Cybersecurity Engineer (Software Assurance / ISSO Support)
Job Description
Astrion is hiring an onsite Cybersecurity Engineer to support the U.S. Space Force Space Sensing Directorate at BGIF, with a primary focus on Software Assurance in classified environments and supplemental ISSO support.
Responsibilities
- Evaluate software architecture and design to confirm systems are functional and resilient against cyber-attacks.
- Integrate security tooling and vulnerability checks into CI/CD pipelines for continuous delivery security.
- Review results from code scanning and vulnerability assessments and coordinate with development teams to remediate software issues.
- Apply Secure Technical Implementation Guide (STIG) best practices for software, applications, and databases.
- Assist in developing and maintaining Defensive Cyberspace Operations tactics for application-level security monitoring.
- Support ISSM and senior ISSOs with Assessment and Authorization (A&A) documentation updates, including:
- System Security Plan (SSP)
- Security Controls Traceability Matrices (SCTMs)
- Assist in tracking and updating Plan of Action and Milestones (POA&M) for software and system vulnerabilities.
- Support periodic reviews and evaluations of Information System (IS) policies and procedures.
- Assist in preparation for and execution of IS Security Inspections, tests, and reviews.
- Contribute to vulnerability and risk assessment analysis to support authorization and accreditation activities.
Requirements
- Bachelor’s degree in Computer Science, Cybersecurity, Engineering, or a related technical field (Required).
- 1 to 3 years of experience in cybersecurity, software engineering, or IT security. Internships and academic project experience in secure coding or cyber compliance will be considered (Required).
- Valid Security+ CE certification. Must meet the position and certification requirements in DoD Directive 8570.01-M for Information Assurance Technical (IAT) Level II (Required).
- Familiarity with secure coding, DevSecOps pipelines, and application security testing tools (e.g., SAST, DAST, SCA) (Highly Desired).
- Basic understanding of Risk Management Framework (RMF) and Authorization to Operate (ATO) (Desired).
- Familiarity with DISA STIGs and applying them to applications and operating systems (Desired).
- Basic understanding of cloud-based systems, Linux/Windows operating systems, and networking fundamentals (Desired).
- Ability to obtain and maintain the required security clearance for access to classified systems.
Technologies
- DevSecOps
- CI/CD
- SAST
- DAST
- SCA
- STIGs
- RMF
- ATO
- Linux
- Windows
Clearance
- Active Secret / SCI Eligible
Location
- Boulder Ground Innovation Facility (BGIF), Boulder, CO
- Onsite
Salary
- Estimated $125,000 + annually *
- Depending on experience, certifications, and qualifications
*Salary range shown as provided: estimated $125,000 + annually.