SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.
CX2 is a next-generation defense technology company building AI-enabled hardware and software platforms to detect, disrupt, and defend the electromagnetic spectrum across land, air, sea, and space domains. The company is backed by leading venture investors in the defense ecosystem and led by founders with track records at Meta, SpaceX, Epirus, and the U.S. Department of Defense.
You will join CX2's foundational engineering team as a Software Infrastructure Engineer specializing in cybersecurity. You will own the security of edge and hybrid cloud infrastructure end-to-end, ensuring that CX2's sensor and effector systems, and the platform that orchestrates them, can be trusted in any operational environment. Your work must account for disrupted, degraded, intermittent, or limited (DDIL) network conditions.
Key responsibilities include:
• Design, harden, and defend containerized application infrastructure across small form factor edge compute and cloud environments. Lead threat modeling, vulnerability management, and security reviews. Evaluate and adopt new tools that maximize system security and reliability while protecting developer velocity.
• Build and maintain automated, reproducible provisioning and installation frameworks (Ansible, Chef, etc.) that take hardware and cloud hosts from bare metal to a hardened, mission-ready baseline, including in air-gapped and disconnected environments.
• Own the lifecycle of secrets, keys, and certificates across the fleet, including issuance, distribution, rotation, and revocation, for systems that must operate with intermittent or no connectivity.
• Optimize resource usage and harden against denied or degraded network conditions to serve both mobile and web-based clients.
• Understand, implement, and document the security controls needed to meet software accreditation and certification standards set forth by the United States Department of Defense (DoD) and Intelligence Community (IC).
You will shape security architecture, strengthen engineering culture, and help deliver powerful electromagnetic warfare capabilities.
REQUIREMENTS:
Minimum 8–10 years of experience building, securing, and operating software infrastructure at the edge, on premises, or in the cloud.
Strong foundation in cybersecurity, including system and network hardening, threat modeling, vulnerability management, and incident response.
Deep understanding of containerization technologies, with a focus on Docker and Docker Compose, including image building and hardening, container networking and storage, runtime isolation (namespaces, cgroups, seccomp, capabilities, rootless containers), and securing images and registries.
Hands-on experience with provisioning and configuration management frameworks (Ansible, Chef, Puppet, SaltStack, etc.) and Infrastructure-as-Code tools (Terraform, OpenTofu, etc.).
Experience with secrets management and PKI (HashiCorp Vault, OpenBao, AWS KMS, SOPS, TPM or HSM backed keys, etc.).
Deep proficiency with Linux administration and security (SELinux, AppArmor, firewalls, auditing, disk encryption).
Willing to work extended hours for mission-critical deadlines.
Bachelor's degree in Computer Science, Computer Engineering, Cybersecurity, or a related technical field, or equivalent relevant experience.
ITAR Requirement: Must be a US Citizen, Green Card holder, or be eligible to obtain the required authorizations from the U.S. Department of State.
PREFERRED QUALIFICATIONS:
Experience configuring, building, and hardening custom Linux kernels.
Experience building and maintaining board support packages (BSPs) for embedded or small form factor hardware (L4T, Yocto, Buildroot, U-Boot, etc.), including secure and measured boot.
Familiarity with DoD security frameworks and accreditation processes (RMF, DISA STIGs, NIST SP 800-53, FedRAMP, Impact Level 4–6).
Expertise with government cloud platforms (AWS GovCloud, Azure Government Cloud).
Proficiency with server and embedded Linux distributions (Ubuntu, NixOS, RHEL).
Familiarity with container orchestration platforms such as Kubernetes (K3s, Rancher RKE2, etc.).
Experience securing CI/CD pipelines and the software supply chain (SBOMs, artifact signing, reproducible builds).
Security certifications such as CompTIA Security+, CISSP, or OSCP.
Active Secret or TS/SCI security clearance.