Summary
Axle is a bioscience and information technology company that develops translational research, biomedical informatics, and data science tools for research and healthcare organizations. Axle is seeking an early-career Cybersecurity Research Assistant to implement and monitor security controls across Kubernetes, Linux, database, and AI infrastructure, while supporting automation, vulnerability management, evidence collection, documentation, and federal security authorization activities.
Responsibilities
- Implement assigned security controls as configuration changes across our Kubernetes, Linux, database, and model-serving environments, working from the control catalog and an assigned task list
- Build out and operate monitoring and detection coverage, including metrics collection, dashboards, log aggregation, and alert routing
- Run vulnerability scanning across container images, hosts, and application dependencies on a set schedule, track findings to closure, and keep the plan of action and milestones current
- Write and maintain the automation that applies hardening baselines and checks them for drift, using Ansible and Python
- Contribute to secrets management, network policy, and role-based access control work across the cluster environments
- Build the deterministic collectors that gather control evidence, including cluster API queries, policy engine reports, scan output, access control dumps, and database configuration exports, normalized into a common format and stored with timestamps
- Help build the internal AI tooling that assists with this work, including retrieval over the control catalog and system documentation, drafting from collected evidence, and triaging scanner output into ranked findings for human review
- Keep security documentation in agreement with the deployed configuration, and raise discrepancies promptly through your supervisors
- Test what you build. Restore a backup and confirm it works, break a policy on purpose and confirm the alert fires, and verify that a control you implemented does what the catalog says it does
- Document what you did in enough detail that an assessor can follow it a year from now
- Prepare material for security reviews and continuous monitoring reports, working with your supervisors on anything that goes to an assessor or an authorizing official
Skills
- One to three years of professional experience in IT, systems administration, help desk, network operations, or a comparable hands-on technical role
- Comfort on the Linux command line. You can read a log, trace a permissions problem, and work out what a service is doing
- Scripting ability in Bash and Python. You do not need to be a software engineer, but you should have automated something real and be able to walk us through it
- Demonstrated interest in security. Coursework, a home lab, capture the flag competitions, a Security+ in progress, a personal project, or security work inside a broader IT role all count
- Careful, methodical work habits. Much of this job is doing a procedure correctly, recording what happened, and noticing when the result does not match what was expected
- Willingness to ask questions early and to say plainly when you do not know something
- Ability to work independently on assigned tasks and to give regular updates on what is planned, in progress, and finished
- Ability to obtain and maintain a Public Trust Security clearance
- Associate's or Bachelor's degree in Computer Science, Information Technology, Cybersecurity, Information Systems, or a related field. We will consider equivalent professional experience or a completed technical certification program in place of a degree
- Working knowledge of Linux system administration, ideally on RHEL based systems such as Rocky Linux, and on Ubuntu
- Basic understanding of networking, including TCP/IP, DNS, TLS, firewalls, and how a request travels from a browser to a service
- Basic familiarity with containers, and real interest in learning Kubernetes. We will teach it. You should want to learn it
- Familiarity with version control and comfort working in a shared Git repository
- Ability to follow a written procedure precisely, and to notice when the procedure itself is wrong
- Clear written communication. A large part of this role is documenting what was done and why
- Interest in learning how federal security authorization actually works, including NIST security controls, continuous monitoring, and how evidence is assembled and reviewed
- CompTIA Security+, Network+, or Linux+, a Kubernetes certification, or a cloud certification
- Coursework or a degree concentration in cybersecurity or information assurance
- Any exposure to NIST security standards, security frameworks, or compliance work, including academic exposure
- A home lab, capture the flag participation, open-source contributions, or a personal project you can walk us through
- Experience with Ansible, Terraform, or another configuration management tool
- Any experience with Prometheus, Grafana, Elastic, or another monitoring or logging platform
- Curiosity about large language models and about building tools with them. Prior AI experience is not expected. You would learn that here
- Prior work at NIH or another federal agency, or familiarity with federal IT environments
Qualifications
Must Haves
- One to three years of professional experience in IT, systems administration, help desk, network operations, or a comparable hands-on technical role
- Comfort on the Linux command line. You can read a log, trace a permissions problem, and work out what a service is doing
- Scripting ability in Bash and Python. You do not need to be a software engineer, but you should have automated something real and be able to walk us through it
- Demonstrated interest in security. Coursework, a home lab, capture the flag competitions, a Security+ in progress, a personal project, or security work inside a broader IT role all count
- Careful, methodical work habits. Much of this job is doing a procedure correctly, recording what happened, and noticing when the result does not match what was expected
- Willingness to ask questions early and to say plainly when you do not know something
- Ability to work independently on assigned tasks and to give regular updates on what is planned, in progress, and finished
- Ability to obtain and maintain a Public Trust Security clearance
- Associate's or Bachelor's degree in Computer Science, Information Technology, Cybersecurity, Information Systems, or a related field. We will consider equivalent professional experience or a completed technical certification program in place of a degree
- Working knowledge of Linux system administration, ideally on RHEL based systems such as Rocky Linux, and on Ubuntu
- Basic understanding of networking, including TCP/IP, DNS, TLS, firewalls, and how a request travels from a browser to a service
- Basic familiarity with containers, and real interest in learning Kubernetes. We will teach it. You should want to learn it
- Familiarity with version control and comfort working in a shared Git repository
- Ability to follow a written procedure precisely, and to notice when the procedure itself is wrong
- Clear written communication. A large part of this role is documenting what was done and why
- Interest in learning how federal security authorization actually works, including NIST security controls, continuous monitoring, and how evidence is assembled and reviewed
Nice to Haves
- CompTIA Security+, Network+, or Linux+, a Kubernetes certification, or a cloud certification
- Coursework or a degree concentration in cybersecurity or information assurance
- Any exposure to NIST security standards, security frameworks, or compliance work, including academic exposure
- A home lab, capture the flag participation, open-source contributions, or a personal project you can walk us through
- Experience with Ansible, Terraform, or another configuration management tool
- Any experience with Prometheus, Grafana, Elastic, or another monitoring or logging platform
- Curiosity about large language models and about building tools with them. Prior AI experience is not expected. You would learn that here
- Prior work at NIH or another federal agency, or familiarity with federal IT environments
Benefits
- 100% Medical, Dental & Vision Coverage for Employees
- Paid Time Off and Paid Holidays
- 401K match up to 5%
- Educational Benefits for Career Growth
- Employee Referral Bonus
- Healthcare Flexible Spending Account (FSA)
- Parking Reimbursement Account (PRK)
- Dependent Care Assistant Program (DCAP)
- Transportation Reimbursement Account (TRN)
- Axle will sponsor the right candidate for those certifications and provides working hours to study for them.
- Axle pays for certification exams and study materials, and this role includes scheduled working hours for study rather than expecting it on your own time.
- Remote position within the United States