Experience: 5+ years
- Architect and operationalize security across infrastructure, platform, CI/CD, and application layers, with a focus on AWS (including GovCloud) and Terraform
- Lead readiness across federal compliance frameworks (FedRAMP, CMMC, and DoD Impact Levels), translating NIST 800-53 and related controls into real engineering implementations, and owning the SSPs, POA&Ms, and technical policy documentation
- Build continuous compliance and audit-readiness workflows that make accreditation a byproduct of how we ship, not a separate workstream
- Be smart about AI and tooling. Use automated AI-driven security scanning, modern hardened-image platforms like Chainguard, and other leverage points to multiply the impact of a small security team
- Establish secure software supply chain practices: SBOMs, image signing, workload identity, and hardened deployment pipelines
- Own the technical relationship with assessors, auditors, and federal security stakeholders. You are the credible technical voice in those rooms
- Drive a secure-by-default engineering culture so residents and public servants can trust the systems we put in front of them
- 5+ years of hands-on experience building and securing cloud-native platforms in AWS and Terraform. You can architect controls and also implement them yourself
- Direct experience with federal authorization work in FedRAMP, CMMC, DoD IL, or comparable regulated environments. You don't need to have shepherded a full authorization across the finish line, but you've done enough of the real work to know what it takes
- Deep familiarity with NIST 800-53 and the ability to translate controls into pragmatic engineering work rather than checkbox compliance
- Strong working knowledge of modern supply chain security: SBOMs, image signing, workload identity, secure CI/CD
- Track record operating effectively in early-stage or fast-moving environments where you set the bar rather than inherit it
- Have supported federal SaaS, defense tech, or regulated infrastructure companies through accreditation
- Have led a company through its first federal authorization rather than maintaining an existing one
- Have hands-on experience with Chainguard, AI-powered security tooling, or similar leverage-multiplying platforms
- Have worked with platforms like Second Front or similar federal compliance accelerators
- You want to own policy and hand the implementation to someone else. This role lives in the code and the infrastructure
- You think compliance is paperwork. At Kaizen it's a load-bearing engineering discipline
- You think AI tools are a crutch rather than a force multiplier
- You need a mature security program already in place to be effective
Search Senior Security Engineer jobs near New York, NY (Remote) → Browse all live jobs
This posting was published by Kaizenlabs on their own careers system and is shown here with a direct link to apply there. Employers: for corrections or removal, contact jobs@veritahire.com.