Get more replies from employers
Send a job-specific resume in minutes.
Merlin seeks a systems security engineer to apply security engineering methods across architecture, design, evaluation, and integration of defense programs, partnering with engineering teams to embed security requirements early rather than retrofitting them after development.
Responsibilities include supporting RMF accreditation and authorization activities—categorization, controls selection and implementation, security assessment, and body of evidence development—while engaging government
• Apply systems security engineering methods across the architecture, design, evaluation, and integration of Merlin's defense programs and products, working alongside engineering teams to embed security requirements early rather than retrofitting them once a system is built.
• Support RMF accreditation and authorization activities for supported programs, including categorization, controls selection and implementation, security assessment, and body of evidence package development through all required RMF steps.
• Engage with government customers and their security representatives to define, document, and implement security protection requirements with the technical rigor and fidelity that DoD authorization demands.
• Apply and verify DISA SRGs and STIGs across program environments, and maintain the configuration management processes that keep systems compliant as they evolve through their operational lifecycle.
• Conduct vulnerability assessments using tools such as Tenable NESSUS and ACAS, coordinate remediation with engineering teams, and manage the ongoing security posture of supported systems.
• Evaluate and advise on the selection of COTS, GOTS, and open-source tools entering the program environment, following DoD-approved software approval processes and ensuring security implications are understood before adoption.
• Support DevSecOps security integration by bringing defense-grade practices into our CI/CD pipeline, including static application security testing and security-gated build processes for government-facing deliverables.
Requirements
Core Competencies
Demonstrates expertise in systems security engineering, RMF accreditation, and vulnerability assessments, with a strong focus on integrating security requirements early in the development lifecycle. Proficient in applying DISA SRGs and STIGs while maintaining compliance and security posture in DoD environments.
Highest-signal resume keywords
ATS Optimization Keywords
Hard Skills
Soft Skills
Industry Keywords
Tools & Technologies