Cybersecurity Assessment Engineer

Second Front Systems

Washington (District of Columbia)

On-site

USD 125,000 - 140,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Competitive Salary
Healthcare, vision and dental coverage
401(k) with company contribution
Wellness perks
Equity incentive plan
Tech + office supplies stipend
Annual professional development
Flexible PTO
Parental leave
Work from anywhere
Referral Bonus

Job summary

Second Front Systems is seeking a battle-tested Cybersecurity Assessment Engineer to support our team in defending mission-critical software. You will oversee security assessments of cloud infrastructure, applications, and containers, ensuring compliance with DISA STIGs, SRGs, and CIS Benchmarks.

You will collaborate with DevOps and Mission Success teams to translate NIST controls into actionable technical requirements, drive vulnerability analysis, and strengthen our security posture across

Qualifications

  • Experience solving complex and ill-defined problems.
  • Regular use of DevSecOps tools in a software development context.
  • Ability to create and implement incident response plans.
  • Background in cybersecurity and vulnerability risk analysis.
  • Hands-on experience with cloud environments (AWS/Azure/GCP).
  • Familiarity with NIST 800-37 RMF and NIST 800-53 rev5 controls.
  • Understanding of DoD security standards and FedRAMP processes.
  • 3-5 years of relevant work experience.
  • Ability to attain DOD 8570 IAT II certification within 6 months.

Responsibilities

  • Review customer web application artifacts and provide feedback.
  • Be the primary cybersecurity face to software development and mission success teams.
  • Assist with incident response plans for outages or downtime.
  • Conduct technical security validation to verify compliance with DISA STIGs, SRGs, and CIS Benchmarks.
  • Author and maintain SSPs, SAPs, and SARs.
  • Monitor ConMon and report on ongoing security control effectiveness.
  • Perform vulnerability and risk analysis using scanners to identify true positives and remediation guidance.
  • Manage SBOMs and supply chain security workflows.

Skills

Complex problem solving
DevSecOps tools
Incident response
Vulnerability risk analysis
Cloud security (AWS/Azure/GCP)
NIST SP 800-37 RMF
NIST SP 800-53 rev5
FedRAMP
DOD 8570 IAT II
3-5 years experience

Tools

Docker
Gitlab
Kubernetes
Anchore

Job description

Second Front Systems (2F) is looking for a battle-tested, high-agency Cybersecurity Assessment Engineer to support our team.. We sit at the high-stakes intersection of defense tech and national security, and this role is about building a modern, resilient operations function from the ground up. You’ll be protecting the infrastructure and platforms that power mission-critical software for the free world—ensuring our nation’s defenders have the secure environment they need to move fast.

At 2F, we pair a startup’s bias for action with a relentless sense of purpose. As a Cybersecurity Assessment Engineer at Second Front Systems, you will help ensure that Game Warden maintains a strong security posture. You will work hand-in-hand with the DevOps Engineering and Mission Success teams to oversee the software vulnerability scanning process, review vulnerability scan results, assist the customers in understanding those results, and make approval recommendations for vulnerabilities that can’t be immediately resolved. This role will require learning new things like researching identified vulnerabilities, assessing risk, solving big problems, speaking your mind, and contributing to a culture of diversity, innovation, and excellence. This role is key to the security of our cloud platform and of the customer applications running on it.

Note: Candidates must reside in one of our approved hiring hubs:

  • DC/Maryland/Virginia

  • Raleigh/Durham/Chapel Hill, NC

  • Denver/Colorado Springs, CO

  • Dallas/Fort Worth, TX

What You’ll Do
  • Review web application artifacts of customer developed applications and provide customer feedback

  • Primary face of the cybersecurity team to software development and mission success teams

  • Assist with incident response plans to respond to application outages or downtime

  • Technical Security Validation: Conduct comprehensive assessments of cloud infrastructure, applications, and containerized environments to verify compliance with DISA STIGs, SRGs, and CIS Benchmarks.

  • Authorization Lifecycle Management: Author, review, and maintain high-quality security artifacts, including System Security Plans (SSP), Security Assessment Plans (SAP), and Security Assessment Reports (SAR).

  • Continuous Monitoring (ConMon): Monitor and report on the ongoing effectiveness of security controls, ensuring the platform maintains a robust and authorized security posture.

  • Vulnerability & Risk Analysis: Utilize automated scanning suites (e.g., Anchore, Trivy, Tenable) to identify vulnerabilities, distinguish true positives, and provide actionable remediation guidance to dev teams.

  • Supply Chain Security: Implement and manage technical workflows for SBOMs (Software Bill of Materials) to support modern, continuous authorization standards.

  • Cross-Functional Collaboration: Partner with DevOps and Software Engineering teams to translate complex NIST 800-53 controls into implementable technical requirements.

What You Bring
  • Experience solving complex and sometimes ill-defined problems

  • Intermediate knowledge of DevSecOps tools and software development

  • Ability to create and implement incident response plans

  • Background in cybersecurity and understanding of vulnerability risk analysis

  • Hands-on experience assessing or securing services within AWS, Azure, or GCP, particularly within PaaS or Kubernetes-based environments.

  • Proficient knowledge of NIST SP 800-37 (RMF) and NIST SP 800-53 rev 5 security controls

  • Deep understanding of the FedRAMP authorization process and Department of Defense (DoD) security standards.

  • 3-5 years of relevant experience

  • Ability to attain DOD 8570 Baseline Certification for IAT II within 6 months of hire date (preferably CYSA+)

Preferred
  • Extensive experience with Department of Defense DevSecOps practices, policies, and security

  • Experience with Docker, Gitlab, Kubernetes, Anchore, or other container scanning tools

  • Ability to write basic scripts (Python, Bash, etc.) to automate evidence collection or data parsing

  • Strong interest in matters of national security

  • Having a Secret clearance is preferred

The base salary for this position will fall between $125,000-140,000 Your ultimate compensation will be determined by professional background, technical proficiency, seniority, and regional cost factors. Furthermore, this opportunity includes potential eligibility for equity awards and discretionary bonuses, rounding out a comprehensive total rewards offering.

Success at 2F Looks Like:
  • Viewing obstacles as opportunities for growth

  • Having a bias toward action and tangible, measurable results

  • Striving to be both compassionate and direct with your feedback

  • Being team-oriented and inclusive with your action

Perks & Benefits:

This role is a full time position. As a public benefit corporation, we’re a team of purpose-driven trailblazers transforming the future of U.S. national security. We hire the best to do their best and, as such, we are committed to providing the perks and benefits you need to be successful—both in- and outside the workplace.

We offer you:

  • Competitive Salary

  • 100% Healthcare, vision and dental coverage

  • 401(k) + 3% company contribution

  • Wellness perks (Fitness classes, mental health resources)

  • Equity incentive plan

  • Tech + office supplies stipend

  • Annual professional development stipend

  • Flexible paid time off + federal holidays off

  • Parental leave

  • Work from anywhere

  • Referral Bonus

Who We Are:

Second Front Systems (2F) is a public-benefit software company powering software for the free world. We eliminate the friction that slows innovation, enabling faster, more secure development and deployment of software across government and regulated networks. Built by national security veterans and backed by top-tier venture capital, our platform is trusted by the world’s leading organizations to cut deployment timelines from years to weeks. We move fast, solve hard problems, and deliver trusted capabilities where they’re needed most. Our work strengthens global security and gives the United States and its allies a lasting competitive advantage. Learn more at secondfront.com.

One last thing:

We are an equal opportunity employer and all qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity or expression, pregnancy, age, national origin, disability status, genetic information, protected veteran status, or any other characteristic protected by law.

State notices:

Colorado:

In accordance with Colorado law, applicants may redact their date of birth, dates of attendance, and dates of graduation from any uploaded documents.

Maryland:

Under Maryland law, an employer may not require or demand, as a condition of employment, prospective employment, or continued employment, that an individual submit to or take a polygraph examination or similar test. An employer who violates this law is guilty of a misdemeanor and subject to a fine not exceeding $100.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Forward Deployed Engineer
Forward Deployed Engineer

Second Front Systems • Washington

On-site
USD 105,000 - 141,000
Competitive Salary
Healthcare coverage
401(k) + company contribution
+4
Customer Operations Engineer
Customer Operations Engineer

Second Front • United States

Remote
USD 135,000 - 160,000
100% Healthcare, vision, and dental coverage
401(k) with company contribution
Equity incentive plan
+5
Sr. Enterprise Customer Operations Engineer
Sr. Enterprise Customer Operations Engineer

Second Front • Washington

On-site
USD 140,000 - 190,000
Competitive Salary
Healthcare, vision & dental
401(k) + company contribution
+7
Senior Forward Deployed Engineer
Senior Forward Deployed Engineer

Second Front • Washington

On-site
USD 105,000 - 141,000
100% Healthcare coverage
401(k) with company contribution
Wellness perks
+4
Commercial Sales Account Executive
Commercial Sales Account Executive

Second Front Systems • Washington

On-site
USD 110,000 - 280,000
Competitive salary
100% Healthcare, vision and dental
401(k) + 3% company contribution
+2
SOC Manager
SOC Manager

Second Front • Washington

Hybrid
USD 205,000 - 215,000
Competitive salary
100% employer-paid medical, dental, &
401(k) with company match
+6
Commercial Sales Account Executive
Commercial Sales Account Executive

Second Front • Washington

On-site
USD 110,000 - 140,000
Health coverage
401(k) contribution
Wellness perks
+6
Commercial Business Development Representative
Commercial Business Development Representative

Second Front • Washington

On-site
USD 70,000 - 80,000
Competitive Salary
100% Healthcare, vision and dental
401(k) + 3% company contribution
+6
Senior Forward Deployed Engineer - Implementation Focus
Senior Forward Deployed Engineer - Implementation Focus

Second Front • Washington

On-site
USD 119,000 - 160,000
Competitive Salary
Healthcare coverage
401(k) + company contribution
+3
Commercial Sales Account Executive Growth
Commercial Sales Account Executive Growth

Front Door Defense • United States

On-site
USD 110,000 - 140,000
Competitive salary
Healthcare coverage (vision & dental)
401(k) + 3% company contribution
+8