Cybersecurity Engineer - Clearance Required

Cydecor, Inc.

$120K — $145K *
Aerospace & Defense
5 - 7 years of experience
Job Overview by Ladders

Qualifications

  • 5+ years in cybersecurity engineering with software development life cycle focus
  • Experience with security testing in CI/CD using tools like SonarQube and Fortify
  • Proficient in vulnerability scanning, STIG application, and secure code review
  • Working knowledge of Risk Management Framework (RMF) for DoD systems
  • IAM Level II Information Assurance Certification or equivalent required

Responsibilities

  • Run and tune security testing across development pipeline
  • Triage and prioritize security findings with developers
  • Review code for security issues and provide remediation guidance
  • Apply security hardening baselines and track vulnerability response
  • Enforce secure change management with Security Impact Analyses
  • Review and interpret Cyber Directives for compliance
  • Ensure cybersecurity activities align with the program's RMF posture

Benefits

  • Health and Dental Insurance
  • Vision and Life Insurance
  • Short-Term & Long-Term Disability
  • 401(K) with company match
  • Paid Time Off (PTO) and Paid Company Holidays
  • Tuition and Professional Development Assistance
Full Job Description


Job Description:

We're looking for a cybersecurity engineer to work the security side of software delivery on a large Navy readiness reporting program. You'll work shoulder-to-shoulder with the development teams - finding vulnerabilities early, driving fixes into the code and the pipeline, and helping build security into how software gets designed, built, tested, and deployed. This is a hands-on engineering role. You'll run and tune the security testing, chase findings to closure, and help keep the codebase and its dependencies clean. You'll work under the Cybersecurity Lead Engineer and should have a strong understanding of the Risk Management Framework (RMF) to ensure your work remains aligned with the program's security posture, while the Cybersecurity Lead Engineer retains ownership of the ATO packages.

Responsibilities include:
  • Run security testing across the development pipeline, SAST, DAST, software composition analysis, and container/image scanning - and keep it tuned so it catches what matters.
  • Triage and prioritize security findings, distinguish actionable issues from false positives or low-risk items, and collaborate with developers to implement remediation throughout the code and CI/CD pipeline. Track findings through resolution and ensure timely closure.
  • Review code and dependencies for security issues and give developers clear, specific remediation guidance they can act on.
  • Apply STIGs and hardening baselines, track vulnerability response and patching cadence, and keep the codebase and its dependencies current.
  • Enforce secure change management processes by performing Security Impact Analyses for proposed information system changes to authorized Navy systems.
  • Review DoW and Navy Cyber Tasking Orders and other related Cyber Directives to determine applicability to the NRRE family of systems and coordinate with applicable stakeholders to achieve compliance.
  • Ensure cybersecurity activities remain aligned with the program's Risk Management Framework (RMF) posture and provide the Cybersecurity Lead Engineer with the documentation, evidence, and technical inputs required to support accreditation and continuous monitoring.

Additional duties and Responsibilities of the Cybersecurity Engineer include, but are not limited to the following:
  • Stay current on DoD cybersecurity guidance, tools, technologies, and best practices, incorporating relevant updates and improvements into team and program activities.
  • Effectively communicate cybersecurity posture, risk, and recommendations to technical and non-technical stakeholders, translating complex security concepts into clear, actionable information.
  • Establish and contribute to team standards, best practices, and reusable solutions that improve efficiency, promote consistency, and prevent duplication of effort.
  • Take ownership of issues and gaps, proactively driving solutions and coordinating with appropriate stakeholders to ensure timely and effective resolution.

Here's what you need:
  • 5+ years in cybersecurity engineering, with a focus on the software development life cycle and vulnerability management.
  • Demonstrated experience with security testing in CI/CD pipelines using tools like SonarQube, Fortify, Checkmarx, or Snyk in Azure DevOps or comparable platforms.
  • Comfortable with vulnerability scanning and remediation: STIG application (focused expertise regarding Application Security Development), scan analysis (ACAS/Nessus or equivalent), secure code review, and dependency/patch management.
  • Working knowledge of RMF for DoD systems, enough to keep your work aligned with the program's security posture.
  • IAM Level II Information Assurance Certification (per DoDI 8570.01-M and SECNAV M-5239.2), or equivalent under DoDM 8140.03 at Basic or Intermediate proficiency.

Bonus Points If You Have:
  • CSSLP, GWAPT, GWEB, CySA+, or similar secure-coding/vulnerability credentials; CISSP; prior work on DoD or Navy software programs; experience with cloud-hosted workloads and container security.

Security Clearance:
  • Interim or Active DOD Secret

Education:
  • Bachelor's degree in computer science, cybersecurity, engineering, or a related technical field. Additional relevant experience can substitute for the degree.

Work Schedule:
  • Monday - Friday, 8 hours

Compensation and Benefits:
The projected compensation range for this position is $120,000-145,000. There are numerous factors that can impact a final salary/hourly rate including, but not limited to, relevant work experience, skills and competencies that align to the role, work location, education/certifications, and a contract's Labor Categories.

Cydecor offers a comprehensive compensation package including Health and Dental Insurance, Vision and Life Insurance, Short-Term & Long-Term Disability, 401(K) + company match, Paid Time Off (PTO), Paid Company Holidays, Tuition and Professional Development Assistance and more.

Key words: Cybersecurity, DevSecOps, Secure SDLC, Vulnerability Management, CI/CD, Pipeline Security, SAST, DAST, SCA, Software Composition Analysis, SonarQube, Fortify, Checkmarx, Snyk, Container Security, Image Scanning, STIG, Vulnerability Scanning, ACAS, Nessus, Secure Coding, Secure Code Review, Remediation, Patching, Azure DevOps, ADO, RMF, Risk Management Framework, IAM Level II, DoDM 8140.03, Security+, CSSLP, GWAPT, CISSP, Navy, Secret Clearance

Similar Jobs

More Jobs at Cydecor, Inc.

More Aerospace & Defense Jobs

Find similar Cybersecurity Engineer - Clearance Required jobs: