Merlin Labs

Merlin Labs

Information Systems Security Engineer

Boston · Contract

No sponsorshipDetected 13 days ago
TypeScriptCI/CDCybersecuritySIEMHRIS

About the role

  • You approach security as a systems problem and you bring the technical depth to back it up.

Responsibilities

  • Apply systems security engineering methods across the architecture, design, evaluation, and integration of Merlin's defense programs and products, working alongside engineering teams to embed security requirements early rather than retrofitting them once a system is built.
  • Apply and verify DISA SRGs and STIGs across program environments, and maintain the configuration management processes that keep systems compliant as they evolve through their operational lifecycle.
  • Conduct vulnerability assessments using tools such as Tenable NESSUS and ACAS, coordinate remediation with engineering teams, and manage the ongoing security posture of supported systems.
  • Support DevSecOps security integration by bringing defense-grade practices into our CI/CD pipeline, including static application security testing and security-gated build processes for government-facing deliverables.

Requirements

  • You have spent years working inside the DoD ecosystem and you know what program security actually looks like.
  • If that is the kind of ownership you are looking for, this is the role.
  • Bachelor's degree with 5 years of cybersecurity experience on DoD or government programs.
  • About you: You have spent years working inside the DoD ecosystem and you know what program security actually looks like.
  • Direct experience with RMF accreditation and authorization, including body of evidence package development and working with government ISSOs, SCAs, or authorizing official representatives through the authorization lifecycle.
  • Hands-on experience applying DISA SRGs and STIGs and conducting vulnerability assessments with tools such as Tenable NESSUS, ACAS, or SCC.
  • Active clearance. TS preferred.

Nice to have

  • Experience with government and commercial security tooling and security integration in a DevSecOps environment, or equivalent tools used in a defense or government program context.
  • Familiarity with SIEM platforms and development of detection rulesets and dashboards in a defense program or enterprise security context.
  • Background in aerospace, aviation, autonomous systems, or another safety-critical engineering domain where security and reliability requirements intersect.
  • Merlin Labs is an equal opportunity employer and values diversity.
  • All job offers are contingent upon the candidate passing background and reference checks.
  • Applicants must be authorized to work in the United States without the need for visa sponsorship now or in the future.
  • In compliance with federal law, all persons hired will be required to verify identity and eligibility to work in the United States and to complete the required employment eligibility verification form upon hire.

Company info

  • Merlin is a venture backed aerospace startup building a non-human pilot to enable both reduced crew and uncrewed flight.
  • Backed by some of the world's leading investors, Merlin is scaling alongside our customers to begin leveraging autonomy today to solve some of aviation's biggest challenges.
  • Engage with government customers and their security representatives to define, document, and implement security protection requirements with the technical rigor and fidelity that DoD authorization demands.

Visa & Work Authorization

  • At this time, we are unable to provide visa sponsorship or consider candidates who require visa transfers.

This listing is sourced directly from Merlin Labs's careers page and normalized into a canonical job model.