Second Front logo
Second Front
Posted 79 days agoVerified live 1d ago

Cybersecurity Assessment Engineer

Brief overview

Remote
$125k–$140k/yrStated range
3+ yrsMinimum
Cybersecurity AssessmentVulnerability Risk AnalysisDevSecOps ToolsIncident Response PlanningAWSAzureGoogle Cloud PlatformPaaS EnvironmentsKubernetesNIST SP 800-37 (RMF)NIST SP 800-53 rev 5FedRAMP Authorization ProcessDepartment of Defense Security StandardsDOD 8570 Baseline Certification (IAT II)CYSA+ CertificationDockerGitLab

Job description

Summary

Second Front Systems (2F) is looking for a battle-tested, high-agency Cybersecurity Assessment Engineer to support our team. This role involves protecting the infrastructure and platforms that power mission-critical software for national security, ensuring a strong security posture through collaboration with various teams and conducting comprehensive security assessments.

Responsibilities

  • Review web application artifacts of customer developed applications and provide customer feedback
  • Primary face of the cybersecurity team to software development and mission success teams
  • Assist with incident response plans to respond to application outages or downtime
  • Technical Security Validation: Conduct comprehensive assessments of cloud infrastructure, applications, and containerized environments to verify compliance with DISA STIGs, SRGs, and CIS Benchmarks
  • Authorization Lifecycle Management: Author, review, and maintain high-quality security artifacts, including System Security Plans (SSP), Security Assessment Plans (SAP), and Security Assessment Reports (SAR)
  • Continuous Monitoring (ConMon): Monitor and report on the ongoing effectiveness of security controls, ensuring the platform maintains a robust and authorized security posture
  • Vulnerability & Risk Analysis: Utilize automated scanning suites (e.g., Anchore, Trivy, Tenable) to identify vulnerabilities, distinguish true positives, and provide actionable remediation guidance to dev teams
  • Supply Chain Security: Implement and manage technical workflows for SBOMs (Software Bill of Materials) to support modern, continuous authorization standards
  • Cross-Functional Collaboration: Partner with DevOps and Software Engineering teams to translate complex NIST 800-53 controls into implementable technical requirements

Skills

  • Experience solving complex and sometimes ill-defined problems
  • Intermediate knowledge of DevSecOps tools and software development
  • Ability to create and implement incident response plans
  • Background in cybersecurity and understanding of vulnerability risk analysis
  • Hands-on experience assessing or securing services within AWS, Azure, or GCP, particularly within PaaS or Kubernetes-based environments
  • Proficient knowledge of NIST SP 800-37 (RMF) and NIST SP 800-53 rev 5 security controls
  • Deep understanding of the FedRAMP authorization process and Department of Defense (DoD) security standards
  • 3-5 years of relevant experience
  • Ability to attain DOD 8570 Baseline Certification for IAT II within 6 months of hire date (preferably CYSA+)
  • Extensive experience with Department of Defense DevSecOps practices, policies, and security
  • Experience with Docker, Gitlab, Kubernetes, Anchore, or other container scanning tools
  • Ability to write basic scripts (Python, Bash, etc.) to automate evidence collection or data parsing
  • Strong interest in matters of national security
  • Having a Secret clearance is preferred

Qualifications

Must Haves

  • Experience solving complex and sometimes ill-defined problems
  • Intermediate knowledge of DevSecOps tools and software development
  • Ability to create and implement incident response plans
  • Background in cybersecurity and understanding of vulnerability risk analysis
  • Hands-on experience assessing or securing services within AWS, Azure, or GCP, particularly within PaaS or Kubernetes-based environments
  • Proficient knowledge of NIST SP 800-37 (RMF) and NIST SP 800-53 rev 5 security controls
  • Deep understanding of the FedRAMP authorization process and Department of Defense (DoD) security standards
  • 3-5 years of relevant experience
  • Ability to attain DOD 8570 Baseline Certification for IAT II within 6 months of hire date (preferably CYSA+)

Nice to Haves

  • Extensive experience with Department of Defense DevSecOps practices, policies, and security
  • Experience with Docker, Gitlab, Kubernetes, Anchore, or other container scanning tools
  • Ability to write basic scripts (Python, Bash, etc.) to automate evidence collection or data parsing
  • Strong interest in matters of national security
  • Having a Secret clearance is preferred

Benefits

  • Competitive Salary
  • 100% Healthcare, vision and dental coverage
  • 401(k) + 3% company contribution
  • Wellness perks (Fitness classes, mental health resources)
  • Equity incentive plan
  • Tech + office supplies stipend
  • Annual professional development stipend
  • Flexible paid time off + federal holidays off
  • Parental leave
  • Work from anywhere
  • Referral Bonus

More jobs like this