Cybersecurity Engineer
Job Description
Zaden Technologies, Inc. is hiring a Cybersecurity Engineer (ISSO-focused) to support RMF authorization, continuous monitoring, and DevSecOps enablement on onsite systems in Huntsville, AL.
Responsibilities
- Perform ISSO duties for assigned systems and maintain security posture throughout the RMF lifecycle
- Develop and maintain authorization artifacts, including System Security Plans, POA&Ms, risk assessments, and incident response plans
- Implement and validate security controls and support assessors through the authorization process
- Conduct vulnerability scanning, audit log reviews, and STIG compliance checks, coordinating with system owners to remediate findings
- Harden operating systems, applications, and network components to STIG and SRG baselines
- Partner with DevSecOps engineers to integrate security tooling into CI/CD pipelines and translate control requirements into technical solutions
- Learn and apply DevOps practices such as containerization, Infrastructure-as-Code, and scripting to automate compliance evidence collection
- Identify repeatable manual security tasks and work with the team to automate them
- Investigate and document security incidents and report findings to leadership and stakeholders
- Monitor emerging threats and evolving cybersecurity policy, recommending improvements to Zaden’s security practices
Requirements
- U.S. Citizenship and an active security clearance (minimum Secret)
- 3+ years of cybersecurity experience, including hands-on work as an ISSO or an equivalent information assurance role
- Working knowledge of Risk Management Framework (RMF) and NIST SP 800-53 security controls
- Experience preparing and maintaining authorization packages, including SSPs and POA&Ms
- Experience with vulnerability scanning and compliance tools such as ACAS/Nessus, SCAP Compliance Checker, or STIG Viewer
- Hands-on experience hardening Linux or Windows systems
- Strong written communication skills for security documentation and reporting
- Genuine interest in learning DevOps tools and practices, with motivation to build skills on the job
- DoD 8140/8570 IAT Level II certification (e.g., CompTIA Security+) or ability to obtain within 6 months of hire
Preferred Qualifications
- Experience with eMASS or similar GRC platforms
- Exposure to CI/CD tools such as GitLab CI, GitHub Actions, or Jenkins
- Exposure to containers or orchestration tools such as Docker or Kubernetes
- Basic scripting experience in Bash, Python, or PowerShell
- Familiarity with cloud platforms such as AWS or Azure and their native security services
- Experience with SIEM platforms such as Splunk or Elastic
- Familiarity with zero trust architecture principles
- Advanced certification such as CISSP, CISM, or CASP+
Technologies
- Risk Management Framework (RMF)
- NIST SP 800-53
- System Security Plans (SSPs), POA&Ms
- ACAS/Nessus, SCAP Compliance Checker, STIG Viewer
- Linux, Windows
- STIG, SRG
- DevOps, containerization, Infrastructure-as-Code
- CI/CD pipelines, GitLab CI, GitHub Actions, Jenkins
- Docker, Kubernetes
- Bash, Python, PowerShell
- AWS, Azure
- Splunk, Elastic
- zero trust architecture
- DoD 8140/8570, CompTIA Security+, eMASS
- CISSP, CISM, CASP+
Location: Huntsville, AL (onsite)
Minimum experience: 3 years