Cybersecurity Engineer

Xenon Innovations, Inc.

Fairfax (VA)

On-site

USD 135,000 - 230,000

Full time

14 days+
Application generator

Get a reply from this employer — a resume and cover letter tailored to exactly what they’re hiring for.

Get past ATS filters

Job summary

Xenon Innovations, Inc. is seeking an experienced security engineer to own the security layer across development and delivery environments.

You will build automation to enforce hardening, generate evidence artifacts, and ensure supply chain integrity as a built-in outcome of the build system. You will lead STIG and SRG automation, create SCAP/OpenSCAP content, and integrate SBOM generation into CI so every artifact ships with verified inventories and compliant documentation.

Qualifications

  • BS in Computer Science, Computer Engineering, Cybersecurity, or equivalent hands-on experience.
  • 5+ years in security engineering, DevSecOps, or platform engineering with demonstrable automation work.
  • Strong scripting and automation skills in Python and Bash.
  • Production experience with Ansible or equivalent configuration management.
  • Direct experience implementing DISA STIGs or SRGs in an automated fashion, including SCAP content work.
  • Working knowledge of CI/CD systems (Bitbucket, GitLab CI, or equivalent), containerization, and artifact repository management.
  • Familiarity with RMF, NIST SP 800-53, and NIST SP 800-171.
  • Ability to obtain a TS/SCI clearance.

Responsibilities

  • Design and maintain automated hardening for RHEL, Windows, container, network device, and application baselines against applicable DISA STIGs and SRGs.
  • Author, tailor, and validate SCAP and OpenSCAP content; build and maintain idempotent Ansible-based roles.
  • Automate STIG checklist (CKL) generation, deviation documentation, and evidence packaging so that compliance state is a build output rather than a manual exercise.
  • Engineer tailoring decisions for embedded and real-time targets where stock STIG guidance breaks the mission and document the technical rationale and compensating controls that makes those deviations defensible in review.
  • Stand up automated SBOM generation (CycloneDX or SPDX) across firmware, embedded, and application build pipelines, including for cross-compiled and constrained targets.
  • Integrate SBOM production into CI so every delivered artifact ships with an accurate, signed component inventory.
  • Produce and maintain VEX documentation to communicate real exploitability rather than raw CVE counts.
  • Ensure SBOM output satisfies customer and NDAA/EO supply chain delivery requirements.
  • Triage dependency and component vulnerabilities on technical merit and drive remediation with the engineering teams.
  • Implement artifact signing, provenance, and build attestation (Sigstore/cosign, SLSA-aligned practices) across the delivery chain.
  • Track upstream advisories and patch availability; own the engineering response when a component goes unmaintained or a fix does not exist.
  • Build security gates into CI/CD across both unclassified and accredited enclaves, including air-gapped environments.
  • Implement policy-as-code, IaC scanning, and secrets management within the build system.
  • Automate the production of RMF evidence artifacts to shorten the ATO path.

Skills

Python
Bash
Ansible
CI/CD
SCAP

Education

BS in Computer Science / Computer Engineering / Cybersecurity

Tools

Bitbucket
GitLab CI

Job description

Description

This is an engineering position, not a scanning position. This position is not here to run ACAS sweeps and transcribe findings into spreadsheets. This role is about building the automation that makes hardening, evidence generation, and supply chain assurance a property of the build system. If a control can be enforced by code and proven by an artifact, your job is to make that happen and to make it repeatable across every baseline we deliver.

You will own the security engineering layer across our development and delivery environments, working alongside the embedded, firmware, and platform teams.

STIG and SRG automation

  • Design and maintain automated hardening for RHEL, Windows, container, network device, and application baselines against applicable DISA STIGs and SRGs
  • Author, tailor, and validate SCAP and OpenSCAP content; build and maintain idempotent Ansible-based roles
  • Automate STIG checklist (CKL) generation, deviation documentation, and evidence packaging so that compliance state is a build output rather than a manual exercise
  • Engineer tailoring decisions for embedded and real-time targets where stock STIG guidance breaks the mission and document the technical rationale and compensating controls that makes those deviations defensible in review

Software bill of materials

  • Stand up automated SBOM generation (CycloneDX or SPDX) across firmware, embedded, and application build pipelines, including for cross-compiled and constrained targets
  • Integrate SBOM production into CI so every delivered artifact ships with an accurate, signed component inventory
  • Produce and maintain VEX documentation to communicate real exploitability rather than raw CVE counts
  • Ensure SBOM output satisfies customer and NDAA/EO supply chain delivery requirements

Supply chain security and remediation

  • Triage dependency and component vulnerabilities on technical merit and drive remediation with the engineering teams
  • Implement artifact signing, provenance, and build attestation (Sigstore/cosign, SLSA-aligned practices) across the delivery chain
  • Track upstream advisories and patch availability; own the engineering response when a component goes unmaintained or a fix does not exist

Pipeline and platform

  • Build security gates into CI/CD across both unclassified and accredited enclaves, including air-gapped environments
  • Implement policy-as-code, IaC scanning, and secrets management within the build system
  • Automate the production of RMF evidence artifacts to shorten the ATO path

Requirements

Minimum qualifications
  • BS in Computer Science, Computer Engineering, Cybersecurity, or equivalent hands-on experience
  • 5+ years in security engineering, DevSecOps, or platform engineering, with demonstrable automation work
  • Strong scripting and automation skills in Python and Bash
  • Production experience with Ansible or equivalent configuration management
  • Direct experience implementing DISA STIGs or SRGs in an automated fashion, including SCAP content work
  • Working knowledge of CI/CD systems (Bitbucket, GitLab CI, or equivalent), containerization, and artifact repository management
  • Familiarity with RMF, NIST SP 800-53, and NIST SP 800-171
  • Ability to obtain a TS/SCI clearance
Preferred qualifications
  • Experience with SBOM tooling (JFrog Xray, Syft, Trivy, Grype, cdxgen, or similar) in embedded or cross-compiled build environments
  • Prior work in air-gapped or classified development enclaves
  • Experience hardening embedded Linux or RTOS targets where standard STIG automation does not apply cleanly
  • Exposure to Navy accreditation processes
  • Relevant certification (CISSP, GSEC, or DoD 8570 IAT/IAM Level II+)
  • Active TS/SCI

Estimated Salary Range: $135,000-$230,000 per year

The salary range noted is intended as a general guide. Actual base salary offers from Xenon Innovations are determined based on several factors, including the position's scope and responsibilities, along with the candidate's experience, education, skill set, and prevailing market conditions.

Xenon Innovations, Inc. is an equal opportunity employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, national origin, age, disability, genetic information, or protected veteran status.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Software Engineer
Software Engineer

Xenon Innovations, Inc. • Fairfax (VA)

On-site
USD 130,000 - 225,000
DevOps Engineer
DevOps Engineer

Xenon Innovations, Inc. • Fairfax (VA)

On-site
USD 125,000 - 195,000
Senior Manager, Cybersecurity
Senior Manager, Cybersecurity

Cybersecurity Jobs • Washington

On-site
USD 170,000 - 250,000
Bonus
Benefits
Equity
Security Automation Engineer — CI/CD & SBOM Compliance
Security Automation Engineer — CI/CD & SBOM Compliance

Xenon Innovations, Inc. • Fairfax (VA)

On-site
USD 135,000 - 230,000
Cybersecurity Engineer (DoD Enterprise Security)
Cybersecurity Engineer (DoD Enterprise Security)

SHR CONSULTING GROUP, LLC • Arlington (VA)

On-site
USD 135,000 - 155,000
Medical, dental, vision coverage
401(k) with company match
Paid time off and holidays
+1
IT Security Engineer, Space
IT Security Engineer, Space

LinuxCareers • Costa Mesa (CA), Northern (KY)

On-site
USD 146,000 - 194,000
Health benefits
Comprehensive coverage
Equity grants
Systems Engineer
Systems Engineer

Xenon Innovations, Inc. • Fairfax (VA)

On-site
USD 130,000 - 230,000
Staff / Sr Staff Application Security Engineer
Staff / Sr Staff Application Security Engineer

SciTec • Boulder (CO)

On-site
USD 98,000 - 146,000
401(k) match
HSA Medical insurance
Dental insurance
+10
Cyber Technical Engineer
Cyber Technical Engineer

Technomics, Inc. • Arlington (VA)

On-site
USD 80,000 - 100,000
Cyber Security Specialist 4 - Springfield, VA
Cyber Security Specialist 4 - Springfield, VA

M.C. Dean, Inc. • Springfield (VA)

On-site
USD 125,000 - 172,000
Medical, dental, vision insurance
401k Retirement Plan
Paid time off
+3