What are the responsibilities and job description for the Senior Ground Software Engineer (Cyber Compliance) position at EVONA?
Senior Ground Software Engineer (Compliance Exposure)
Overview
We’re hiring a Senior Ground Software Engineer to join a backend/platform engineering team building mission-critical systems in a highly regulated environment.
This is an engineering-first role focused on designing, building, and maintaining production software systems and infrastructure. The ideal candidate will have strong backend engineering experience alongside exposure to environments operating under standards such as CMMC, SOC2, FedRAMP, GovCloud, or similar compliance frameworks.
This is not a pure cybersecurity role — the focus is on building scalable systems while understanding how security and compliance requirements impact software development and operations.
Key Responsibilities
Core Hiring Need
Core
Overview
We’re hiring a Senior Ground Software Engineer to join a backend/platform engineering team building mission-critical systems in a highly regulated environment.
This is an engineering-first role focused on designing, building, and maintaining production software systems and infrastructure. The ideal candidate will have strong backend engineering experience alongside exposure to environments operating under standards such as CMMC, SOC2, FedRAMP, GovCloud, or similar compliance frameworks.
This is not a pure cybersecurity role — the focus is on building scalable systems while understanding how security and compliance requirements impact software development and operations.
Key Responsibilities
- Design, build, and maintain backend services and distributed systems
- Write and review production-level code
- Contribute to cloud infrastructure and DevOps workflows
- Support CI/CD, automation, and deployment processes
- Collaborate with engineering and security stakeholders to ensure systems align with compliance requirements
- Participate in architecture discussions, code reviews, and operational support
- Strong backend software engineering experience
- Hands-on experience with:
- Go (Golang) preferred
- Or another strongly typed language (Java, C , Rust, C#)
- AWS/cloud infrastructure experience
- Experience building and owning production applications/services
- Familiarity with regulated/compliance-driven environments
- Terraform / Infrastructure-as-Code
- Docker / Kubernetes
- CI/CD pipelines
- Experience with GovCloud, FedRAMP, CMMC, SOC2, or NIST-aligned environments
- Distributed systems / microservices experience
- Backend engineer first, not security-first
- Comfortable operating in fast-paced technical environments
- Strong ownership mentality
- Able to balance engineering velocity with compliance/security expectations
Core Hiring Need
- NOT a cyber hire anymore
- Looking for a:
- Senior backend/platform engineer
- With exposure to regulated/compliance-heavy environments
- Security/compliance ownership sits with another team
- Go/Golang
- Strong preference for production experience
- At minimum: meaningful personal/project exposure strong typed language background
- Backend/service ownership experience
- AWS exposure
- Strong software engineering fundamentals
- Engineers from:
- Government
- Defense
- Healthcare
- Fintech
- Other regulated industries
- Exposure to:
- CMMC
- SOC2
- FedRAMP
- GovCloud
- NIST
Core
- Go/Golang
- AWS
- Backend systems / APIs
- Distributed systems
- Terraform
- Docker/Kubernetes
- CI/CD
- Python
- ~60% coding
- ~20% reviewing/standards
- ~20% infrastructure/Terraform
- Strong backend engineer first
- Has built applications/services end-to-end
- Comfortable in compliance-heavy environments
- Can work closely with infrastructure/security teams
- Ownership mentality
- Pure DevOps engineers
- Pure cybersecurity engineers
- No Go experience
- No strongly typed language background
- Pipeline/infrastructure-only experience
- No application ownership
- What production systems/services have you owned?
- What’s your strongest language day-to-day?
- How much Go experience do you have?
- Have you worked in regulated/compliance-heavy environments?
- Have you worked alongside security/compliance requirements in production systems?
- What AWS services are you most comfortable with?
- Any Terraform/IaC exposure?
- US Citizen required
- Hybrid role (Lanham/DC area)
- Backend-heavy despite “full-stack” wording
- Supporting mission-critical/defense-related systems