About this role
Meet Slingshot
At Slingshot Aerospace, we're on a mission to make space safer and more secure for everyone. Our work directly impacts global security, disaster response, climate monitoring, and the critical infrastructure that connects our world. We're a team of builders, thinkers, and problem-solvers who believe that the next generation of space operations will be powered by better data and smarter software.
We move fast, we're not afraid to fail, and we believe the best ideas can come from anywhere—whether you're in engineering, sales, product, or operations. If you want to work on something that truly matters, with people who care deeply about the impact we're making and help shape the future of an industry that's just getting started, you're in the right place.
The DevSecOps Director leads Slingshot's cloud platform operations and security engineering across company-owned, partner, and customer environments. Reporting to the CISO, this role is accountable for secure-by-default engineering across AWS, Azure, and classified platforms while ensuring reliable operations and readiness for regulated missions.
This leader owns the DevSecOps operating model, including team development, capacity planning, on-call escalation, cloud and pipeline security, operational KPIs, and roadmaps for new environments and security improvements. The role also provides architecture and compliance input for RFIs and RFPs, supports pricing estimates, and communicates plans, staffing needs, risks, and decisions in executive-ready narratives.
We're building a team of sharp, creative people who love solving hard problems. We value curiosity over ego, initiative over waiting for permission, and people who genuinely care about doing great work. Bring your expertise, your fresh ideas, and your drive, we'll bring the rocket fuel.
What You'll Be Launching
The DevSecOps Director leads Slingshot's cloud platform operations and security engineering across company-owned, partner, and customer environments. Reporting to the CISO, this role is accountable for secure-by-default engineering across AWS, Azure, and classified platforms while ensuring reliable operations and readiness for regulated missions.
This leader owns the DevSecOps operating model, including team development, capacity planning, on-call escalation, cloud and pipeline security, operational KPIs, and roadmaps for new environments and security improvements. The role also provides architecture and compliance input for RFIs and RFPs, supports pricing estimates, and communicates plans, staffing needs, risks, and decisions in executive-ready narratives.
We're building a team of sharp, creative people who love solving hard problems. We value curiosity over ego, initiative over waiting for permission, and people who genuinely care about doing great work. Bring your expertise, your fresh ideas, and your drive, we'll bring the rocket fuel.
Your Mission (Should you choose to accept it)
Cloud Platform Security, Reliability & Automation
- Own secure and reliable multi-cloud operations, primarily in AWS with Azure as needed, including AWS Organizations, account baselines, guardrails, and coverage across commercial, GovCloud, and classified environments.
- Lead infrastructure-as-code and compliance-as-code using Terraform, Kubernetes, and Helm, and embed security into CI/CD workflows using tools such as GitHub Advanced Security and JFrog.
- Ensure comprehensive scanning, observability, and pre-deployment security gates, including GuardDuty, Inspector, Security Hub, SBOM intake, container and image scanning, and dependency risk triage for Slingshot and partner components.
- Own the on-call program and executive escalation paths for cloud operational and security incidents, while improving availability, response times, pipeline performance, and cloud cost efficiency.
Classified & Regulated Mission Readiness
- Lead authorization-to-operate readiness for high-side environments, including SSP and POA&M tracking, evidence collection, ISSO coordination, and accreditation milestones.
- Guide secure enclave designs, including GCC High and Azure Virtual Desktop, with effective identity federation, logging and monitoring, and incident response processes.
- Maintain CMMC Level 2 alignment for internal controls and program delivery, and apply FedRAMP familiarity to preserve a credible future path to authorization.
Team Leadership, Capacity & Operating Model
- Build, mentor, and manage a growing team of employees and contractors, with clear tasking, performance coaching, career development, and accountability aligned to defined job ladders.
- Plan capacity, hiring, vendor and contractor utilization, and onboarding so team members become productive quickly and consistently meet Slingshot security standards.
- Establish operating rhythms, roadmaps, and priorities for security mitigation and the deployment of new environments in support of company initiatives and customer programs.
- Drive tool selection and staffing plans in partnership with the CISO, GRC, IT and Enterprise Security, Engineering, Product, Research, Program Security, Procurement, and Finance while fostering an inclusive, high-trust culture.
Mission Architecture, Proposals & Executive Alignment
- Provide architecture options, systems diagrams, and security control mappings for RFIs, RFPs, and customer program planning.
- Own technical proposal sections addressing security and compliance requirements, and contribute level-of-effort estimates and bills of materials that support accurate pricing.
- Establish and publish operational KPIs, including mean time to resolution, urgent incidents, and availability, and provide regular reporting on performance, delivery progress, and roadmap risk.
- Brief executives on plans, staffing needs, risks, and mitigation strategies, translating technical tradeoffs into clear business and mission outcomes and escalating blockers or decision needs early.
Pre-flight Checklist
- 12+ years of experience in DevOps, DevSecOps, or cloud platform engineering, including 5+ years leading technical teams.
- Active TS/SCI clearance or eligibility for TS/SCI, with experience working in AWS Top Secret, Secret, or other classified cloud regions.
- Hands-on experience with AWS Organizations, IAM, VPC, EKS or ECS, Kubernetes, Helm, Terraform, Linux, and CI/CD tooling such as GitHub Actions, Jenkins, or GitLab.
- Direct experience with authorization-to-operate processes and CMMC 2.0 control implementation for Department of Defense programs, with familiarity with FedRAMP requirements.
- Strong executive communication skills, including briefings, risk narratives, staffing plans, KPI readouts, and roadmap documents.
- Demonstrated ability to collaborate across engineering, research and data science, product, program security, procurement, finance, and customer-facing teams.
Bonus Cargo
- Experience with Azure and GCC High, including identity federation, Azure Virtual Desktop, and Okta, SAML, or SSO design.
- Experience reducing pipeline costs and optimizing build systems through approaches such as self-hosted runners, caching strategies, and workflow improvements.
- FedRAMP authorization experience and public-sector proposal support, including BOEs, NIST 800-171 and NIST 800-53 control mappings, DFARS clauses, and subcontractor attestation processes.
Location & Travel
Location: Remote, United States
Travel: Periodic travel of approximately 10-20% for program and customer engagements.
Equity, Diversity & Inclusion
Equity, Diversity & Inclusion are key to our success. We are an Equal Opportunity Employer and our employees are people with different strengths, experiences, and backgrounds who share a passion for creating a safer, more connected world. Diversity includes race and gender identity, national origin, citizenship, sex, color, veteran status, disability, genetic information, and any other protected characteristic that is part of one's identity. All of our employees' points of view are key to our success, and we embrace individuality.
US-based Candidates: we are currently only able to hire residents of the following U.S. states: AL, AZ, CA, CO, DC, FL, GA, HI, IL, IN, KS, MA, MD, MI, MN, MO, MT, NC, NJ, NM, NV, NY, OH, OK, OR, RI, TN, TX, UT, VA, WA, WI, WV We are unable to consider candidates residing in other U.S. states at this time.
Internationally-based Candidates: we are currently only able to hire residents of the following locations: United Kingdom. We are unable to consider candidates residing in other countries at this time.
Equity, Diversity & Inclusion are key to our success. We are an Equal Opportunity Employer and our employees are people with different strengths, experiences, and backgrounds, who share a passion for creating a safer, more connected world. Diversity not only includes race and gender identity, but also national origin, citizenship, sex, color, veteran status, disability, genetic information, or any other protected characteristic that is part of one’s identity. All of our employees’ points of view are key to our success, and we embrace individuality.
