Base Career helps you apply smarter for this job.
Key skills for this role
Review web application artifacts of customer developed applications and provide customer feedback
Primary face of the cybersecurity team to software development and mission success teams
Assist with incident response plans to respond to application outages or downtime
Technical Security Validation: Conduct comprehensive assessments of cloud infrastructure, applications, and containerized environments to verify compliance with DISA STIGs, SRGs, and CIS Benchmarks.
Authorization Lifecycle Management: Author, review, and maintain high-quality security artifacts, including System Security Plans (SSP), Security Assessment Plans (SAP), and Security Assessment Reports (SAR).
Continuous Monitoring (ConMon): Monitor and report on the ongoing effectiveness of security controls, ensuring the platform maintains a robust and authorized security posture.
Vulnerability & Risk Analysis: Utilize automated scanning suites (e.g., Anchore, Trivy, Tenable) to identify vulnerabilities, distinguish true positives, and provide actionable remediation guidance to dev teams.
Supply Chain Security: Implement and manage technical workflows for SBOMs (Software Bill of Materials) to support modern, continuous authorization standards.
Cross-Functional Collaboration: Partner with DevOps and Software Engineering teams to translate complex NIST 800-53 controls into implementable technical requirements.
Experience solving complex and sometimes ill-defined problems
Intermediate knowledge of DevSecOps tools and software development
Ability to create and implement incident response plans
Background in cybersecurity and understanding of vulnerability risk analysis
Hands-on experience assessing or securing services within AWS, Azure, or GCP, particularly within PaaS or Kubernetes-based environments.
Skip the repetitive application forms
Install the Base Career Chrome Extension and autofill job applications across major job boards with your profile.
Trusted by over 500,000 job seekers on Base Career
More from this employer
, USA
, USA
, USA
, USA
, USA
, USA
, USA
, USA
Proficient knowledge of NIST SP 800-37 (RMF) and NIST SP 800-53 rev 5 security controls
Deep understanding of the FedRAMP authorization process and Department of Defense (DoD) security standards.
3-5 years of relevant experience
Ability to attain DOD 8570 Baseline Certification for IAT II within 6 months of hire date (preferably CYSA+)
Extensive experience with Department of Defense DevSecOps practices, policies, and security
Experience with Docker, Gitlab, Kubernetes, Anchore, or other container scanning tools
Ability to write basic scripts (Python, Bash, etc.) to automate evidence collection or data parsing
Strong interest in matters of national security
Having a Secret clearance is preferred
The base salary for this position will fall between $125,000-140,000 Your ultimate compensation will be determined by professional background, technical proficiency, seniority, and regional cost factors. Furthermore, this opportunity includes potential eligibility for equity awards and discretionary bonuses, rounding out a comprehensive total rewards offering.
Viewing obstacles as opportunities for growth
Having a bias toward action and tangible, measurable results
Striving to be both compassionate and direct with your feedback
Being team-oriented and inclusive with your action
Second Front Systems (2F) is a public-benefit software company powering software for the free world. We eliminate the friction that slows innovation, enabling faster, more secure development and deployment of software across government and regulated networks. Built by national security veterans and backed by top-tier venture capital, our platform is trusted by the world’s leading organizations to cut deployment timelines from years to weeks. We move fast, solve hard problems, and deliver trusted capabilities where they’re needed most. Our work strengthens global security and gives the United States and its allies a lasting competitive advantage. Learn more at secondfront.com .
We are an equal opportunity employer and all qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity or expression, pregnancy, age, national origin, disability status, genetic information, protected veteran status, or any other characteristic protected by law.
Colorado:
In accordance with Colorado law, applicants may redact their date of birth, dates of attendance, and dates of graduation from any uploaded documents.
Maryland:
Under Maryland law, an employer may not require or demand, as a condition of employment, prospective employment, or continued employment, that an individual submit to or take a polygraph examination or similar test. An employer who violates this law is guilty of a misdemeanor and subject to a fine not exceeding $100.
Public-benefit software company helping governments and defense organizations securely deploy mission-critical SaaS.
Visit company websiteJobs and hiring trendsUSD 125000-140000 yearly / year
Full-time
Mid · 3+ years experience
Remote
Apply faster on company sites with our extension.