Skip to main content
Xometry logo

Staff Cyber Resilience Engineer

Xometry
Full Timestaff
Denver, CO$205k – $233kPosted 6 weeks ago

Resume Keywords to Include

Make sure these keywords appear in your resume to improve ATS scoring

PythonGoShellBootstrapAWSGCPAzureKubernetesTerraformGitHub ActionsGitHubCI/CDAPI

Sign up free to auto-tailor your resume with all these keywords and get a higher ATS score

Job Description

<div class="content-intro"><p><span style="font-size: 10pt; font-family: arial, helvetica, sans-serif;">Xometry (NASDAQ: XMTR) powers the industries of today and tomorrow by connecting the people with big ideas to the manufacturers who can bring them to life. Xometry’s digital marketplace gives manufacturers the critical resources they need to grow their business while also making it easy for buyers at Fortune 1000 companies to tap into global manufacturing capacity.</span></p></div><p><span style="font-family: arial, helvetica, sans-serif;"></span></p> <p><span style="font-family: arial, helvetica, sans-serif; font-size: 10pt;">We’re looking for a <strong>Staff Cyber Resilience Engineer</strong> to lead our defense against the attacks that matter most: ransomware, destructive wipes, and data loss at scale. This is a hands-on technical leadership role.&nbsp; You will own the design and engineering of our Isolated Recovery Environment, set the standard for Infrastructure as Code across the organization, and ensure that if our AWS environment is ever compromised, we can restore operations with certainty and speed.</span></p> <p><span style="font-family: arial, helvetica, sans-serif; font-size: 10pt;">You will work with a high-caliber engineering team, have direct influence on our security architecture, and lead recovery exercises that test the organization end-to-end.</span></p> <h1><span style="font-family: arial, helvetica, sans-serif; font-size: 10pt;">What You’ll Do</span></h1> <p><span style="font-family: arial, helvetica, sans-serif; font-size: 10pt;"><strong>Own Our Recovery Architecture</strong></span></p> <ul> <li style="font-family: arial, helvetica, sans-serif; font-size: 10pt;"><span style="font-family: arial, helvetica, sans-serif; font-size: 10pt;">&nbsp; &nbsp; &nbsp; Design and build our Isolated Recovery Environment — a hardened AWS account with immutable vaults that break the attacker’s kill chain before it reaches our data.</span></li> <li style="font-family: arial, helvetica, sans-serif; font-size: 10pt;"><span style="font-family: arial, helvetica, sans-serif; font-size: 10pt;">&nbsp; &nbsp; &nbsp; Threat model our environment with a deep understanding of cloud-native attack patterns: IAM privilege escalation, backup deletion, ransomware persistence, and lateral movement across accounts.</span></li> <li style="font-family: arial, helvetica, sans-serif; font-size: 10pt;"><span style="font-family: arial, helvetica, sans-serif; font-size: 10pt;">&nbsp; &nbsp; &nbsp; Validate and continuously improve backup configurations to ensure recoverability, not just existence.</span></li> </ul> <p><span style="font-family: arial, helvetica, sans-serif; font-size: 10pt;"><strong>Standardize and Automate Infrastructure</strong></span></p> <ul> <li style="font-family: arial, helvetica, sans-serif; font-size: 10pt;"><span style="font-family: arial, helvetica, sans-serif; font-size: 10pt;">&nbsp; &nbsp; &nbsp; Lead our transition to 100% Infrastructure as Code. Every asset (VPCs, IAM roles, security groups) must be defined in Terraform so we can redeploy the entire stack into a clean account via automated pipeline.</span></li> <li style="font-family: arial, helvetica, sans-serif; font-size: 10pt;"><span style="font-family: arial, helvetica, sans-serif; font-size: 10pt;">&nbsp; &nbsp; &nbsp; Build automated recovery workflows that can tear down a compromised environment and bootstrap a fresh, hardened one from verified code and clean data.</span></li> <li style="font-family: arial, helvetica, sans-serif; font-size: 10pt;"><span style="font-family: arial, helvetica, sans-serif; font-size: 10pt;">&nbsp; &nbsp; &nbsp; Write and maintain executable recovery playbooks that detail the exact API calls and CLI commands needed to restore the application — tested, versioned, and runnable, not static documents.</span></li> </ul> <p><span style="font-family: arial, helvetica, sans-serif; font-size: 10pt;"><strong>Validate, Test, and Lead Exercises</strong></span></p> <ul> <li style="font-family: arial, helvetica, sans-serif; font-size: 10pt;"><span style="font-family: arial, helvetica, sans-serif; font-size: 10pt;">&nbsp; &nbsp; &nbsp; Develop automated scripts (Python or Go) to smoke test recovered data and validate integrity post-restoration.</span></li> <li style="font-family: arial, helvetica, sans-serif; font-size: 10pt;"><span style="font-family: arial, helvetica, sans-serif; font-size: 10pt;">&nbsp; &nbsp; &nbsp; Lead regular hands-on recovery drills that simulate total loss of a critical environment and full recovery into a secondary clean account. Own the after-action process and drive improvements.</span></li> </ul> <p><span style="font-family: arial, helvetica, sans-serif; font-size: 10pt;"><strong>Drive Engineering Standards</strong></span></p> <ul> <li style="font-family: arial, helvetica, sans-serif; font-size: 10pt;"><span style="font-family: arial, helvetica, sans-serif; font-size: 10pt;">&nbsp; &nbsp; &nbsp; Act as the resilience authority for the engineering organization — shaping high-availability architecture decisions, influencing design reviews, and raising the floor on how we think about recoverability.</span></li> <li style="font-family: arial, helvetica, sans-serif; font-size: 10pt;"><span style="font-family: arial, helvetica, sans-serif; font-size: 10pt;">&nbsp; &nbsp; &nbsp; Partner with the Site Reliability Engineering team on multi-region deployments and high-availability design, ensuring cyber resilience is embedded in architecture from the start.</span></li> <li style="font-family: arial, helvetica, sans-serif; font-size: 10pt;"><span style="font-family: arial, helvetica, sans-serif; font-size: 10pt;">&nbsp; &nbsp; &nbsp; Champion IaC and immutable infrastructure practices across teams, not just within your own workstream.</span></li> </ul> <h1><span style="font-family: arial, helvetica, sans-serif; font-size: 10pt;">What You Bring</span></h1> <p><span style="font-family: arial, helvetica, sans-serif; font-size: 10pt;"><strong>Required</strong></span></p> <ul> <li style="font-family: arial, helvetica, sans-serif; font-size: 10pt;"><span style="font-family: arial, helvetica, sans-serif; font-size: 10pt;">&nbsp; &nbsp; &nbsp; 8+ years of experience in complex cloud environments (any of AWS/GCP/Azure), including at least 3 years in AWS.&nbsp; EKS/Kubernetes experience is a strong plus.</span></li> <li style="font-family: arial, helvetica, sans-serif; font-size: 10pt;"><span style="font-family: arial, helvetica, sans-serif; font-size: 10pt;">&nbsp; &nbsp; &nbsp; Strong Terraform skills. You should be able to modularize complex environments so they are environment-agnostic.</span></li> <li style="font-family: arial, helvetica, sans-serif; font-size: 10pt;"><span style="font-family: arial, helvetica, sans-serif; font-size: 10pt;">&nbsp; &nbsp; &nbsp; Hands-on familiarity with the Secure Vault pattern: protecting data in a separate, highly restricted AWS account with tight network controls.</span></li> <li style="font-family: arial, helvetica, sans-serif; font-size: 10pt;"><span style="font-family: arial, helvetica, sans-serif; font-size: 10pt;">&nbsp; &nbsp; &nbsp; Advanced shell scripting and proficiency in either Python or Go to automate restoration tasks that native AWS tooling doesn’t cover.</span></li> <li style="font-family: arial, helvetica, sans-serif; font-size: 10pt;"><span style="font-family: arial, helvetica, sans-serif; font-size: 10pt;">&nbsp; &nbsp; &nbsp; Experience with CI/CD tooling (Scalr, GitHub Actions, or equivalent) to enable broad adoption of recovery pipelines across the organization.</span></li> <li style="font-family: arial, helvetica, sans-serif; font-size: 10pt;"><span style="font-family: arial, helvetica, sans-serif; font-size: 10pt;">&nbsp; &nbsp; &nbsp; Proven ability to engineer and automate end-to-end restoration workflows.</span></li> </ul> <p><span style="font-family: arial, helvetica, sans-serif; font-size: 10pt;"><strong>Preferred</strong></span></p> <ul> <li style="font-family: arial, helvetica, sans-serif; font-size: 10pt;"><span style="font-family: arial, helvetica, sans-serif; font-size: 10pt;">&nbsp; &nbsp; &nbsp; Hands-on experience leading technical recovery efforts from an actual cyber attack or destructive incident.</span></li> <li style="font-family: arial, helvetica, sans-serif; font-size: 10pt;"><span style="font-family: arial, helvetica, sans-serif; font-size: 10pt;">&nbsp; &nbsp; &nbsp; Experience with chaos engineering tooling to stress-test recovery assumptions.</span></li> <li style="font-family: arial, helvetica, sans-serif; font-size: 10pt;"><span style="font-family: arial, helvetica, sans-serif; font-size: 10pt;">&nbsp; &nbsp; &nbsp; Familiarity with NIST SP 800-34 (Contingency Planning) or similar frameworks.</span></li> <li style="font-family: arial, helvetica, sans-serif; font-size: 10pt;">&nbsp; &nbsp; &nbsp; AWS Security Specialty certification or equivalent demonstrated expertise.</li> </ul> <p><span style="font-family: arial, helvetica, sans-serif; font-size: 10pt;">The estimated base salary range for new hires into this role is $205,000- $233,000 annually + annual bonus depending on factors such as job-related skills, relevant experience, and location. We also offer a competitive benefits package, including 401(k) match, medical, dental and vision insurance; life and disability insurance; generous paid time off including vacation, sick leave, floating and fixed holidays, maternity and bonding leave; EAP, other wellbeing resources; and much more.</span></p> <p><span style="font-family: arial, helvetica, sans-serif;"></span></p> <p>#LI-Hybrid</p> <h4>&nbsp;</h4><div class="content-conclusion"><p><span style="font-size: 10pt; font-family: arial, helvetica, sans-serif;">Xometry is an equal opportunity employer. All applicants will be considered for employment without attention to race, color, religion, sex, sexual orientation, gender identity, national origin, veteran, or disability status.</span></p> <p><span style="font-family: arial, helvetica, sans-serif; font-size: 10pt;">For US based roles: Xometry participates in E-Verify and after a job offer is accepted, will provide the federal government with your Form I-9 information to confirm that you are authorized to work in the U.S.</span></p></div>

About Xometry

Want AI-powered job matching?

Upload your resume and get every job scored, your resume tailored, and hiring manager emails found - automatically.

Get Started Free