Cybersecurity Engineer
Cybersecurity Engineer
- Job Type: Full-time, W-2
- Experience: 5-10 years
- Location: Kansas City metro preferred; U.S.-based candidates considered
About Bubbleware Technology
Bubbleware Technology is a small business providing software engineering, cloud, geospatial, data, and IT modernization services to federal government customers. We work on mission-critical applications and infrastructure and emphasize practical engineering, strong technical ownership, and close collaboration with our government and industry partners.
We are expanding our cybersecurity capabilities and are looking for an experienced Cybersecurity Engineer to support a large federal civilian IT environment.
The Role
The Cybersecurity Engineer will help design, automate, and maintain security capabilities across cloud, hybrid, and on-premises systems.
This is a hands-on engineering role. You will work with cloud engineers, DevSecOps engineers, application teams, and security/compliance personnel to improve platform security, automate repetitive security processes, identify vulnerabilities, and implement lasting technical solutions.
The environment includes FedRAMP-authorized AWS infrastructure, Azure, on-premises systems, legacy applications, containerized workloads, CI/CD pipelines, and enterprise geospatial platforms supporting a large portfolio of federal applications.
This position is focused more on **building and improving security capabilities** than simply monitoring existing tools.
Responsibilities
- Develop and maintain security automation using Python, PowerShell, Bash, Go, or similar technologies.
- Build security controls and hardened configurations into cloud infrastructure and infrastructure-as-code.
- Implement and maintain security checks within CI/CD pipelines, including:
- Static application security testing
- Dependency scanning
- Container image scanning
- Secrets detection
- Policy-as-code controls
- Develop hardened operating system, container, and cloud service baselines.
- Help design and implement secure identity, access management, encryption, key management, and centralized logging.
- Engineer secure connectivity between cloud and on-premises environments.
- Develop and maintain security monitoring, detection rules, alerting, and log integrations.
- Automate vulnerability scanning, remediation tracking, ticketing, prioritization, and escalation.
- Develop automated incident response processes and technical playbooks.
- Support investigation, containment, recovery, and root cause analysis for security incidents.
- Turn vulnerability and incident findings into long-term engineering improvements.
- Maintain technical documentation, runbooks, security designs, and reference architectures.
- Provide technical evidence and documentation supporting Federal security and authorization requirements.
- Participate in code reviews and technical design reviews.
- Mentor less experienced engineers and assist with knowledge transfer to client teams.
- Participate in scheduled after-hours or on-call support when required.
Required Qualifications
- **5-10 years of relevant cybersecurity, cloud, DevSecOps, or security engineering experience.**
- Hands-on experience developing, deploying, or securing containerized applications.
- Experience developing production-quality automation or software using at least one language such as: Python, PowerShell, Bash,Go
- Experience using Git or comparable source-control systems with standard code review and testing practices.
- Hands-on AWS security experience.
- Working knowledge of Microsoft Azure security and cloud services.
- Experience integrating security tools into CI/CD pipelines using GitLab, GitHub, Jenkins, Azure DevOps, or comparable platforms.
- Experience with infrastructure-as-code technologies such as Terraform, CloudFormation, or similar tools.
- Familiarity with system and application hardening practices.
- Working knowledge of federal cybersecurity frameworks and requirements, including:
NIST SP 800-53
FISMA
FedRAMP
- Experience with vulnerability management, security monitoring, detection engineering, or centralized logging.
- Strong troubleshooting and analytical skills.
- Ability to document technical designs and operational procedures clearly.
- Ability to manage multiple technical assignments with limited day-to-day supervision.
- Ability to appropriately handle sensitive client and system information.
- Must be authorized to work in the United States without sponsorship.
- Must be able to obtain and maintain a **Federal Public Trust** background investigation.
- Must be available during normal client operating hours and provide occasional after-hours support for deployments or security incidents.
Education
Associate's degree or higher preferred.
Relevant professional experience and industry certifications may be considered in place of a degree.
Preferred Certifications
One or more advanced cybersecurity, cloud, or engineering certifications are preferred, including:
- **AWS Certified Security - Specialty**
- **Certified Cloud Security Professional (CCSP)**
- **Certified Information Systems Security Professional (CISSP)**
- **GIAC Cloud Security Automation (GCSA)**
- Comparable advanced AWS, Azure, cloud security, DevSecOps, or cybersecurity certifications
Background Requirements
Employment is contingent upon successful completion of applicable screening requirements, which may include:
- Professional reference checks
- Commercial background check
- Federal OF-306 documentation
- Federal Public Trust background investigation
Work Location and Travel
Bubbleware Technology strongly prefers candidates located in the **Kansas City metropolitan area**, particularly for positions requiring regular interaction with client teams.
Candidates elsewhere in the United States may also be considered if they are able to travel to client locations when necessary.
This position supports a U.S. federal government customer. **Work must be performed within the United States. Working internationally is not permitted.**
The position may include a combination of remote work, company or partner office work, and visits to federal client facilities depending on project requirements.
Takes about 5 minutes. You'll get a confirmation email right away.