Security Engineer - Federal (FieldOps)

C3 AI
United States
Workplace: OnsiteFull timeUSD 134,000 - 167,000 annuallyFunction: CybersecurityExperience: 5+ yearsEducation: bachelorsSkills: ["Problem-solving","Attention to detail","Communication","Collaboration"]

Serve as the named technical owner for Federal release-gate evidence and Continuous Monitoring (ConMon) automation, ensuring deployments meet rigorous security standards across the FedRAMP/ATO boundary. Own per-release evidence across the 8 gates, build and maintain ConMon BOMs and metrics feeds, and act as the engineering interface with the boundary partner. Triage vulnerabilities, support SCAP/STIG and compliance tooling, and manage hardened container registries for Federal programs.

Loading

Loading job details...

Preparing the role view and application actions.

FursaFursa
C3 AI
C3 AI
2 weeks ago

Security Engineer - Federal (FieldOps)

✓ Verified Job

Canonical indexed version, validated from employer's careers page.

Source: Company careers pageValidated by: Fursa AI
Last checked: 25 minutes agoStatus: Live

Job Summary

Serve as the named technical owner for Federal release-gate evidence and Continuous Monitoring (ConMon) automation, ensuring deployments meet rigorous security standards across the FedRAMP/ATO boundary. Own per-release evidence across the 8 gates, build and maintain ConMon BOMs and metrics feeds, and act as the engineering interface with the boundary partner. Triage vulnerabilities, support SCAP/STIG and compliance tooling, and manage hardened container registries for Federal programs.
Location: United States
Workplace: Onsite
Employment Type: Full time
Job Function: Cybersecurity
Seniority: Mid level

Key Responsibilities

  • •Own per-release gate evidence across the 8 gates in the Federal Release-Gate Standard.
  • •Build and maintain Continuous Monitoring (ConMon) automation, including generated BOMs, POA&M classification automation, and live ConMon metrics feeds.
  • •Act as the engineering-level interface with SMX on FedRAMP boundary-register items (e.g., image provenance and patch-uplift vs. CA-6, SCAP scope).
  • •Address Federal customer security requirements across the deployment lifecycle, including STIG/SCAP/OpenSCAP compliance and hardened container registries.
  • •Triage and resolve security vulnerabilities and support upstream controls with product, engineering, compliance, and operations teams to maintain C3 AI security posture.

Pay and Benefits

Salary: USD 134,000 - 167,000 annually
Equity and Bonus:Equity

Key Requirements

  • •Bachelor's degree in Computer Science, Information Security, or a related field.
  • •5+ years of experience in information security, DevSecOps, or a related field.
  • •Strong understanding of security principles, practices, and technologies, including vulnerability management (CVEs/IOCs).
  • •Hands-on Linux experience and scripting languages such as JavaScript, Shell, and/or Python.
  • •Active DoD 8570 IAT II or above certification (e.g., CISSP or Security+), or ability to obtain; experience with SCAP/OpenSCAP and automated STIG scanning/remediation.
Experience:5+ years
Education:Bachelor's in Computer Science, Information Security, or a related field
Skills:Problem-solvingAttention to detailCommunicationCollaboration
Certifications:DoD 8570 IAT IICISSPSecurity+
Tech Stack:LinuxJavaScriptShellPythonSCAPOpenSCAPSTIGCVEIOCsConMonBOMPOA&MFedRAMPATOFIPSSBOMIron BankChainguardSCAP/OpenSCAP

Eligibility

Nationality:US National
Work Authorization:Authorization required. Sponsorship not provided.
Security Clearance:Secret

Company Brief

C3 AI
Provides an enterprise AI platform and applications that help organizations build, deploy, and operate machine learning and generative AI solutions across industries such as manufacturing, energy, defense, and finance.
Industry: AI & Machine Learning
Company Size: Enterprise (1,001+ employees)
Growth: Public Company
Valuation: Public Company (Market Cap in USD)
Funding: IPO / Publicly Listed
Headquarters: Redwood City, United States
Founded: 2009
WebsiteLinkedIn