Senior Cybersecurity Engineer
Job Description
<p><strong><span data-contrast="none">Why This Role Matters</span></strong><span data-ccp-props="{"134233117":false,"134233118":false,"335551550":0,"335551620":0,"335559738":280,"335559739":80,"335572079":8,"335572080":1,"335572081":14800331,"469789806":"single"}"> <br></span><span data-contrast="auto">The Senior Cybersecurity Engineer at Bluestaq owns the defensive posture of software systems that underpin national security decisions — space domain awareness, satellite command and control, and the infrastructure behind them. This is not a scan-and-report seat. You close vulnerabilities, build detection logic that catches real threats, and lead incident response when things get loud. No playbook required. If you need to be told what to look for, this isn't the right level.</span><span data-ccp-props="{"134233117":false,"134233118":false,"335551550":0,"335551620":0,"335559738":0,"335559739":80}"> </span></p> <p><strong><span data-contrast="none">What You Own</span></strong><span data-ccp-props="{"134233117":false,"134233118":false,"335551550":0,"335551620":0,"335559738":280,"335559739":80,"335572079":8,"335572080":1,"335572081":14800331,"469789806":"single"}"> </span></p> <ul> <li><span data-contrast="auto">Own the full vulnerability lifecycle — scanning with vulnerability management tools, triage by mission risk, remediation tracking, and verified closure across the fleet.</span><span data-ccp-props="{"134233117":false,"134233118":false,"335551550":0,"335551620":0,"335559685":720,"335559737":0,"335559738":0,"335559739":0,"335559991":360}"> </span></li> <li><span data-contrast="auto">Build and tune detection rules in SIEM tools (Splunk, Elastic, ArcSight, Sentinel, etc.) mapped to MITRE ATT&CK tactics relevant to Bluestaq's threat model.</span><span data-ccp-props="{"134233117":false,"134233118":false,"335551550":0,"335551620":0,"335559737":0,"335559738":0,"335559739":0}"> </span></li> <li><span data-contrast="auto">Serve as an incident responder for security events — contain, help scope, and provide clear status to the IR lead/leadership.</span><span data-ccp-props="{"134233117":false,"134233118":false,"335551550":0,"335551620":0,"335559737":0,"335559738":0,"335559739":0}"> </span></li> <li><span data-contrast="auto">Deliver written post-mortems with root cause, timeline, and tracked action items following incident closure.</span><span data-ccp-props="{"134233117":false,"134233118":false,"335551550":0,"335551620":0,"335559737":0,"335559738":0,"335559739":0}"> </span></li> <li><span data-contrast="auto">Maintain endpoint antivirus coverage across the fleet — configure policies, ensure definition currency, and coordinate remediation of flagged systems.</span><span data-ccp-props="{"134233117":false,"134233118":false,"335551550":0,"335551620":0,"335559737":0,"335559738":0,"335559739":0}"> </span></li> <li><span data-contrast="auto">Apply DISA STIGs to operating systems (Linux, Windows, etc.); document deviations and manage compliance artifacts (POA&Ms) in compliance management platforms (eMASS, Xacta, or equivalent RMF tools).</span><span data-ccp-props="{"134233117":false,"134233118":false,"335551550":0,"335551620":0,"335559737":0,"335559738":0,"335559739":0}"> </span></li> <li><span data-contrast="auto">Assist in CI/CD pipeline security — provide guidance as far left as possible in the development cycle to ensure developers are generating clean, secure code and catching vulnerabilities before they reach production.</span><span data-ccp-props="{"134233117":false,"1342331