Security Automation Engineer — CI/CD & SBOM Compliance

Xenon Innovations, Inc.

Fairfax (VA)

On-site

USD 135,000 - 230,000

Full time

14 days+
Application generator

Stand out for this role — generate a tailored resume and cover letter in about a minute.

Get past ATS filters

Job summary

Xenon Innovations, Inc. is seeking an experienced security engineer to own the security layer across development and delivery environments.

You will build automation to enforce hardening, generate evidence artifacts, and ensure supply chain integrity as a built-in outcome of the build system. You will lead STIG and SRG automation, create SCAP/OpenSCAP content, and integrate SBOM generation into CI so every artifact ships with verified inventories and compliant documentation.

Qualifications

  • BS in Computer Science, Computer Engineering, Cybersecurity, or equivalent hands-on experience.
  • 5+ years in security engineering, DevSecOps, or platform engineering with demonstrable automation work.
  • Strong scripting and automation skills in Python and Bash.
  • Production experience with Ansible or equivalent configuration management.
  • Direct experience implementing DISA STIGs or SRGs in an automated fashion, including SCAP content work.
  • Working knowledge of CI/CD systems (Bitbucket, GitLab CI, or equivalent), containerization, and artifact repository management.
  • Familiarity with RMF, NIST SP 800-53, and NIST SP 800-171.
  • Ability to obtain a TS/SCI clearance.

Responsibilities

  • Design and maintain automated hardening for RHEL, Windows, container, network device, and application baselines against applicable DISA STIGs and SRGs.
  • Author, tailor, and validate SCAP and OpenSCAP content; build and maintain idempotent Ansible-based roles.
  • Automate STIG checklist (CKL) generation, deviation documentation, and evidence packaging so that compliance state is a build output rather than a manual exercise.
  • Engineer tailoring decisions for embedded and real-time targets where stock STIG guidance breaks the mission and document the technical rationale and compensating controls that makes those deviations defensible in review.
  • Stand up automated SBOM generation (CycloneDX or SPDX) across firmware, embedded, and application build pipelines, including for cross-compiled and constrained targets.
  • Integrate SBOM production into CI so every delivered artifact ships with an accurate, signed component inventory.
  • Produce and maintain VEX documentation to communicate real exploitability rather than raw CVE counts.
  • Ensure SBOM output satisfies customer and NDAA/EO supply chain delivery requirements.
  • Triage dependency and component vulnerabilities on technical merit and drive remediation with the engineering teams.
  • Implement artifact signing, provenance, and build attestation (Sigstore/cosign, SLSA-aligned practices) across the delivery chain.
  • Track upstream advisories and patch availability; own the engineering response when a component goes unmaintained or a fix does not exist.
  • Build security gates into CI/CD across both unclassified and accredited enclaves, including air-gapped environments.
  • Implement policy-as-code, IaC scanning, and secrets management within the build system.
  • Automate the production of RMF evidence artifacts to shorten the ATO path.

Skills

Python
Bash
Ansible
CI/CD
SCAP

Education

BS in Computer Science / Computer Engineering / Cybersecurity

Tools

Bitbucket
GitLab CI

Job description

Xenon Innovations, Inc. is seeking an experienced security engineer to own the security layer across development and delivery environments.

You will build automation to enforce hardening, generate evidence artifacts, and ensure supply chain integrity as a built-in outcome of the build system. You will lead STIG and SRG automation, create SCAP/OpenSCAP content, and integrate SBOM generation into CI so every artifact ships with verified inventories and compliant documentation.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

DevOps Engineer: Secure Air-Gapped CI/CD & Release
DevOps Engineer: Secure Air-Gapped CI/CD & Release

Xenon Innovations, Inc. • Fairfax (VA)

On-site
USD 125,000 - 195,000
Cybersecurity Engineer
Cybersecurity Engineer

Xenon Innovations, Inc. • Fairfax (VA)

On-site
USD 135,000 - 230,000
Remote DevSecOps Engineer: Pipelines & Security Automation
Remote DevSecOps Engineer: Pipelines & Security Automation

asmexternalcareersite • United States

Remote
USD 120,000 - 150,000
DevSecOps Engineer: Secure CI/CD & SBOM for Spacecraft
DevSecOps Engineer: Secure CI/CD & SBOM for Spacecraft

Apex Technology, Inc. • Los Angeles (CA)

On-site
USD 180,000 - 230,000
Equity
Healthcare
PTO 15–20 days
+4
Senior DevSecOps Engineer: Secure Delivery & Automation
Senior DevSecOps Engineer: Secure Delivery & Automation

9025 CVS Shared Services Resources LLC • Massachusetts

Hybrid
USD 130,000 - 260,000
DevSecOps Tech Lead
DevSecOps Tech Lead

CIBR Warriors • Charlotte (NC)

On-site
USD 120,000 - 150,000
DevSecOps Engineer: Secure CI/CD & Cloud Platforms
DevSecOps Engineer: Secure CI/CD & Cloud Platforms

AAA Auto Club Enterprises • Costa Mesa (CA)

On-site
USD 109,000 - 146,000
Health coverage (medical, dental, vis​
401(K) with company match and Pension
Tuition assistance
+4
Security Automation Engineer — Orchestrate Scalable Defenses
Security Automation Engineer — Orchestrate Scalable Defenses

Insight Global • Atlanta (GA)

On-site
USD 120,000 - 150,000
Cybersecurity Engineer – Security Infrastructure & Automation Lead
Cybersecurity Engineer – Security Infrastructure & Automation Lead

Charter Global • Atlanta (GA)

On-site
USD 100,000 - 130,000
Spacecraft DevSecOps Engineer — Secure CI/CD & SBOM (Equity)
Spacecraft DevSecOps Engineer — Secure CI/CD & SBOM (Equity)

Apex - Satellite Platforms • Los Angeles (CA)

On-site
USD 150,000 - 187,000
Equity
Healthcare
PTO & Holidays
+4