Zaden Tech

Cybersecurity Engineer (Assessment and Authorization / Compliance)

Zaden Tech Quinte West, Ontario, Canada · $120K–$155K/yr

Software Development · 11-50 employees

23 h ago
security Mid (2-5 yrs) Full-time Canada
Log in to apply, save this posting, or score it against your profile with AI.

About the role

The Cybersecurity Engineer will integrate security evidence collection into CI/CD pipelines to support continuous ATO for containerized applications. They will manage security artifacts, coordinate with government stakeholders, and maintain compliance documentation for DoD systems.

What they look for

Cybersecurity RMF A&A DevSecOps CI/CD Container security SBOM SonarQube Kubernetes Scripting eMASS Security+ CE DoD compliance Static analysis Dynamic analysis

Requirements

Candidates must possess an active TS/SCI clearance and at least 4 years of experience in cybersecurity for federal systems with RMF/A&A expertise. A DoD 8140/8570 baseline certification, such as Security+ CE, is required along with proficiency in container security and pipeline automation.

Benefits

Paid holidays Flexible paid time off 401k Health insurance

Full description

Zaden Technologies is hiring a Cybersecurity Engineer to bring a DevSecOps mindset to ATO: instead of assembling a security package by hand at the end of a release, you'll wire evidence collection directly into the delivery pipeline so authorization keeps pace with continuous deployment. This is package cyber, not SOC work — you'll own the artifacts that let containerized applications move onto a government system, treating SBOMs, scan results, and compliance evidence as pipeline outputs rather than one-off paperwork. This is a full-time, on-site position in Aurora, CO, with some travel, and an anticipated start of April 2027.

Role Responsibilities:

  • Prepare and maintain security packages for containerized deployments, including SSP, ATO artifacts, and supporting RMF documentation
  • Build automated evidence collection into the CI/CD pipeline so SBOMs, scan outputs, and compliance artifacts generate continuously rather than at release time
  • Own static/dynamic analysis tooling (SonarQube or similar) and container image scanning as part of the delivery pipeline
  • Coordinate package submission and remediation with government security stakeholders, keeping pace with an evidence-as-code approach to ATO
  • Partner with the DevSecOps team to treat authorization gates like any other pipeline gate: automated, repeatable, and continuously validated
  • Flex into DevSecOps tasks as workload allows

Required Qualifications:

  • Active TS/SCI clearance, or current TS/SCI eligibility, and U.S. citizenship
  • 4+ years in cybersecurity for DoD or federal systems with direct RMF/A&A package experience (SSP, POA&M, ATO artifacts)
  • DoD 8140/8570 baseline certification (Security+ CE or equivalent minimum)
  • Working knowledge of container security: image scanning, SBOMs, and static/dynamic analysis tooling
  • Comfort working inside a CI/CD pipeline and automating evidence generation rather than assembling it manually

Preferred Qualifications:

  • Hands-on DevSecOps skills (pipelines, Kubernetes, scripting) to serve as a cross-certified cyber/DevOps resource
  • Experience with continuous-ATO or evidence-as-code approaches on DoD software factory programs
  • eMASS or equivalent authorization-tracking system experience
  • Experience supporting space or missile warning ground systems

What we offer:

  • Robust startup environment with a variety of projects to work on
  • Growth paths and endless opportunities to learn and develop
  • Paid holidays and flexible paid time off
  • Employer contributions toward 401k
  • 50% coverage of health insurance for employees and their dependents

Similar roles