Cherokee Federal
Information System Security Engineer
Full details on LinkedIn
The complete job description, requirements, and application details are available on the original posting.
About Cherokee Federal
Cherokee Federal is a tribally owned government contracting company that operates globally as part of Cherokee Nation Businesses. The company focuses on delivering innovative solutions to complex federal challenges, dedicating all profits to enhancing the future for tribal citizens. With over 5,000 employees, including a significant number of veterans, Cherokee Federal manages more than 2,000 projects for over 60 U.S. federal agencies and ranks #120 on Bloomberg Government's BGOV200 list of top federal contractors. The company offers a wide range of services across seven primary areas, including advanced technology services, health services, intelligence analysis, logistics operations, manufacturing, civil support, and engineering technical services. Cherokee Federal is structured as a team of small disadvantaged business entities, many of which hold 8(a) and HUBZone certifications, facilitating efficient contract management and delivery. The company is also recognized for its initiatives, such as creating job opportunities for individuals with disabilities through partnerships that enhance operational effectiveness in federal health systems.
Security at Cherokee Federal
Compiled from public job postings, careers pages, and company materials. Data may not reflect current state — verify during interviews.
Security Philosophy
- Cherokee Federal's AppSec philosophy emphasizes early integration of security into development and automated DevSecOps pipelines.
- Their risk posture references Zero Trust frameworks that verify every connection and continuous monitoring with AI-driven threat intelligence.
- They also promote developer enablement, stating that security is a shared responsibility and security testing is integrated into CI/CD.
Security Team
Information not publicly available.
Key Initiatives
- Cherokee Federal integrates security practices early in the development process, including security testing, static and dynamic analysis, and vulnerability assessments into the CI/CD pipeline.
- They also utilize an automated DevSecOps pipeline toolset to ensure security and Section 508 requirements are built into the lifecycle.
Preparing for an AppSec interview?
Get the weekly briefing 2,000+ security pros trust.