Cydecor is a premier Federal Government solutions provider, delivering differentiated innovations in mission systems and business platforms. We leverage leading-edge secure systems and software development, backed by industry-leading subject matter expertise, and business intelligence to enable decision-support and remain ahead of ever-evolving national security challenges. Our success rests squarely on three bedrock principles:
People, our center of gravity;
Mission, what inspires us; and an unyielding commitment to Excellence, what separates us.
We’re looking for a cybersecurity engineer to work the security side of software delivery on a large Navy readiness reporting program. You’ll work shoulder-to-shoulder with the development teams - finding vulnerabilities early, driving fixes into the code and the pipeline, and helping build security into how software gets designed, built, tested, and deployed. This is a hands‑on engineering role. You’ll run and tune the security testing, chase findings to closure, and help keep the codebase and its dependencies clean.
You’ll work under the Cybersecurity Lead Engineer and should have a strong understanding of the Risk Management Framework (RMF) to ensure your work remains aligned with the program’s security posture, while the Cybersecurity Lead Engineer retains ownership of the ATO packages.
- Run security testing across the development pipeline, SAST, DAST, software composition analysis, and container/image scanning - and keep it tuned so it catches what matters.
- Triage and prioritize security findings, distinguish actionable issues from false positives or low‑risk items, and collaborate with developers to implement remediation throughout the code and CI/CD pipeline. Track findings through resolution and ensure timely closure.
- Review code and dependencies for security issues and give developers clear, specific remediation guidance they can act on.
- Apply STIGs and hardening baselines, track vulnerability response and patching cadence, and keep the codebase and its dependencies current.
- Enforce secure change management processes by performing Security Impact Analyses for proposed information system changes to authorized Navy systems.
- Review DoW and Navy Cyber Tasking Orders and other related Cyber Directives to determine applicability to the NRRE family of systems and coordinate with applicable stakeholders to achieve compliance.
- Ensure cybersecurity activities remain aligned with the program’s Risk Management Framework (RMF) posture and provide the Cybersecurity Lead Engineer with the documentation, evidence, and technical inputs required to support accreditation and continuous monitoring.
- Stay current on DoD cybersecurity guidance, tools, technologies, and best practices, incorporating relevant updates and improvements into team and program activities.
- Effectively communicate cybersecurity posture, risk, and recommendations to technical and non‑technical stakeholders, translating complex security concepts into clear, actionable information.
- Establish and contribute to team standards, best practices, and reusable solutions that improve efficiency, promote consistency, and prevent duplication of effort.
- Take ownership of issues and gaps, proactively driving solutions and coordinating with appropriate stakeholders to ensure timely and effective resolution.
- 5+ years in cybersecurity engineering, with a focus on the software development life cycle and vulnerability management.
- Demonstrated experience with security testing in CI/CD pipelines using tools like Sonar Qube, Fortify,…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).