Security Engineer
Role summary
We are seeking a Security Engineer to join our growing security function as an early hire. This role will be instrumental in shaping our security posture, focusing initially on securing Microsoft 365 environments (commercial and GCC-High) and supporting CMMC L2 compliance. You will implement security controls, integrate DevSecOps practices, build automation for security workflows, and contribute to security architecture decisions. The ideal candidate has 7+ years of security engineering experience, with significant depth in Microsoft cloud security and hands-on experience with compliance frameworks like CMMC L2 and NIST 800-171. You should also have demonstrated experience with DevSecOps and scripting/automation for security operations. This role offers a unique opportunity to influence security design in a fast-paced, mission-driven environment.
About Us
We’re a combat-tested group of engineers, operators, and entrepreneurs who believe America’s edge depends on autonomous airpower that’s trusted and deployable today, not in 2040. Backed by tier-one investors, we’ve secured the runway - financial, regulatory, and literal - to move at startup speed while tackling a national-security mission that matters. We’ve structured the company for radical ownership: no silos, no “systems integrator” overhead, just tightly knit mission-focused IPTs that live and breathe the hardware and code they ship.
If you thrive where hard-tech ambition meets national-security urgency, you’ll build faster here than anywhere else. Let’s get after it.
Culture That Ships
Strong Core Values, Startup Execution.
Integrity, Service Before Self, Excellence, Honor, Courage, Commitment—powered by a bias for action and a “figure it out” mindset.
Self-Starters Only.
You’ll have clear objectives, a blank sheet of paper, and the trust (plus capital) to move fast. Bureaucracy stays out of your way.
One Team, No Tourists.
Whether you’re tuning a control law at 2 a.m. or heat-treating a Ti-6Al-4V spar, everyone sweats the details. We celebrate wins together and own failures together.
What’s In It For You
Mission With a Pulse
. Every line of code, bracket, or test you deliver expands the toolbox of the warfighter on Day 1 of a conflict.
Resources Without Red Tape
. VC speed + DoD customer pull: access to test ranges, flight hours, and operator feedback while retaining startup agility.
Career-Defining Upside
. Significant equity, best-in-class benefits, and the chance to see your product deliver in months, not decades.
About The Role
We're looking for a Security Engineer to join our growing security function. As an early hire on the team, you'll have a front row seat in shaping not just how we protect our environment today, but how security is designed, governed, and scaled going forward. The immediate work is hands-on: securing our Microsoft 365 commercial and GCC-High environments, supporting our CMMC L2 compliance posture, and working with developers to ensure our processes are built with security in mind from the start.
The future holds the chance to define how the security team grows alongside engineers, IT, and compliance. While your primary focus will be on the immediate needs of cloud- and IT-security, there will be opportunities to influence the secure design of the aircraft, if you want them.
We believe security is an enabler, not a blocker. The right person for this role shares that mindset and knows how to move fast with guardrails rather than block with gates.
We know there’s a lot of ground to cover and that successful candidates won’t necessarily have experience in everything we need to do. If you’re solid in one or more areas and hungry to grow in the rest, apply.
What You'll Do
- Spearhead security efforts and improvements for our Microsoft 365 commercial and GCC-High environments, covering identity, device management, data protection, and access governance.
- In coordination with the GRC engineer, design, implement, and maintain security controls aligned to compliance frameworks like CMMC L2 and ISO 27001, with an eye toward repeatability, auditability, and scale.
- Partner with our MSP/MSSP on security operations and maintain internal ownership of security outcomes alongside the Head of Security.
- Provide incident response, when needed, to augment our MSSP.
- Embed security into our development lifecycle through DevSecOps practices, ensuring pipelines, repositories, and deployment processes meet security standards without becoming a bottleneck.
- Build and maintain automation to support configuration management, compliance evidence collection, alerting, and remediation workflows.
- Contribute to security architecture decisions, including environment design, tooling selection, segmentation strategy, and cloud security posture management.
- Develop and maintain security documentation, runbooks, and procedures that reduce single-point-of-failure risk and support future team growth.
- Communicate security risk clearly to both technical and non-technical stakeholders, translating complexity into decisions the business can act on.
What You'll Bring
- 7+ years of security engineering experience with meaningful depth in Microsoft cloud security.
- Hands-on experience implementing NIST 800-171 and CMMC L2 controls in a technical capacity, including system boundary management and evidence production.
- Demonstrated experience with DevSecOps practices, including securing CI/CD pipelines, managing secrets, and integrating security tooling into development workflows.
- Scripting or automation experience (PowerShell, Python, or Bash) applied to security operations, configuration management, or compliance workflows.
- Enough architectural awareness to contribute meaningfully to environment design conversations, not just execute on them.
- Strong documentation and communication skills suited to a cross-functional environment where security is one piece of a broader compliance and business program.
- The ability to see the big picture: understanding how individual security decisions connect to regulatory posture, business risk, and company growth.
Bonus Points
- Exposure to operational or platform security beyond corporate IT (cloud infrastructure, SaaS security, endpoint detection).
- Experience designing and implementing guardrails on AI-powered tooling (e.g., Claude Code)
- Experience building or evolving a security program at a startup or high-growth company.
- Current clearance (Secret or above) is nice but not required.
- Certifications that aid with 8140 compliance (CISSP, CISM, CISA, etc)
Why You’ll Love Working Here (Compensation And Benefits)
Base Salary: $170,000 to $225,000 USD
Benefits
The salary range for this role is an estimate based on a wide range of compensation factors, inclusive of base salary only. Actual salary offer may vary based on (but not limited to) work experience, education and/or training, critical skills, and/or business considerations. Highly competitive equity grants are included in the majority of full time offers; and are considered part of Atropos's total compensation package. Additionally, Atropos offers top-tier benefits for full-time employees, including:
- Platinum Healthcare Benefits: Atropos offers comprehensive medical, dental, and vision plans with 100% employer-paid premiums and little to no cost to you
- Basic Life/AD&D and long-term disability insurance 100% covered by Atropos, plus the option to purchase additional life insurance for you and your dependents
- Unlimited PTO, with minimum of 15 days enforced
- 20 weeks of paid Caregiver & Wellness Leave to care for a family member, bond with your baby, or tend to your own medical condition
- Family Planning & Parenting Support: Fertility (eg, IVF, preservation), adoption, and gestational carrier coverage with additional benefits and resources to provide support from planning to parenting
- Mental Health Resources: We provide free mental health resources 24/7 including therapy, life coaching, and more. Additional work-life services, such as free legal and financial support, available to you as well
- Tuition and professional development reimbursement for STEM, MBA, and licenses
- In-Office Daily Lunch catered
- Company-funded child care stipend
- Company-funded commuter benefits available based on your region.
- Relocation assistance (depending on role eligibility).
- 401(k) retirement savings plan - both a traditional and Roth 401(k). 6% employer matching contribution
The recruiter assigned to this role can share more information about the specific compensation and benefit details associated with this role during the hiring process.
Atropos is an equal-opportunity employer committed to creating a diverse and inclusive workplace. The Atropos team is made up of incredibly talented and unique individuals. All qualified applicants will be treated with respect and receive equal consideration for employment without regard to race, color, creed, religion, sex, gender identity, sexual orientation, national origin, disability, uniform service, Veteran status, age, or any other protected characteristic per federal, state, or local law, including those with a criminal history, in a manner consistent with the requirements of applicable state and local laws. We actively encourage members of recognized minorities, women, Veterans, and those with disabilities to apply, and we work to create a welcoming and supportive environment for all applicants throughout the interview process. If you are someone who is interested in disrupting the way the Department of Defense buys and operates unmanned weapon systems, please apply!
Similar roles
Staff Security EngineerPivotal Health · Los Angeles, California, United States · Hybrid- Security EngineerLawrence Harvey · Toronto, Ontario, Canada · Hybrid
- Security EngineerARQ · New York, New York, United States · Remote
Security EngineerAP Professionals · United States · Remote- Senior Security EngineerSystems Integration Solutions · Cupertino, California, United States · Onsite