Senior Cybersecurity Engineer

Bluestaq LLC

$100K — $155K *
Information Technology
Less than 5 years of experience
Job Overview by Ladders

Qualifications

  • 8+ years of relevant experience with a High School Diploma/GED, or 6+ years with an Associate degree, or 4+ years with a Bachelor’s degree in Cybersecurity or related field, or 2+ years with a Master’s degree.
  • Production experience managing the vulnerability lifecycle, including risk-based triage and verification processes.
  • Hands-on experience with SIEM detection engineering, particularly in constructing and tuning rules based on the MITRE ATT&CK framework.
  • Real-world incident response experience, including containment, scoping, and post-mortem documentation.
  • Proficient in applying DISA STIGs and managing compliance artifacts using platforms like eMASS or Xacta.
  • Experience with endpoint anti-malware deployment and maintenance.
  • Familiarity with cloud services such as AWS, Google Cloud, or Azure and scripting/automation languages.

Responsibilities

  • Lead the entire vulnerability management lifecycle from scanning to verified closure across software systems.
  • Develop and refine detection rules in SIEM tools tailored to specific threats and MITRE ATT&CK tactics.
  • Act as an incident responder, managing security events and communicating effectively with leadership during incidents.
  • Create post-mortem reports detailing root causes and action items after security incidents.
  • Maintain antivirus systems across fleets, ensuring up-to-date definitions and addressing flagged issues.
  • Enforce OS hardening measures using DISA STIGs and document compliance management artifacts.
  • Support secure software development in CI/CD pipelines to prevent vulnerabilities before production.

Benefits

  • Relocation assistance may be available based on individual cases.
  • Opportunities for professional development and skill enhancement within national security.
  • Access to potentially high-impact projects related to national defense and cybersecurity.
Full Job Description
Why This Role Matters
The Senior Cybersecurity Engineer at Bluestaq owns the defensive posture of software systems that underpin national security decisions - space domain awareness, satellite command and control, and the infrastructure behind them. This is not a scan-and-report seat. You close vulnerabilities, build detection logic that catches real threats, and lead incident response when things get loud. No playbook required. If you need to be told what to look for, this isn't the right level.

What You Own
  • Own the full vulnerability lifecycle - scanning with vulnerability management tools, triage by mission risk, remediation tracking, and verified closure across the fleet.
  • Build and tune detection rules in SIEM tools (Splunk, Elastic, ArcSight, Sentinel, etc.) mapped to MITRE ATT&CK tactics relevant to Bluestaq's threat model.
  • Serve as an incident responder for security events - contain, help scope, and provide clear status to the IR lead/leadership.
  • Deliver written post-mortems with root cause, timeline, and tracked action items following incident closure.
  • Maintain endpoint antivirus coverage across the fleet - configure policies, ensure definition currency, and coordinate remediation of flagged systems.
  • Apply DISA STIGs to operating systems (Linux, Windows, etc.); document deviations and manage compliance artifacts (POA&Ms) in compliance management platforms (eMASS, Xacta, or equivalent RMF tools).
  • Assist in CI/CD pipeline security - provide guidance as far left as possible in the development cycle to ensure developers are generating clean, secure code and catching vulnerabilities before they reach production.
  • Review threat intelligence and peer-organization incident disclosures; translate findings into deployed detection logic within a sprint cycle.

What You Bring

Must-Haves
  • Production experience across the vulnerability lifecycle - scanning, risk-based triage, and driving findings to verified closure.
  • Hands-on SIEM detection engineering - building and tuning rules, mapped to MITRE ATT&CK, beyond running queries.
  • Real incident response reps - containment, scoping, and writing clear post-mortems with root cause and action items.
  • Applied DISA STIG and NIST RMF - OS hardening (Linux, Windows), managing POA&Ms, and working in compliance platforms (eMASS, Xacta, or equivalent).
  • Endpoint anti-malware / on-access scanning experience - deploying and maintaining coverage across a fleet.
  • Linux and Windows systems Administration in production environments.
  • Cloud experience - AWS, Google Cloud, Azure, or equivalent.
  • Scripting and automation - Python, Bash, Go, or similar, plus config management / IaC (Ansible, Terraform, or equivalent).
  • Threat-intel-to-detection -consuming external findings and translating them into deployed detection logic.
  • Security-minded in Ci/CD and architecture - flagging design risk and steering developers toward secure practices.
  • Investigative rigor - you dig deep, ask why, and don't settle for surface-level answers.
  • Strong written and verbal communication - you can put technical findings in front of peers, leadership, and cross-functional teams.
  • Ownership mentality - you follow through, document your work, and know when to persevere vs. ask for help.

Required Education & Experience
  • High School Diploma/GED and 8+ years of relevant experience, OR
  • Associate degree in a related field and 6+ years of relevant experience, OR
  • Bachelor's degree in Cybersecurity, Computer Science, Information Technology, or related field and 4+ years of relevant experience, OR
  • Master's degree in a related field and 2+ years of relevant experience


Salary Range (CO)

$100,000-$155,000 USD

Clearance Requirement: This position may require an active TS/SCI Clearance. Current clearance holders are strongly encouraged to apply. If you don't currently hold one, Bluestaq will sponsor eligible candidates through the clearance process based on program needs.

Relocation: Relocation assistance may be available for this role and is evaluated on a case-by-case basis.

Date the Position Closes: Applications will be accepted for 60 days beyond the posting date, or until the position is filled, whichever comes first.

Similar Jobs

More Jobs at Bluestaq LLC

  • Operations Integration Lead
    $135K — $200K *
    Colorado Springs, CO 80918 (El Paso County)
    Aerospace & Defense
    In-Person
  • Systems Course Designer
    $115K — $200K *
    Colorado Springs, CO 80918 (El Paso County)
    Education, Government & Non-Profit
    In-Person

More Information Technology Jobs

Find similar Senior Cybersecurity Engineer jobs: