Quantum Sky Engineering LLC

Senior Software Engineer

Location US-Remote
ID 2026-2135
Category
Information Technology
Position Type
Full-Time

Description

Quantum Sky is searching for a Senior Full-Stack Software Engineer to build and enhance cloud-based and on-premise cybersecurity and compliance applications for highly regulated environments. This is a hands-on development role

The ideal candidate is a strong software engineer with experience developing applications in FISMA/FedRAMP environments and familiarity with NIST security and compliance frameworks. They are comfortable owning software across the full development lifecycle—from design and development through CI/CD, deployment, and production operations—and can effectively work across software development, cloud infrastructure, cybersecurity, and compliance.

This role includes work on data-intensive risk and compliance analytics products: applications that ingest security and inventory data from multiple, heterogeneous, and sometimes inconsistent sources, normalize it into a consistent internal model, and present risk, gap, and prioritization analytics to different classes of users (executive, program-management, and technical).

Responsibilities:

  • Design, develop, test, and maintain full-stack application capabilities with an emphasis on secure, scalable, maintainable, and production-ready software.
  • Develop backend services, APIs, integrations, automation, and supporting tools.
  • Build new product capabilities and enhance existing functionality across cloud-based/on-premise cybersecurity and compliance applications, including backend services and user-facing application features.
  • Design and implement integrations with cloud services, security technologies, vulnerability management platforms, monitoring solutions, and third-party systems using REST APIs and structured.
  • Develop capabilities that ingest, process, correlate, and present security and compliance information while automating workflows such as security monitoring, vulnerability management, evidence collection, control management, and reporting.
  • Design data models and normalization/correlation logic capable of reconciling overlapping or conflicting records from multiple independent data sources into a single, consistent, and traceable representation, preserving source provenance and confidence.
  • Design and implement configurable scoring, prioritization, or risk-analytics logic as discrete, testable components rather than embedded business rules — supporting features such as gap analysis, trend analysis, and what-if/scenario comparison.
  • Model relationships and dependencies between assets, systems, and organizational entities in a way that supports drill-down analysis and can scale toward graph-based or dependency-graph representations as products mature.
  • Implement role-based access control and role-differentiated views so that different user types (executive, program/system management, technical) see appropriately scoped and appropriately detailed information.
  • Develop, maintain, and improve CI/CD pipelines and automated deployment processes that support application builds, automated testing, security validation, and reliable deployment across development, staging, and production environments.
  • Build, deploy, and support containerized and cloud-native applications, collaborating with cloud and DevOps engineers to improve application scalability, reliability, observability, security, and performance.
  • Use AI-assisted software development tools such as Claude Code, OpenAI Codex, Cursor, GitHub Copilot, or similar technologies as part of day-to-day engineering workflows to accelerate coding, debugging, refactoring, testing, documentation, and code analysis.
  • Apply engineering judgment when working with AI-generated code and recommendations, validating outputs for correctness, security, maintainability, performance, and alignment with engineering standards.
  • Troubleshoot complex application, integration, deployment, and production issues, identify root causes, and implement sustainable solutions.
  • Participate throughout the software development lifecycle, including architecture and design discussions, code reviews, testing, documentation, release management, deployment, and continuous improvement of engineering practices.
  • Apply secure software development and DevSecOps practices throughout the application lifecycle and collaborate with cybersecurity and compliance subject matter experts to translate security and domain requirements into practical software capabilities.

Qualifications

Required:

  • Demonstrated professional experience designing, developing, and supporting production software applications.
  • Experience designing, developing, and consuming RESTful APIs and integrating applications with external systems and services.
  • Experience with relational databases, data modeling, backend application architecture, and modern front-end web development technologies — including designing schemas for data that is multi-source, or evolving, not just well-specified from the outset.
  • Experience modeling and querying hierarchical or graph-like relationship data.
  • Experience working within a CI/CD and DevOps-based software delivery environment, including automated builds, testing, deployments, version control, and release processes.
  • Experience working with Infrastructure as Code, using technologies to support repeatable and automated deployments. Experience with Docker, containers, or other managed container platforms
  • Demonstrated experience using AI-assisted software development tools such as Claude Code, OpenAI Codex, Cursor, GitHub Copilot, or comparable technologies as part of day-to-day professional software development.
  • Ability to independently troubleshoot software, integration, deployment, and production issues and develop secure, reliable, and maintainable solutions.
  • Strong analytical, problem-solving, and communication skills with the ability to collaborate across software engineering, product, cloud, cybersecurity, and compliance teams.
  • Comfort operating in a high-ambiguity, early-stage product environment: able to ask clarifying questions, propose trade-offs, and iterate without fully specified requirements.
  • Experience working with Modular Open Systems Architecture relying largely on open-source technology

Desired:

  • Experience developing software for cybersecurity, cloud security, GRC, compliance, or continuous monitoring use cases.
  • Experience building data ingestion, correlation, or entity-resolution logic that reconciles records from multiple independent tools or data sources.
  • Experience building scoring, prioritization, ranking, or recommendation engines as reusable, configurable components.
  • Exposure to graph databases (e.g., Neo4j or Postgres-native graph extensions like Apache AGE) or graph/network analysis libraries (e.g., NetworkX) — relevant to dependency- and relationship-modeling features.
  • Hands-on experience with technologies such as Kubernetes, GitHub Actions, GitLab CI, or comparable DevOps automation technologies.
  • Experience with advanced AI-assisted or agentic software engineering workflows, including AI-driven testing and validation, code analysis, workflow automation, or agent orchestration.
  • Knowledge of the NIST Risk Management Framework (RMF), NIST SP 800-53 Revision 5, NIST Cybersecurity Framework (CSF), FedRAMP, and FISMA security and compliance requirements.
  • Experience translating cybersecurity or regulatory requirements into application features, automation, workflows, integrations, or reporting capabilities.
  • Familiarity with vulnerability management, POA&M management, security controls, evidence collection, and continuous monitoring concepts.
  • Familiarity with cryptographic concepts (e.g., PKI, certificates, key management, cryptographic algorithms and protocols) sufficient to work productively with subject-matter experts.
  • Experience integrating applications with security tools, cloud APIs, vulnerability scanners, SIEM platforms, asset inventorying or other cybersecurity technologies such as Tychon, Tenable, ServiceNow, etc...
  • Experience developing and operating software supporting federal government, enterprise, or other highly regulated environments.
  • Software development experience with Python or professional experience developing applications using Django or Go (Golang) and familiarity with JavaScript/TypeScript or other modern application development languages.

Clearance: 

  • US Citizenship with the ability to obtain a security clearance
  • DOD/DoW Secret or Top Secret clearance is preferred

Location:

  • Remote, US with 10% travel as needed

About Quantum Sky

Compensation:

  • Compensation is unique to each candidate and relative to the skills and experience they bring to the position. The salary range for this position is typically between $165,000-$200,000. This does not guarantee a specific salary as compensation is based upon multiple factors such as education, experience, certifications, and other requirements, and may fall outside of the above-stated range.

Benefits:

  • Highlights of our benefits include Health/Dental/Vision, 401(k) match, Paid Time Off, STD/LTD/Life Insurance, Referral Bonuses, professional development reimbursement, and parental leave.

 


The world the mission operates in is going post-quantum, contested, and machine-speed. Quantum Sky engineers the advantage across cyber, networks, software, and quantum because the mission demands dominance, not parity. We don't follow the map. We draw it. 

 

At Quantum Sky, we believe that success starts with our people. We foster a collaborative, innovative, and mission-driven environment where every team member plays a critical role in shaping the future of technology. Are you ready to join #TeamQuantumSky? 

 

Quantum Sky Engineering LLC is an Equal Opportunity Employer; all qualified applicants will receive consideration for employment without regard to race, color, religion, sex, [sexual orientation, gender identity,] national origin, disability, status as a protected veteran, or any characteristic protected by applicable law.

Options

Sorry the Share function is not working properly at this moment. Please refresh the page and try again later.