Back to jobs
New

Senior DevSecOps Cybersecurity Engineer

El Segundo, California, United States

For more than 50 years, ENSCO has been providing leading-edge engineering, science and advanced technology solutions to governments and private industries worldwide.

ENSCO prides itself in creating and applying advanced technologies for mission success. We provide systems engineering, integration, and advanced technology services to transform the future safety, security, and resiliency of critical missions on the ground, in the air, in space, and in the information systems that connect these domains.

Learn more about ENSCO.


Position Description

 

ENSCO, Inc is a diverse engineering and technology company that provides engineering, science and advanced technology solutions that guarantee mission success, safety, and security to governments and private industries worldwide.

ENSCO is seeking a Senior DevSecOps Cybersecurity Engineer to join our team in Colorado Springs, CO or El Segundo, CA. This role serves as a senior cybersecurity and RMF expert embedded within Agile and DevSecOps development teams responsible for delivering capabilities into government-owned production environments operating at IL5 and IL6. The emphasis is on CVE analysis and remediation, RMF execution, cybersecurity documentation, deployment approval activities, security compliance, and effective communication of cyber risk to government stakeholders while enabling rapid and secure mission capability delivery.

The Cybersecurity Engineer will work closely with software developers, cloud engineers, mission owners, systems engineers, Information System Security Managers (ISSMs), Authorizing Officials (AOs), and government cybersecurity personnel to ensure software releases meet security, compliance, and operational requirements.

The position requires deep expertise in RMF implementation, vulnerability management, CVE assessment and remediation, secure deployment methodologies, and cybersecurity activities necessary to support Authority to Operate (ATO) accredited environments.

The candidate must be capable of explaining cybersecurity risk to both technical and non-technical stakeholders, developing mitigation strategies for identified vulnerabilities, and ensuring mission capabilities can be rapidly and securely deployed into operational environments.

The MILSATCOM Systems Engineering, Integration, and Test (MSEIT) effort provides leading edge Systems Engineering & Integration (SE&I) for the Air Force's Space and Missiles System Center. We support the Air Force's acquisition of state of the art Military Satellite Communications systems, providing global secure, survivable, and protected communications for our nation's warfighters. We seek technical individuals who will thrive in a highly collaborative work environment of small teams, using the most modern tools and methodologies to tackle the challenges of integrating complex space and ground communications systems. This position is on-site in Colorado Springs, CO or El Segundo, CA. Some of the job responsibilities include but are not limited to:

Cybersecurity Engineering
• Serve as the primary cybersecurity engineering lead supporting DevSecOps software delivery efforts.
• Provide cybersecurity guidance throughout the software development lifecycle from design through production deployment.
• Evaluate system architectures, software components, and deployment pipelines for compliance with DoD and Department of the Air Force cybersecurity requirements.
• Partner with development, platform, cloud, and infrastructure teams to ensure security is integrated into all phases of delivery.

CVE Analysis & Remediation
• Assess Common Vulnerabilities and Exposures (CVEs) identified through automated scanning, security testing, and cybersecurity reviews.
• Analyze operational impact, exploitability, mission risk, and remediation options for vulnerabilities affecting mission systems.
• Develop mitigation strategies and Plans of Action and Milestones (POA&M) recommendations when immediate remediation is not feasible.
• Provide technical justification and risk-based explanations to government stakeholders regarding vulnerability disposition decisions.
• Support vulnerability review boards and release decisions for software entering production environments.

RMF & Compliance
• Support Risk Management Framework (RMF) activities across development, test, staging, and production environments.
• Assist with implementation and maintenance of NIST 800-53 security controls.
• Develop and maintain cybersecurity artifacts required to support system authorization and continuous monitoring activities.
• Prepare material supporting cybersecurity assessments, authorization reviews, and package updates.
• Assist with security control assessments and remediation activities associated with authorization findings.

Secure Deployment & Operations
• Support secure software release processes into IL5 and IL6 production environments.
• Collaborate with DevSecOps teams to establish compliant deployment methodologies and release procedures.
• Validate cybersecurity readiness prior to production deployments and major software releases.
• Review security impacts of infrastructure, software, and configuration changes.
• Ensure application, container, platform, and infrastructure security requirements are met prior to deployment.

Security Documentation & Readiness Activities
• Support development and maintenance of cybersecurity documentation including Cybersecurity Strategies (CSS), System Security Plans (SSPs), authorization package artifacts, and supporting cybersecurity documentation.
• Participate in Cyber Vulnerability Identification (CVI) events, cybersecurity assessments, security audits, and remediation activities.
• Support Continuity of Operations (COOP) planning, tabletop exercises, incident response activities, and operational readiness events.
• Assist mission teams in preparing for cybersecurity inspections, compliance reviews, and authorization activities.
• Coordinate with government cybersecurity organizations to ensure documentation remains current and audit-ready.

Stakeholder Collaboration
• Interface directly with government cybersecurity personnel, ISSMs, ISSOs, Authorizing Officials, mission owners, and engineering teams.
• Communicate cybersecurity risks, mitigation options, and deployment recommendations to leadership and operational stakeholders.
• Support Agile ceremonies, release planning events, architecture reviews, and technical working groups.
• Provide cybersecurity guidance to software teams on secure coding, vulnerability remediation, and release readiness.

Qualifications Required
• Bachelor's degree in engineering, computer science, information systems, cybersecurity or related technical field
• 7+ years of cybersecurity, information assurance, DevSecOps, system security engineering, or related defense experience
• Extensive experience implementing and supporting the Risk Management Framework (RMF)
• Strong understanding of NIST 800-53 security controls and DoD cybersecurity policies
• Demonstrated experience evaluating, explaining, mitigating, and remediating Common Vulnerabilities and Exposures (CVEs)
• Experience supporting software deployments within accredited government production environments
• Strong understanding of IL5 and IL6 cloud environments and associated cybersecurity requirements
• Experience supporting ATO and continuous monitoring activities
• Experience working directly with government cybersecurity organizations and mission stakeholders
• Ability to communicate technical cybersecurity issues to both technical and executive audiences
• Strong written communication skills supporting cybersecurity documentation, risk acceptance packages, and authorization artifacts
• ABILITY TO OBTAIN AND MAINTAIN A DOD SECRET SECURITY CLEARANCE FOR WHICH, YOU MUST BE A U.S. CITIZEN

Qualifications Desired
• Master’s degree in engineering, computer science, information systems, cybersecurity or related technical field
• Experience supporting Space Systems Command (SSC), Space Operations Command (SpOC), U.S. Space Force, or other DoD space organizations
• Experience supporting operational systems accredited under RMF within classified environments
• Familiarity with Platform One, Cloud One, Kubernetes, Iron Bank, Big Bang, and related DoD DevSecOps ecosystems
• Experience supporting Authority to Operate (ATO) and Continuous Authorization to Operate (cATO) initiatives
• Knowledge of Secure Software Development Framework (SSDF) and modern DevSecOps pipelines
• Experience supporting Cybersecurity Strategies (CSS), Cyber Vulnerability Identification (CVI) events, cybersecurity inspections, and COOP tabletop exercises
• Experience with STIG implementation, SCAP compliance, ACAS, Nessus, Fortify, SonarQube, Snyk, Prisma Cloud, Twistlock, or similar security tooling
• Security certifications such as CISSP, CASP+, Security+, CISM, CCSP, or GIAC certifications
• Experience supporting mission-critical systems deployed in classified cloud environments
• Experience supporting software modernization efforts within U.S. Space Force programs
• Familiarity with SATCOM, space operations, command and control systems, mission planning systems, or enterprise management platforms
• Experience implementing Zero Trust architectures within DoD environments
• Experience balancing mission delivery timelines with cybersecurity compliance requirements in operational production systems
• Experience supporting large-scale software factories or government-managed production environments
• Certifications such as CISSP, CompTIA Security+
• Certifications such as INCOSE CSEP or ESEP
• Active DoD Secret security clearance or higher

Required Certifications: None
U.S. Citizenship Required: Yes
Security Clearance Required: Ability to Obtain
Employment Type: Regular Full-time
Background Check Type: 7 Year Pre-Employment
Drug Screen Required: None
Position Contingent Upon Contract Award: No

 
 
 
 

 

Salary Range

$149,000 - $186,000 USD

REAL ID Requirement

This position may require the ability to access to U.S. federal facilities. In accordance with the Department of Homeland Security’s enforcement of the REAL ID Act, as of May 7, 2025, individuals must present a REAL ID-compliant form of identification or an acceptable alternative to gain entry. For a list of acceptable forms of identification, please click here.

Benefits

At ENSCO, a positive working environment and a competitive salary are only part of the reason for choosing a career here. We offer a comprehensive benefits package that creates a stimulating and supportive environment where you can thrive - visit ensco.com/careers/benefits to learn more.

Export Control and Licensing

This position may involve access to technology or technical data that is controlled under U.S. export control laws and regulations and the release of which to a non US person may require an export license from the U.S. Government.

Privacy

Your data privacy is important to ENSCO. Please click here to view our privacy policy. California residents can click here to view your California privacy rights.

EEO Statement

ENSCO, Inc. and its wholly owned U.S. subsidiaries are Equal Opportunity Employers– veterans, disability

Apply for this job

*

indicates a required field

Phone
Resume/CV*

Accepted file types: pdf, doc, docx, txt, rtf

Cover Letter

Accepted file types: pdf, doc, docx, txt, rtf


Select...
Select...
Select...
Select...
Select...
Select...
Select...
Select...

Voluntary Self-Identification of Veteran Status

For government reporting purposes, we ask candidates to respond to the below self-identification survey. Completion of the form is entirely voluntary. Whatever your decision, it will not be considered in the hiring process or thereafter. Any information that you do provide will be recorded and maintained in a confidential file.

As set forth in ENSCO, Inc.’s Equal Employment Opportunity policy, we do not discriminate on the basis of any protected group status under any applicable law.

If you believe you belong to any of the categories of protected veterans listed below, please indicate by making the appropriate selection. As a government contractor subject to the Vietnam Era Veterans Readjustment Assistance Act (VEVRAA), we request this information in order to measure the effectiveness of the outreach and positive recruitment efforts we undertake pursuant to VEVRAA. Classification of protected categories is as follows:

A "disabled veteran" is one of the following: a veteran of the U.S. military, ground, naval or air service who is entitled to compensation (or who but for the receipt of military retired pay would be entitled to compensation) under laws administered by the Secretary of Veterans Affairs; or a person who was discharged or released from active duty because of a service-connected disability.

A "recently separated veteran" means any veteran during the three-year period beginning on the date of such veteran's discharge or release from active duty in the U.S. military, ground, naval, or air service.

An "active duty wartime or campaign badge veteran" means a veteran who served on active duty in the U.S. military, ground, naval or air service during a war, or in a campaign or expedition for which a campaign badge has been authorized under the laws administered by the Department of Defense.

An "Armed forces service medal veteran" means a veteran who, while serving on active duty in the U.S. military, ground, naval or air service, participated in a United States military operation for which an Armed Forces service medal was awarded pursuant to Executive Order 12985.

Select...

 

Form CC-305
Page 1 of 1
Voluntary Self-Identification of Disability OMB Control Number 1250-0005
Expires 07/31/2029
Why are you being asked to complete this form?

We are a federal contractor or subcontractor. The law requires us to provide equal employment opportunity to qualified people with disabilities. We have a goal of having at least 7% of our workers as people with disabilities. The law says we must measure our progress towards this goal. To do this, we must ask applicants and employees if they have a disability or have ever had one. People can become disabled, so we need to ask this question at least every five years.

Completing this form is voluntary, and we hope that you will choose to do so. Your answer is confidential. No one who makes hiring decisions will see it. Your decision to complete the form and your answer will not harm you in any way. If you want to learn more about the law or this form, visit the U.S. Department of Labor's Office of Federal Contract Compliance Programs (OFCCP) website at www.dol.gov/ofccp .

How do you know if you have a disability?

A disability is a condition that substantially limits one or more of your “major life activities.” If you have or have ever had such a condition, you are a person with a disability. Disabilities include, but are not limited to:

  • Alcohol or other substance use disorder (not currently using drugs illegally)
  • Autoimmune disorder, for example, lupus, fibromyalgia, rheumatoid arthritis, HIV/AIDS
  • Blind or low vision
  • Cancer (past or present)
  • Cardiovascular or heart disease
  • Celiac disease
  • Cerebral palsy
  • Deaf or serious difficulty hearing
  • Diabetes
  • Disfigurement, for example, disfigurement caused by burns, wounds, accidents, or congenital disorders
  • Epilepsy or other seizure disorder
  • Gastrointestinal disorders, for example, Crohn's Disease, irritable bowel syndrome
  • Intellectual or developmental disability
  • Mental health conditions, for example, depression, bipolar disorder, anxiety disorder, schizophrenia, PTSD
  • Missing limbs or partially missing limbs
  • Mobility impairment, benefiting from the use of a wheelchair, scooter, walker, leg brace(s) and/or other supports
  • Nervous system condition, for example, migraine headaches, Parkinson's disease, multiple sclerosis (MS)
  • Neurodivergence, for example, attention-deficit/hyperactivity disorder (ADHD), autism spectrum disorder, dyslexia, dyspraxia, other learning disabilities
  • Partial or complete paralysis (any cause)
  • Pulmonary or respiratory conditions, for example, tuberculosis, asthma, emphysema
  • Short stature (dwarfism)
  • Traumatic brain injury
Select...

PUBLIC BURDEN STATEMENT: According to the Paperwork Reduction Act of 1995 no persons are required to respond to a collection of information unless such collection displays a valid OMB control number. This survey should take about 5 minutes to complete.

Select...