Description:
Aspis strives to make enterprise cybersecurity solutions and professional services accessible to organizations of all sizes, from small and medium-sized businesses to large enterprises, nonprofits, and municipal, state, and federal government agencies. Aspis is a HUBZone-certified small business. Our values are Integrity, Community, and Diversity. https://aspis.consulting
Aspis is expanding its cybersecurity team and seeking a hands-on Cybersecurity Engineer to build the security capability for our client behind a large Federal civilian cloud platform operations and maintenance program. You will perform cybersecurity engineering and security operations support across the program's cloud, hybrid, and on-premises environments; conduct vulnerability assessment and remediation tracking, security monitoring, configuration review, incident support, and technical hardening; and work with engineering and compliance teams to incorporate security requirements into designs and operations, maintain evidence and documentation, analyze security findings, and reduce operational risk through practical corrective actions.
The environment is hybrid: a FedRAMP-authorized AWS cloud footprint alongside Azure, on-premises data centers, legacy and mainframe-connected applications, and enterprise geospatial platforms supporting hundreds of business applications. You will write and maintain the automation, pipeline security stages, hardened baselines, detection content, and integrations that make security continuous instead of manual. You will work alongside cloud engineers, DevSecOps engineers, and our compliance and authorization staff, with real ownership on a small, senior team.
This is a full-time W-2 position supporting a federal government client as part of a contract delivery team. This is not designed to be a full-time remote position. Relocation assistance may be considered. The Kansas City, Missouri metropolitan area is strongly preferred and candidates who reside in and can work from the Kansas City metro will receive preference; however, residency there is not required, and we will consider candidates elsewhere in the United States who are able to travel to the client sites as needed. Due to the support a federal client, working abroad (outside of the United States) is explicitly prohibited. Travel to Kansas City for remote workers will not be reimbursed. Consistent with Aspis' return to office and telework policy, employees are required to report to an Aspis office on a regular basis but may be allowed to work from home and are required to visit client job sites as applicable. The company reserves the right to change its employment policies at any time without notice.
To be considered for this position, your resume must clearly document knowledge, skills, experience, and abilities similar to the responsibilities, qualifications, and requirements below.
A Cybersecurity Engineer may perform any combination of the functions below based on assignment and experience level. This position is oriented toward building and maintaining security capability rather than operating it.
Responsibilities
-
Design, code, test, and maintain security automation - scripts, modules, services, and integrations - that replace manual security work.
-
Build and maintain infrastructure-as-code modules that deliver hardened, compliant cloud resources by default.
-
Build and maintain security stages in CI/CD pipelines, including static analysis, dependency and container image scanning, secrets detection, and policy-as-code gates.
-
Engineer hardened operating system, container, and cloud service baselines, plus the automation that applies and enforces them.
-
Build identity, access, encryption, key management, and logging capability into the platform, and engineer secure interfaces between on-premises systems and cloud services.
-
Build and maintain detection content, correlation rules, and alerting as code, with version control and testing.
-
Automate vulnerability scanning coverage, finding enrichment, deduplication, ticket creation, and aging escalation so remediation service levels are met without manual tracking.
-
Build response automation and playbooks-as-code for containment, isolation, evidence capture, and recovery, and participate in the on-call rotation.
-
Convert incident findings and root cause analysis into durable engineering fixes rather than repeat manual response.
-
Maintain design documentation, run books, reference architectures, and code documentation, and provide control implementation evidence to compliance and authorization staff.
-
Mentor junior engineers, perform code review, and support knowledge transfer to client staff.
-
Other duties as assigned.
Qualifications
-
Demonstrated experience in developing, testing, and maintaining containerized applications.
-
Demonstrated ability to build and maintain production code or automation in at least one language such as Python, Bash, PowerShell, or Go, with source control, testing, and peer review discipline.
-
Hands-on cloud security engineering experience in AWS, with working knowledge of Azure, appropriate to experience level.
-
Experience building CI/CD pipeline security stages using GitLab or comparable tooling, and infrastructure-as-code proficiency such as Terraform or CloudFormation.
-
Working knowledge of hardening standards and of security frameworks relevant to Federal work (NIST SP 800-53, FISMA, FedRAMP), appropriate to experience level.
-
Experience building or tuning vulnerability scanning coverage, detection content, or log pipelines.
-
Strong analytical skills and attention to detail.
-
Clear, professional written and verbal communication, including design and operational documentation.
-
Ability to manage multiple assignments and deadlines with limited day-to-day oversight.
-
Discretion in handling sensitive client, system, and company information.
-
Ability to obtain and maintain a Federal Public Trust background investigation; must be authorized to work in the United States without sponsorship.
-
Availability during client core hours with on-call and after-hours support as needed for deployments and incidents.
Requirements:
Skills:
-
Developing, testing, and maintaining containerized applications.
-
Build and maintain production code or automation
-
Security automation and tooling development, secure CI/CD pipeline engineering, infrastructure-as-code, platform hardening, detection engineering, and cloud security engineering.
-
Demonstrated coding or automation ability with source control and peer review discipline.
-
Microsoft Office Suite (e.g., Word, PowerPoint, Excel, etc.)
-
Strong verbal and written communication skills.
Background Check:
-
Successful completion of reference check.
-
Successful completion of a commercial background check.
-
Successful completion of an OF-306 (as a contractor).
-
Successful completion of a Federal Public Trust background check required.
Degree Required: Associate's degree or higher preferred; equivalent experience and/or certifications considered in lieu of a degree.
Experience Required: 5-10 years of relevant cybersecurity engineering experience.
Industry Certifications: Advanced cloud and engineering certifications (e.g., AWS Certified Security - Specialty, CCSP, GIAC GCSA, CISSP).
We are an equal opportunity employer and all qualified applicants will receive consideration for employment without regard to race, color, religion, sex, national origin, sexual orientation, gender identity, disability, protected veteran status, or any other characteristic protected by law. We will consider for employment qualified applicants with criminal histories consistent with applicable law.