Quantum Sky Engineering LLC Logo

Quantum Sky Engineering LLC

ISSM / Security Automation Engineer

Posted 2 Days Ago
Remote
Hiring Remotely in US
175K-190K Annually
Entry level
Remote
Hiring Remotely in US
175K-190K Annually
Entry level
Leads NIST RMF, security authorization, continuous monitoring, and cybersecurity risk activities while engineering automation for compliance, vulnerability management, evidence collection, and remediation. Develops integrations, dashboards, policy validation, and Compliance as Code using cloud platforms, APIs, CI/CD, Infrastructure as Code, containers, and scripting languages. Partners with engineering and security teams to embed controls into cloud and DevSecOps workflows.
The summary above was generated by AI
Description

Quantum Sky is searching for a highly technical Information System Security Manager (ISSM) / Security Automation Engineer to lead cybersecurity risk management and security authorization activities while designing and developing automation that enables continuous security and compliance.


This is a hands-on engineering role for an individual who can operate effectively across cybersecurity governance, cloud security, DevSecOps, software automation, and NIST Risk Management Framework (RMF) environments. The successful candidate will own traditional ISSM responsibilities while also developing scripts, integrations, and automated workflows that reduce manual compliance activities and provide continuous visibility into system security posture.


The ideal candidate has previous software development or automation engineering experience and is comfortable working directly with source code, APIs, cloud services, CI/CD pipelines, Infrastructure as Code, security tooling, and machine-readable compliance data.The objective of this position is to move security programs away from periodic, document-driven compliance toward automated, continuous security assurance and Compliance as Code.


Responsibilities:

  • Lead RMF, Security Authorization & Continuous Assurance — Own NIST RMF implementation, system authorization and ongoing authorization activities, including SSPs, control implementation documentation, risk assessments, continuous monitoring artifacts, and coordination with system owners, assessors, ISSOs, engineers, and Authorizing Officials.
  • Engineer Security & Compliance Automation — Design, develop, and maintain production-quality automation using Python, PowerShell, Bash, APIs, and cloud-native technologies to automate control validation, evidence collection, compliance reporting, security assessments, and remediation workflows.
  • Implement Compliance as Code & Continuous Control Monitoring — Translate NIST SP 800-53 controls and organizational requirements into measurable technical requirements, machine-readable policies, automated validation procedures, and continuous control monitoring capabilities.
  • Embed Security into Cloud & DevSecOps Workflows — Partner with engineering and platform teams to integrate security into cloud architectures, Infrastructure as Code, CI/CD pipelines, containers, Kubernetes, and software delivery processes, including automated testing, policy validation, and security gates.
  • Integrate Security Platforms, Data & Tooling — Build integrations and reusable services connecting cloud platforms, vulnerability scanners, security tools, GRC platforms, ticketing systems, source-code repositories, and CI/CD systems using APIs and structured data such as JSON and YAML.
  • Manage Vulnerabilities, Findings & Cybersecurity Risk — Automate vulnerability and configuration finding ingestion, correlation, prioritization, assignment, tracking, and reporting; manage POA&Ms, exceptions, and remediation through closure; and evaluate system architectures and changes for cybersecurity risk.
  • Deliver Continuous Security Visibility & Improvement — Develop dashboards, metrics, and automated reporting that provide actionable visibility into vulnerabilities, configuration compliance, control status, POA&Ms, and organizational risk while identifying opportunities to replace manual security reviews with automated technical validation.
Qualifications

Required:

  • Bachelor’s degree in Cybersecurity, Computer Science, Information Technology, Software Engineering, or a related field, or equivalent professional experience.
  • Demonstrated experience as an ISSM, ISSO, Security Engineer, Cloud Security Engineer, DevSecOps Engineer, or similar technical cybersecurity professional.
  • Strong knowledge of NIST SP 800-53, NIST SP 800-37, RMF, security authorization, security control assessment, and continuous monitoring.
  • Demonstrated hands-on experience developing production-quality automation, scripts, integrations, or software.
  • Strong programming or scripting experience with Python and experience with one or more additional languages or scripting environments such as PowerShell, Bash, JavaScript, or Go.
  • Experience working with JSON and YAML.
  • Experience automating cybersecurity, infrastructure, compliance, or operational processes.
  • Experience with vulnerability scanning and vulnerability management technologies.
  • Experience with cloud platforms such as AWS, Azure or GCP.
  • Ability to understand cloud and enterprise system architectures and evaluate their security implications.
  • Ability to translate regulatory and cybersecurity requirements into technical engineering requirements.

Desired:

  • Experience developing automation against AWS, Azure or GCP API/SDKs
  • Experience with Infrastructure as Code technologies such as Terraform.
  • Experience with configuration management and automation technologies such as Ansible.
  • Experience with CI/CD platforms such as GitHub Actions, GitLab CI/CD, Jenkins, or Azure DevOps.
  • Experience with container and orchestration technologies such as Docker and Kubernetes.
  • Experience integrating vulnerability scanners, SIEM platforms, CSPM/CNAPP solutions, GRC platforms, and ticketing systems.
  • Experience developing security dashboards and data pipelines.
  • Experience with automated testing frameworks and software engineering practices.
  • Experience with serverless architectures and event-driven automation.
  • Experience transforming NIST controls and security documentation into structured, machine-readable data.
  • Experience with Compliance as Code and Policy as Code technologies such as Open Policy Agent (OPA).
  • Experience implementing automated security evidence collection and continuous control validation.

Desired Federal Cybersecurity Experience:

  • Experience supporting FISMA, FedRAMP, DoD RMF, CMMC, or other federal cybersecurity programs.
  • Experience supporting systems through initial authorization and ongoing authorization processes.
  • Experience working with Security Control Assessors (SCAs), Third Party Assessment Organizations (3PAOs), or government Authorizing Officials.
  • Experience developing or maintaining SSPs, POA&Ms, Security Assessment Reports, continuous monitoring documentation, and supporting authorization artifacts.
  • Familiarity with federal security baselines, implementation guidance, and security assessment procedures.

Desired Certifications:

  • One or more of the following is preferred:
  • CISSP, CGRC, CISM, CCSP, Security+
  • AWS Solution Architect or Security Specialty
  • GCP Cloud Architect or Security Engineer
  • Certified Kubernetes Security Specialist (CKS)
About Quantum Sky

Compensation:

  • Compensation is unique to each candidate and relative to the skills and experience they bring to the position. The salary range for this position is typically between $175,000-$190,000. This does not guarantee a specific salary as compensation is based upon multiple factors such as education, experience, certifications, and other requirements, and may fall outside of the above-stated range.

Benefits:

  • Highlights of our benefits include Health/Dental/Vision, 401(k) match, Paid Time Off, STD/LTD/Life Insurance, Referral Bonuses, professional development reimbursement, and parental leave.

The world the mission operates in is going post-quantum, contested, and machine-speed. Quantum Sky engineers the advantage across cyber, networks, software, and quantum because the mission demands dominance, not parity. We don't follow the map. We draw it. 


At Quantum Sky, we believe that success starts with our people. We foster a collaborative, innovative, and mission-driven environment where every team member plays a critical role in shaping the future of technology. Are you ready to join #TeamQuantumSky? 


Quantum Sky Engineering LLC is an Equal Opportunity Employer; all qualified applicants will receive consideration for employment without regard to race, color, religion, sex, [sexual orientation, gender identity,] national origin, disability, status as a protected veteran, or any characteristic protected by applicable law.


Similar Jobs

47 Minutes Ago
Remote or Hybrid
US
124K-170K Annually
Mid level
124K-170K Annually
Mid level
Information Technology
Owns the strategy, roadmap, backlog, and delivery of professional services products. Partners with technical and business stakeholders to define product vision, prioritize features, manage Agile release planning, track KPIs, conduct research, and communicate product direction to senior leaders. The role requires strong analytical, presentation, negotiation, and cross-functional collaboration skills, plus experience with professional or managed services and Agile methodologies.
Top Skills: AgileCertinia PsaKanbanLucidchartMS OfficePowerPointSafeSalesforce CpqSalesforce CRMScrum
47 Minutes Ago
Remote or Hybrid
US
132K-193K Annually
Expert/Leader
132K-193K Annually
Expert/Leader
Information Technology
Leads strategic technology consulting engagements and advises clients on transformation, risk, and business objectives. Defines and governs enterprise integration architectures across ServiceNow and business systems, using APIs, workflows, data architecture, and security controls. Develops recommendations, roadmaps, executive presentations, and architectural standards; manages stakeholders, project governance, business development, and client relationships. Mentors consultants and designs secure, scalable, maintainable integration solutions across ServiceNow modules and enterprise technologies.
Top Skills: AIAnsibleAPIsArtifactoryCommvaultCyberarkData ArchitectureDigicertGithub Ci/CdHashicorp VaultKubernetesPanoramaSecurity ControlsServicenowWorkflow OrchestrationXsoar
An Hour Ago
Remote or Hybrid
88K-141K Annually
Senior level
88K-141K Annually
Senior level
Blockchain • Fintech • Payments • Consulting • Cryptocurrency • Cybersecurity • Quantum Computing
The Senior Analyst leads enhancements of the Internal Audit OpenPages, ensuring successful deployment, training, and adoption of data-driven solutions, while collaborating with teams across the organization.
Top Skills: AlteryxIbm OpenpagesMs AccessExcelTableauWatsonx

What you need to know about the Seattle Tech Scene

Home to tech titans like Microsoft and Amazon, Seattle punches far above its weight in innovation. But its surrounding mountains, sprinkled with world-famous hiking trails and climbing routes, make the city a destination for outdoorsy types as well. Established as a logging town before shifting to shipbuilding and logistics, the Emerald City is now known for its contributions to aerospace, software, biotech and cloud computing. And its status as a thriving tech ecosystem is attracting out-of-town companies looking to establish new tech and engineering hubs.

Key Facts About Seattle Tech

  • Number of Tech Workers: 287,000; 13% of overall workforce (2024 CompTIA survey)
  • Major Tech Employers: Amazon, Microsoft, Meta, Google
  • Key Industries: Artificial intelligence, cloud computing, software, biotechnology, game development
  • Funding Landscape: $3.1 billion in venture capital funding in 2024 (Pitchbook)
  • Notable Investors: Madrona, Fuse, Tola, Maveron
  • Research Centers and Universities: University of Washington, Seattle University, Seattle Pacific University, Allen Institute for Brain Science, Bill & Melinda Gates Foundation, Seattle Children’s Research Institute

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account