← Back to results

sbom jobs in San Diego

$164,000 – $328,000 · Posted 6 days ago

Senior Cyber Systems Engineer responsible for developing and maintaining RMF artifacts (SSPs, SARs, SAPs, POA&Ms), coordinating with Navy Authorizing Officials and Security Control Assessors, and managing cybersecurity authorization packages for ATO/IATT/IATO activities. The role involves vulnerability remediation, STIG compliance, access control policy development, patch management, and server/network infrastructure oversight.… Requires mastery of the Risk Management Framework, CI/CD security pipelines, container hardening (Docker/Kubernetes), infrastructure-as-code tools (Terraform, Ansible), and automated security assessment tools (ACAS/Nessus). Serves as Information Systems Security Manager (ISSM) for product ATOs and coordinates with government agencies to ensure DoD and Navy cyber security requirements are met.

San DiegoLast seen 5 days ago
Posted 7 days ago

This is a hands-on DevSecOps engineering role focused on designing and maintaining secure CI/CD pipelines, software supply-chain controls, and Kubernetes deployment standards. The engineer will work across Azure DevOps, Nexus, SonarQube, and container orchestration to integrate security and quality checks into build and release workflows, support platform engineering teams, and enable developers with documentation and automation.… Responsibilities include implementing SAST, SCA, dependency scanning, secrets management, artifact controls, and compliance alignments (NIST, CMMC, RMF, Zero Trust); troubleshooting pipeline and deployment failures; and creating runbooks and guardrails. The role requires 5+ years in DevOps/DevSecOps, hands-on Azure DevOps and Kubernetes experience, scripting proficiency, and an active Secret Clearance with eligibility for TS/SCI.

San DiegoLast seen 5 days ago
Posted 12 days ago

AMD seeks a security engineer to implement, validate, and secure AI platform features on internal test hardware and customer systems. The role spans hardware, firmware, and software security—including secure boot, attestation, key/certificate management, vulnerability analysis, and fix development and verification.… You will conduct security assessments, develop tooling and automation for testing and remediation, and partner across architecture, firmware, and software teams. The position requires proficiency in C/C++ and scripting languages, deep platform security knowledge (cryptography, memory safety, isolation, trusted execution environments), and experience with AI/ML infrastructure security.

San DiegoLast seen 10 days ago
Posted 12 days ago

AMD is seeking an AI Systems Security Architect to drive system-wide threat modeling and security analysis across hardware, firmware, and software platforms. The role involves designing secure debug architectures, writing platform security specifications, and leveraging AI-assisted engineering tooling to accelerate security analysis.… The ideal candidate has deep expertise in computer architecture, confidential computing, root of trust, boot chain architecture, firmware security, cryptography, and threat modeling at platform scope, with proficiency in C/C++ and experience securing AI/ML workloads at datacenter scale.

San DiegoLast seen 10 days ago
Posted 16 days ago

This role leads product security engineering for FDA-regulated medical devices (Class I/II) and their cloud-connected platforms. The engineer owns the full security lifecycle—threat modeling, risk assessments, security architecture, secure SDLC integration, and regulatory documentation—balancing patient safety, data protection, and FDA compliance.… Responsibilities span device and cloud security, vulnerability management, SBOM processes, and cross-functional collaboration with engineering, quality, and regulatory teams. Required: 5+ years cybersecurity experience, hands-on work with embedded/cloud/application security, FDA submission experience, and medical device development background.

San DiegoLast seen 14 days ago
Posted 20 days ago

Secure the application development lifecycle and software supply chain as a Security Engineer, embedding with engineering teams to design and implement threat modeling, secure code review, SAST/DAST/SCA integration into CI/CD pipelines, and secrets management. Own dependency and supply-chain security including SCA, SBOMs, and artifact signing, while designing hardened infrastructure patterns for self-hosted applications across AWS, Azure, and on-premises.… Build durable tooling through scripting and Infrastructure-as-Code to scale security across the organization, making secure deployment and controls the default rather than exceptions.

San DiegoLast seen 18 days ago
Posted 1 month ago

This role involves implementing, validating, and securing AI platform security features across AMD's hardware, firmware, and software stack. You will conduct security assessments, develop and verify security fixes, manage cryptographic keys and device identities, and provision secure boot and attestation mechanisms.… The position requires hands-on experience securing systems across hardware-firmware-software integration, proficiency in C/C++ and scripting, and familiarity with GPU/accelerator platforms, confidential computing, and trusted execution environments. You will partner with architecture, firmware, and software teams to resolve security issues and apply AI-assisted tooling to accelerate remediation and testing.

San DiegoLast seen 1 month ago
$100,000 – $200,000 · Posted 1 month ago

Design and implement security strategies for Abbott's cloud-based applications and medical devices, including hardening, incident response, penetration testing, and disaster recovery. Apply expertise in user authentication, certificate management, digital signatures, and cloud security architecture while ensuring compliance with ISO, FDA, and regulatory standards.… Leverage AI-assisted development tools and cybersecurity platforms to automate vulnerability analysis, evidence collection, and remediation tracking. Conduct hands-on web, mobile, and cloud infrastructure security testing using DAST, SAST, SCA, and vulnerability scanning tools, with demonstrated experience in product security and medical device environments preferred.

San DiegoLast seen 1 month ago
$100,000 – $200,000 · Posted 1 month ago

Design and develop security strategies for Abbott's cloud-based medical devices and applications, including hardening, incident response, penetration testing, and disaster recovery. Apply expertise in user authentication, certificate management, digital signatures, and cloud security architecture while ensuring compliance with ISO, FDA, and regulatory standards.… Conduct web, mobile, and cloud infrastructure security testing using DAST, SAST, SCA, and vulnerability scanning tools. Leverage AI-assisted development and cybersecurity tools—including building agentic AI applications—to automate security deliverables, with responsibility for evaluating AI tools for safe, policy-compliant use and mitigating AI/LLM-specific risks.

San DiegoLast seen 1 month ago
Posted 1 month ago

This Staff Engineer role owns and executes BD's product security lifecycle for FDA-regulated medical device dispensing systems and their cloud platforms. Key responsibilities include defining end-to-end security architecture, conducting threat modeling and risk assessments, implementing secure SDLC practices aligned to NIST/OWASP/BSIMM, managing SBOMs and vulnerability remediation, and ensuring regulatory compliance (IEC 62304, ISO 14971, FDA cybersecurity guidance).… The role requires 5+ years of cybersecurity experience with FDA Class I/II devices, hands-on expertise in embedded/cloud/application security, and the ability to balance security controls with usability while supporting FDA submissions.

San DiegoLast seen 1 month ago
$150,000 – $175,000 · Posted 1 month ago

Senior DevOps Build Engineer responsible for designing, building, and maintaining CI/CD pipelines that compile, test, package, and publish software across defense and government contract programs. The role owns build automation, release engineering, artifact management, and container registries end-to-end, while integrating security and compliance checks directly into the build process.… Requires 8+ years of hands-on experience with CI/CD tools (GitLab CI, GitHub Actions, Jenkins), strong scripting skills in Python and Bash, and proficiency with containerization, artifact management, and cloud platforms (AWS or Azure). The engineer will partner with development, security, and compliance teams to deliver self-service tooling and standardize builds across unclassified and controlled unclassified environments.

San DiegoLast seen 1 month ago
$150,000 – $175,000 · Posted 1 month ago

Senior DevOps Build Engineer responsible for designing and maintaining CI/CD pipelines, build automation, and artifact management systems across defense and government contract programs. The role owns end-to-end build and release engineering, standardizing compilation, packaging, versioning, and promotion across unclassified and controlled environments while integrating security and compliance checks into the build process.… Key responsibilities include pipeline design (GitLab CI, GitHub Actions, Jenkins), artifact repository management, build tooling development (Bash, Python, Bazel, Gradle), container image management, and infrastructure provisioning using Terraform. The position requires 8+ years of build/release engineering or DevOps experience, strong scripting skills, and U.S. citizenship with the ability to obtain a security clearance.

San DiegoLast seen 6 days ago
Posted 1 month ago

This Staff Platform Engineer role owns operational strategy and technical direction for enterprise GitLab (3,000+ users) and JFrog Artifactory platforms, leading cloud-native transformation and Kubernetes migrations. The position requires 7+ years of enterprise-scale platform operations, 5+ years each with self-managed GitLab and Artifactory in high-availability deployments, and 3+ years of deep Kubernetes expertise.… Responsibilities include designing multi-region active-active systems, establishing cloud-native best practices, mentoring team members, and influencing organizational standards for platform engineering and developer experience. Required expertise spans Linux kernel/networking, PostgreSQL high availability, AWS/Azure/GCP, Kubernetes operators, service mesh (Istio), infrastructure-as-code (Terraform), observability (Prometheus), and production automation in Python, Go, and Bash.

San DiegoLast seen 1 month ago