
Cybersecurity Engineer
Defense Unicorns
full-time
Posted on:
Location Type: Remote
Location: United States
Visit company websiteExplore more
Salary
💰 $123,250 - $166,750 per year
Tech Stack
About the role
- Leading and pathfinding the effort to achieve accreditation in accordance with NIST-800 series requirements.
- Developing and implementing cybersecurity policies, procedures, and controls necessary to meet DoD accreditation standards.
- Conducting comprehensive risk assessments and vulnerability analyses to identify potential security threats and mitigate risks.
- Collaborating with cross-functional teams including software developers, system architects, and other Government stakeholders to integrate cybersecurity measures into the software development lifecycle.
- Performing security testing and evaluation of our software platform to identify vulnerabilities and weaknesses (STIGs, ACAS, CI/CD security testing, etc.)
- Providing guidance and support to ensure continuous monitoring and maintenance of cybersecurity controls.
- Preparing and maintaining documentation required for the accreditation process, including System Security Plans (SSPs), Security Assessment Reports (SARs), and other relevant artifacts.
- Staying up-to-date with evolving cybersecurity threats, technologies, and regulations to proactively address security challenges and compliance requirements.
- Serving as a subject matter expert on cybersecurity best practices, standards, and procedures within the organization.
- Supporting automated Compliance-as-Code capabilities that continuously evaluate the cybersecurity posture of the tech stack.
Requirements
- Proven experience in cybersecurity engineering, with a focus on achieving accreditation for software systems within the DoD environment.
- Proven track record of thinking outside the box and pushing the boundaries of the RMF/ATO status quo.
- In-depth knowledge of NIST-800 series standards, particularly NIST-800-53, and experience applying these standards to achieve accreditation.
- Skilled at translating technical implementation (infrastructure as code and configuration as code) into verifiable eMASS security control responses that Approving Officials (AOs), and their staffs, can understand.
- Strong understanding of cybersecurity principles, technologies, and best practices, including encryption, authentication, access control, and secure coding practices.
- Hands-on experience with security assessment tools and techniques, such as vulnerability scanning and security analysis.
- Familiarity with software development methodologies and practices, particularly Agile and DevSecOps.
- Excellent analytical and problem-solving skills, with the ability to assess complex systems and identify security risks.
- Effective communication and interpersonal skills, with the ability to collaborate with cross-functional teams and communicate technical concepts to non-technical stakeholders.
- Eligibility to obtain and maintain a DoD security clearance.
- Eligibility to obtain and maintain privileged access in a Government Cloud Environment (relevant training and/or certifications).
Benefits
- Medical/Dental/Vision
- Premiums are 100% Company Paid
- Health Reimbursement Account
- Life Insurance
- Disability Insurance
- 401k Retirement Plan
- Company Stock Options
- Home Office Budget
- Flexible Time Off (FTO) plus all Federal Holidays, one week for Thanksgiving, and two weeks for Christmas and New Year’s
- Paid Parental Leave
Applicant Tracking System Keywords
Tip: use these terms in your resume and cover letter to boost ATS matches.
Hard Skills & Tools
cybersecurity engineeringNIST-800 seriesNIST-800-53risk assessmentsvulnerability analysessecurity testinginfrastructure as codeconfiguration as codevulnerability scanningsecure coding practices
Soft Skills
analytical skillsproblem-solving skillseffective communicationinterpersonal skillscollaborationthinking outside the box
Certifications
DoD security clearance