Summary
Second Front Systems (2F) is looking for a battle-tested, high-agency Cybersecurity Assessment Engineer to support our team. This role involves protecting the infrastructure and platforms that power mission-critical software for national security, ensuring a strong security posture through collaboration with various teams and conducting comprehensive security assessments.
Responsibilities
- Review web application artifacts of customer developed applications and provide customer feedback
- Primary face of the cybersecurity team to software development and mission success teams
- Assist with incident response plans to respond to application outages or downtime
- Technical Security Validation: Conduct comprehensive assessments of cloud infrastructure, applications, and containerized environments to verify compliance with DISA STIGs, SRGs, and CIS Benchmarks
- Authorization Lifecycle Management: Author, review, and maintain high-quality security artifacts, including System Security Plans (SSP), Security Assessment Plans (SAP), and Security Assessment Reports (SAR)
- Continuous Monitoring (ConMon): Monitor and report on the ongoing effectiveness of security controls, ensuring the platform maintains a robust and authorized security posture
- Vulnerability & Risk Analysis: Utilize automated scanning suites (e.g., Anchore, Trivy, Tenable) to identify vulnerabilities, distinguish true positives, and provide actionable remediation guidance to dev teams
- Supply Chain Security: Implement and manage technical workflows for SBOMs (Software Bill of Materials) to support modern, continuous authorization standards
- Cross-Functional Collaboration: Partner with DevOps and Software Engineering teams to translate complex NIST 800-53 controls into implementable technical requirements
Skills
- Experience solving complex and sometimes ill-defined problems
- Intermediate knowledge of DevSecOps tools and software development
- Ability to create and implement incident response plans
- Background in cybersecurity and understanding of vulnerability risk analysis
- Hands-on experience assessing or securing services within AWS, Azure, or GCP, particularly within PaaS or Kubernetes-based environments
- Proficient knowledge of NIST SP 800-37 (RMF) and NIST SP 800-53 rev 5 security controls
- Deep understanding of the FedRAMP authorization process and Department of Defense (DoD) security standards
- 3-5 years of relevant experience
- Ability to attain DOD 8570 Baseline Certification for IAT II within 6 months of hire date (preferably CYSA+)
- Extensive experience with Department of Defense DevSecOps practices, policies, and security
- Experience with Docker, Gitlab, Kubernetes, Anchore, or other container scanning tools
- Ability to write basic scripts (Python, Bash, etc.) to automate evidence collection or data parsing
- Strong interest in matters of national security
- Having a Secret clearance is preferred
Qualifications
Must Haves
- Experience solving complex and sometimes ill-defined problems
- Intermediate knowledge of DevSecOps tools and software development
- Ability to create and implement incident response plans
- Background in cybersecurity and understanding of vulnerability risk analysis
- Hands-on experience assessing or securing services within AWS, Azure, or GCP, particularly within PaaS or Kubernetes-based environments
- Proficient knowledge of NIST SP 800-37 (RMF) and NIST SP 800-53 rev 5 security controls
- Deep understanding of the FedRAMP authorization process and Department of Defense (DoD) security standards
- 3-5 years of relevant experience
- Ability to attain DOD 8570 Baseline Certification for IAT II within 6 months of hire date (preferably CYSA+)
Nice to Haves
- Extensive experience with Department of Defense DevSecOps practices, policies, and security
- Experience with Docker, Gitlab, Kubernetes, Anchore, or other container scanning tools
- Ability to write basic scripts (Python, Bash, etc.) to automate evidence collection or data parsing
- Strong interest in matters of national security
- Having a Secret clearance is preferred
Benefits
- Competitive Salary
- 100% Healthcare, vision and dental coverage
- 401(k) + 3% company contribution
- Wellness perks (Fitness classes, mental health resources)
- Equity incentive plan
- Tech + office supplies stipend
- Annual professional development stipend
- Flexible paid time off + federal holidays off
- Parental leave
- Work from anywhere
- Referral Bonus