Application close date:
Applications will be accepted on an ongoing basis until the requisition is closed.
The role is part of the In-Space Systems business unit, which is focused on addressing two of the most compelling challenges in spaceflight today: space infrastructure and increasing mobility on-orbit.
Blue National Security (BNS) builds and operates space systems for the Intelligence Community and Department of Defense. The classified enclaves, mission ground systems, and labs behind those missions have to be secure, accredited, and available every time.
We're looking for aSenior Cybersecurity Engineerto do that work hands-on. You'll engineer and harden the systems our programs depend on, drive them through accreditation, and stand watch over them once they're operational.
This is a builder's role on a team that is still writing its own playbooks. You'll have real ownership over specific systems and enclaves, and direct influence over the standards the rest of the team adopts.
What You'll Do
- Engineer and harden.Implement security architecture across classified enclaves, mission ground systems, and lab environments
ndmdash; network segmentation, identity and access management, endpoint hardening, logging and audit, and encryption at rest and in transit.
- Drive accreditation.Author and maintain SSPs, security control implementation statements, risk assessments, and POA&Ms. Take systems through RMF to ATO and ATC, then keep them compliant through continuous monitoring.
- Defend the environment.Perform vulnerability scanning and remediation, patch management, log review and audit reduction, and triage of security events alongside the enterprise SOC.
- Respond to incidents.Participate in the on-call rotation. Investigate, contain, and document incidents, and drive corrective actions to closure with system owners.
- Automate the toil.Build the scripting and tooling that make compliance evidence, STIG application, and reporting repeatable rather than manual.
- Support the mission directly.Work shoulder-to-shoulder with program engineers and system administrators to deliver secure systems on mission schedule inding the compliant path toyes.
- Raise the bar.Mentor junior engineers and analysts, and contribute to team standards, baselines, and accreditation playbooks.
Minimum Qualifications
- Bachelor's degree in a technical discipline (Computer Science, Cybersecurity, Computer/Electrical Engineering, or similar), or equivalent experience
- 6+ years of hands-on cybersecurity engineering experience
- Direct experience implementing and sustaining security controls on classified systems in DoD or IC environments
- Working experience with RMF control implementation, SSP and artifact development, POA&M remediation, and continuous monitoring
- Hands-on depth in at least three of: Linux and Windows hardening (STIG/SCAP), network security and segmentation, IAM and PKI, government cloud (AWS GovCloud / Azure Government), SIEM and log analysis, vulnerability management tooling
- Scripting proficiency (Python, PowerShell, Bash) for automation of security operations and compliance tasks
- Active U.S. Government Top Secret clearance with SCI eligibility and eligibility for SAP access determination
- DoD 8140 IAT/IAM Level II certification (Security+ CE or equivalent) at hire
Preferred Qualifications
- Prior ISSO or ISSE role on SAP/SAR programs
- Working knowledge of JSIG, ICD 503/705, and NIST SP 800-53 / 800-171
- Experience standing up and accrediting new classified enclaves, labs, or facilities
- Infrastructure-as-code and configuration management (Terraform, Ansible, Puppet)
- Cross-domain solution implementation or accreditation support
- Detection engineering, threat hunting, or incident response experience
- Active TS/SCI with polygraph, SAP Eligible
Why This Role
Most senior cyber engineering jobs in this space are compliance jobs wearing an engineering title. This one isn't. The baselines, the automation, the detection coverage, and the accreditation playbooks are all still being built and the person in this seat gets to build them. You'll see your work go operational on real national security missions, fast.
Logistics
- Primarily onsite in classified spaces; limited telework by nature of the work
- Travel up to 10
ndndash;15% to other Blue Origin sites and customer facilities
- Participation in an on-call rotation; occasional extended hours to support mission-critical events and incident response
- Must be able to obtain and maintain access to classified facilities; periodic polygraph may be required
Base Pay Range for:
CO applicants is $133,500.00 - $186,898.95
WA applicants is $145,188.00 - $203,263.20
Other site ranges may differ
Benefits
- Benefits include: Medical, dental, vision, basic and supplemental life insurance, paid parental leave, short and long-term disability, 401(k) with a company match of up to 5%, and an Education Support Program.
- Stock Options for all regular employees (working at least 20 hours/week)
- Paid Time Off: Up to four (4) weeks per year based on weekly scheduled hours, and up to 14 company-paid holidays.
- Dependent on role type and job level, employees may be eligible for benefits and bonuses based on the company's intent to reward individual contributions and enable them to share in the company's results, or other factors at the company's sole discretion. Bonus amounts and eligibility are not guaranteed and subject to change and cancellation. Please check with your recruiter for more details.