Senior Cybersecurity Analyst - DevSecOps RMF Expert

Scientific Research Corporation

North Charleston (SC)

On-site

USD 140,000 - 190,000

Full time

2 days ago
Be an early applicant
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Job summary

Scientific Research Corporation (SRC) in the United States is seeking a senior cybersecurity professional to integrate security controls across the software development lifecycle, review architectures for risk, and support secure DevSecOps practices. The role involves RMF artifacts, risk analyses, and collaboration with developers to remediate security defects.

The qualified candidate will hold an active TS/SCI clearance with CISSP, a bachelor’s degree in a technical field, and 8+ years of

Qualifications

  • Active TS/SCI clearance with the ability to maintain eligibility throughout employment.
  • Active CISSP certification in good standing.
  • Bachelor’s degree in cybersecurity, computer science, information systems, software engineering, engineering, or a related technical field.
  • Eight or more years of progressive experience in cybersecurity, information assurance, application security, systems security engineering, or a related technical discipline.
  • Three or more years of experience supporting cybersecurity activities on software development, software modernization, systems integration, or DevSecOps programs.
  • Demonstrated experience applying cybersecurity principles within the SDLC, including requirements analysis, design review, development, testing, deployment, and sustainment.
  • Experience with security-control assessment, risk analysis, vulnerability management, and remediation tracking.
  • Working knowledge of NIST cybersecurity guidance and risk-management practices, including RMF, 800-53, 800-37, 800-218 SSDF.
  • Experience reviewing or analyzing findings from vulnerability-scanning, configuration-compliance, web application security, SAST, DAST, SCA, or similar tools.
  • Familiarity with secure coding concepts, common application vulnerabilities, and remediation approaches, including OWASP risks.
  • Experience producing cybersecurity documentation, such as security assessment reports, system security plans, risk registers, POA&Ms, vulnerability-management reports, and briefing materials.
  • Experience obtaining system authorization, performing continuous monitoring, obtaining ATO packages, and performing control-assessment activities.
  • Ability to communicate cybersecurity risks and recommendations effectively to software developers, engineers, program managers, and government stakeholders.
  • Ability to work independently, manage competing priorities, and operate effectively in a mission-focused government program environment.

Responsibilities

  • Integrating cybersecurity requirements and security controls into the software development lifecycle, from requirements definition through deployment and sustainment
  • Reviewing system, application, interface, and architecture designs for cybersecurity risks and compliance with applicable government requirements
  • Supporting implementation and maintenance of secure DevSecOps practices, including automated security testing and continuous monitoring
  • Conducting or supporting security assessments, control validation, risk analysis, and remediation tracking for software applications and supporting infrastructure
  • Analyzing vulnerability scan results, application security findings, code-scanning results, and configuration-compliance data; validate findings and coordinate mitigation actions
  • Performing RMF activities, including preparation and maintenance of security documentation, assessment artifacts, risk registers, and POA&Ms
  • Evaluating security impacts of software releases, configuration changes, third-party components, and architecture modifications
  • Collaborating with developers to implement secure coding practices and remediate security defects
  • Supporting security incident analysis, root-cause analysis, corrective-action development, and after-action reporting
  • Developing technical reports, executive summaries, risk briefings, security recommendations, and status updates for program and government stakeholders
  • Providing technical mentorship and quality review for junior cybersecurity analysts
  • Participating in Agile ceremonies, technical interchange meetings, architecture reviews, release-readiness reviews, and cybersecurity working groups

Job description

Scientific Research Corporation (SRC) in the United States is seeking a senior cybersecurity professional to integrate security controls across the software development lifecycle, review architectures for risk, and support secure DevSecOps practices. The role involves RMF artifacts, risk analyses, and collaboration with developers to remediate security defects.

The qualified candidate will hold an active TS/SCI clearance with CISSP, a bachelor’s degree in a technical field, and 8+ years of

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Senior Cybersecurity Analyst — Cloud, DevSecOps & RMF Expert
Senior Cybersecurity Analyst — Cloud, DevSecOps & RMF Expert

Scientific Research Corporation • North Charleston (SC)

On-site
USD 120,000 - 180,000
Medical, dental, vision plans
401(k) with company match
Paid time off (vacation and sick)
Senior RMF Cybersecurity Analyst (TS/SCI)
Senior RMF Cybersecurity Analyst (TS/SCI)

Military, Veterans and Diverse Job Seekers • Stafford (VA)

On-site
USD 120,000 - 170,000
RMF Cybersecurity Analyst - DoD Risk and Compliance
RMF Cybersecurity Analyst - DoD Risk and Compliance

DAn Solutions • Corridor North (MD)

On-site
USD 110,000 - 150,000
Cybersecurity Practitioner: DevSecOps & RMF Focus
Cybersecurity Practitioner: DevSecOps & RMF Focus

KBR Careers • Oklahoma

On-site
USD 85,000 - 120,000
Senior RMF Cyber Security Analyst – Secret Clearance
Senior RMF Cyber Security Analyst – Secret Clearance

Comunidade Metodista • Quantico (VA)

On-site
USD 85,000 - 130,000
Strategic InfoSec Leader, RMF & DoD Cyber Compliance
Strategic InfoSec Leader, RMF & DoD Cyber Compliance

ASRC Federal • Maryland

On-site
USD 130,000 - 190,000
TS/SCI Cyber Security Engineer — RMF+ DoD Compliance
TS/SCI Cyber Security Engineer — RMF+ DoD Compliance

Cybersecurity Jobs • Bethesda (MD)

On-site
USD 120,000 - 170,000
Premium health benefits
401(k) with matching
Senior Cybersecurity Analyst - RMF Lead (Secret/TS)
Senior Cybersecurity Analyst - RMF Lead (Secret/TS)

People Technology And Processes • Washington

On-site
USD 127,000 - 138,000
Senior RMF Security Controls Specialist
Senior RMF Security Controls Specialist

Strategic Analysis, Inc. • Arlington (VA)

On-site
USD 120,000 - 180,000
Cloud Security Engineer — DoD RMF Expert
Cloud Security Engineer — DoD RMF Expert

Scientific Research Corporation • Augusta (GA)

On-site
USD 90,000 - 120,000
Medical, dental, and vision plans
401(k) with company match
Life insurance
+2