cause and action items. 
  • Applied DISA STIG and NIST RMF — OS hardening (Linux, Windows), managing POA&Ms, and working in compliance platforms (eMASS, Xacta, or equivalent). 
  • Endpoint anti-malware / on-access scanning experience — deploying and maintaining coverage across a fleet. 
  • Linux and Windows systems Administration in production environments. 
  • Cloud experience — AWS, Google Cloud, Azure, or equivalent. 
  • Scripting and automation – Python, Bash, Go, or similar, plus config management / IaC (Ansible, Terraform, or equivalent). 
  • Threat-intel-to-detection –consuming external findings and translating them into deployed detection logic. 
  • Security-minded in Ci/CD and architecture - flagging design risk and steering developers toward secure practices. 
  • Investigative rigor – you dig deep, ask why, and don't settle for surface-level answers. 
  • Strong written and verbal communication – you can put technical findings in front of peers, leadership, and cross-functional teams. 
  • Ownership mentality – you follow through, document your work, and know when to persevere vs. ask for help. 

Required Education & Experience 

  • High School Diploma/GED and 8+ years of relevant experience, OR 
  • Associate degree in a related field and 6+ years of relevant experience, OR 
  • Bachelor's degree in Cybersecurity, Computer Science, Information Technology, or related field and 4+ years of relevant experience, OR 
  • Master's degree in a related field and 2+ years of relevant experience 

Salary Range (CO)

$100,000 - $155,000 USD

Clearance Requirement: This position may require an active TS/SCI Clearance. Current clearance holders are strongly encouraged to apply. If you don't currently hold one, Bluestaq will sponsor eligible candidates through the clearance process based on program needs.


About Bluestaq
At Bluestaq, we build secure data platforms that matter for space missions, national defense, healthcare systems, and commercial innovation. Founded in 2018, we've become a leader in enterprise software and secure data management by staying focused on what counts: modern architecture, operational excellence, and mission impact.

We're engineers, problem-solvers, and builders who take the mission seriously, but not ourselves. We automate the repeatable, question the status quo, and design systems that are as reliable as they are scalable. Whether we're supporting space, defense systems, or healthcare advancements, we build with the same principles: cloud-native solutions, security by design, and relentless simplicity.


Relocation: Relocation assistance may be available for this role and is evaluated on a case-by-case basis.

Date the Position Closes: Applications will be accepted for 60 days beyond the posting date, or until the position is filled, whichever comes first.

Bluestaq is an Equal Opportunity Employer. We prohibit unlawful discrimination against applicants or employees on the basis age 40 and over, color, disability, gender identity, genetic information, military or veteran status, national origin, race, religion, sex, sexual orientation, or any other status protected by state or local law.

Bluestaq will make reasonable accommodations for qualified individuals with known disabilities and employees whose work requirements interfere with a religious belief unless doing so would result in an undue hardship to Bluestaq or a direct threat. Employees needing such accommodation are instructed to contact Human Resources immediately at contact.us@bluestaq.com.

Create a Job Alert

Interested in building your career at Bluestaq US External? Get future opportunities sent straight to your email.

Apply for this job

*

indicates a required field

Phone
Resume/CV*

Accepted file types: pdf, doc, docx, txt, rtf

Cover Letter

Accepted file types: pdf, doc, docx, txt, rtf


Education

Select...
Select...
Select...

Select...
Select...
Select...
Select...

Voluntary Self-Identification

For government reporting purposes, we ask candidates to respond to the below self-identification survey. Completion of the form is entirely voluntary. Whatever your decision, it will not be considered in the hiring process or thereafter. Any information that you do provide will be recorded and maintained in a confidential file.

As set forth in Bluestaq US External’s Equal Employment Opportunity policy, we do not discriminate on the basis of any protected group status under any applicable law.

Select...
Select...
Race & Ethnicity Definitions

If you believe you belong to any of the categories of protected veterans listed below, please indicate by making the appropriate selection. As a government contractor subject to the Vietnam Era Veterans Readjustment Assistance Act (VEVRAA), we request this information in order to measure the effectiveness of the outreach and positive recruitment efforts we undertake pursuant to VEVRAA. Classification of protected categories is as follows:

A "disabled veteran" is one of the following: a veteran of the U.S. military, ground, naval or air service who is entitled to compensation (or who but for the receipt of military retired pay would be entitled to compensation) under laws administered by the Secretary of Veterans Affairs; or a person who was discharged or released from active duty because of a service-connected disability.

A "recently separated veteran" means any veteran during the three-year period beginning on the date of such veteran's discharge or release from active duty in the U.S. military, ground, naval, or air service.

An "active duty wartime or campaign badge veteran" means a veteran who served on active duty in the U.S. military, ground, naval or air service during a war, or in a campaign or expedition for which a campaign badge has been authorized under the laws administered by the Department of Defense.

An "Armed forces service medal veteran" means a veteran who, while serving on active duty in the U.S. military, ground, naval or air service, participated in a United States military operation for which an Armed Forces service medal was awarded pursuant to Executive Order 12985.

Select...