System Engineer 2

Gormat

Corridor North (MD)

On-site

USD 110,000 - 165,000

Full time

14 days+
Application generator

A complete application in a minute — tailored resume and cover letter, ready to send.

Get past ATS filters

Job summary

Gormat is seeking a Software Analyst to conduct SBOM analysis and assess software supply chain security for commercial technologies evaluated for National Security Systems and other sensitive U.S. government environments.

The role emphasizes software provenance, dependency analysis, OSS risk, and vulnerability identification, with rigorous evaluation of SBOM formats, vendor practices, and build pipelines. You will produce technical reports and briefings for technical and non-technical

Qualifications

  • Experience in software supply chain security, cybersecurity analysis, or SCRM.
  • Strong understanding of SBOMs, OSS ecosystems, and software composition analysis (SCA).
  • Familiarity with Common Criteria, NIAP evaluation concepts, NIST guidance, and federal software initiatives.
  • Knowledge of software package managers such as npm, PyPI, Maven, NuGet, GitHub.

Responsibilities

  • Conduct SBOM analysis on commercial products undergoing evaluation or review.
  • Analyze dependencies, transitive dependencies, and third-party libraries for supply chain risks.
  • Review SBOM formats (SPDX, CycloneDX, SWID tags) for accuracy and completeness.
  • Assess software provenance, code lineage, package integrity, and component authenticity.
  • Identify vulnerabilities via CVE analysis, KEV review, and vulnerability databases.
  • Evaluate risks from OSS, foreign-developed components, end-of-life dependencies, and unmaintained libraries.
  • Perform secure software supply chain assessments aligned with NIST SSDF, EO 14028, and NIAP guidance.
  • Conduct vendor due diligence and analyze secure development practices (build pipelines, CI/CD, patching, code signing).
  • Review architectures for supply chain attack vectors and support CC evaluations through risk analysis.
  • Produce technical reports, risk summaries, and executive briefings; collaborate with stakeholders to improve SBOM use.

Skills

Software analysis
Cybersecurity knowledge
Technical risk analysis
OSS risk analysis
Vulnerability identification

Education

Bachelor's degree in System Engineering, Computer Science, Information Systems, Engineering Science, Engineering Management, or related discipline

Tools

Dependency-Track
Syft
Grype
Black Duck
Snyk
Sonatype Nexus
Mend.io
Anchore

Job description

Software Analyst supports the mission of the National Information Assurance Partnership by conducting in-depth software assurance and Software Bill of Materials (SBOM) analysis for commercial technologies seeking evaluation, authorization, or deployment within National Security Systems (NSS) and other sensitive U.S. Government environments.

This role focuses heavily on software supply chain transparency, software provenance, open-source software (OSS) risk analysis, vulnerability identification, and vendor cybersecurity practices. The analyst evaluates software components, dependencies, development practices, and third-party supplier risks to identify potential threats to the confidentiality, integrity, and availability of government systems.

The position requires strong technical analysis, cybersecurity knowledge, and the ability to assess software ecosystems from both a security and supply chain perspective.

Key Responsibilities
  • Conduct Software Bill of Materials (SBOM) analysis on commercial software products, platforms, and applications undergoing evaluation or review.
  • Analyze software dependencies, transitive dependencies, and third-party libraries to identify supply chain risks and hidden software exposure.
  • Review and validate SBOM formats and standards including:
    • SPDX
    • CycloneDX
    • SWID tags
  • Assess software provenance, code lineage, package integrity, and software component authenticity.
  • Identify known vulnerabilities and software weaknesses through:
    • CVE analysis
    • KEV review
    • Vulnerability databases
    • Threat intelligence sources
  • Evaluate risks associated with:
    • Open-source software (OSS)
    • Foreign-developed software components
    • Unsupported or end-of-life dependencies
    • Unmaintained libraries
    • Software obfuscation or lack of transparency
  • Perform secure software supply chain assessments aligned with:
    • NIST SSDF
    • Executive Order 14028
    • Federal software assurance guidance
    • NIAP protection profile requirements
  • Conduct due diligence research on software vendors, developers, maintainers, and software ecosystems.
  • Analyze vendor secure development practices including:
    • Secure coding methodologies
    • Build pipeline security
    • CI/CD protections
    • Dependency management
    • Patch management
    • Code signing
  • Review software development and deployment architectures for potential supply chain attack vectors.
  • Support Common Criteria evaluations and software assurance activities through technical risk analysis and supply chain assessments.
  • Produce technical reports, analytical findings, risk summaries, and executive-level briefings related to software supply chain security.
  • Collaborate with government, industry, evaluation labs, and cybersecurity stakeholders to improve software assurance practices and SBOM utilization.
  • Monitor emerging software supply chain threats, malware campaigns, dependency compromise incidents, and malicious package activity.
Preferred Education & Certifications
  • (U) Fourteen (14) years experience as a SE in programs and contracts of similar scope, type and complexity is required. Bachelor's degree in System Engineering, Computer Science, Information Systems, Engineering Science, Engineering Management, or related discipline from an accredited college or university is required. Five (5) years of additional SE experience may be substituted for a bachelor's degree.
  • Preferred certifications may include:
    • CISSP
    • CSSLP
    • Security+
    • GIAC certifications
    • Certified SCRM Professional
    • Cloud security certifications
Published Required Skills
  • Experience in software supply chain security, cybersecurity analysis, application security, or SCRM.
  • Strong understanding of:
    • Software Bills of Materials (SBOMs)
    • Open-source software ecosystems
    • Software composition analysis (SCA)
    • Vulnerability management
    • Secure software development
  • Familiarity with:
    • Common Criteria
    • NIAP evaluation concepts
    • NIST cybersecurity guidance
    • Federal software security initiatives
  • Knowledge of software package managers and ecosystems such as:
    • npm
    • PyPI
    • Maven
    • NuGet
    • GitHub repositories
  • Ability to analyze complex software dependency structures and identify risk indicators.
  • Experience writing technical analytical reports and communicating findings to technical and non-technical audiences.
LCAT Domain Experience Needed:
  • IA and cybersecurity architectures, concepts, principles, use cases, and standards;
    DoD, IC, and other federal government (e.g., NIST) policy, directives, and instructions relevant to IA and cybersecurity strategic planning and direction.
Published Desired Skills
  • Experience with SBOM and software analysis tools such as:
    • Dependency-Track
    • Syft
    • Grype
    • Black Duck
    • Snyk
    • Sonatype Nexus
    • Mend.io
    • Anchore
  • Familiarity with:
    • Static Application Security Testing (SAST)
    • Dynamic Application Security Testing (DAST)
    • Malware analysis
    • Reverse engineering
    • Code signing validation
  • Understanding of:
    • Supply chain attacks
    • Dependency confusion
    • Typosquatting
    • Build system compromise
    • Malicious open-source package activity
  • Experience evaluating software vendor security maturity and secure development lifecycle practices.
  • Knowledge of cloud-native software architectures and container security.

TS/SCI with polygraph is required.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

System Engineer 2
System Engineer 2

Gormat • Maryland

On-site
USD 110,000 - 150,000
Open Source Software Security Engineer – Software Supply Chain
Open Source Software Security Engineer – Software Supply Chain

Jobtailor • North Carolina

On-site
USD 120,000 - 180,000
Information Assurance Engineer
Information Assurance Engineer

Agile IT Synergy, LLC • Tampa (FL)

On-site
USD 90,000 - 130,000
Systems Security Engineer II – Onsite
Systems Security Engineer II – Onsite

Jobtailor • Massachusetts

On-site
USD 90,000 - 130,000
DevSecOps & Supply Chain Security Consultant
DevSecOps & Supply Chain Security Consultant

Zappsec • Tewksbury (MA), Northern (KY)

Hybrid
USD 150,000 - 210,000
Cyber Security Systems Engineer
Cyber Security Systems Engineer

VTG Defense • Chantilly (VA)

On-site
USD 120,000 - 160,000
Principal, Product Security
Principal, Product Security

Jobtailor • Illinois

On-site
USD 140,000 - 200,000
Information Assurance Security Engineer
Information Assurance Security Engineer

Jobtailor • Town of Montana (WI)

On-site
USD 100,000 - 160,000
Senior Product Security Engineer
Senior Product Security Engineer

Jobtailor • Illinois

On-site
USD 120,000 - 180,000
Senior Information Systems Security Engineer – ISSE
Senior Information Systems Security Engineer – ISSE

Jobtailor • Maryland

On-site
USD 140,000 - 180,000