Position Details
Senior Cybersecurity Engineer
- Location
- Remote
- Work Setting
- Remote
- Employment Type
- Full Time
Position Overview
DSD Laboratories is hiring its first dedicated Senior Cybersecurity Engineer to own the security engineering, assurance, and continuity of an environment that supports Department of Defense work — a Microsoft Government-cloud estate, a set of internal business platforms, and a product suite heading toward a formal authorization. Much of what you will own does not exist yet; you will be defining it. This role was approved and funded following an independent 2026 review of DSD's technology function, with managed detection and response, retained incident response, and external assessment funded alongside it. Your mandate is to make DSD's security posture demonstrable — to customers, assessors, and auditors — and to build the operational depth that lets this environment run and recover without depending on any one person.
Responsibilities
• Serve as the named alternate administrator for the Microsoft 365 and Azure Government tenant, HAL, GitLab, and the corporate wiki
• Hold escrowed break-glass credentials under dual control, and demonstrate recovery competence through restore tests you personally perform
• Own the control register, System Security Plan, and plan of action and milestones
• Support the NIST SP 800-53 Rev 5 policy programme and the authorization package for the DSD Forge product suite
• Own daily triage and disposition of alerts from the managed detection service and internal automation
• Own vulnerability management end to end, and manage the managed detection vendor relationship
• Serve on the incident command roster as a deputy commander, and hold a DoD-approved medium assurance certificate for regulatory incident reporting
• Own evidence preservation configuration, retention verification, and chain of custody
• Administer privileged access management, conditional access policy, and secrets management across the estate
• Embed secrets scanning, dependency analysis, and software bill of materials generation into product pipelines
• Respond to customer and prime contractor security questionnaires and supply chain due diligence
• Hold escrowed break-glass credentials under dual control, and demonstrate recovery competence through restore tests you personally perform
• Own the control register, System Security Plan, and plan of action and milestones
• Support the NIST SP 800-53 Rev 5 policy programme and the authorization package for the DSD Forge product suite
• Own daily triage and disposition of alerts from the managed detection service and internal automation
• Own vulnerability management end to end, and manage the managed detection vendor relationship
• Serve on the incident command roster as a deputy commander, and hold a DoD-approved medium assurance certificate for regulatory incident reporting
• Own evidence preservation configuration, retention verification, and chain of custody
• Administer privileged access management, conditional access policy, and secrets management across the estate
• Embed secrets scanning, dependency analysis, and software bill of materials generation into product pipelines
• Respond to customer and prime contractor security questionnaires and supply chain due diligence
Qualifications
• Seven or more years in cybersecurity engineering or a closely related discipline, including at least three in a regulated or government-adjacent environment
• Hands-on administration and security engineering in Microsoft 365 and Azure — Entra ID, conditional access, Defender, and log analytics
• Demonstrated experience implementing or evidencing a formal control framework such as NIST SP 800-171 or 800-53
• Direct experience responding to security incidents in a production environment, including the judgement calls made under time pressure
• Active U.S.
• Government Secret clearance preferred; at minimum, must be eligible to obtain and maintain a Secret clearance
• Hands-on administration and security engineering in Microsoft 365 and Azure — Entra ID, conditional access, Defender, and log analytics
• Demonstrated experience implementing or evidencing a formal control framework such as NIST SP 800-171 or 800-53
• Direct experience responding to security incidents in a production environment, including the judgement calls made under time pressure
• Active U.S.
• Government Secret clearance preferred; at minimum, must be eligible to obtain and maintain a Secret clearance