{"id":24475,"url":"https://alion.io/job/armada-security-engineer","title":"Senior Security Engineer, Federal","company":{"id":6241,"name":"Armada Investment","domain":"armada.com","url":"https://alion.io/company/armada","size_band":"501-1000","is_staffing_agency":false,"employer_type":"direct","is_intermediary":true,"listed_via":null,"ats_vendor":"Greenhouse","truth_index":{"grade":"B","score":74,"open_postings":6,"ghost_share":0,"stale_share":0.833,"repost_share":0,"time_to_fill_p50_days":66,"computed_at":"2026-10-04T05:45:00Z"}},"role":"Security","role_family":"Security","seniority":"senior","employment_type":null,"work_mode":"on_site","remote_scope":null,"remote_scope_basis":null,"remote_working_hours":null,"hiring_geo_confidence":"structured","locations":["United States"],"countries":["US"],"hiring_countries":[],"hiring_countries_total":0,"salary":{"min":157596,"max":196995,"currency":"USD","period":"year","gross":null,"usd_annual":196995},"salary_estimate":null,"experience_years_min":8,"visa_sponsorship":false,"relocation_package":false,"has_equity":false,"technologies":[{"name":"AI Agents","optional":false},{"name":"Azure","optional":false},{"name":"CI/CD","optional":false},{"name":"ISO 27001","optional":false},{"name":"Kubernetes","optional":false},{"name":"Kyverno","optional":false},{"name":"LLM Guardrails","optional":false},{"name":"Microsoft Defender for Cloud","optional":false},{"name":"Microsoft Entra ID","optional":false},{"name":"Microsoft Sentinel","optional":false},{"name":"Nessus","optional":false},{"name":"OWASP Top 10","optional":false},{"name":"Python","optional":false},{"name":"Qualys Cloud Platform","optional":false},{"name":"SBOM","optional":false},{"name":"SIEM","optional":false},{"name":"SLI/SLO/SLA","optional":false},{"name":"SOC 2","optional":false},{"name":"SQL","optional":false},{"name":"Bicep","optional":true},{"name":"FedRAMP","optional":true},{"name":"LLM","optional":true},{"name":"Terraform","optional":true},{"name":"Threat Modeling","optional":true}],"status":"closed","first_seen_at":"2026-07-28T23:22:32Z","employer_posted_date":"2026-09-08","last_verified_at":"2026-10-03T12:18:15Z","board_verified":false,"closed_at":"2026-10-03T12:18:15Z","days_open":66,"trust":{"level":"ok","repost_count":1,"flags":[],"days_open":66},"description":"About the Company\nArmada is the hyperscaler for the edge, delivering modular AI infrastructure from first deployment to AI factory with speed, scale and sovereignty. Named one of Fast Company's Most Innovative Companies and to the CNBC Disruptor 50, Armada’s solutions are deployed in over 60 countries globally for organizations ranging from energy to defense. \nWith nearly $500 million in funding to date, Armada is backed by leading investors including Founders Fund, Lux, BlackRock and Microsoft (M12), alongside strategic partnerships with Microsoft, Dell, Palantir, NVIDIA, SpaceX, and Skydio. We are building the infrastructure layer for sovereign and edge AI - rugged, deployable compute for customers that cannot rely on centralized cloud.\nWorking at Armada means taking ownership, driving autonomy, and delivering impact. You’ll tackle challenges that haven’t been solved before and help build something transformative from the ground up. What you do here will not only define your career but help further Armada’s mission to bridge the digital divide for customers around the world. \nAbout the Role\nYou will own and drive security engineering strategy across our Azure cloud, hybrid infrastructure, and edge computing platform. This is a senior, hands-on role: you'll set direction for detection engineering, application security testing, Kubernetes hardening, and CI/CD controls, while also advising other engineers and teams on complex security decisions. You will also help define our strategic approach to securing AI/ML workloads running at the edge.\nLocation. This role is office-based at our Bellevue, Washington office. \nWhat You'll Do (Key Responsibilities)\nCloud and Infrastructure Security \nOwn and evolve security architecture strategy across Azure, hybrid infrastructure, and edge deployments, guiding design decisions across teams \nDirect the use of SIEM (Microsoft Sentinel), EDR/XDR, WAF, email security, and CSPM/CNAPP tooling, adapting approach as the environment evolves \nDesign detection rules, correlation logic, and automated response playbooks, and guide others in building their own \nLead incident response end-to-end, from triage through containment and remediation, serving as the senior escalation point for complex incidents \nOffensive Security and Assessment \nLead security assessments, vulnerability scanning, and penetration testing across cloud, infrastructure, and application layers \nTest web applications and APIs for authentication and authorization flaws, business logic abuse, and OWASP Top 10 issues \nThreat model new services and architectures before they ship, advising engineering teams on risk tradeoffs \nOwn the vulnerability lifecycle end-to-end: risk-based prioritization, SLA tracking, and remediation follow-through, holding owning teams accountable \nDirect the integration of SAST, DAST, SCA, secrets scanning, IaC scanning, and container image scanning into CI/CD as automated gates \nHarden the software supply chain: build provenance, artifact signing, SBOM generation, dependency governance \nDefine and enforce guardrails as policy-as-code using Azure Policy, OPA/Gatekeeper, or Kyverno \nServe as a senior security reviewer for designs and code across engineering teams, influencing secure deployment practices org-wide \nAI/ML Security \nDefine and lead our approach to securing AI/ML development and deployment, including model and data supply chain integrity, inference endpoint exposure, prompt injection and agentic tool abuse, and training data governance \nGovernance \nOwn security policies, standards, and procedures aligned to NIST, ISO 27001, and SOC 2, and drive their adoption across teams \nProduce audit evidence and lead customer security assessments \nTrack emerging threats and translate them into roadmap priorities, advising leadership on risk \nRequired Qualifications:\nBachelor's degree in Computer Science, Cybersecurity, or a related field and 8+ years of experience; or Master's degree and 6+ years; or equivalent practical experience \n8+ years in information security, including 5+ years focused on cloud security \nDeep, hands-on expertise with Azure security services including Defender for Cloud, Sentinel, Entra ID, Key Vault, Azure Policy, and network security \nProduction experience across multiple of: SIEM, EDR/XDR, WAF, email security, CSPM/CNAPP, vulnerability management, with the judgment to adapt tooling strategy as needs evolve \nProven experience securing Kubernetes and containerized workloads in production at scale \nExperience embedding security testing into CI/CD pipelines using SAST, DAST, SCA, secrets scanning, and IaC scanning \nAdvanced application security testing experience covering web and API penetration testing and secure code review \nProficiency with vulnerability management platforms such as Nessus, Nexpose, Qualys, or Defender Vulnerability Management \nPython and SQL/KQL for automation, tooling, and log analysis \nStrong working knowledge of NIST, ISO 27001, and SOC 2, with experience applying them to real audit and compliance cycles \nExperience leading incident response as the primary or senior responder on complex, high-stakes incidents \nDemonstrated experience advising or mentoring other engineers on security best practices \nU.S. Citizenship required \nPreferred Qualifications:\nExperience securing edge, disconnected, or intermittently connected environments \nExperience securing AI/ML or LLM-based systems, including OWASP Top 10 for LLM Applications and MITRE ATLAS \nAdvanced detection engineering experience: writing and tuning KQL, detection-as-code, purple team exercises \nInfrastructure-as-code fluency with Terraform or Bicep \nFamiliarity with MITRE ATT&CK for threat modeling and detection coverage mapping \nExperience leading or supporting SOC 2 Type II or FedRAMP audit cycles \nCertifications \nAt least one from either group is preferred. \n Defensive and architecture: CISSP, CCSP, Azure Security Engineer Associate (AZ-500), GCIH, GCIA \nOffensive: OSCP, OSWE, OSWP, OSEE, GPEN, GWAPT, CEH \nCitizenship Requirements \nFor select roles, due to the nature of our clientele and the technologies involved, there may be specific nationality or citizenship indicated in the required qualifications section. These roles may involve access to sensitive information that is subject to export control regulations or other legal restrictions. In such cases, employment offers will be contingent upon your ability to comply with these requirements. \nCompensation\nFor U.S. Based candidates: To ensure fairness and transparency, the starting base salary range for this role for candidates in the U.S. are listed below, varying based on location experience, skills, and qualifications.\nIn addition to base salary, this role will also be offered equity and subsidized benefits(details available upon request).\nBenefits\nCompetitive base salary and equity\nMedical, dental, and vision (subsidized cost)\nHealth savings accounts (HSA), flexible spending accounts (FSA), and dependent care FSAs (DCFSA)\nRetirement plan options, including 401(k) and Roth 401(k)\nUnlimited paid time off (PTO)\n14 paid company holidays per year\nCompensation\n$157,596—$196,995 USD\nYou're a Great Fit if You're\nA go-getter with a growth mindset. You're intellectually curious, have strong business acumen, and actively seek opportunities to build relevant skills and knowledge \nA detail-oriented problem-solver. You can independently gather information, solve problems efficiently, and deliver results with a \"get-it-done\" attitude \nThrive in a fast-paced environment. You're energized by an entrepreneurial spirit, capable of working quickly, and excited to contribute to a growing company\nA collaborative team player. You focus on business success and are motivated by team accomplishment vs personal agenda \nHighly organized and results-driven. Strong prioritization skills and a dedicated work ethic are essential for you \nEqual Opportunity Statement\nAt Armada, we are committed to fostering a work environment where everyone is given equal opportunities to thrive. As an equal opportunity employer, we strictly prohibit discrimination or harassment based on race, color, gender, religion, sexual orientation, national origin, disability, genetic information, pregnancy, or any other characteristic protected by law. This policy applies to all employment decisions, including hiring, promotions, and compensation. Our hiring is guided by qualifications, merit, and the business needs at the time.\nUnsolicited Resumes and Candidates\nArmada does not accept unsolicited resumes or candidate submissions from external agencies or recruiters. All candidates must apply directly through our careers page. Any resumes submitted by agencies without a prior signed agreement will be considered unsolicited and Armada will not be obligated to pay any fees.","description_format":"text","description_chars":8842,"description_truncated":false,"requirements":{"experience_years_min":8,"management_years_min":null,"team_size_min":null,"manages_managers":false,"education":{"level":"bachelor","optional":false},"security_clearance":false,"languages":[]},"benefits":["Equity","Retirement plans"],"hiring_locations":[],"hiring_excludes":[],"relocation_offered":false,"industries":["Venture Capital","Family Offices"],"lifecycle":[{"event":"open","at":"2026-07-28T23:22:32Z"},{"event":"close","at":"2026-09-01T17:53:10Z"},{"event":"reopen","at":"2026-09-04T23:54:47Z"},{"event":"close","at":"2026-10-03T12:18:15Z"}],"visa":[],"liveness":null,"pay":{"stated_usd_annual":196995,"is_top_pay":true},"html_url":"https://alion.io/job/armada-security-engineer","json_url":"https://alion.io/job/armada-security-engineer.json","meta":{"generated_at":"2026-10-05T00:26:34Z","cache_seconds":300,"methodology":"https://alion.io/methodology","terms":"https://alion.io/terms","contact":"https://alion.io/contact","api":"https://alion.io/developers","usage":{"tier":"crawler","counted_by":"address","units_charged":1,"used_today":411,"day_limit":5000,"remaining_today":4589,"minute_limit":60,"resets_at":"2026-10-06T00:00:00Z"}}}