Back to all jobs
C
About the role
<p>CHAOS Industries is redefining modern defense with a multi-product portfolio that gives the ultimate advantage—domain dominance. The company's products are powered by Coherent Distributed Networks (CDN™), empowering warfighters, commercial air operators, and border protection teams to act faster, adapt rapidly, and stay ahead of evolving threats. </p>
<p>CHAOS Industries was founded in 2022 and has raised a total of $1 billion in funding from leading investors, including 8VC, Accel, and Valor Equity Partners. The company is headquartered in Los Angeles, with offices in Washington, D.C., San Francisco, San Diego, Seattle, and London. For more information, please visit <a href="https://www.chaosinc.com">www.chaosinc.com</a>.</p>
<p><strong><span data-contrast="auto">Role Overview:</span></strong></p>
<p><span data-contrast="auto">We are seeking a Cybersecurity Engineer focused on Product Security to help design, assess, and secure our next-generation sensor platforms and supporting software ecosystems. This role will work closely with Software Engineering, Embedded Systems, Hardware Engineering, Infrastructure, and Program teams to ensure security is integrated throughout the product lifecycle — from architecture and development through deployment and operational support.</span><span data-ccp-props="{"134233117":false,"134233118":false,"335551550":1,"335551620":1,"335559738":240,"335559739":240}"> </span></p>
<p><span data-contrast="auto">The ideal candidate has experience securing complex software and hardware systems within defense, aerospace, or other highly regulated environments. This individual will lead software security architecture efforts, perform threat modeling and risk assessments, support compliance initiatives, and help establish secure engineering standards across the organization.</span><span data-ccp-props="{"134233117":false,"134233118":false,"335551550":1,"335551620":1,"335559738":240,"335559739":240}"> </span></p>
<p><span data-contrast="auto">This is a highly collaborative and hands-on role with direct impact on the security and resiliency of mission-critical technologies deployed in operational environments.</span><span data-ccp-props="{"134233117":false,"134233118":false,"335551550":1,"335551620":1,"335559738":240,"335559739":240}"> </span></p>
<p><strong><span data-contrast="auto">Responsibilities: </span></strong><span data-ccp-props="{"201341983":0,"335559685":360,"335559739":0,"335559740":240}"> </span></p>
<ul>
<li><strong><span data-contrast="auto"><span data-ccp-parastyle="heading 2">Product Security Engineering</span></span></strong><span data-ccp-props="{"134233117":false,"134233118":false,"134245418":true,"134245529":true,"335551550":1,"335551620":1,"335559738":299,"335559739":299}"> </span>
<ul>
<li><span data-contrast="auto">Design and implement secure software and hardware system architectures for mission-critical platforms and supporting infrastructure </span><span data-ccp-props="{"134233117":false,"134233118":false,"335551550":1,"335551620":1,"335559738":0,"335559739":0}"> </span></li>
<li><span data-contrast="auto">Partner with engineering teams to integrate security requirements throughout the software development lifecycle (SDLC) </span><span data-ccp-props="{"134233117":false,"134233118":false,"335551550":1,"335551620":1,"335559738":0,"335559739":0}"> </span></li>
<li><span data-contrast="auto">Conduct architecture reviews and identify security risks across software, embedded, cloud, and hardware systems </span><span data-ccp-props="{"134233117":false,"134233118":false,"335551550":1,"335551620":1,"335559738":0,"335559739":0}"> </span></li>
<li><span data-contrast="auto">Develop secure design standards, engineering guidance, and product security best practices </span><span data-ccp-props="{"134233117":false,"134233118":false,"335551550":1,"335551620":1,"335559738":0,"335559739":0}"> </span></li>
<li><span data-contrast="auto">Support secure development initiatives including code review, dependency management, secrets management, and vulnerability remediation </span><span data-ccp-props="{"134233117":false,"134233118":false,"335551550":1,"335551620":1,"335559738":0,"335559739":0}"> </span></li>
</ul>
</li>
<li><strong><span data-contrast="auto"><span data-ccp-parastyle="heading 2">Threat Modeling & Risk Assessment</span></span></strong><span data-ccp-props="{"134233117":false,"134233118":false,"134245418":true,"134245529":true,"335551550":1,"335551620":1,"335559738":299,"335559739":299}"> </span>
<ul>
<li><span data-contrast="auto">Lead threat modeling exercises for software, embedded systems, hardware platforms, and supporting infrastructure </span><span data-ccp-props="{"134233117":false,"134233118":false,"335551550":1,"335551620":1,"335559738":0,"335559739":0}"> </span></li>
<li><span data-contrast="auto">Conduct cybersecurity risk assessments for products, systems, and operational environments </span><span data-ccp-props="{"134233117":false,"134233118":false,"335551550":1,"335551620":1,"335559738":0,"335559739":0}"> </span></li>
<li><span data-contrast="auto">Identify attack surfaces, trust boundaries, and potential exploitation paths </span><span data-ccp-props="{"134233117":false,"134233118":false,"335551550":1,"335551620":1,"335559738":0,"335559739":0}"> </span></li>
<li><span data-contrast="auto">Work with engineering teams to prioritize and remediate identified security risks </span><span data-ccp-props="{"134233117":false,"134233118":false,"335551550":1,"335551620":1,"335559738":0,"335559739":0}"> </span></li>
<li><span data-contrast="auto">Develop mitigation strategies for cybersecurity threats impacting deployed systems and sensitive technologies </span><span data-ccp-props="{"134233117":false,"134233118":false,"335551550":1,"335551620":1,"335559738":0,"335559739":0}"> </span></li>
</ul>
</li>
<li><strong><span data-contrast="auto"><span data-ccp-parastyle="heading 2">Compliance & Security Authorization</span></span></strong><span data-ccp-props="{"134233117":false,"134233118":false,"134245418":true,"134245529":true,"335551550":1,"335551620":1,"335559738":299,"335559739":299}"> </span>
<ul>
<li><span data-contrast="auto">Support cybersecurity compliance initiatives and product authorization efforts including: </span><span data-ccp-props="{"134233117":false,"134233118":false,"335551550":1,"335551620":1,"335559738":0,"335559739":0}"> </span></li>
<li><span data-contrast="auto">RMF (Risk Management Framework) </span><span data-ccp-props="{"134233117":false,"134233118":false,"335551550":1,"335551620":1,"335559738":0,"335559739":0}"> </span></li>
<li><span data-contrast="auto">ATO (Authority to Operate) </span><span data-ccp-props="{"134233117":false,"134233118":false,"335551550":1,"335551620":1,"335559738":0,"335559739":0}"> </span></li>
<li><span data-contrast="auto">Export control and regulated data handling requirements </span><span data-ccp-props="{"134233117":false,"134233118":false,"335551550":1,"335551620":1,"335559738":0,"335559739":0}"> </span></li>
<li><span data-contrast="auto">Assist with development of system security documentation, security controls, SSPs, and assessment artifacts </span><span data-ccp-props="{"134233117":false,"134233118":false,"335551550":1,"335551620":1,"335559738":0,"335559739":0}"> </span></li>
<li><span data-contrast="auto">Support internal and external security audits, assessments, and accreditation activities </span><span data-ccp-props="{"134233117":false,"134233118":false,"335551550":1,"335551620":1,"335559738":0,"335559739":0}"> </span></li>
<li><span data-contrast="auto">Collaborate with government, customer, and program stakeholders on security requirements and authorization activities </span><span data-ccp-props="{"134233117":false,"134233118":false,"335551550":1,"335551620":1,"335559738":0,"335559739":0}"> </span></li>
</ul>
</li>
<li><strong><span data-contrast="auto"><span data-ccp-parastyle="heading 2">Security Testing & Validation</span></span></strong><span data-ccp-props="{"134233117":false,"134233118":false,"134245418":true,"134245529":true,"335551550":1,"335551620":1,"335559738":299,"335559739":299}"> </span>
<ul>
<li><span data-contrast="auto">Assist with security testing activities including vulnerability assessments, penetration testing coordination, and validation of remediation efforts </span><span data-ccp-props="{"134233117":false,"134233118":false,"335551550":1,"335551620":1,"335559738":0,"335559739":0}"> </span></li>
<li><span data-contrast="auto">Support secure configuration and hardening efforts across software, operating systems, and embedded environments </span><span data-ccp-props="{"134233117":false,"134233118":false,"335551550":1,"335551620":1,"335559738":0,"335559739":0}"> </span></li>
<li><span data-contrast="auto">Review software and system telemetry to identify potential security weaknesses or anomalous behavior </span><span data-ccp-props="{"134233117":false,"134233118":false,"335551550":1,"335551620":1,"335559738":0,"335559739":0}"> </span></li>
<li><span data-contrast="auto">Collaborate with Security Operations and Infrastructure teams to improve enterprise and product security visibility </span><span data-ccp-props="{"134233117":false,"134233118":false,"335551550":1,"335551620":1,"335559738":0,"335559739":0}"> </span></li>
</ul>
</li>
<li><strong><span data-contrast="auto"><span data-ccp-parastyle="heading 2">Cross-Functional Collaboration</span></span></strong><span data-ccp-props="{"134233117":false,"134233118":false,"134245418":true,"134245529":true,"335551550":1,"335551620":1,"335559738":299,"335559739":299}"> </span>
<ul>
<li><span data-contrast="auto">Work closely with Software, Embedded, Hardware, DevOps, and Infrastructure teams to balance security, performance, and operational requirements </span><span data-ccp-props="{"134233117":false,"134233118":false,"335551550":1,"335551620":1,"335559738":0,"335559739":0}"> </span></li>
<li><span data-contrast="auto">Contribute to the development of scalable product security processes and governance </span><span data-ccp-props="{"134233117":false,"134233118":false,"335551550":1,"335551620":1,"335559738":0,"335559739":0}"> </span></li>
<li><span data-contrast="auto">Support customer and internal security reviews related to deployed technologies and operational environments </span><span data-ccp-props="{"134233117":false,"134233118":false,"335551550":1,"335551620":1,"335559738":0,"335559739":0}"> </span></li>
<li><span data-contrast="auto">Mentor engineering teams on secure development and security-by-design principles </span><span data-ccp-props="{"134233117":false,"134233118":false,"335551550":1,"335551620":1,"335559738":0,"335559739":0}"> </span></li>
</ul>
</li>
</ul>
<p><span data-ccp-props="{"201341983":0,"335559685":360,"335559739":0,"335559740":240}"> </span><strong><span data-contrast="auto">Minimum Requirements:</span></strong><span data-ccp-props="{"201341983":0,"335559685":360,"335559739":0,"335559740":240}"> </span></p>
<ul>
<li><span data-contrast="auto">5+ years of experience in cybersecurity engineering, product security, application security, or related engineering roles </span><span data-ccp-props="{"134233117":false,"134233118":false,"335551550":1,"335551620":1,"335559738":0,"335559739":0}"> </span></li>
<li><span data-contrast="auto">Experience with software security design and secure system architecture principles </span><span data-ccp-props="{"134233117":false,"134233118":false,"335551550":1,"335551620":1,"335559738":0,"335559739":0}"> </span></li>
<li><span data-contrast="auto">Hands-on experience conducting threat modeling and cybersecurity risk assessments </span><span data-ccp-props="{"134233117":false,"134233118":false,"335551550":1,"335551620":1,"335559738":0,"335559739":0}"> </span></li>
<li><span data-contrast="auto">Knowledge of secure software development lifecycle (SSDLC) practices and application security concepts </span><span data-ccp-props="{"134233117":false,"134233118":false,"335551550":1,"335551620":1,"335559738":0,"335559739":0}"> </span></li>
<li><span data-contrast="auto">Familiarity with cybersecurity frameworks and compliance standards including: </span><span data-ccp-props="{"134233117":false,"134233118":false,"335551550":1,"335551620":1,"335559738":0,"335559739":0}"> </span></li>
<li><span data-contrast="auto">RMF </span><span data-ccp-props="{"134233117":false,"134233118":false,"335551550":1,"335551620":1,"335559738":0,"335559739":0}"> </span></li>
<li><span data-contrast="auto">NIST 800-53 </span><span data-ccp-props="{"134233117":false,"134233118":false,"335551550":1,"335551620":1,"335559738":0,"335559739":0}"> </span></li>
<li><span data-contrast="auto">NIST 800-171 </span><span data-ccp-props="{"134233117":false,"134233118":false,"335551550":1,"335551620":1,"335559738":0,"335559739":0}"> </span></li>
<li><span data-contrast="auto">CMMC </span><span data-ccp-props="{"134233117":false,"134233118":false,"335551550":1,"335551620":1,"335559738":0,"335559739":0}"> </span></li>
<li><span data-contrast="auto">DFARS </span><span data-ccp-props="{"134233117":false,"134233118":false,"335551550":1,"335551620":1,"335559738":0,"335559739":0}"> </span></li>
<li><span data-contrast="auto">Experience supporting security authorization activities such as ATO processes and security documentation development, and eMASS</span><span data-ccp-props="{"134233117":false,"134233118":false,"335551550":1,"335551620":1,"335559738":0,"335559739":0}"> </span></li>
<li><span data-contrast="auto">Understanding of cloud, endpoint, network, and identity security concepts </span><span data-ccp-props="{"134233117":false,"134233118":false,"335551550":1,"335551620":1,"335559738":0,"335559739":0}"> </span></li>
<li><span data-contrast="auto">Strong analytical, troubleshooting, and technical communication skills </span><span data-ccp-props="{"134233117":false,"134233118":false,"335551550":1,"335551620":1,"335559738":0,"335559739":0}"> </span></li>
<li><span data-contrast="auto">Ability to operate effectively in a fast-paced startup environment </span><span data-ccp-props="{"134233117":false,"134233118":false,"335551550":1,"335551620":1,"335559738":0,"335559739":0}"> </span></li>
<li><span data-ccp-props="{"134233117":false,"134233118":false,"335559738":0,"335559739":0}">Must be a U.S. Citizen eligible for government facilities and sensitive information</span></li>
<li><span data-ccp-props="{"134233117":false,"134233118":false,"335559738":0,"335559739":0}">Ability to obtain additional security clearances as required by contract</span></li>
</ul>
<p><strong><span data-contrast="auto">Preferred Requirements:</span></strong><span data-ccp-props="{"201341983":0,"335559685":360,"335559739":0,"335559740":240}"> </span></p>
<ul>
<li><span data-contrast="auto">Active Security Clearance</span></li>
<li><span data-contrast="auto">Experience supporting defense, aerospace, government contracting, or regulated technology environments </span><span data-ccp-props="{"134233117":false,"134233118":false,"335551550":1,"335551620":1,"335559738":0,"335559739":0}"> </span></li>
<li><span data-contrast="auto">Experience securing embedded systems, sensor platforms, or edge computing technologies </span><span data-ccp-props="{"134233117":false,"134233118":false,"335551550":1,"335551620":1,"335559738":0,"335559739":0}"> </span></li>
<li><span data-contrast="auto">Familiarity with export control requirements including ITAR and EAR </span><span data-ccp-props="{"134233117":false,"134233118":false,"335551550":1,"335551620":1,"335559738":0,"335559739":0}"> </span></li>
<li><span data-contrast="auto">Experience with secure DevSecOps pipelines and automation practices </span><span data-ccp-props="{"134233117":false,"134233118":false,"335551550":1,"335551620":1,"335559738":0,"335559739":0}"> </span></li>
<li><span data-contrast="auto">Experience with Microsoft GCC High environments and regulated cloud architectures </span><span data-ccp-props="{"134233117":false,"134233118":false,"335551550":1,"335551620":1,"335559738":0,"335559739":0}"> </span></li>
<li><span data-contrast="auto">Firmware development experience </span><span data-ccp-props="{"134233117":false,"134233118":false,"335551550":1,"335551620":1,"335559738":0,"335559739":0}"> </span></li>
<li><span data-contrast="auto">BIOS/UEFI security or development experience </span><span data-ccp-props="{"134233117":false,"134233118":false,"335551550":1,"335551620":1,"335559738":0,"335559739":0}"> </span></li>
<li><span data-contrast="auto">Hardware security design experience </span><span data-ccp-props="{"134233117":false,"134233118":false,"335551550":1,"335551620":1,"335559738":0,"335559739":0}"> </span></li>
<li><span data-contrast="auto">Trusted Platform Module (TPM), secure boot, cryptographic hardware, or supply chain security knowledge </span><span data-ccp-props="{"134233117":false,"134233118":false,"335551550":1,"335551620":1,"335559738":0,"335559739":0}"> </span></li>
<li><span data-contrast="auto">Experience with scripting or automation using Python, PowerShell, or Bash </span><span data-ccp-props="{"134233117":false,"134233118":false,"335551550":1,"335551620":1,"335559738":0,"335559739":0}"> </span></li>
<li><span data-contrast="auto">Security certifications such as CISSP, CSSLP, GSEC, Security+, or equivalent </span><span data-ccp-props="{"134233117":false,"134233118":false,"335551550":1,"335551620":1,"335559738":0,"335559739":0}"> </span></li>
</ul>
<p><strong>Why CHAOS?</strong></p>
<ul>
<li><strong>Health Benefits: </strong>Medical, dental, and vision benefits 100% paid for by the company</li>
<li><strong>Additional benefits</strong>: 401k (+ 50% company match up to 6% of pay), FSA, HSA, life insurance, and more</li>
<li><strong>Our Perks: </strong>Free daily lunch, ‘No meeting Fridays’, unlimited PTO, casual dress code</li>
<li><strong>Compensation Components:</strong> Competitive base salaries, generous pre-IPO stock option grants, relocation assistance, and (coming soon!) annual bonuses</li>
<li><strong>Team Growth: </strong>250 employees and counting across 5 global offices</li>
</ul>
<div><em><strong>Salary Range: $110,000 - $190,000</strong></em></div>
<p><em>The stated compensation range reflects only the targeted base compensation range and excludes additional earnings such as bonus, equity, and benefits. If your compensation requirements fall outside of the range, we still encourage you to apply. The salary range for this role is an estimate based on a range of compensation factors, inclusive of base salary only. Actual salary offer may vary based on (but not limited to) work experience, education and/or training, critical skills, and/or business considerations. </em></p>
<p> </p>
<hr>
<h3>Recruiting Agencies: CHAOS Industries does not accept unsolicited resumes or outreach. Unsolicited submissions will not be reviewed or compensated.</h3>
<hr>
<p> </p>
<p><em>#LI-onsite</em></p>
Perks & benefits
- 401k
- Vision Insurance
- Unlimited Vacation
- Paid Time Off
- Pension Matching
- Equity Compensation
747,000+ hidden jobs like this
CHAOS Industries and thousands of companies post here first — often days before LinkedIn or Indeed. Your first 5 applications are free; go Pro to apply without limits.
Everything Pro unlocks:
- Unlimited applications — free stops at 5
- Track every application in one place
- Apply straight to the source, one click
- Save & organize roles you love
- Roles pulled from company boards before the big sites