Job DescriptionMSTS is seeking a highly experienced Cybersecurity professional for a Principal Software Security Engineer. The software engineer in this role (Principal Cyber Security Analyst) will be responsible for leading the testing, implementation, operation, and maintenance of secure software solutions, ensuring confidentiality, integrity, and the availability of sensitive data.
Key Responsibilities- Implement, test, and operate advanced software security in compliance with federal security requirements including SBOM (Software Bill of Materials) policy enforcement.
- Serve as the System Administrator for CI/CD related tools and equipment.
- Lead the effort to automate application scanning and vulnerability assessment processes to support CI/CD (Continuous Integration and Continuous Delivery/Deployment) releases.
- Develop and maintain software C-SCRM program to continuously monitor and periodically reassess critical software and suppliers.
- Conduct threat hunting and mitigations on malicious packages.
- Assist with AI architecture development as well as source code vetting.
- Provide engineering designs for new software applications to help mitigate security vulnerabilities.
- Brief executive management as the security subject matter expert on software development and related opportunities within the enterprise.
- Perform ongoing security testing and code review to improve software security.
- Validate identified security issues within applications and recommend fixes.
- Develop programs to train team members on secure coding practices.
- Create and maintain technical documentation.
- Lead team in researching, compiling, and analyzing technical data for software related tasks.
- Perform Security Test and Evaluations of information systems in support of a security plan.
- Write complex information system plans (ISSPs) for classified and unclassified systems.
- Complete certification and accreditation of information systems on unclassified and classified networks, assist with the completion and mitigation of security testing and evaluation results, and be a resource for MSTS and other NvE enterprises for the Certification and Accreditation (C&A) process.
- Review purchase requests for technology items and provide input for senior level Cyber Security staff regarding the risks associated with purchases.
- Assist the Information System Security Manager (ISSM) and Information System Security Officers (ISSOs) with the execution of their assigned duties, act as a liaison between the ISSM and other ISSOs, and provide training to ISSOs about their Cyber Security role.
- Serve as the primary point of contact for software related data calls, Federal Information Security Modernization Act (FISMA) reporting, compliance scanning and reporting, continuous monitoring, and compiling reports for auditors.
- Provide Cyber Security training to non-technical and technical individuals.
- Participate in business development by defining customer needs, developing proposals and planning projects that will produce results that meet customer needs.
- Develop standards, practices, and procedures as well as an increasing technical knowledge to solve problems and complete projects.
- Contribute to an overall productive and respectful work environment by providing excellent customer service and working in a positive, collegial manner. Maintain cooperative and respectful working relationships with Cyber Security staff, other divisions, and customers.
Qualifications- Bachelor's degree or equivalent training and experience in a computer-related field and at least 8 years of related experience.
- Detailed technical knowledge of techniques, standards, and state-of-the-art capabilities for authentication and authorization, applied cryptography, security vulnerabilities and remediation.
- Adequate knowledge of web related technologies (web applications, web services and services-oriented architectures) and of network/web related protocols.
- Strong understanding of secure web application design principles and frameworks such as OWASP.
- Experience with development security scanning tools such as static and dynamic analysis.
- Experience with containerization security practices.
- Experience with scripting or code development using the following languages: C#, Node.jd, Java, jQuery, .Net, ASP.NET, Cold Fusion, SQL, PHP, and HTML.
- Experience working with developers and development groups.
- Experience in code review process.
- Experience with Software Composition Analysis (SCA) tools.
- Experience in Open-Source component review and Software Bill of Materials (BOM).
- Experience with AI large Language Models.
- Have command of a broad range of the most advanced Cyber Security principles, protocols, concepts, and theories in a wide range of disciplines.
- Ability to integrate work of specialized personnel to produce the desired results.
- Ability to brief senior and non-technical stakeholders.
- Ability to serve as system administrator for cybersecurity related tools.
- Ability to serve as technical lead on software security related projects.
- Knowledge of network-based services and client/server applications, familiarity with intrusion detection systems, familiarity with network architecture, and security infrastructure placement.
- Ability to analyze network traffic, identify misconfigurations of information systems and networks, troubleshoot security appliances, independently identify network and host security vulnerabilities.
- Understand the Windows operating system and command line tools, network protocols, and TCP/IP fundamentals.
- Ability to maintain strict confidentiality.
- Ability to communicate effectively in English, both verbally and in writing, sufficient to communicate with co-workers, customers, testify, write clear and concise reports, and collect information.
- Ability to use multiple electronic devices including standard office machines, cellular phones, and security appliances.
- Ability to articulate highly technical processes and information to a non-technical audience.
- Ability to meet the physical requirements necessary to safely and effectively perform all assigned duties.
- Preferred Additional Qualifications:
- GIAC Certified Web Application Defender (GWEB)
- GIAC Web Application Penetration Tester (GWAPT)
- GIAC Python Web Coder (GPYC)
- GIAC Security Essentials (GSEC)
- Certified Information System Security Professional (CISSP)
- The primary work location will be at the Losee Road Facility, located in North Las Vegas, Nevada.
- Work schedule will be 4/10's, Monday through Thursday (subject to change).
- Pre-placement physical examination, which includes a drug screen, is required. MSTS maintains a substance abuse policy that includes random drug testing.
- Must possess a valid driver's license.
Annual salary range for this position is:
$118,560.00 - $180,814.00.Starting salary is determined based on the position market value, the individual candidate education and experience and internal equity.