Cybersecurity Engineer - DSOP

SAIC

California (MO)

On-site

USD 160,001 - 200,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

SAIC is seeking a Cybersecurity Engineer (DSOP) to build and operate CMCC’s secure DSOP pipeline at Beale AFB, CA. You will integrate automated SAST/DAST and container security, enforce secure coding gates, validate artifacts, and deliver evidence for RMF/cATO readiness.

The role requires US Citizenship and strong DevSecOps tooling experience. You will collaborate with cloud engineers and operators to enable secure-by-default CI/CD automation and support mission readiness across multiple

Qualifications

  • US Citizenship required.
  • 9+ years experience with a Bachelor’s; 7+ with a Master’s; 4+ with a PhD/JD.
  • Hands-on automated SAST/DAST/container scans with Fortify, ZAP, Grype/Trivy.
  • Proficiency with DevSecOps tooling including GitLab CI/CD and SBOM/SCA.

Responsibilities

  • Build, enhance, and operate DSOP pipeline stages (SAST, DAST, container scanning, SBOM/SCA).
  • Implement pipeline blocking rules for Critical/High vulnerabilities.
  • Integrate cyber validation tasks into CI/CD for multiple environments.
  • Validate artifact integrity and provide developer enablement for DSOP tools.
  • Review CWE/CVE findings and drive remediation across DSOPS, Cloud, CE, CP teams.
  • Ensure rollback readiness when cyber gates block promotion.

Skills

SAST
DAST
Container security
GitLab CI/CD
SBOM/SCA
Fortify
ZAP
Grype/Trivy
RMF/cATO pipelines
Vulnerability remediation

Education

Bachelor's degree
Master's degree
PhD/JD

Job description

Minimum Clearance Required TS.SCI

Job ID 2614830-OTHLOC-100000685974616

Location Beale AFB, CA, US

Date Posted 2026-07-23

Category Software

Subcategory DevSecOps

Schedule Full-Time

Shift Day Job

Travel Yes - 10% of the time

Minimum Clearance Required TS.SCI

Clearance Level Must Be Able to Obtain None

Potential for Remote Work ORA_ON_SITE

Description

SAIC is a trusted leader in delivering advanced command and control capabilities across the Department of the Air Force, bringing deep expertise in how cutting edge technologies are engineered, secured, and delivered to the fight. At the center of this mission, the Common Mission Control Center (CMCC) unifies data, sensors, mission applications, cloud based services, and emerging AI enabled automation to give warfighters a decisive edge—turning complex, multidomain information into fast, clear, and actionable decisions in the moments that matter most. The CMCC System Facilitator contract positions SAIC to accelerate how new capabilities are integrated, tested, secured, and transitioned into operational use, working side by side with operators, engineers, Capability Providers, and government teams to ensure every delivery strengthens mission readiness. This effort offers the chance to directly shape how the Air Force sees, decides, and acts across all domains—making a tangible and immediate impact on warfighter effectiveness.

The Cybersecurity Engineer (DSOP) builds and operates CMCC’s secure DSOP pipeline to enable rapid, safe development and onboarding of Capability Provider applications. This role integrates automated SAST/DAST/container security and SBOM/SCA scanning, enforces secure coding gates, validates cyber artifacts, and ensures all pipeline evidence is routed to Infrastructure TO for Operational Baseline updates. The DSOP Engineer provides direct developer support, jointly participates in early DSOP/cloud design, and lays the foundation for secure-by-default CI/CD automation.

Job Duties Include

  • Build, enhance, and operate DSOP cyber pipeline stages (SAST, DAST, container scanning, SBOM/SCA).
  • Implement pipeline blocking rules for Critical/High vulnerabilities.
  • Integrate cyber validation tasks into CI/CD for multiple environments.
  • Perform functional validation of CP/External artifacts when possible; deliver validated cyber outputs to Infrastructure TO.
  • Produce RMF/cATO‑ready cyber evidence (scan results, mitigation records, SBOM/SCA, logs).
  • Validate artifact integrity (image signing, checksum enforcement, provenance tracking).
  • Provide direct developer enablement onboarding into DSOP tools, secure coding guidance, WHY‑based mentorship.
  • Review, categorize, and drive remediation of CWE/CVE findings across DSOPS, Cloud, CE, and CP teams.
  • Validate rollback readiness when cyber gates block promotion.
  • Partner with Cloud engineers on early pipeline/environment design and promote secure-by-default automation.
Qualifications

  • Bachelors and nine (9) years or more experience; Masters and seven (7) years or more experience; PhD or JD and four (4) years or more experience.
  • US Citizenship.

Required Qualifications & Experience

  • Hands on experience running automated SAST/DAST/container scans using Fortify, ZAP, Grype/Trivy or similar tools.
  • Experience documenting mitigations, reviewing CWE/CVE outputs, and validating secure coding practices.
  • Proficiency with DevSecOps tooling (GitLab CI/CD, container registries, SBOM/SCA tools).
  • Experience supporting secure coding compliance and vulnerability remediation.
  • 8140 aligned certifications such as Security+, CISSP, CCSP, CASP+, or equivalent.

Desired Qualifications And Experience

  • Experience supporting RMF/cATO pipelines—producing cyber evidence, aligning pipeline scans with SSP/POA&M updates.
  • Background integrating secure DevSecOps automation across multi classification environments.
  • Experience enabling developers by creating training, guidance, and best practice workflows.

Desired Skills And Certifications

  • Deep experience with GitLab CI/CD, image signing, SBOM/SCA creation, and pipeline compliance validation.
  • Familiarity with secure by design and shift left security principles embedded across DSOP automation.
  • Strong communication habits—providing timely vector checks, developer friendly guidance, and clear evidence trails.

Target salary range $160,001 - $200,000. The estimate displayed represents the typical salary range for this position based on experience and other factors.
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Cybersecurity Engineer - DSOP
Cybersecurity Engineer - DSOP

Saic • Chantilly (VA)

On-site
USD 160,000 - 200,000
Cybersecurity Engineer - Cloud
Cybersecurity Engineer - Cloud

SAIC • California (MO)

Hybrid
USD 160,000 - 200,000
Cybersecurity Lead - ISSM
Cybersecurity Lead - ISSM

SAIC • California (MO)

Hybrid
USD 160,000 - 200,000
Cybersecurity Engineer - Cloud
Cybersecurity Engineer - Cloud

Saic • Beale Air Force Base (CA)

On-site
USD 160,000 - 200,000
Cybersecurity Engineer - Cloud
Cybersecurity Engineer - Cloud

Saic • Chantilly (VA)

On-site
USD 160,000 - 200,000
DevSecOps Engineer Principal - Cyber
DevSecOps Engineer Principal - Cyber

SAIC • Arlington (VA)

On-site
USD 160,000 - 200,000
DSOP Cybersecurity Engineer - Secure DevSecOps for CMCC
DSOP Cybersecurity Engineer - Secure DevSecOps for CMCC

SAIC • California (MO)

On-site
USD 160,000 - 200,000
DevSecOps Engineer Principal - Platform
DevSecOps Engineer Principal - Platform

Saic • Arlington (VA)

Hybrid
USD 160,000 - 200,000
Secure DevSecOps Engineer: DSOP CI/CD Automation
Secure DevSecOps Engineer: DSOP CI/CD Automation

Saic • Chantilly (VA)

On-site
USD 160,000 - 200,000
DevSecOps Engineer Principal - Cyber
DevSecOps Engineer Principal - Cyber

Socket.dev • Arlington (VA)

Hybrid
USD 120,000 - 190,000