second-front-systems - Cybersecurity Assessment Engineer
Requirements
• Experience solving complex and sometimes ill-defined problems • Intermediate knowledge of DevSecOps tools and software development • Ability to create and implement incident response plans • Background in cybersecurity and understanding of vulnerability risk analysis • Hands-on experience assessing or securing services within AWS, Azure, or GCP, particularly within PaaS or Kubernetes-based environments. • Proficient knowledge of NIST SP 800-37 (RMF) and NIST SP 800-53 rev 5 security controls • Deep understanding of the FedRAMP authorization process and Department of Defense (DoD) security standards. • Ability to attain DOD 8570 Baseline Certification for IAT II within 6 months of hire date (preferably CYSA+) • Extensive experience with Department of Defense DevSecOps practices, policies, and security • Experience with Docker, Gitlab, Kubernetes, Anchore, or other container scanning tools • Ability to write basic scripts (Python, Bash, etc.) to automate evidence collection or data parsing • Strong interest in matters of national security • Having a Secret clearance is preferred • The base salary for this position will fall between $125,000-140,000 Your ultimate compensation will be determined by professional background, technical proficiency, seniority, and regional cost factors. Furthermore, this opportunity includes potential eligibility for equity awards and discretionary bonuses, rounding out a comprehensive total rewards offering. • SUCCESS AT 2F LOOKS LIKE: • Viewing obstacles as opportunities for growth • Having a bias toward action and tangible, measurable results • Striving to be both compassionate and direct with your feedback • Being team-oriented and inclusive with your action
Responsibilities
• Review web application artifacts of customer developed applications and provide customer feedback • Primary face of the cybersecurity team to software development and mission success teams • Assist with incident response plans to respond to application outages or downtime • Technical Security Validation: Conduct comprehensive assessments of cloud infrastructure, applications, and containerized environments to verify compliance with DISA STIGs, SRGs, and CIS Benchmarks. • Authorization Lifecycle Management: Author, review, and maintain high-quality security artifacts, including System Security Plans (SSP), Security Assessment Plans (SAP), and Security Assessment Reports (SAR). • Continuous Monitoring (ConMon): Monitor and report on the ongoing effectiveness of security controls, ensuring the platform maintains a robust and authorized security posture. • Vulnerability & Risk Analysis: Utilize automated scanning suites (e.g., Anchore, Trivy, Tenable) to identify vulnerabilities, distinguish true positives, and provide actionable remediation guidance to dev teams. • Supply Chain Security: Implement and manage technical workflows for SBOMs (Software Bill of Materials) to support modern, continuous authorization standards. • Cross-Functional Collaboration: Partner with DevOps and Software Engineering teams to translate complex NIST 800-53 controls into implementable technical requirements.
Benefits
• This role is a full time position. As a public benefit corporation, we’re a team of purpose-driven trailblazers transforming the future of U.S. national security. We hire the best to do their best and, as such, we are committed to providing the perks and benefits you need to be successful—both in- and outside the workplace. • 100% Healthcare, vision and dental coverage • 401(k) + 3% company contribution • Wellness perks (Fitness classes, mental health resources) • Equity incentive plan • Tech + office supplies stipend • Annual professional development stipend • Flexible paid time off + federal holidays off • Parental leave • Work from anywhere • Referral Bonus • Visit our careers page https://www.secondfront.com/company/careers to learn more.
Apply in one click
Upload My Resume
Drop here or click to browse · Tap to choose · PDF, DOCX, DOC, RTF, TXT