All jobs

Raft

Senior Engineer

United States · Remote

About this role

This is a U.S. based position. All of the programs we support require U.S. citizenship to be eligible for employment. All work must be conducted within the continental U.S. Who we are: Raft ( is a customer-obsessed non-traditional defense tech company dedicated to empowering U.S. military and government agencies with cutting-edge AI/ML and data solutions. We are a leader in autonomous data fusion and Agentic AI, with a purposeful focus on Distributed Data Systems, Platforms at Scale, and Complex Application Development. With headquarters in McLean, VA, our range of clients includes innovative federal and public agencies leveraging design thinking, cutting-edge tech stack, and cloud-native ecosystem. We build digital solutions that impact the lives of millions of Americans. About the role: The SeniorCybersecurity Engineer supports a DoW program by ensuring Information Assurance (IA), cybersecurity, and security engineering requirements are incorporated directly into the platform’s DevSecOps pipelines, tooling, configurations, and software delivery processes. This role works closely with the Pipeline Architect, Software Engineering SMEs, infrastructure/platform engineers, and government stakeholders to ensure required DoD cybersecurity thresholds are met without creating unnecessary friction in the software delivery lifecycle. The Senior Cybersecurity Engineer helps translate security and compliance requirements into technical controls that can be automated, validated, and continuously enforced within the pipeline. Key Responsibilities Work with the Pipeline Architect and Software Engineering SMEs to ensure DoD IA and cybersecurity thresholds are met and built directly into pipeline tooling, configurations, and workflows. Translate DoD cybersecurity, RMF, and DevSecOps requirements into actionable technical requirements for engineering teams. Design, implement, configure, and maintain automated security controls within CI/CD pipelines. Integrate and maintain security tooling for SAST, DAST, software composition analysis (SCA), container scanning, secrets detection, dependency scanning, and vulnerability management. Establish and enforce security gates and thresholds within GitLab CI/CD pipelines to prevent noncompliant or vulnerable software artifacts from progressing through the delivery lifecycle. Support secure software supply chain practices, including artifact integrity, SBOM generation, vulnerability scanning, signing, provenance, and software attestations. Work with engineering teams to integrate tools such as Fortify, SonarQube, Trivy, Twistlock/Prisma Cloud, NeuVector, Cosign/Sigstore, and similar security capabilities into automated workflows. Review Kubernetes, container, GitLab Runner, infrastructure-as-code, and pipeline configurations for security vulnerabilities and configuration weaknesses. Support vulnerability triage and remediation by working directly with software and platform engineering teams to determine severity, operational impact, remediation approaches, and acceptable mitigation strategies. Develop and maintain security-as-code and policy-as-code approaches that allow cybersecurity requirements to be consistently enforced across environments. Support compliance with the DoD DevSecOps Reference Design, NIST Risk Management Framework (RMF), NIST 800-53 controls, and applicable DoD cybersecurity requirements. Support the collection and automation of security evidence required for authorization and continuous monitoring activities. Partner with platform and application teams to ensure cybersecurity requirements support the UP continuous Authority to Operate (cATO) approach and Continuous Delivery/Continuous Deployment processes. Identify cybersecurity risks associated with changes to pipeline architecture, platform baselines, infrastructure, and application delivery processes and recommend technical mitigations. Develop security documentation, technical implementation guidance, configuration standards, and

Skills and categories

Cybersecurity-EngineeringDevSecOpsCloud-SecurityApplication-SecurityPlatform-EngineeringSenior-EngineerSenior-EngineeringSenior-Lead-EngineerSenior-Staff-EngineerSenior-Principal-EngineerSenior-Engineering-JobsSenior-Staff-EngineeringSenior-Technical-EngineerSenior-Lead-EngineeringDeveloperDeveloper

Listing provided by Himalayas. Verify availability on the source board before applying — Kartavyam aggregates public listings as they appear and does not manage this application.

Similar roles

Browse all jobs