InfoSec Lead
Listed on 2026-03-01
-
IT/Tech
Cybersecurity, Systems Engineer
About Northwood
Northwood is deploying a global network of phased array ground stations that will fundamentally change how satellites communicate with Earth. These systems support real-time, high-throughput communications that commercial and government customers rely on for mission-critical operations. As a Senior Security Engineer, you will design and implement security architectures for infrastructure that simply does not exist anywhere else.
This is an opportunity to define the security posture of a rapidly scaling space-communications network—where the stakes include national security, global communications integrity, and uninterrupted mission operations.
Role:We're building the internet for space. Help us stay compliant while we do it.
Northwood is deploying a global network of phased array ground stations for mission-critical government and commercial space communications. We're scaling fast with major government and commercial customer who demand the highest compliance standards. We need a Senior Security Engineer for Compliance who can own our compliance programs while building the technical controls and automation that enable us to move at startup speed without compromising our security posture.
Responsibilities:
Own compliance programs end-to-end - Lead FedRAMP authorization efforts (Moderate/High), CMMC certification, and NIST 800-171 and/or NIST 800-53 implementation. You're the expert who translates framework requirements into actionable technical controls and documentation that pass audits the first time.
Build compliance automation, not spreadsheets - Implement continuous monitoring pipelines using infrastructure as code. Create automated evidence collection systems that pull directly from AWS Cloud Trail Wiz Gov, and our SIEM rather than manual documentation. Build POA&M tracking workflows that integrate with our existing Git Ops processes.
Be the bridge between engineering and auditors - Work directly with our Infrastructure and Network Engineering teams to implement security controls that satisfy FedRAMP/CMMC requirements without blocking deployments. Review Terraform configurations, ArgoCD deployments, and Vault policies to ensure they meet compliance mandates. Own the follow through for security control implementation to ensure controls are implemented on or ahead of schedule.
Support the Mission Management team and our customers - Partner with our Mission management team on customer compliance artifacts. Serve as technical POC during government customer security reviews and assessments. Create compliance documentation packages demonstrate the security of our offerings and build trust with our customers.
Drive risk management processes - Conduct risk assessments for new ground station deployments, cloud infrastructure changes, and third-party integrations. Maintain our risk register and work with stakeholders to implement risk treatment plans that balance security requirements with operational needs.
Build and maintain the System Security Plan (SSP
) - Own our FedRAMP SSP as a living technical document. Implement control mappings across multiple frameworks (FedRAMP, CMMC, NIST 800-171, ITAR). Create and maintain POA&M, security assessment reports, and continuous monitoring documentation.Implement security tooling for compliance visibility - Deploy and configure SIEM correlation rules, vulnerability scanning automation, and asset inventory systems. Build dashboards that provide real-time compliance posture visibility. Create automated reporting for monthly continuous monitoring requirements.
Basic Qualifications:
5+ years of hands‑on experience implementing compliance frameworks in production environments - You've successfully led organizations through FedRAMP, CMMC, or similar authorizations
Strong technical foundation with infrastructure as code - You can read and review Terraform configurations, understand AWS security architectures, and write scripts (Python, Power Shell, Bash) to automate compliance processes
Experience with SIEM platforms, vulnerability management tools, and continuous monitoring - You know how to configure Splunk/Sentinel correlation rules, automate…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).