OverviewCybersecurity Engineer (Software Assurance / ISSO Support)
: U.S. Space Force – Space Systems Command (SSC), Space Sensing (SN) DirectorateLOCATION: Boulder Ground Innovation Facility (BGIF), Boulder, COSALARY RANGE: Estimated $125,000 +\xa0annually*
*depending on experience, certifications, and qualifications
CLEARANCE: Active Secret / SCI Eligible
\xa0
Astrion is seeking an experienced\xa0Cybersecurity Engineer\xa0to support the Space Sensing Directorate at the Boulder Ground Innovation Facility (BGIF). This is a hands-on, onsite role safeguarding some of the nation’s most critical space and intelligence capabilities. In this role, you will focus primarily on Software Assurance (SwA) within our classified environments while providing supplemental Information Systems Security Officer (ISSO) support. You will work closely with senior Cybersecurity Engineers and the Information Systems Security Manager (ISSM) to integrate security into the software development lifecycle (DevSecOps), conduct application security testing, and assist in maintaining Assessment and Authorization (A&A) documentation. Your efforts will directly contribute to safeguarding valuable intelligence systems and ensuring positive mission outcomes.
\xa0
\xa0
REQUIRED QUALIFICATIONS / SKILLS
- Education: Bachelor's degree in Computer Science, Cybersecurity, Engineering, or a related technical field (Required).
- Experience: 1 to 3 years of experience in cybersecurity, software engineering, or an IT security-related role. Internships and academic project experience in secure coding or cyber compliance will be considered. (Required)
- Certification: Valid Security+ CE Certification. Must meet position and certification requirements outlined in DoD Directive 8570.01-M for Information Assurance Technical (IAT) Level II. (Required)
- Software Assurance: Familiarity with secure coding principles, DevSecOps pipelines, and application security testing tools (e.g., SAST, DAST, SCA). Highly Desired.
- Compliance: Basic understanding of the Risk Management Framework (RMF) and the Authorization to Operate (ATO) process. Desired.
- System Configuration: Familiarity with Defense Information Systems Agency (DISA) Security Technical Implementation Guides (STIGs) and applying them to applications and operating systems. Desired.
- Technical Familiarity: Basic understanding of cloud-based systems, Linux/Windows operating systems, and networking fundamentals. Desired.
- Clearance: Must be capable of obtaining and maintaining the required security clearance for access to classified systems.
RESPONSIBILITIES
Software Assurance & DevSecOps
- Assist in evaluating software architecture and design to ensure systems are functional and secure against cyber-attacks.
- Support the integration of security tools and vulnerability checks into the continuous integration/continuous deployment (CI/CD) pipeline.
- Analyze results from code scans and vulnerability assessments, working with development teams to remediate identified software flaws.
- Apply Secure Technical Implementation Guide (STIG) best practices specifically targeted at software, applications, and databases.
- Assist in developing and maintaining Defensive Cyberspace Operations tactics to monitor application-level security.
ISSO & Compliance Support
- Work with the ISSM and senior ISSOs to create, update, and maintain Assessment and Authorization (A&A) documentation, including the System Security Plan (SSP) and Security Controls Traceability Matrices (SCTMs).
- Assist in tracking and updating the Plan of Action and Milestones (POA&M) for software and system vulnerabilities.
- Support periodic reviews and evaluations of Information System (IS) policies and procedures.
- Assist in preparing for and executing IS Security Inspections, tests, and reviews.
- Contribute to vulnerability and risk assessment analysis to support ongoing authorization and accreditation efforts.
\xa0
#CJ