
Software Engineer - Software Infrastructure (Cybersecurity)
What you need
- 8-10 yrs software infrastructure security experience
- Deep Docker/Docker Compose container hardening expertise
- Ansible/Chef/Terraform provisioning and IaC experience
- Secrets management with Vault, PKI, HSM
- Linux security hardening (SELinux, AppArmor, encryption)
What you'll do
- Design and harden containerized edge/cloud infrastructure
- Build automated provisioning for air-gapped environments
- Manage secrets lifecycle across disconnected fleets
- Implement DoD/IC security controls (RMF, STIGs)
- Optimize systems for DDIL network conditions
CX2 is seeking an experienced Software Infrastructure Engineer specializing in cybersecurity to harden the infrastructure that lets CX2 detect, disrupt, and defend the electromagnetic spectrum.
You will own the security of our edge and hybrid cloud infrastructure from end to end. That means how devices are provisioned, how secrets are issued and rotated, and how systems are locked down, monitored, and accredited. All of it has to hold up in disrupted, degraded, intermittent, or limited (DDIL) network conditions. Your work ensures that CX2’s sensor and effector systems, and the platform that orchestrates them, can be trusted on any battlefield.
As a key member of CX2’s foundational engineering team, you will shape our security architecture, strengthen our engineering culture, and help deliver powerful electromagnetic warfare capabilities.
Key Responsibilities
Secure Infrastructure Engineering: Design, harden, and defend containerized application infrastructure across small form factor edge compute and cloud environments. Lead threat modeling, vulnerability management, and security reviews, and evaluate and adopt new tools that maximize system security and reliability while protecting developer velocity.
Provisioning and Configuration Management: Build and maintain automated, reproducible provisioning and installation frameworks (Ansible, Chef, etc.) that take hardware and cloud hosts from bare metal to a hardened, mission-ready baseline, including in air-gapped and disconnected environments.
Secrets Management: Own the lifecycle of secrets, keys, and certificates across the fleet, including issuance, distribution, rotation, and revocation, for systems that must operate with intermittent or no connectivity.
Constrained and Disconnected Environments: Optimize resource usage and harden against denied or degraded network conditions to serve both mobile and web based clients.
Fulfill Department of Defense (DoD) and Intelligence Community (IC) Requirements: Understand, implement, and document the security controls needed to meet the software accreditation and certification standards set forth by the United States DoD and IC.
Required Qualifications
Minimum of 8-10 years of experience building, securing, and operating software infrastructure at the edge, on premises, or in the cloud.
Strong foundation in cybersecurity, including system and network hardening, threat modeling, vulnerability management, and incident response.
Deep understanding of containerization technologies, with a focus on Docker and Docker Compose, including image building and hardening, container networking and storage, runtime isolation (namespaces, cgroups, seccomp, capabilities, rootless containers), and securing images and registries.
Hands-on experience with provisioning and configuration management frameworks (Ansible, Chef, Puppet, SaltStack, etc.) and Infrastructure-as-Code tools (Terraform, OpenTofu, etc.).
Experience with secrets management and PKI (HashiCorp Vault, OpenBao, AWS KMS, SOPS, TPM or HSM backed keys, etc.).
Deep proficiency with Linux administration and security (SELinux, AppArmor, firewalls, auditing, disk encryption).
Willing to work extended hours for mission critical deadlines.
Bachelor’s degree in Computer Science, Computer Engineering, Cybersecurity, or a related technical field, or equivalent relevant experience.
Preferred Qualifications
Experience configuring, building, and hardening custom Linux kernels.
Experience building and maintaining board support packages (BSPs) for embedded or small form factor hardware (L4T, Yocto, Buildroot, U-Boot, etc.), including secure and measured boot.
Familiarity with DoD security frameworks and accreditation processes (RMF, DISA STIGs, NIST SP 800-53, FedRAMP, Impact Level (IL) 4-6).
Expertise with government cloud platforms (AWS GovCloud, Azure Government Cloud).
Proficiency with server and embedded Linux distributions (Ubuntu, NixOS, RHEL).
Familiarity with container orchestration platforms such as Kubernetes (K3s, Rancher RKE2, etc.).
Experience securing CI/CD pipelines and the software supply chain (SBOMs, artifact signing, reproducible builds).
Security certifications such as CompTIA Security+, CISSP, or OSCP.
Active Secret or TS/SCI security clearance.
ITAR Requirements
What We Offer
Competitive salary, stock options and benefits, including health, vision and dental.
401K enrollment at 90 days.
Unlimited PTO plus most Federal Holidays observed.
High levels of responsibility and autonomy.
Professional growth and development opportunities.
Optimize your resume for this job
Get a match score and the keywords you're missing
About CX2
The future of warfare will be fought and won in the electromagnetic spectrum. In battlefields dominated by remotely-operated, unmanned systems, connectivity and control are as critical as firepower. The RF spectrum is the new frontline. At CX2, we’re fighting to deliver spectrum dominance for the United States and our Allies.
Similar Software roles


