
Cybersecurity Assessment Engineer
Second Front Systems2 months ago
Remote, United StatesMid Level / Senior
Base Salary
$125k - $140k/yr
Responsibilities
- Review web application artifacts for customer-developed applications and provide customer feedback.
- Serve as the primary cybersecurity contact for software development and mission success teams.
- Assist with incident response plans for application outages or downtime.
- Assess cloud infrastructure, applications, and containerized environments for compliance with DISA STIGs, SRGs, and CIS Benchmarks.
- Author, review, and maintain System Security Plans, Security Assessment Plans, and Security Assessment Reports.
- Monitor and report on the ongoing effectiveness of security controls through continuous monitoring.
- Use Anchore, Trivy, Tenable, and similar scanning suites to identify vulnerabilities, distinguish true positives, and provide remediation guidance.
- Implement and manage SBOM workflows to support continuous authorization standards.
- Partner with DevOps and software engineering teams to translate NIST 800-53 controls into technical requirements.
Requirements
- 3–5 years of relevant experience.
- Intermediate knowledge of DevSecOps tools and software development.
- Background in cybersecurity and vulnerability risk analysis.
- Ability to create and implement incident response plans.
- Hands-on experience assessing or securing services in AWS, Azure, or GCP, particularly PaaS or Kubernetes-based environments.
- Proficient knowledge of NIST SP 800-37 Risk Management Framework and NIST SP 800-53 revision 5 security controls.
- Deep understanding of the FedRAMP authorization process and Department of Defense security standards.
- Ability to attain DOD 8570 Baseline Certification for IAT II within six months of hire, preferably CYSA+.
- Preferred experience with Department of Defense DevSecOps practices, policies, and security.
- Preferred experience with Docker, GitLab, Kubernetes, Anchore, or other container scanning tools.
- Ability to write basic Python or Bash scripts for evidence collection or data parsing.
- Secret clearance is preferred.
- Ability to solve complex and ill-defined problems and collaborate effectively across teams.
Benefits
- Full-time position
- 100% healthcare, vision, and dental coverage
- 401(k) with 3% company contribution
- Wellness perks including fitness classes and mental health resources
- Equity incentive plan
- Technology and office supplies stipend
- Annual professional development stipend
- Flexible paid time off and federal holidays off
- Parental leave
- Work from anywhere
- Referral bonus
- Candidates must reside in an approved hiring hub: DC/Maryland/Virginia; Raleigh/Durham/Chapel Hill, NC; Denver/Colorado Springs, CO; or Dallas/Fort Worth, TX
Tech Stack
Categories
About Second Front Systems
Fast-track your FedRAMP certifications, DoW and GovRAMP authorizations. FedRAMP Class A-Class D | DoW IL2-6+ | GovRAMP Low-High | JWICS | UK MoD | NATO