Oddball believes that the best products are built when companies understand and value the things they are working on. We value learning and growth and the ability to make a big impact at a small company. We believe that we can make big changes happen and improve the daily lives of millions of people by bringing quality software to the federal space.
We’re looking for a Security Engineer to join our SEC team, working alongside our DevSecOps engineers to harden our cloud environment, maintain our ATO, and actively drive down the program’s POAM backlog.
What you’ll be doing:
- Deploy and automate CI/CD pipelines and establish IaC using modern DevSecOps techniques including serverless and Zero Trust patterns
- Own the POAM process end to end — develop a plan of attack with target dates, track progress in real time, and close findings proactively
- Assess incoming security findings, identify duplicates and dependencies, and develop LOEs for remediation
- Conduct Security Impact Analyses (SIAs) to achieve and maintain ATO
- Implement data tagging and sensitivity management practices to reduce the SEC’s ATO management burden
- Engage directly with engineers and external stakeholders to drive remediation forward
- Maintain a live dashboard and tracker for all security findings and POAM status
What you’ll bring:
Hands-on experience remediating POAMs and navigating the federal ATO process
Proficiency with AWS environments and cloud security practices
Experience with CI/CD pipelines, CloudFormation, and infrastructure as code
Familiarity with Zero Trust principles and federal cybersecurity frameworks including FISMA and NIST 800-53
Strong organizational skills with the ability to manage multiple findings, timelines, and stakeholders simultaneously
Comfortable engaging directly with engineers and external stakeholders to move remediation forward
Experience with Docker and containerized environments is a plus
Thrives in a remote, collaborative Agile environment and genuinely enjoys working closely with a cross-functional team
Communicates clearly and openly, whether updating a tracker or presenting findings to leadership
Performs other related duties as assigned
Requirements:
- Applicants must be authorized to work in the United States. In alignment with federal contract requirements, certain roles may also require U.S. citizenship and the ability to obtain and maintain a federal background investigation and/or a security clearance.
Education:
- Bachelor’s degree
Benefits:
- Fully remote
- Annual stipend
- Comprehensive Benefits Package
- Company Match 401(k) plan
- Flexible PTO, Paid Holidays
Oddball is an Equal Opportunity Employer and does not discriminate against applicants based on race, religion, color, disability, medical condition, legally protected genetic information, national origin, gender, sexual orientation, marital status, gender identity or expression, sex (including pregnancy, childbirth or related medical conditions), age, veteran status or other legally protected characteristics. Any applicant with a mental or physical disability who requires an accommodation during the application process should contact an Oddball HR representative to request such an accommodation by emailing hello@Oddball.io
Compensation:
At Oddball, it’s important each employee is compensated competitively and fairly. In alignment with state legal requirements. A range for the included position is listed below. Be advised, actual offer details are determined by job category, job location, and candidate skill level.
United States Wage Range: $120,000 – $155,000
Career Guide for Security Engineer at Oddball
Job Overview
As a Security Engineer at Oddball, you’ll focus on enhancing the security of cloud environments, ensuring compliance with federal regulations, and driving the effectiveness of software security measures. Your role is crucial in maintaining the company’s security posture while working in a collaborative DevSecOps team.
Key Responsibilities
- Deploy and automate Continuous Integration/Continuous Deployment (CI/CD) pipelines.
- Manage and remediate the Plan of Actions and Milestones (POAM) process.
- Assess security findings and prioritize actionable insights.
- Conduct Security Impact Analyses (SIAs) to maintain Authorization to Operate (ATO).
- Implement data management practices to streamline ATO processes.
- Collaborate with engineers and stakeholders to drive security advancements.
- Maintain a dashboard to track security findings and POAM status.
Required Skills and Knowledge
Technical Skills
- Cloud Security: Proficiency with AWS environments and cloud security practices.
- DevSecOps: Experience with CI/CD pipelines, CloudFormation, and Infrastructure as Code (IaC).
- Security Frameworks: Familiarity with Zero Trust principles, FISMA, and NIST 800-53.
- Containerization: Experience with Docker and containerized environments (a plus).
Soft Skills
- Strong organizational abilities for managing multiple tasks and timelines.
- Effective communication skills, both verbal and written, for engaging with teams and stakeholders.
- Collaboration skills to work effectively in a remote Agile environment.
Tools and Technologies
- AWS, Docker, CI/CD tools, CloudFormation, security tracking dashboards.
Certifications or Training
- Certifications such as AWS Certified Security – Specialty or Certified Information Systems Security Professional (CISSP) can enhance qualifications.
Interview Preparation
Common Interview Questions
What is your experience with federal ATO processes?
- Structure your answer around specific experiences and challenges faced.
Can you explain the principles of Zero Trust architecture?
- Discuss how Zero Trust can improve security and any practical experiences.
How do you prioritize security findings?
- Share your process and tools used for prioritization.
What steps do you take in conducting a Security Impact Analysis?
- Detail your approach and any specific experiences.
How have you automated CI/CD pipelines in your previous roles?
- Provide examples of tools you used and the outcomes.
Describe your experience with data tagging and sensitivity management.
- Discuss your processes and its impact on ATO management.
How do you handle conflicts that arise with stakeholders during security remediation?
- Share your conflict resolution strategies.
What tools do you use to track security findings?
- Mention specific dashboards or software and their effectiveness.
Can you give an example of a challenging security remediation you successfully managed?
- Discuss the challenge, your approach, and the outcome.
Why are you interested in working at Oddball?
- Align your motivations with the company’s values and mission.
Important Topics to Review
- Federal cybersecurity frameworks (FISMA, NIST 800-53).
- Best practices in DevSecOps and CI/CD pipeline automation.
- Cloud security standards, particularly for AWS.
- Current trends in cybersecurity and Zero Trust implementations.
How to Increase Your Hiring Chances
CV Improvement
- Highlight relevant experiences with federal compliance, cloud security, and automation.
- Use action verbs and quantify achievements when possible (e.g., reduced ATO timelines by X%).
LinkedIn Profile Optimization
- Reflect your skills and experiences pertinent to the job.
- Engage with security-related content or share articles that showcase your expertise.
Portfolio or Project Ideas
- Create a GitHub repository with sample CI/CD pipelines or automation scripts.
- Document a project that outlines your approach to security remediation and results achieved.
Learning Recommendations
- Enroll in online courses for advanced AWS security or DevSecOps practices.
- Participate in cybersecurity hackathons or workshops to gain practical experience.
Career Growth
Possible career trajectories may include:
- Senior Security Engineer
- Security Architect
- DevSecOps Manager
- Chief Information Security Officer (CISO)
Investing in continuous education, certifications, and gaining hands-on experience will support your advancement in this field.
How to Apply
Apply for this position through the original job source:

