Helsing is a Munich-based defence AI and drone company that develops defence software, drones, and military systems for air, land, sea, and underwater operations.
<h2><span data-contrast="none"><span data-ccp-parastyle="heading 2">Who we are</span></span><span data-ccp-props="{"134245418":true,"134245529":true,"335559738":160,"335559739":80}"> </span></h2> <p><span data-contrast="auto">Helsing develops artificial intelligence-enabled capabilities to protect and defend democracies. We build Altra, an AI-powered drone software platform, and HX-2, our autonomous drone. We are growing our US operations, cultivating an ambitious and committed team of mission-driven professionals to apply their skills to solve challenging problems.</span><span data-ccp-props="{}"> </span></p> <h2><span data-contrast="none"><span data-ccp-parastyle="heading 2">The role</span></span><span data-ccp-props="{"134245418":true,"134245529":true,"335559738":160,"335559739":80}"> </span></h2> <p><span data-contrast="auto">You will join the Platform Engineering team as a security-focused engineer responsible for embedding security into every layer of our developer platform and software delivery pipeline. You will own the security posture of our development environment — ensuring CMMC Level 2 compliance, hardening our software supply chain, and implementing the controls required for product teams to achieve ATO against NIST and other cybersecurity frameworks. You will work closely with platform and product engineers to build secure CI/CD pipelines, enforce policy-as-code, and maintain the shared infrastructure that all teams depend on. This role combines hands-on engineering with deep security expertise: you are not just auditing compliance, you are building the systems that make compliance automatic.</span><span data-ccp-props="{}"> </span></p> <h2><span data-contrast="none"><span data-ccp-parastyle="heading 2">The day-to-day</span></span><span data-ccp-props="{"134245418":true,"134245529":true,"335559738":160,"335559739":80}"> </span></h2> <ul> <li data-leveltext="" data-font="Symbol" data-listid="5" data-list-defn-props="{"335552541":1,"335559685":720,"335559991":360,"469769226":"Symbol","469769242":[8226],"469777803":"left","469777804":"","469777815":"hybridMultilevel"}" data-aria-posinset="1" data-aria-level="1"><span data-contrast="auto">Deploying, updating, and securing Kubernetes workloads through ArgoCD and GitOps workflows</span><span data-ccp-props="{"134233117":false,"134233118":false,"335559738":0,"335559739":0}"> </span></li> </ul> <ul> <li data-leveltext="" data-font="Symbol" data-listid="5" data-list-defn-props="{"335552541":1,"335559685":720,"335559991":360,"469769226":"Symbol","469769242":[8226],"469777803":"left","469777804":"","469777815":"hybridMultilevel"}" data-aria-posinset="2" data-aria-level="1"><span data-contrast="auto">Building and maintaining secure CI/CD pipelines that enforce policy, scan for vulnerabilities, and produce auditable build artifacts</span><span data-ccp-props="{"134233117":false,"134233118":false,"335559738":0,"335559739":0}"> </span></li> </ul> <ul> <li data-leveltext="" data-font="Symbol" data-listid="5" data-list-defn-props="{"335552541":1,"335559685":720,"335559991":360,"469769226":"Symbol","469769242":[8226],"469777803":"left","469777804":"","469777815":"hybridMultilevel"}" data-aria-posinset="3" data-aria-level="1"><span data-contrast="auto">Maintaining and hardening shared services (GitLab, Artifactory, container registries) that the entire organization depends on</span><span data-ccp-props="{"134233117":false,"134233118":false,"335559738":0,"335559739":0}"> </span></li> </ul> <ul> <li data-leveltext="" data-font="Symbol" data-listid="5" data-list-defn-props="{"335552541":1,"335559685":720,"335559991":360,"469769226":"Symbol","469769242":[8226],"469777803":"left","469777804":"","469777815":"hybridMultilevel"}" data-aria-posinset="4" data-aria-level="1"><span data-contrast="auto">Implementing and enforcing security controls aligned with CMMC L2, NIST 800-171, and other frameworks required for ATO</span><span data-ccp-props="{"134233117":false,"134233118":false,"335559738":0,"335559739":0}"> </span></li> </ul> <ul> <li data-leveltext="" data-font="Symbol" data-listid="5" data-list-defn-props="{"335552541":1,"335559685":720,"335559991":360,"469769226":"Symbol","469769242":[8226],"469777803":"left","469777804":"","469777815":"hybridMultilevel"}" data-aria-posinset="5" data-aria-level="1"><span data-contrast="auto">Securing the software supply chain: image signing, SBOM generation, dependency scanning, and provenance tracking</span><span data-ccp-props="{"134233117":false,"134233118":false,"335559738":0,"335559739":0}"> </span></li> </ul> <ul> <li data-leveltext="" data-font="Symbol" data-listid="5" data-list-defn-props="{"335552541":1,"335559685":720,"335559991":360,"469769226":"Symbol","469769242":[8226],"469777803":"left","469777804":"","469777815":"hybridMultilevel"}" data-aria-posinset="6" data-aria-level="1"><span data-contrast="auto">Conducting threat modeling to surface architectural risks before they become incidents</span><span data-ccp-props="{"134233117":false,"134233118":false,"335559738":0,"335559739":0}"> </span></li> </ul> <ul> <li data-leveltext="" data-font="Symbol" data-listid="5" data-list-defn-props="{"335552541":1,"335559685":720,"335559991":360,"469769226":"Symbol","469769242":[8226],"469777803":"left","469777804":"","469777815":"hybridMultilevel"}" data-aria-posinset="7" data-aria-level="1"><span data-contrast="auto">Detecting, investigating, and responding to security incidents across infrastructure and applications</span><span data-ccp-props="{"134233117":false,"134233118":false,"335559738":0,"335559739":0}"> </span></li> </ul> <ul> <li data-leveltext="" data-font="Symbol" data-listid="5" data-list-defn-props="{"335552541":1,"335559685":720,"335559991":360,"469769226":"Symbol","469769242":[8226],"469777803":"left","469777804":"","469777815":"hybridMultilevel"}" data