Pdw logo

Senior Cybersecurity GRC Engineer

Hiring from
United States
Work type
Remote
Posted
Oct 2, 2026
Is this job info correct?

Performance Drone Works (PDW) is building the next generation of tactical robotic systems used across defense, national security, and public safety missions. We are building a new center of engineering excellence to design our new category of tactical robotic systems and the industrial capacity to deliver them, bringing decisive airpower into the hands of every operator. We are not here to make promises; we are here to deliver real systems with real capabilities for real missions. 

You will join a team of operators, engineers, and builders who solve hard problems with humility and focus. We design and produce multi-mission aerial systems that operators trust to perform in real-world conditions, reliably, repeatedly, and at scale. Our approach is grounded in operator-centered design, rapid iteration from field use, and U.S.-based manufacturing. We operate by a clear set of values: Mission First, Aim Farther, Own It, Win Together. This is how we build advantage and how we help protect our service members, our communities, and our country. 


Now, we’re entering a new phase of growth and are looking for a Senior Cybersecurity GRC Engineer to help build, operate, and mature PDW's cybersecurity and compliance program. This is a hands-on technical role for a cybersecurity practitioner who can translate requirements from CMMC, ISO 27001, ITAR, and customer obligations into practical controls - and personally help implement, validate, and improve those controls across the organization.

What You’ll Do

  • Serve as a senior technical contributor to PDW's cybersecurity governance, risk, and compliance program, helping define priorities, technical standards, control requirements, and roadmaps across enterprise IT, engineering, manufacturing, and business systems.
  • Lead and support readiness efforts for applicable compliance frameworks and customer requirements, including CMMC, NIST SP 800-171, ISO 27001, ITAR and export-control obligations, and other defense-industry security requirements.
  • Translate regulatory, contractual, and framework requirements into clear, actionable technical and administrative controls; partner with system owners to implement controls that are effective, sustainable, and appropriate for PDW's operating environment.
  • Own and continuously improve core GRC processes, including risk assessments, control assessments, system security plans, plans of action and milestones, evidence collection, policy and standard development, third-party risk, audit preparation, and remediation tracking.
  • Remain hands-on in cybersecurity operations: configure, administer, tune, and validate security tooling such as endpoint detection and response, identity and access management, email security, logging, security monitoring, and related controls.
  • Ensure standardized vulnerability-management processes are consistently followed across the organization, including asset coverage, scan cadence, remediation tracking, exception management, and evidence collection. Leverage platforms such as Tenable and related security tools to support compliance validation, audit evidence, risk reporting, and verification of remediation activities.
  • Partner with IT and engineering teams to secure endpoints, identity systems, cloud services, networks, collaboration platforms, and business applications through practical configuration, hardening, monitoring, and access-control improvements.
  • Support incident-response preparedness and execution, including developing playbooks, participating in investigations, coordinating technical response activities, documenting lessons learned, and improving controls after incidents.
  • Develop meaningful cybersecurity and compliance metrics for leadership, including risk trends, control maturity, audit readiness, vulnerability remediation, security-tool coverage, and outstanding corrective actions.
  • Work directly with internal stakeholders, external auditors, customers, assessors, and technology vendors to communicate PDW's security posture, answer evidence requests, and drive timely resolution of findings.
  • Build repeatable cybersecurity processes, technical baselines, policies, procedures, and evidence-collection mechanisms that enable PDW to scale while protecting sensitive, controlled, and export-controlled information.

Requirements

  • 7+ years of progressive experience in cybersecurity, information security, GRC, security engineering, IT security, or a related technical discipline, including meaningful hands-on experience operating cybersecurity controls and tools.
  • Bachelor's degree in Cybersecurity, Information Technology, Computer Science, Engineering, or a related discipline; equivalent relevant professional experience, technical training, and industry certifications will be considered in lieu of a degree.
  • Demonstrated experience implementing or assessing security programs against CMMC and/or NIST SP 800-171, including familiarity with assessment, evidence, and remediation expectations associated with defense-industry cybersecurity requirements.
  • Working knowledge of ISO 27001 and experience applying its control-based approach to a real-world information security management system.
  • Experience working in an environment subject to ITAR, export controls, controlled unclassified information, defense contracts, or similarly regulated and sensitive data environments.
  • Hands-on experience administering, configuring, or validating security tools such as EDR, endpoint-management tools, identity and access-management systems, SIEM and logging platforms, email-security tools, or cloud-security controls.
  • Familiarity with vulnerability-management platforms such as Tenable, Qualys, or Rapid7, including using scan results and platform reporting to gather compliance evidence, support risk assessments, validate control effectiveness, and track remediation.
  • Demonstrated ability to investigate technical issues, assess security configurations, validate control effectiveness, identify gaps, and work directly with system owners to remediate risk.
  • Experience developing and maintaining cybersecurity documentation, including system security plans, risk registers, policies, procedures, control narratives, audit evidence, and remediation plans.
  • Strong understanding of endpoint security, vulnerability management, identity and access management, least privilege, network security, logging and monitoring, incident response, encryption, asset management, and secure configuration.
  • Ability to independently translate ambiguous compliance or security requirements into pragmatic action plans; prioritize risk; communicate effectively with technical and non-technical stakeholders; and drive work through completion.
  • Must have the ability to obtain and maintain a U.S. Security Clearance.

Preferred

  • Relevant certifications such as CISSP, CISM, CRISC, CISA, Security+, ISO 27001 Lead Implementer or Lead Auditor, Certified CMMC Professional, Certified CMMC Assessor, or similar credentials.
  • Experience supporting a CMMC assessment, ISO 27001 certification audit, NIST SP 800-171 assessment, customer security review, or government-contracting security evaluation.
  • Experience in aerospace, defense, robotics, manufacturing, or another highly technical and regulated environment.
  • Experience with Microsoft 365 and Azure security, Microsoft Defender, CrowdStrike, SentinelOne, Tenable, Jira, ServiceNow, SIEM platforms, or comparable technologies.
  • Experience building cybersecurity programs in a fast-growing organization where controls, systems, and processes are evolving rapidly.

Physical Requirements

The physical demands described here are representative of those that must be met to successfully perform the essential functions of the job. Ability to sit, stand, bend, reach, climb, and move about regularly throughout the day and lift / carry up to 25 pounds. Must have manual dexterity to operate standard office or manufacturing equipment. Must be physically capable of occasionally assisting with the setup, movement, and installation of computer, networking, or security-related equipment.

Work Environment

PDW will consider remote, hybrid, or on-site work arrangements for the right candidate. This role requires the use of standard office and computing equipment and close cross-departmental collaboration with both independent and team-based responsibilities. Occasional travel between PDW sites, partner locations, industry events, or other business locations may be required. Standard work hours are PDW's core business hours, with availability outside those hours as needed for significant cybersecurity incidents or operational priorities.


Benefits 

PDW values our team, and we offer a compensation package reflective of your experience and capabilities. Benefits include:

  • Comprehensive BCBS medical, dental, and vision coverage; 80% sponsored by the company.
  • Safe Harbor 401(K) with company match.
  • Paid Parental Leave.
  • On-site gym at our Denver, CO & Huntsville, AL locations.
  • Employer provided life insurance.
  • Robust Employee Assistance Program (EAP).
  • A work environment that encourages teamwork and innovation.
  • Competitive salary, generous paid time off (PTO), and flexible leave options.

 

EEO Statement 

PDW is an equal opportunity employer that upholds all federal and state non-discrimination laws. We ensure a fair and unbiased evaluation for employment for all qualified candidates regardless of race, color, religion, age, sex, sexual orientation, gender identity, national origin, marital status, medical condition, disability, genetic information, veteran status, or any other characteristic protected by law. 

Similar jobs

Apply for this job