Security Engineer II

ADP, Inc.

Illinois

On-site

USD 80,000 - 85,000

Full time

6 days ago
Be an early applicant
Application generator

Get a reply from this employer — a resume and cover letter tailored to exactly what they’re hiring for.

Get past ATS filters

Job summary

Paragon Technology Group is seeking a Security Engineer II to support the USTRANSCOM PEO-T contract. The role involves reviewing NIST requirements, creating specifications to address cybersecurity gaps, and collaborating with government customers on risk management activities.

The candidate should have 1-3 years of relevant experience in security testing, threat modeling, and DevSecOps practices, with strong communication skills and the ability to work with cross-functional teams.

Qualifications

  • Experience reviewing vulnerability scans with SAST tools and mitigating findings.
  • Knowledge of multiple programming languages (Java, C#, Python, .NET, SQL).
  • Experience with threat modeling and presenting findings to stakeholders.
  • Understanding of CI/CD, containerization, and microservices architecture.
  • Familiarity with OWASP Top 10 and secure coding practices.
  • Experience with static code analysis tools: SonarSource, OpenText SAST, TruffleHog.
  • Proficiency in DevSecOps practices and security automation.
  • Strong knowledge of network and system security and cryptography.
  • Ability to communicate remediation plans to development teams.
  • Comfort working in fast-paced environments with clear communication.
  • Experience hardening servers and network devices.
  • Ability to coordinate with developers, vendors and government agencies.
  • Experience contributing to Technical Interchange Meetings on security topics.
  • Support PMO systems compliance with executive orders and policy.
  • Suggest improvements to network/security architectures to boost security posture.

Responsibilities

  • Review evolving NIST requirements to support risk assessment.
  • Prepare detailed specs to mitigate security deficiencies from risk assessments.
  • Collaborate with government customers to develop POA&Ms and support risk acceptance.

Skills

Vulnerability scanning (SAST)
Programming languages
Threat modeling
CI/CD & DevSecOps
Containerization (Kubernetes, Docker)
OWASP Top 10
Static code analysis tools
Security architecture & hardening
Security reviews & remediation
Cross-team communication
Stakeholder collaboration
PMO & government compliance
Network security & cryptography
Technical interchanges & meetings
DISA STIG/SRGs knowledge

Education

IAM II Certification (CGRC, Security X, CISM, CISSP, GSLC, CCISO)
Bachelor’s in Computer Science or Cybersecurity

Tools

Kubernetes
Docker
SonarSource
OpenText SAST
TruffleHog

Job description

If you are unable to complete this application due to a disability, contact this employer to ask for an accommodation or an alternative application process.

Security Engineer II

Full Time Technical Scott AFB, IL, US

Salary Range: $80,000.00 To $85,000.00 Annually

Paragon is recruiting for a Security Engineer II to work on the PEO-T contract for USTRANSCOM.

The tasks for this person will be, but not limited to, the following:

  • Reviews evolving NIST requirements to support risk assessment activities associated with the affiliated system requirements and specifications.
  • Prepares detailed specifications from which cybersecurity deficiencies identified during risk assessment will be mitigated/remediated and conducts follow-up risk assessment to ensure proper secure coding practices are being built-in/enforced to the greatest extent possible.
  • Collaborates closely with government customers to develop appropriate POA&Ms and support risk acceptance activities as needed to support risk management processes.

Qualifications:

1-3 years relevant experience in the following:

  • Experience reviewing vulnerability scans using SAST (Static Application Security Testing) tools, analyze outputs to identify vulnerabilities, and recommend mitigation and remediation actions
  • Knowledge of multiple programming languages (e.g., Java, C#, Python, .NET, SQL)
  • Experience with threat modeling and presenting findings/recommendations to lead stakeholders.
  • Thorough understanding of CI/CD pipeline components, containerization technologies (e.g., Kubernetes, Docker, etc.,) and microservices architecture.
  • In-depth knowledge of critical application security vulnerabilities and OWASP Top 10
  • Experience with following static code analysis tools: SonarSource, OpenText SAST, and TruffleHog.
  • In-depth knowledge of DevSecOps practices and principles
  • Solid understanding of system and network security, authentication protocols, and cryptography.
  • Ability to communicate with development teams on mitigation and remediation of vulnerabilities and security control implementation.
  • Ability to work in a fast-paced environment and possess excellent communication skills.
  • Experience with security lockdown and/or hardening of servers and network devices
  • Possess skills to conduct Technical Reviews of Development Contractor produced security deliverables
  • Ability to coordinate with developers, vendors, and other government organizations/agencies to assess security engineering issues
  • Experience participating in Technical Interchange Meetings on a wide range of PMO security engineering topics
  • Experience providing support to ensure PMO systems are designed, developed, and deployed in accordance with applicable Executive Orders, Federal Policy, DOW regulations, USTRANSCOM requirements, and commercial best practice
  • Experience recommending changes to network and security architecture to improve security posture and meet operational performance requirements
  • Experience supporting operational security activities (e.g., researching coding languages, vulnerabilities associated with secure coding practices, etc.)
  • Experience supporting the Customer through critical review of documented DISA STIG/SRGs (e.g., Application Security and Development) and ingesting them in the government-supplied tools to support risk assessment of the NIST controls.

Required Education/Certification

  • Active IAM II Certification in Good Standing (e.g., CGRC (formerly CAP), Security X (formerly CASP+CE), CISM, CISSP (or associate), GSLC, CCISO)
  • Bachelor’s in Computer Science or Cybersecurity or equivalent

What Success Looks Like

Success in this role is demonstrated by clearly defined, traceable requirements that reflect validated operational needs; well-facilitated stakeholder forums that drive timely decisions; and functional designs that enable development teams to deliver compliant, mission-aligned capabilities. The Analyst is trusted by government leadership as a reliable integrator across Services, Agencies, and functional domains.

How the Work Gets Done at Paragon

At Paragon, work is executed through disciplined collaboration, accountability to mission outcomes, and respect for government processes. Analysts lead with preparation and clarity, facilitate structured decision-making forums, and ensure requirements are governed, documented, and traceable from operational need through delivery. The focus is on predictable execution, transparency, and stewardship of government resources.

Working Conditions

Work is primarily performed in a professional office or government facility environment.

Position may require participation in classified discussions consistent with clearance level.

Collaboration with geographically dispersed stakeholders is expected.

Standard business hours with occasional schedule flexibility to support mission needs.

Why Paragon

Paragon Technology Group delivers mission-critical outcomes through disciplined execution, professional accountability, and respect for the trust placed in us by our government partners. Team members are empowered to own their work, contribute meaningfully to national defense missions, and operate in an environment that values clarity, predictability, and long-term stewardship.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Security Engineer II
Security Engineer II

Paragon Technology • Illinois

On-site
USD 80,000 - 85,000
Security Engineer II
Security Engineer II

Paragon Technology Group, Inc. • Illinois

On-site
USD 95,000 - 135,000
System Engineer III
System Engineer III

ADP, Inc. • Illinois

On-site
USD 90,000 - 95,000
Health and Wellness
Health Coverage
Vision Coverage
+9
System Engineer III
System Engineer III

Paragon Technology Group • Illinois

On-site
USD 110,000 - 160,000
Health and Wellness
Vision Coverage
401(k) with Company Match
+2
System Engineer III
System Engineer III

Paragon Technology Group, Inc. • Illinois

On-site
USD 90,000 - 120,000
Health Coverage
Dental Coverage
Vision Coverage
+2
Security Engineer II — DevSecOps for Defense Systems
Security Engineer II — DevSecOps for Defense Systems

Paragon Technology Group, Inc. • Illinois

On-site
USD 95,000 - 135,000
Security Engineer II: DevSecOps & Risk Mitigation
Security Engineer II: DevSecOps & Risk Mitigation

Paragon Technology • Illinois

On-site
USD 80,000 - 85,000
Security Engineer II: DevSecOps & Risk Modeling
Security Engineer II: DevSecOps & Risk Modeling

ADP, Inc. • Illinois

On-site
USD 80,000 - 85,000
Security Engineer III
Security Engineer III

ADP, Inc. • Illinois

On-site
USD 85,000 - 90,000
Security Engineer II: RMF & ISCM Specialist
Security Engineer II: RMF & ISCM Specialist

Paragon Technology Group • Illinois

On-site
USD 90,000 - 125,000