Back to jobs

Infosec Engineering & GRC Manager

Remote, United States

Position Summary 

Slingshot Aerospace is seeking a hands-on, technical engineer focused on Information Security & GRC Manager to protect the systems, cloud infrastructure, data, and intellectual property that power our mission to make space safer, smarter, and more connected. This role blends information security engineering, platform and systems ownership, cloud and identity architecture, and governance, risk, and compliance (GRC) while partnering closely with IT and Engineering on day-to-day operations. You will serve as the senior technical escalation point for Information Security and IT, own and operate core security platforms, strengthen Zero Trust and identity controls, lead incident response, drive automation, maintain continuous audit readiness, and lead Slingshot’s security awareness training program.  

Information Security Engineering & IT Partnership 

  • Act as the senior escalation point for Information Security, GRC, and IT across identity, endpoint, network, cloud, and SaaS ecosystems.
  • Partner with IT on joiner/mover/leaver (JML) lifecycle operations, secure configurations, patch management, device compliance, and SaaS administration.
  • Lead engineering projects including security platform buildouts, integrations, migrations, and modernization efforts.
  • Maintain runbooks, SOPs, hardening guides, operational baselines, and technical documentation aligned with CMMC 2.0, NIST 800-171, ISO 27001, SOC 2, and internal governance.
  • Provide security architecture and design guidance to Engineering, Product, Data, and Operations teams.
  • Deliver regular security metrics, risk posture reporting, and compliance status updates to leadership and customers. 

Platform Ownership & Zero Trust Architecture 

  • Manage and secure Azure, Microsoft 365, Entra ID, Conditional Access, Intune, Defender, and Purview DLP/Insider Risk.
  • Operate CrowdStrike Falcon (EDR, behavioral detections, OS hardening) and Zscaler ZIA/ZPA (secure web gateway, private access, posture checks, traffic inspection).
  • Oversee VPN/firewall governance, secure remote access, and enterprise browser management platforms.
  • Govern cloud posture using Wiz or similar CSPM/CNAPP tools across AWS and Azure.
  • Use modern vulnerability and configuration management tools across cloud, endpoint, and SaaS environments.
  • Manage identity & SaaS governance including Okta/Entra SSO, RBAC, and access reviews.
  • Manage MDM platforms (Intune, Addigy ) for secure configuration and OS governance.
  • Govern GitHub Enterprise security including SSO, permissions, branch protections, scanning, and CI/CD guardrails.
  • Strengthen Zero Trust across identity, device, network, and cloud. 

Security Operations & Automation

  • Lead end-to-end incident response including detection, triage, containment, recovery, forensics, and corrective actions.
  • Maintain and refine SIEM/SOAR or equivalent log analytics for high-fidelity alerts and correlation.
  • Build automation using Python, PowerShell, or Go for evidence, monitoring, configuration validation, and remediation.
  • Govern SaaS access, vendor permissions, app approvals, and shadow IT remediation.
  • Support DNS security, certificate lifecycle management, segmentation, and secure remote connectivity.
  • Improve disaster recovery (DR) and business continuity (BCP) through structured testing and validation. 

Data Security & AI Governance 

  • Manage data classification, encryption, retention, access controls, and lifecycle protections across endpoints and cloud/SaaS.
  • Operate Microsoft Purview DLP, information protection, and insider-risk features.
  • Partner with Product, Engineering, Data, and Legal to ensure secure data handling.
  • Support AI governance including model/vendor risk assessments, data sanitization, and secure AI usage patterns.
  • Ensure secure adoption of emerging technologies (AI, automation, analytics). 

Governance, Risk & Compliance (GRC) 

You will own compliance across CMMC 2.0, NIST 800-171, ISO 27001 and other frameworks as needed : SOC 2, Cyber Essentials Plus, GDPR, and customer-required frameworks. Maintain SSPs, POA&Ms, diagrams, inventories, control mappings, risk assessments, policies, and audit evidence. Use Vanta and Paramify for continuous monitoring and evidence readiness. Maintain submissions and scoring in SPRS and eMASS. Lead vendor and third-party risk management including assessments and supply chain documentation. Partner with Sales, Growth, Legal, and Customer teams for RFIs, RFPs, questionnaires, and assurance activities. 

Security Awareness & Training 

  • Own and administer the KnowBe4 program.
  • Deliver role-based and companywide training and simulations.
  • Track participation, behavior trends, and measurable risk reduction.
  • Integrate security training into onboarding and recurring training cycles. 

Basic Qualifications 

  • CISSP certification.
  • 8+ years of experience across Information Security, IT, and GRC.
  • Hands-on experience operating and maturing CMMC 2.0 and NIST 800-171.
  • Strong experience with Azure, M365, Entra ID, Intune, Defender, Purview, AWS, CrowdStrike, Zscaler, and Wiz or similar CSPM/CNAPP.
  • Experience with GitHub Enterprise, SaaS security, enterprise browser management, and MDM (Intune/Addigy).
  • Experience with Vanta/Paramify.
  • Scripting/automation skills in Python, PowerShell, or Go.
  • Strong communication skills across technical and non-technical stakeholders.
  • U.S. citizenship and TS/SCI eligibility required. 

Preferred Qualifications 

  • CMMC Certified Professional (CCP) or ability to obtain.
  • Experience with ISO 27001, SOC 2, GDPR, and Cyber Essentials Plus.
  • Experience with secure SDLC, CI/CD, and DevSecOps.
  • Experience supporting U.K./E.U. sovereignty requirements.
  • Experience in defense, aerospace, or other regulated environments. 

Why Slingshot 

Slingshot Aerospace builds technology used for mission-critical decisions in national security, defense, and space operations. As the Infosec Engineering & GRC Manager, you will shape the systems, controls, engineering practices, and compliance frameworks that protect Slingshot’s global mission. 

Location, Clearance & Compensation

  • Remote (United States)
  • U.S. citizenship and TS/SCI eligibility required
  • Salary Range: $120,000 – $190,000 

 

US-based Candidates: we are currently only able to hire residents of the following U.S. states: AZ, CA, CO, DC, FL, GA, HI, IL, IN, KS, MD, MA, MI, MN, MO, MT, NV, NJ, NM, NY, NC, OR, RI, TN, TX, UT, VT, VA, WA, WV, and WI. We are unable to consider candidates residing in other U.S. states at this time.

Internationally-based Candidates: we are currently only able to hire residents of the following locations: United Kingdom. We are unable to consider candidates residing in other countries at this time.

Equity, Diversity & Inclusion are key to our success. We are an Equal Opportunity Employer and our employees are people with different strengths, experiences, and backgrounds, who share a passion for creating a safer, more connected world. Diversity not only includes race and gender identity, but also national origin, citizenship, sex, color, veteran status, disability, genetic information, or any other protected characteristic that is part of one’s identity. All of our employees’ points of view are key to our success, and we embrace individuality.

Create a Job Alert

Interested in building your career at Slingshot Aerospace? Get future opportunities sent straight to your email.

Apply for this job

*

indicates a required field

Phone
Resume/CV*

Accepted file types: pdf, doc, docx, txt, rtf

Cover Letter

Accepted file types: pdf, doc, docx, txt, rtf


Select...
Select...

Please explore the requirements to obtain a US Government Security Clearance through the US Intelligence Security Clearance Process informational.

Select...

Voluntary Self-Identification

For government reporting purposes, we ask candidates to respond to the below self-identification survey. Completion of the form is entirely voluntary. Whatever your decision, it will not be considered in the hiring process or thereafter. Any information that you do provide will be recorded and maintained in a confidential file.

As set forth in Slingshot Aerospace’s Equal Employment Opportunity policy, we do not discriminate on the basis of any protected group status under any applicable law.

Select...
Select...
Race & Ethnicity Definitions

If you believe you belong to any of the categories of protected veterans listed below, please indicate by making the appropriate selection. As a government contractor subject to the Vietnam Era Veterans Readjustment Assistance Act (VEVRAA), we request this information in order to measure the effectiveness of the outreach and positive recruitment efforts we undertake pursuant to VEVRAA. Classification of protected categories is as follows:

A "disabled veteran" is one of the following: a veteran of the U.S. military, ground, naval or air service who is entitled to compensation (or who but for the receipt of military retired pay would be entitled to compensation) under laws administered by the Secretary of Veterans Affairs; or a person who was discharged or released from active duty because of a service-connected disability.

A "recently separated veteran" means any veteran during the three-year period beginning on the date of such veteran's discharge or release from active duty in the U.S. military, ground, naval, or air service.

An "active duty wartime or campaign badge veteran" means a veteran who served on active duty in the U.S. military, ground, naval or air service during a war, or in a campaign or expedition for which a campaign badge has been authorized under the laws administered by the Department of Defense.

An "Armed forces service medal veteran" means a veteran who, while serving on active duty in the U.S. military, ground, naval or air service, participated in a United States military operation for which an Armed Forces service medal was awarded pursuant to Executive Order 12985.

Select...

Voluntary Self-Identification of Disability

Form CC-305
Page 1 of 1
OMB Control Number 1250-0005
Expires 04/30/2026

Why are you being asked to complete this form?

We are a federal contractor or subcontractor. The law requires us to provide equal employment opportunity to qualified people with disabilities. We have a goal of having at least 7% of our workers as people with disabilities. The law says we must measure our progress towards this goal. To do this, we must ask applicants and employees if they have a disability or have ever had one. People can become disabled, so we need to ask this question at least every five years.

Completing this form is voluntary, and we hope that you will choose to do so. Your answer is confidential. No one who makes hiring decisions will see it. Your decision to complete the form and your answer will not harm you in any way. If you want to learn more about the law or this form, visit the U.S. Department of Labor’s Office of Federal Contract Compliance Programs (OFCCP) website at www.dol.gov/ofccp.

How do you know if you have a disability?

A disability is a condition that substantially limits one or more of your “major life activities.” If you have or have ever had such a condition, you are a person with a disability. Disabilities include, but are not limited to:

  • Alcohol or other substance use disorder (not currently using drugs illegally)
  • Autoimmune disorder, for example, lupus, fibromyalgia, rheumatoid arthritis, HIV/AIDS
  • Blind or low vision
  • Cancer (past or present)
  • Cardiovascular or heart disease
  • Celiac disease
  • Cerebral palsy
  • Deaf or serious difficulty hearing
  • Diabetes
  • Disfigurement, for example, disfigurement caused by burns, wounds, accidents, or congenital disorders
  • Epilepsy or other seizure disorder
  • Gastrointestinal disorders, for example, Crohn's Disease, irritable bowel syndrome
  • Intellectual or developmental disability
  • Mental health conditions, for example, depression, bipolar disorder, anxiety disorder, schizophrenia, PTSD
  • Missing limbs or partially missing limbs
  • Mobility impairment, benefiting from the use of a wheelchair, scooter, walker, leg brace(s) and/or other supports
  • Nervous system condition, for example, migraine headaches, Parkinson’s disease, multiple sclerosis (MS)
  • Neurodivergence, for example, attention-deficit/hyperactivity disorder (ADHD), autism spectrum disorder, dyslexia, dyspraxia, other learning disabilities
  • Partial or complete paralysis (any cause)
  • Pulmonary or respiratory conditions, for example, tuberculosis, asthma, emphysema
  • Short stature (dwarfism)
  • Traumatic brain injury
Select...

PUBLIC BURDEN STATEMENT: According to the Paperwork Reduction Act of 1995 no persons are required to respond to a collection of information unless such collection displays a valid OMB control number. This survey should take about 5 minutes to complete.