Cybersecurity Consultant
galvion · Portsmouth, NH, United States
About The Role
Employment Type: Contract
Schedule: 40 hours/week, Monday–Friday
Help Secure the Next Generation of Defense Technology
Galvion is seeking a Cybersecurity Consultant to join our Advanced Development Engineering team in Portsmouth, NH.
This role is ideal for a security professional who enjoys working directly with hardware and software engineers to build security into innovative embedded systems from the ground up.
You’ll provide hands-on cybersecurity guidance across custom hardware, embedded computing, firmware, operating systems, and application software , helping engineering teams meet demanding DoD and Army security requirements without compromising performance or usability.
What You’ll Do
- Partner with hardware and software engineers to implement security-by-design principles, including Secure Boot, code signing, key management, access controls, and hardware security.
- Interpret and map applicable DISA STIGs and SRGs to firmware, embedded operating systems, and application software.
- Establish and support Software Bill of Materials (SBOM) processes across development and build environments.
- Help engineering teams track third-party dependencies, open-source software, and software supply-chain vulnerabilities.
- Review architectures, technical documentation, and software builds for alignment with NIST SP 800-53 Rev. 5 controls.
- Analyze static code analysis, vulnerability scanning, and SBOM findings and work with engineers to develop practical remediation strategies.
- Collaborate with external cybersecurity and compliance stakeholders to support successful system accreditation.
- Balance security requirements with the real-world constraints of power, weight, processing capacity, and latency in embedded and soldier-portable systems.
What You Bring
- Bachelor’s degree in Cybersecurity, Computer Science, Computer Engineering , or a related technical discipline.
- 5+ years of experience in system security engineering, cybersecurity consulting, or a related advisory role.
- Strong knowledge of NIST SP 800-53 Rev. 5 and DISA STIG/SRG implementation.
- Understanding of federal software supply-chain security requirements and practices.
- Familiarity with SBOM standards , including SPDX and CycloneDX , and software dependency-management tools.
- Experience or familiarity with embedded environments such as Android, embedded Linux, or RTOS .
- Understanding of C/C++ or low-level software development and hardware security principles.
- Strong communication skills and the ability to translate cybersecurity requirements into actionable engineering guidance.
We’d Especially Like to Meet You If You Have
- Experience automating SBOM generation and vulnerability scanning within CI/CD pipelines .
- Experience securing embedded or hardware-focused products.
- Exposure to DoD Risk Management Framework (RMF) processes.
- Experience with tactical, soldier-portable, IoT, or other resource-constrained platforms.
- Practical experience with TPMs, hardware roots of trust, Secure Boot, and code signing .
- A track record of finding pragmatic ways to satisfy security requirements while preserving system performance.
The Kind of Person Who Will Thrive Here
We’re looking for a collaborative advisor , not simply someone who identifies security problems.
You should be comfortable sitting alongside engineers, understanding their technical challenges, and turning complex security standards into practical solutions. You’ll bring a pragmatic, engineering-focused mindset to cybersecurity and help teams build secure systems without creating unnecessary development friction.
Work Environment
- This is an on-site position in Portsmouth, New Hampshire , with occasional travel between Galvion facilities and to customer locations.
- Security clearance is not required for this position.
- Galvion is an equal opportunity employer and complies with all applicable federal, state, and local employment laws.
Similar roles you might like
See all →This is an external listing. JobSpring does not represent or verify the employer. Report this listing
