NextPath Jobs

Senior Cybersecurity Engineer

Bluestaq · Colorado Springs

TS/SCI clearance required

Posted 2026-09-17 · Verified live 2026-09-17

See how your real experience scores against this role — our AI drafts an honest, verifiable resume tailor. Nothing invented, ever. You approve everything.

Get matched — join the waitlist Apply on company site ↗

About this role

<p><strong>Why This Role Matters</strong> <br>The Senior Cybersecurity Engineer at&nbsp;Bluestaq&nbsp;owns the defensive posture of software systems that underpin national security decisions — space domain awareness, satellite command and control, and the infrastructure behind them. This is not a scan-and-report seat. You close vulnerabilities, build detection logic that catches real threats, and lead incident response when things get loud. No playbook&nbsp;required. If you need to be told what to look for, this&nbsp;isn't&nbsp;the right level.&nbsp;</p>

<p><strong>What You Own</strong>&nbsp;</p>

<ul>

<li>Own the full vulnerability lifecycle — scanning with vulnerability management tools, triage by mission risk, remediation tracking, and verified closure across the fleet.&nbsp;</li>

<li>Build and tune detection rules in SIEM tools (Splunk, Elastic, ArcSight, Sentinel, etc.) mapped to MITRE ATT&amp;CK tactics relevant to&nbsp;Bluestaq's&nbsp;threat model.&nbsp;</li>

<li>Serve as an incident responder for security events —&nbsp;contain, help scope, and provide clear status to the IR lead/leadership.&nbsp;</li>

<li>Deliver written post-mortems with root cause, timeline, and tracked action items following incident closure.&nbsp;</li>

<li>Maintain endpoint antivirus coverage across the fleet — configure policies, ensure definition currency, and coordinate remediation of flagged systems.&nbsp;</li>

<li>Apply DISA STIGs to operating systems (Linux, Windows, etc.); document deviations and manage compliance artifacts (POA&amp;Ms) in compliance management platforms (eMASS,&nbsp;Xacta, or equivalent RMF tools).&nbsp;</li>

<li>Assist&nbsp;in CI/CD pipeline security — provide guidance as far left as possible in the development cycle to ensure developers are generating clean, secure code and catching vulnerabilities before they reach production.&nbsp;</li>

<li>Review threat intelligence and peer-organization incident disclosures; translate findings into deployed detection logic within a sprint cycle.&nbsp;</li>

</ul>

<p><strong>What You Bring</strong></p>

<p>Must-Haves&nbsp;</p>

<ul>

<li>Production experience across the vulnerability lifecycle — scanning, risk-based triage, and driving findings to verified closure.&nbsp;</li>

<li>Hands-on SIEM detection engineering — building and tuning rules, mapped to MITRE ATT&amp;CK, beyond running queries.&nbsp;</li>

<li>Real incident response reps — containment, scoping, and writing clear post-mortems with root cause and action items.&nbsp;</li>

<li>Applied DISA STIG and NIST RMF — OS hardening (Linux, Windows), managing POA&amp;Ms, and working in compliance platforms (eMASS,&nbsp;Xacta, or equivalent).&nbsp;</li>

<li>Endpoint anti-malware / on-access scanning experience — deploying and&nbsp;maintaining&nbsp;coverage across a fleet.&nbsp;</li>

<li>Linux and Windows systems Administration in production&nbsp;environments.&nbsp;</li>

<li>Cloud experience — AWS, Google Cloud, Azure, or equivalent.&nbsp;</li>

<li>Scripting and automation&nbsp;– Python, Bash, Go, or&nbsp;similar, plus config management /&nbsp;IaC&nbsp;(Ansible, Terraform, or equivalent).&nbsp;</li>

<li>Threat-intel-to-detection –consuming&nbsp;external&nbsp;findings&nbsp;and translating them into deployed detection logic.&nbsp;</li>

<li>Security-minded in Ci/CD and architecture - flagging design risk&nbsp;and&nbsp;steering&nbsp;developers toward secure practices.&nbsp;</li>

<li>Investigative rigor&nbsp;– you dig deep,&nbsp;ask&nbsp;why, and&nbsp;don't&nbsp;settle for&nbsp;surface-level answers.&nbsp;</li>

<li>Strong written and verbal communication – you can&nbsp;put technical findings in front of peers, leadership, and cross-functional teams.&nbsp;</li>

<li>Ownership mentality&nbsp;– you follow through, document your work, and&nbsp;know&nbsp;when&nbsp;to persevere vs. ask for help.&nbsp;</li>

</ul>

<p>Required Education &amp; Experience&nbsp;</p>

<ul>

<li>High School Diploma/GED and 8+ years of relevant experience, OR&nbsp;</li>

<li>Associate degree in a related field and 6+ years of relevant experience, OR&nbsp;</li>

<li>Bachelor's degree in Cybersecurity, Computer Science, Information Technology, or related field and 4+ years of relevant experience, OR&nbsp;</li>

<li>Master's degree in a related field and 2+ years of relevant experience&nbsp;</li>

</ul>Salary Range (CO)$100,000—$155,000 USD<p><strong>Clearance Requirement: </strong>This position may require an active TS/SCI Clearance. Current clearance holders are strongly encouraged to apply. If you don't currently hold one, Bluestaq will sponsor eligible candidates through the clearance process based on program needs.</p>

<p><strong>About Bluestaq<br></strong>At Bluestaq, we build secure data platforms that matter for space missions, national defense, healthcare systems, and commercial innovation. Founded in 2018, we've become a leader in enterprise software and secure data management by staying focused on what counts: modern architecture, operational excellence, and mission impact.</p>

<p>We're engineers, problem-solvers, and builders who take the mission seriously, but not ourselves. We automate the repeatable, question the status quo, and design systems that are as reliable as they are scalable. Whether we're supporting space, defense systems, or healthcare advancements, we build with the same principles: cloud-native solutions, security by design, and relentless simplicity.</p>

<p><strong>Relocation:</strong> Relocation assistance may be available for this role and is evaluated on a case-by-case basis.</p>

<p><strong>Date the Position Closes:</strong> Applications will be accepted for 60 days beyond the posting date, or until the position is filled, whichever comes first.</p>

<p><em>Bluestaq is an Equal Opportunity Employer.&nbsp;We prohibit unlawful discrimination against applicants or employees on the basis age 40 and over, color, disability, gender identity, genetic information, military or veteran status, national origin, race, religion, sex, sexual orientation, or any other status protected by state or local law.</em></p>

<p><em>Bluestaq will make reasonable accommodations for qualified individuals with known disabilities and employees whose work requirements interfere with a religious belief unless doing so would result in an undue hardship to Bluestaq or a direct threat. Employees needing such accommodation are instructed to contact Human Resources immediately at <a href="mailto:[email protected]" rel="noopener noreferrer">[email protected]</a>.</em></p>

One of thousands of fresh listings refreshed nightly, built for cleared & defense careers.

Browse all jobs