Cybersecurity Engineer (Software Assurance / ISSO Support)

ASTRION, INC.
Boulder, CO, United States
13 days ago

Role details

Contract type
Internship / Graduate position
Employment type
Full-time (> 32 hours)
Experience level
Starter
Experience required
1 year minimum
Compensation
$125,000.0
Working hours
Regular working hours

Tech stack

Microsoft Windows Cloud Computing Cyber Security Information Systems Databases System Configuration Continuous Delivery Continuous Integration Linux Networking Basics Software Architecture Secure Coding
+8 more
Software Engineering Information Security Management System Information Technology Devsecops Plan of Action and Milestones Static Application Security Testing Vulnerability Analysis Dynamic Application Security Testing

Job description

Astrion is seeking an experiencedCybersecurity Engineerto support the Space Sensing Directorate at the Boulder Ground Innovation Facility (BGIF). This is a hands-on, onsite role safeguarding some of the nation’s most critical space and intelligence capabilities. In this role, you will focus primarily on Software Assurance (SwA) within our classified environments while providing supplemental Information Systems Security Officer (ISSO) support. You will work closely with senior Cybersecurity Engineers and the Information Systems Security Manager (ISSM) to integrate security into the software development lifecycle (DevSecOps), conduct application security testing, and assist in maintaining Assessment and Authorization (A&A) documentation. Your efforts will directly contribute to safeguarding valuable intelligence systems and ensuring positive mission outcomes., Software Assurance & DevSecOps

  • Assist in evaluating software architecture and design to ensure systems are functional and secure against cyber-attacks.
  • Support the integration of security tools and vulnerability checks into the continuous integration/continuous deployment (CI/CD) pipeline.
  • Analyze results from code scans and vulnerability assessments, working with development teams to remediate identified software flaws.
  • Apply Secure Technical Implementation Guide (STIG) best practices specifically targeted at software, applications, and databases.
  • Assist in developing and maintaining Defensive Cyberspace Operations tactics to monitor application-level security.

ISSO & Compliance Support

  • Work with the ISSM and senior ISSOs to create, update, and maintain Assessment and Authorization (A&A) documentation, including the System Security Plan (SSP) and Security Controls Traceability Matrices (SCTMs).
  • Assist in tracking and updating the Plan of Action and Milestones (POA&M) for software and system vulnerabilities.
  • Support periodic reviews and evaluations of Information System (IS) policies and procedures.
  • Assist in preparing for and executing IS Security Inspections, tests, and reviews.
  • Contribute to vulnerability and risk assessment analysis to support ongoing authorization and accreditation efforts.

Requirements

  • Education: Bachelor’s degree in Computer Science, Cybersecurity, Engineering, or a related technical field (Required).
  • Experience: 1 to 3 years of experience in cybersecurity, software engineering, or an IT security-related role. Internships and academic project experience in secure coding or cyber compliance will be considered. (Required)
  • Certification: Valid Security+ CE Certification. Must meet position and certification requirements outlined in DoD Directive 8570.01-M for Information Assurance Technical (IAT) Level II. (Required)
  • Software Assurance: Familiarity with secure coding principles, DevSecOps pipelines, and application security testing tools (e.g., SAST, DAST, SCA). Highly Desired.
  • Compliance: Basic understanding of the Risk Management Framework (RMF) and the Authorization to Operate (ATO) process. Desired.
  • System Configuration: Familiarity with Defense Information Systems Agency (DISA) Security Technical Implementation Guides (STIGs) and applying them to applications and operating systems. Desired.
  • Technical Familiarity: Basic understanding of cloud-based systems, Linux/Windows operating systems, and networking fundamentals. Desired.
  • Clearance: Must be capable of obtaining and maintaining the required security clearance for access to classified systems.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on diversityjobs.com

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

52 sec

Running persistent Linux environments directly on Windows

Ben Breard Ben Breard · WWC 2025

3:04 min

Database evolution and the funding behind vector databases

Erik Bamberg · LIVE

1:15 min

Key lessons learned from implementing automated mobile DevSecOps

Moataz Nabil Moataz Nabil · LIVE

1:45 min

Transitioning from software development to security roles

Stefania Chaplin · WWC 2022

3:55 min

Demonstrating .NET installation on Debian and Azure Linux

Silvano Coriani Silvano Coriani · Europe 2026 Virtual

4:01 min

Finding personal fulfillment in the cybersecurity industry

LIVE

Videos

See all

Related articles

See all