Cybersecurity Engineer (Software Assurance / ISSO Support)
Job Description
Astrion is seeking a hands-on Cybersecurity Engineer to support the U.S. Space Force Space Sensing Directorate at Boulder Ground Innovation Facility (BGIF) in Boulder, CO on an onsite basis. This role centers on Software Assurance work inside classified environments, with supplemental support for ISSO activities, including DevSecOps security integration, application security testing, and assistance with A&A documentation.
Role focus
- Software Assurance within classified environments, with supplemental ISSO support
- DevSecOps security integration across CI/CD
- Application security testing and remediation coordination
- Support for security documentation and authorization activities
Responsibilities
- Assist in evaluating software architecture and design to help ensure systems are functional and secure against cyber-attacks
- Support the integration of security tools and vulnerability checks into the CI/CD pipeline
- Analyze results from code scans and vulnerability assessments, coordinating with development teams to remediate identified software flaws
- Apply Secure Technical Implementation Guide (STIG) best practices for software, applications, and databases
- Assist in developing and maintaining Defensive Cyberspace Operations tactics to monitor application-level security
- Assist in creating, updating, and maintaining Assessment and Authorization (A&A) documentation with the ISSM and senior ISSOs, including the System Security Plan (SSP) and Security Controls Traceability Matrices (SCTMs)
- Assist in tracking and updating the Plan of Action and Milestones (POA&M) for software and system vulnerabilities
- Support periodic reviews and evaluations of Information System (IS) policies and procedures
- Assist in preparing for and executing IS Security Inspections, tests, and reviews
- Contribute to vulnerability and risk assessment analysis to support ongoing authorization and accreditation efforts
Requirements
- Bachelor's degree in Computer Science, Cybersecurity, Engineering, or a related technical field (Required)
- 1 to 3 years of experience in cybersecurity, software engineering, or an IT security-related role. Internships and academic project experience in secure coding or cyber compliance will be considered (Required)
- Valid Security+ CE Certification. Must meet position and certification requirements outlined in DoD Directive 8570.01-M for Information Assurance Technical (IAT) Level II (Required)
- Familiarity with secure coding principles, DevSecOps pipelines, and application security testing tools (e.g., SAST, DAST, SCA) (Highly Desired)
- Basic understanding of the Risk Management Framework (RMF) and the Authorization to Operate (ATO) process (Desired)
- Familiarity with DISA Security Technical Implementation Guides (STIGs) and applying them to applications and operating systems (Desired)
- Basic understanding of cloud-based systems, Linux/Windows operating systems, and networking fundamentals (Desired)
- Must be capable of obtaining and maintaining the required security clearance for access to classified systems
Technologies
- DevSecOps, CI/CD
- SAST, DAST, SCA
- STIGs, RMF, ATO
- Linux, Windows
Clearance & location
- Clearance: Active Secret / SCI Eligible
- Location: Boulder Ground Innovation Facility (BGIF), Boulder, CO (onsite)
Compensation
- Salary: USD 125,000 per year
- Salary range: Estimated $125,000 + annually, depending on experience, certifications, and qualifications
Education: Bachelor's degree required. Experience minimum: 1 years.