Cybersecurity Engineer
Job Description
Zaden Technologies, Inc. is seeking a Cybersecurity Engineer with an ISSO background to support RMF authorization activities and strengthen system security posture. The position also partners closely with DevSecOps to embed security into CI/CD workflows and streamline compliance evidence collection.
Responsibilities
- Perform ISSO duties for assigned systems, maintaining their security posture through the RMF lifecycle
- Develop and maintain authorization artifacts, including System Security Plans, POA&Ms, risk assessments, and incident response plans
- Implement and validate security controls, and support assessors during the authorization process
- Conduct vulnerability scanning, review audit logs, and perform STIG compliance checks; coordinate with system owners to remediate findings
- Harden operating systems, applications, and network components to align with STIG and SRG baselines
- Collaborate with DevSecOps engineers to integrate security tooling into CI/CD pipelines and translate control requirements into technical solutions
- Apply DevOps practices such as containerization, Infrastructure-as-Code, and scripting to automate compliance evidence collection
- Identify repeatable manual security tasks and work with the team to automate them
- Investigate and document security incidents, and report findings to leadership and relevant stakeholders
- Track emerging threats and evolving cybersecurity policy, and recommend improvements to Zaden’s security practices
Requirements
- U.S. Citizenship and active security clearance (minimum Secret)
- 3+ years of cybersecurity experience, including hands-on work as an ISSO or in an equivalent information assurance role
- Working knowledge of the Risk Management Framework (RMF) and NIST SP 800-53 security controls
- Experience preparing and maintaining authorization packages, including SSPs and POA&Ms
- Experience with vulnerability scanning and compliance tools such as ACAS/Nessus, SCAP Compliance Checker, or STIG Viewer
- Hands-on experience hardening Linux or Windows systems
- Strong written communication skills for security documentation and reporting
- Genuine interest in learning DevOps tools and practices, with motivation to build those skills on the job
- DoD 8140/8570 IAT Level II certification (for example, CompTIA Security+) or ability to obtain within 6 months of hire
Preferred Qualifications
- Experience with eMASS or similar GRC platforms
- Exposure to CI/CD tools such as GitLab CI, GitHub Actions, or Jenkins
- Exposure to containers or orchestration tools such as Docker or Kubernetes
- Basic scripting experience in Bash, Python, or PowerShell
- Familiarity with cloud platforms such as AWS or Azure and their native security services
- Experience with SIEM platforms such as Splunk or Elastic
- Familiarity with zero trust architecture principles
- Advanced certification such as CISSP, CISM, or CASP+
Technologies
- Risk Management Framework (RMF), NIST SP 800-53
- System Security Plans (SSPs), POA&Ms
- ACAS/Nessus, SCAP Compliance Checker, STIG Viewer
- Linux, Windows
- DevOps, containerization, Infrastructure-as-Code, CI/CD pipelines
- STIG, SRG
- DoD 8140/8570, CompTIA Security+
- eMASS
- GitLab CI, GitHub Actions, Jenkins
- Docker, Kubernetes
- Bash, Python, PowerShell
- AWS, Azure
- Splunk, Elastic
- Zero trust architecture
- CISSP, CISM, CASP+
Location and Experience
Location: Huntsville, AL (onsite)
Minimum Experience: 3 years