Cybersecurity Engineer - DevOps

๐Ÿข Sphera ยท all 21 jobs
๐Ÿ“ United States
๐Ÿ’ฐ USD 112,000 - 178,000 / annual
๐Ÿ“… Posted Sep 19, 2026 ยท via Himalayas
๐Ÿท Cybersecurity Engineering, Government Cybersecurity, Devsecops, Compliance And Risk Management, Security Engineering, DevOps Security Engineer +5 more
Apply on original site โ†—

Sphera is a leading global provider of enterprise software and services that enables companies to manage and optimize their environmental, health, safety and sustainability. Our mission is to create a safer, more sustainable and productive world.

Sphera is a portfolio company of Blackstone, a U.S.-based alternative asset investment company that focuses on private equity, technology and innovation, and more. Blackstone businesses succeed through strong partnerships, a personalized approach and a commitment to exceptional performance with uncompromising integrity. Sphera and Blackstone are leaders in the Environmental, Social and Governance (ESG) space.

We are guided by our core values of Customer Centricity, Accountability, Bias to Action, Innovation, and Collaboration. These values help us recruit the right talent to join our rapidly expanding team around the globe. It is important to us that each and every Spherion is not only eager to challenge themselves and knows how to get work done but is an awesome addition to our company culture.
POSITION SUMMARY

This role will be pivotal in advancing the company's mission of delivering secure, reliable, and innovative software solutions for U.S. government and DoD clients. The Cybersecurity Engineer serves as the resident security subject-matter expert embedded within the DevOps squad, owning the security compliance posture for software deployed in federal, DoD, and other highly regulated secure environments. The ideal candidate brings direct, hands-on experience operating within secure federal technology environments and a strong working knowledge of the security frameworks, tooling, and authorization processes that govern government-hosted systems. This individual will drive RMF/ATO lifecycle management, STIG implementation, vulnerability remediation, and DevSecOps integration across Sphera 's product lines, ensuring that all systems maintain continuous compliance and readiness for deployment in secure government operating environments.
KEY RESPONSIBILITIES

- Lead cybersecurity for software deployed in secure federal and DoD environments, ensuring compliance with applicable government security policies, access requirements, and accreditation expectations.

- Execute RMF activities, including system categorization, security control selection, implementation, assessment, and ATO documentation for federal or DoD-hosted systems.

- Implement, configure, and validate STIGs across layers using DISA-approved or equivalent government security tooling.

- Mitigate OWASP Top 10 and application-layer vulnerabilities across services.

- Monitor security controls, scan vulnerabilities, and audit systems, producing reports and coordinating remediation with development and DevOps.

- Manage POA&Ms, coordinating with government security stakeholders, ISSMs, and internal teams to track and resolve open findings.

- Support FedRAMP and FISMA compliance, aligning controls with NIST SP 800-53 Rev. 5.

- Integrate security tooling and automated checks into CI/CD pipelines, advancing DevSecOps maturity.

- Collaborate with engineers and the Principal Solutions Architect to conduct threat modeling, security design reviews, and application-level security assessments.

- Maintain System Security Plans (SSPs), security architectures, and supporting ATO documentation packages in alignment with federal and DoD requirements.

- Lead incident response activities for security events affecting systems deployed in secure government environments, coordinating with customer cybersecurity personnel and internal stakeholders.

- Monitor SIEM alerts, analyze logs, and investigate anomalous activity.

- Evaluate the security posture of third-party integrations, vendor tools, and emerging technologies for adoption in secure federal or DoD environments.

- Embed security requirements into sprint planning, feature development, and release processes with the TPM, engineering squads, and product owners.

- Stay informe

Flights + hotels

This role requires you to be in the United States. If that means relocating or flying in, it is worth checking fares before you commit to a start date.

Compare flights and hotels โ†’

โ† All remote jobs

Comparing DevOps Engineer pay and openings โ€” the live median is $119k?All remote DevOps Engineer jobs โ†’DevOps Engineer salary data โ†’
Want more like this? Browse every live remote developer role.All remote developer jobs โ†’
Get new developer jobs by email
Daily email, only when there's something new. One click to stop.

Get remote developer jobs like this by email

10 hand-picked jobs, one email a day. No spam, unsubscribe anytime.

Similar for you