Staff/Principal Security Engineer (U. S. Air Force)
About Skylight
Skylight is a digital consultancy using design and technology to help government agencies deliver better public services.
We’re at the forefront of a civic movement to reinvent how all levels of government serve families, patients, and many others in today’s digital world.
If you want to play a part in driving this critical movement forward, we’d love for you to join our growing team of public interest technologists.
The work we do matters.
About the job
At Skylight, security engineers stay up to date with the cutting edge of security and help teams implement new processes, tools, and remediations. They’re familiar with modern software development and work in cross-functional teams to inform and guide security best practices at all stages of the software development life cycle.
Skylight has partnered with the U.S. Air Force across multiple legacy modernization efforts. The work spans modernization of legacy systems, new capability development in multi-vendor environments, iteration on established platforms, all inside an agile transformation and broader organizational change.
You’ll be the security voice across several modernization efforts: assessing legacy applications, guiding teams toward compliant architectures on Air Force platforms, and making security an enabler of faster delivery rather than a gate at the end.
What to know going in
Your first 30 days are about working with the Skylight team and government personnel, learning the client’s domain and organization, and enabling your government partners. Access to users varies from team to team, so you’ll need to get creative about how you reach them. The client is early- to mid-transformation, so expect organizational and operational change along the way.
This role is contingent on Skylight being awarded the underlying contract. If we’re not awarded the contract, we’ll let you know promptly and discuss whether there are other opportunities that fit.
What you’ll do
- Protect sensitive data by applying security and privacy best practices
- Conduct security audits and risk analyses of legacy applications and their modernized replacements
- Execute Risk Management Framework (RMF), Authorization to Operate (ATO), and continuous ATO (cATO) processes, and carry the security documentation and narrative that supports authorization
- Write security controls and documentation as the build proceeds, so security is a build-time deliverable in the pipeline rather than an audit at the end
- Conduct ongoing research to keep up with industry practices and new attack vectors
- Select and use the right tools, frameworks, languages, and technologies for the job, with a preference for open-source solutions
- Pair with and coach government engineers so secure practices become part of how the teams work
What we’re looking for
Basic qualifications
- Experience taking systems through RMF and ATO, ideally in a DoD context, including authoring the control implementation and body of evidence
- Able to detect risks by continually reviewing all aspects of the application for vulnerabilities and enumerating them
- Able to mitigate and prevent risks by proactively working with teams to build secure and compliant systems
- Familiarity with common sources of vulnerability information
- Familiarity with regulatory requirements regarding security and compliance
- Experience working in agile software development
- Interest in mentoring, coaching, and pairing with government partners so they can carry the work forward
- Experience working on cross-functional teams (product, design, engineering, ops) in iterative delivery
- A mindset and work approach that aligns with our core values
Nice-to-haves
- Can write clean, working, and reusable code in at least one programming language
- Experience with application development, particularly web development and testing frameworks
- Experience with cloud infrastructure and infrastructure as code
- Military or government experience
- Experience delivering technology in government, regulated industries, or other public-benefit settings
- A track record of staying aligned and accountable on remote teams
Don’t meet every qualification but think you can do the job? We’d still love to hear from you. If you’re excited about the role, apply. We consider candidates with a range of backgrounds and experiences.
Other requirements
- Some of our available roles are on federal contracts that require a degree or additional years of experience as a substitute.
- All work must be conducted within the U.S., excluding U.S. territories.
- This contract requires U.S. citizenship to be eligible for employment.
- You must be able to obtain and maintain a Common Access Card (CAC), which requires a favorable background check.
- You must complete a company background check successfully.
Logistics
Position type
This is a full-time, exempt position.
Location
This is a fully remote position.
Travel
Expect occasional travel to Air Force bases across the U.S., quarterly at most.
Expected start date
November 2026
Care package
Salary
We want to give you the most competitive salary possible. After all, you deserve it! To that end, we use the results of our interview process to determine what salary is most appropriate given your current level of seniority. For a Security Engineer at Skylight, the current salary ranges are as follows:
- Associate Security Engineer: $90,000–$125,000
- Security Engineer I: $120,000–$140,000
- Security Engineer II: $135,000–$160,000
- Senior Security Engineer: $150,000–$185,000
- Staff Security Engineer: $170,000–$203,000
- Principal Security Engineer: $180,000–$230,000
Benefits
Your well-being is important to us, so we focus on supporting you in a variety of ways:
- Medical insurance, dental insurance, vision insurance
- Short-term and long-term disability insurance
- Life and AD&D insurance
- Dependent care FSA, healthcare FSA, health savings account
- Dollar-for-dollar 401(k) match up to 10% of your salary with no vesting period
- Flexible paid-time-off policy (generally around 25 days per year), plus 11 paid federal holidays
- Up to 12 weeks paid-time-off for all eligible new birth, adoption, or foster parents
- Performance rewards, including annual salary increase, annual performance bonus, spot bonuses, and stock options
- Business development / sales bonuses
- Referral bonuses
- Annual $2000 allowance for professional development
- Annual $750 allowance for tech-related purchases
- Annual swag budget of $100 to display your Skylight pride with some merchandise (hoodies, hats, and more)
- Flexible, remote-friendly work environment
- An environment that empowers you to unleash your superpowers for public good
Interview tips
Our process includes a preliminary screen, a skills interview, a behavioral interview, and a reverse interview where you meet your potential team — usually four conversations across two to three weeks. Here are some tips to help you prepare for a successful interview:
- Visit our join page to learn more about how our interview process works.
- Check out our Career Pathways framework to learn more about the different roles within Skylight and the skills needed to do them.
- Browse our case studies to learn more about our work.
If you’d like to request reasonable accommodations during the application or interviewing process, please contact our recruiting team at recruiting@skylight.digital.
We participate in E-Verify and upon hire, will provide the federal government with your Form I-9 information to confirm that you’re authorized to work in the U.S.
We are an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, national origin, sex, religion, age, disability, veteran status, or any other category protected by applicable law.
Create a Job Alert
Interested in building your career at Skylight? Get future opportunities sent straight to your email.
Apply for this job
*
indicates a required field