Cybersecurity Assessment Engineer
Listed on 2026-08-09
-
IT/Tech
Cybersecurity, Information Security & Data Protection, Security Management & Operations
Second Front Systems (2F) is looking for a battle-tested, high-agency Cybersecurity Assessment Engineer to support our team.. We sit at the high-stakes intersection of defense tech and national security, and this role is about building a modern, resilient operations function from the ground up. You’ll be protecting the infrastructure and platforms that power mission-critical software for the free world—ensuring our nation’s defenders have the secure environment they need to move fast.
At 2F, we pair a startup’s bias for action with a relentless sense of purpose. As a Cybersecurity Assessment Engineer at Second Front Systems, you will help ensure that Game Warden maintains a strong security posture. You will work hand-in-hand with the Dev Ops Engineering and Mission Success teams to oversee the software vulnerability scanning process, review vulnerability scan results, assist the customers in understanding those results, and make approval recommendations for vulnerabilities that can’t be immediately resolved.
This role will require learning new things like researching identified vulnerabilities, assessing risk, solving big problems, speaking your mind, and contributing to a culture of diversity, innovation, and excellence. This role is key to the security of our cloud platform and of the customer applications running on it.
Note:
Candidates must reside in one of our approved hiring hubs:
DC/Maryland/Virginia
Raleigh/Durham/Chapel Hill, NC
Denver/Colorado Springs, CO
Dallas/Fort Worth, TX
Review web application artifacts of customer developed applications and provide customer feedback
Primary face of the cybersecurity team to software development and mission success teams
Assist with incident response plans to respond to application outages or downtime
Technical Security Validation:
Conduct comprehensive assessments of cloud infrastructure, applications, and containerized environments to verify compliance with DISA STIGs, SRGs, and CIS Benchmarks.Authorization Lifecycle Management:
Author, review, and maintain high-quality security artifacts, including System Security Plans (SSP), Security Assessment Plans (SAP), and Security Assessment Reports (SAR).Continuous Monitoring (Con Mon):
Monitor and report on the ongoing effectiveness of security controls, ensuring the platform maintains a robust and authorized security posture.Vulnerability & Risk Analysis:
Utilize automated scanning suites (e.g., Anchore, Trivy, Tenable) to identify vulnerabilities, distinguish true positives, and provide actionable remediation guidance to dev teams.Supply Chain Security:
Implement and manage technical workflows for SBOMs (Software Bill of Materials) to support modern, continuous authorization standards.Cross-Functional Collaboration:
Partner with Dev Ops and Software Engineering teams to translate complex NIST 800-53 controls into implementable technical requirements.
Experience solving complex and sometimes ill-defined problems
Intermediate knowledge of Dev Sec Ops tools and software development
Ability to create and implement incident response plans
Background in cybersecurity and understanding of vulnerability risk analysis
Hands-on experience assessing or securing services within AWS, Azure, or GCP, particularly within PaaS or Kubernetes-based environments.
Proficient knowledge of NIST SP 800-37 (RMF) and NIST SP 800-53 rev 5 security controls
Deep understanding of the FedRAMP authorization process and Department of Defense (DoD) security standards.
3-5 years of relevant experience
Ability to attain DOD 8570 Baseline Certification for IAT II within 6 months of hire date (preferably CYSA+)
Extensive experience with Department of Defense Dev Sec Ops practices, policies, and security
Experience with Docker, Gitlab, Kubernetes, Anchore, or other container scanning tools
Ability to write basic scripts (Python, Bash, etc.) to automate evidence collection or data parsing
Strong interest in matters of national security
Having a Secret clearance is preferred
The base salary for this position will fall between $,000 Your ultimate compensation will be determined by professional background, technical…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).