Cybersecurity Engineer - Software Assurance Implementation
Listed on 2026-01-09
-
IT/Tech
Cybersecurity
Cybersecurity Engineer - Software Assurance Implementation
*** To be considered for this role, you must be a US Citizen and have an active US government security clearance. Additionally, you must either live near or be willing to move to the Boulder, CO area.***
About Centil
Centil represents the intersection of innovation and trusted expertise required for keeping rapid pace with the dynamic and emergent technological needs of Aerospace, Defense, and Government systems. Our trusted team of engineers excel in deploying value stream management, short-cycle feedback loops, infrastructure on-demand, and secure, disciplined pipelines to our customers. If you are interested in learning more about Centil or our team, check out our website til.io.
Centil is a talented team of trusted engineers working to provide optimized and effective technology value streams for defense industry clients. We believe in a culture of innovation, empowerment and collaboration. We place a high value on learning and growth, providing ongoing support to our team to learn new skills and become fulfilled in both their personal and professional life.
Centil is hiring exceptional individuals to join our growing team. We look for candidates who are inspired and passionate, highly collaborative, and who demonstrate the courage to challenge the status quo with forward thinking ideas and practices. We also seek out individuals who demonstrate servant leadership by supporting their colleagues with a sense of positivity, humility and open mindedness.
About the role
This opening is for a Cybersecurity Engineer to support our Missile Track Custody program in the execution of software assurance activities, focusing on secure development practices and vulnerability management.
The ideal candidate has 3-5 years of professional experience in cybersecurity software development or related fields. They possess a deep understanding of secure development practices, vulnerability management, and the ability to integrate security into the Dev Sec Ops pipeline. Proven technical expertise in static code analysis and a solid understanding of secure software engineering principles are critical to success in this role.
This position will work closely with other engineers and program leadership to support the overall goals and objectives of the program.
Please note this is a full time position and will be onsite in Boulder a minimum of 3 days per week.
What you'll do
- Develop the Software Assurance Plan as part of the Program Protection Implementation Plan (PPIP), detailing secure coding, vulnerability assessment, and remediation strategies.
- Conduct immediate Static Code Analysis and Vulnerability Scanning on mission-unique software, identifying and tracking vulnerabilities.
- Collaborate with the MSOC Software team to implement secure software development practices and ensure vulnerabilities are remediated according to the Software Assurance Plan.
- Provide ongoing vulnerability assessments, periodic code reviews, and Software Assurance metrics to track progress and compliance.
Required Qualifications
- Current Secret security clearance or higher
- 3-5 years of professional experience in software assurance, cybersecurity or a related field
- Proficiency with Static Code Analysis Tools:
Hands-on experience with tools such as Coverity, Code Sonar, Parasoft
C/C++test, Fortify Static Code Analyzer, LDRA Tool Suite, or equivalent. Ability to configure, run, and interpret analysis results. - Secure Software Development Expertise:
Strong understanding of secure coding principles and the ability to embed security into all phases of the SDLC. - Threat Identification and Mitigation:
Experience identifying software vulnerabilities and proposing actionable mitigation strategies based on analysis results.
Proficient in applying Risk Management Framework (RMF) principles to assess, mitigate, and monitor security risks across systems and processes. - Collaboration
Skills:
Demonstrated ability to work closely with development teams, testers, and stakeholders to integrate security practices seamlessly into workflows. - Documentation and Reporting:
Ability to document findings, prepare reports for…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).