Senior Ground Software Engineer (Cyber Compliance)

Senior Ground Software Engineer (Compliance Exposure)

Overview

We’re hiring a Senior Ground Software Engineer to join a backend/platform engineering team building mission-critical systems in a highly regulated environment.

This is an engineering-first role focused on designing, building, and maintaining production software systems and infrastructure. The ideal candidate will have strong backend engineering experience alongside exposure to environments operating under standards such as CMMC, SOC2, FedRAMP, GovCloud, or similar compliance frameworks.

This is not a pure cybersecurity role — the focus is on building scalable systems while understanding how security and compliance requirements impact software development and operations.


Key Responsibilities

  • Design, build, and maintain backend services and distributed systems
  • Write and review production-level code
  • Contribute to cloud infrastructure and DevOps workflows
  • Support CI/CD, automation, and deployment processes
  • Collaborate with engineering and security stakeholders to ensure systems align with compliance requirements
  • Participate in architecture discussions, code reviews, and operational support

Required Experience

  • Strong backend software engineering experience
  • Hands-on experience with:
    • Go (Golang) preferred
    • Or another strongly typed language (Java, C++, Rust, C#)
  • AWS/cloud infrastructure experience
  • Experience building and owning production applications/services
  • Familiarity with regulated/compliance-driven environments

Nice to Have

  • Terraform / Infrastructure-as-Code
  • Docker / Kubernetes
  • CI/CD pipelines
  • Experience with GovCloud, FedRAMP, CMMC, SOC2, or NIST-aligned environments
  • Distributed systems / microservices experience

What We’re Looking For

  • Backend engineer first, not security-first
  • Comfortable operating in fast-paced technical environments
  • Strong ownership mentality
  • Able to balance engineering velocity with compliance/security expectations

Qualification Call Notes – Senior GSW (Compliance Exposure)

Core Hiring Need

  • NOT a cyber hire anymore
  • Looking for a:
    • Senior backend/platform engineer
    • With exposure to regulated/compliance-heavy environments
  • Security/compliance ownership sits with another team

Must-Haves

  • Go/Golang
    • Strong preference for production experience
    • At minimum: meaningful personal/project exposure + strong typed language background
  • Backend/service ownership experience
  • AWS exposure
  • Strong software engineering fundamentals

Preferred Background

  • Engineers from:
    • Government
    • Defense
    • Healthcare
    • Fintech
    • Other regulated industries
  • Exposure to:
    • CMMC
    • SOC2
    • FedRAMP
    • GovCloud
    • NIST

Tech Stack

Core

  • Go/Golang
  • AWS
  • Backend systems / APIs
  • Distributed systems

Secondary / Nice-to-Have

  • Terraform
  • Docker/Kubernetes
  • CI/CD
  • Python

Day-to-Day Split

  • ~60% coding
  • ~20% reviewing/standards
  • ~20% infrastructure/Terraform

What Good Looks Like

  • Strong backend engineer first
  • Has built applications/services end-to-end
  • Comfortable in compliance-heavy environments
  • Can work closely with infrastructure/security teams
  • Ownership mentality

Red Flags

  • Pure DevOps engineers
  • Pure cybersecurity engineers
  • No Go experience
  • No strongly typed language background
  • Pipeline/infrastructure-only experience
  • No application ownership

Screening Questions

  • What production systems/services have you owned?
  • What’s your strongest language day-to-day?
  • How much Go experience do you have?
  • Have you worked in regulated/compliance-heavy environments?
  • Have you worked alongside security/compliance requirements in production systems?
  • What AWS services are you most comfortable with?
  • Any Terraform/IaC exposure?

Logistics

  • US Citizen required
  • Hybrid role (Lanham/DC area)
  • Backend-heavy despite “full-stack” wording
  • Supporting mission-critical/defense-related systems