
Cybersecurity Engineer – DevOps
Posted 13 hours ago

Posted 13 hours ago
This is a fully remote position, open to applicants in United States.
• Oversee cybersecurity measures for software utilized in secure federal and Department of Defense (DoD) settings.
• Carry out Risk Management Framework (RMF) activities, which include system categorization, selection and implementation of security controls, assessment, and documentation for Authority to Operate (ATO).
• Implement, configure, and validate Security Technical Implementation Guides (STIGs) using DISA-approved or equivalent security tools provided by the government.
• Address OWASP Top 10 vulnerabilities and mitigate issues at the application layer.
• Monitor security controls, conduct vulnerability scans, and perform system audits; generate reports and facilitate remediation efforts.
• Manage Plans of Action and Milestones (POA&Ms) and collaborate with government security stakeholders, Information System Security Managers (ISSMs), and internal teams.
• Assist in ensuring compliance with FedRAMP and FISMA, in alignment with NIST SP 800-53 Rev. 5 standards.
• Incorporate security tools and automated checks into Continuous Integration/Continuous Deployment (CI/CD) pipelines to enhance DevSecOps maturity.
• Perform threat modeling, conduct security design reviews, and carry out application-level security assessments.
• Maintain System Security Plans, security architectures, and ATO documentation sets.
• Lead incident response procedures for security incidents and coordinate with client cybersecurity teams.
• Monitor Security Information and Event Management (SIEM) alerts, analyze logs, and investigate suspicious activities.
• Assess the security posture of third-party integrations, vendor technologies, and new advancements.
• Integrate security requirements into sprint planning, feature development, and release cycles.
• Stay updated on federal, DoD, DISA, and agency-specific security policy changes and communicate their implications to the engineering team.
• Must be a U.S. citizen.
• Active DoD security clearance or the capability to obtain and retain one due to access to secure federal environments.
• At least 3-5 years of direct cybersecurity experience in federal, DoD, or similarly regulated secure settings.
• Strong understanding of secure federal or DoD environments, encompassing segmented networks, access controls, approved software baselines, and relevant security requirements.
• Experience in supporting or leading RMF processes, including the preparation and submission of ATO packages for federal or DoD systems.
• Expertise in applying STIGs using DISA-approved tools (SCC, STIG Viewer, Nessus/ACAS) or similar vulnerability and compliance platforms.
• Comprehensive knowledge of FedRAMP Moderate and FISMA compliance, with the ability to correlate security controls to NIST SP 800-53 Rev. 5.
• Familiarity with vulnerability management tools such as Tenable.sc, Nessus, and ACAS within federal or DoD environments.
• Knowledge of enterprise security solutions including SIEM, Intrusion Detection Systems (IDS)/Intrusion Prevention Systems (IPS), and network security measures.
• Experience with DevSecOps, integrating Static Application Security Testing (SAST), Dynamic Application Security Testing (DAST), and Software Composition Analysis (SCA) scanning into CI/CD pipelines using Azure DevOps, Jenkins, or similar tools.
• Understanding of Public Key Infrastructure (PKI), Common Access Card (CAC)/Personal Identity Verification (PIV) authentication, and certificate management in federal or DoD contexts.
• Compliance with DoD 8570/8140 certification requirements at IAT Level II or higher, such as CompTIA Security+, CISSP, CEH, or CAP.
• Bachelor’s degree in Computer Science, Information Security, Cybersecurity, or a related discipline, or equivalent practical experience.
• Experience working within segmented networks, understanding the infrastructure and security requirements of federal, DoD, or similarly regulated environments.
• Demonstrated time management, organizational, and follow-up abilities to meet deadlines.
• Capacity to work efficiently, both independently and within a dynamic team environment.
• Strong interpersonal skills.
• Openness to acquiring new technologies and processes as required.
• Medical, Dental, and Vision Insurance.
• Health Savings Account.
• Flexible Spending Account.
• 401(k) Retirement Plan with Company Match.
• Life and Disability Insurance.
• Critical Illness Insurance.
• Accident Insurance.
• Hospital Indemnity Insurance.
• Paid Time Off and Holidays.
• Flexible Working Schedule.
• Eligible for Variable Compensation Plan.
OnePay
Arista Networks
Octus
Tandem Diabetes Care
Get handpicked remote jobs straight to your inbox weekly.