CybersecurityJobs.io
← Back to all jobs

Job Description

Blue Origin’s Blue National Security organization is building and securing classified enclaves, mission ground systems, and labs that support national security operations. In this role, you will engineer security controls end to end, help move systems through RMF for accreditation, and strengthen day-to-day defenses through vulnerability management, event triage, and incident support.

Role focus

  • Implement security architecture across classified enclaves, mission ground systems, and lab environments, including network segmentation, identity and access management, endpoint hardening, logging and audit, and encryption at rest and in transit.
  • Author and maintain SSPs, security control implementation statements, risk assessments, and POA&Ms.
  • Drive systems through RMF to achieve ATO and ATC, then maintain compliance through continuous monitoring.
  • Conduct vulnerability scanning and remediation, perform patch management, support log review and audit reduction, and triage security events alongside the enterprise SOC.
  • Investigate, contain, and document incidents, then drive corrective actions to closure with system owners.
  • Participate in an on-call rotation.
  • Build scripting and tooling to make compliance evidence, STIG application, and reporting repeatable rather than manual.
  • Collaborate with program engineers and system administrators to deliver secure systems on mission schedules.
  • Mentor junior engineers and analysts, and contribute to team standards, baselines, and accreditation playbooks.

Qualifications

  • Bachelor’s degree in a technical discipline (Computer Science, Cybersecurity, Computer/Electrical Engineering, or similar) or equivalent experience.
  • 6+ years of hands-on cybersecurity engineering experience.
  • Direct experience implementing and sustaining security controls on classified systems in DoD or IC environments.
  • Working knowledge of RMF control implementation, SSP and artifact development, POA&M remediation, and continuous monitoring.
  • Hands-on depth in at least three of: Linux and Windows hardening (STIG/SCAP), network security and segmentation, IAM and PKI, government cloud (AWS GovCloud / Azure Government), SIEM and log analysis, vulnerability management tooling.
  • Scripting proficiency (Python, PowerShell, Bash) to automate security operations and compliance tasks.
  • Active U.S. Government Top Secret clearance with SCI eligibility and eligibility for SAP access determination.
  • DoD 8140 IAT/IAM Level II certification (Security+ CE or equivalent) at hire.

Technologies

  • Python, PowerShell, Bash
  • Linux, Windows
  • STIG, SCAP
  • IAM, PKI
  • AWS GovCloud, Azure Government
  • SIEM, RMF
  • SSP, POA&M
  • STIG application
  • Terraform, Ansible, Puppet
  • JSIG
  • ICD 503/705
  • NIST SP 800-53, NIST SP 800-171

Location and logistics

  • Denver, CO (onsite), primarily onsite in classified spaces with limited telework due to the nature of the work.
  • Travel up to 10–15% to other Blue Origin sites and customer facilities.
  • On-call rotation participation, with occasional extended hours to support mission-critical events and incident response.
  • Must be able to obtain and maintain access to classified facilities; periodic polygraph may be required.

Base pay range

  • CO applicants: $133,500.00 - $186,898.95 (yearly)
  • WA applicants: $145,188.00 - $203,263.20 (yearly)

Benefits

  • Medical, dental, vision
  • Basic and supplemental life insurance
  • Paid parental leave
  • Short and long-term disability
  • 401(k) with a company match of up to 5%
  • Education Support Program
  • Stock Options for all regular employees (working at least 20 hours/week)
  • Paid Time Off: up to four (4) weeks per year based on weekly scheduled hours
  • Up to 14 company-paid holidays

Application details

Applications will be accepted on an ongoing basis until the requisition is closed.

Preferred qualifications

  • Prior ISSO or ISSE role on SAP/SAR programs.
  • Working knowledge of JSIG, ICD 503/705, and NIST SP 800-53 / 800-171.
  • Experience standing up and accrediting new classified enclaves, labs, or facilities.
  • Infrastructure-as-code and configuration management (Terraform, Ansible, Puppet).
  • Cross-domain solution implementation or accreditation support.
  • Detection engineering, threat hunting, or incident response experience.
  • Active TS/SCI with polygraph, SAP Eligible.

Background check and eligibility

  • Required for all positions: Blue’s Standard Background Check.
  • Required for certain job profiles: DBIDS background check if the role requires being on a military installation.
  • Required for certain job profiles: additional requirements may apply for drivers operating certain commercial motor vehicles and/or transporting placardable hazardous materials.
  • Required for certain job profiles: ability to obtain and maintain a Merchant Mariner Credential, including pre-employment and random drug testing and a DOT physical.
  • Export control regulations: applicants must be a U.S. citizen or national, U.S. permanent resident, or lawfully admitted as a refugee or granted asylum.

Similar Jobs