Software Systems Engineer III

Altron Inc.
Manassas, VA, United States
3 months ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Experienced
Experience required
3 years minimum
Compensation
$110,000.0 - $150,000.0
Working hours
Regular working hours
Job source

Tech stack

Kubernetes Security Agile Methodology Amazon Web Services Systems Engineering Cyber Security Information Systems Computer Networks Databases Network Diagrams OpenShift Software Systems Data Streaming
+12 more
Systems Architecture Trusted Systems Software Vulnerability Management SARS Software Products SC Clearance Navsea Kubernetes Information Technology Nessus Scap Compliance Checker Devsecops Vulnerability Analysis

Job description

We are seeking a Software Systems Engineer - RMF to join our cybersecurity engineering team supporting U.S. Navy programs. In this role, you will lead the end-to-end Risk Management Framework (RMF) lifecycle for multiple Navy information systems, supporting authorization efforts from categorization through authorization and continuous monitoring. You will play a critical role in developing, maintaining, and defending Authorization to Operate (ATO) packages while ensuring systems meet evolving cybersecurity and compliance requirements., * Develop, submit and maintain complete authorization packages including SSPs, SAPs, SARs, RARs, POA&Ms, architectural diagrams, and hardware/software inventories.

  • Assess and validate NIST SP 800-53 security controls and develop defensible control implementation narratives to support SCA and AO reviews.
  • Implement and validate STIG compliance across operating systems, databases, applications, and network components.
  • Conduct vulnerability scanning and analysis using ACAS/Nessus, SCAP Compliance Checker, and related cybersecurity assessment tools.
  • Manage POA&M activities including risk characterization, remediation tracking, milestone management, and evidence validation through closure.
  • Collaborate with system owners, ISSMs, ISSOs, SCAs, AOs, developers, and engineers to support authorization decisions and continuous monitoring activities.
  • Develop and maintain authorization boundary diagrams, system architectures, data flow mappings, and security documentation.
  • Support change impact analysis, ongoing authorization activities, and continuous monitoring strategies across multiple systems.
  • Integrate cybersecurity and assessment activities into Agile development and DevSecOps workflows where applicable.

Requirements

Do you have experience in Vuls?, Do you have a Bachelor’s degree?, The ideal candidate will bring expertise in RMF implementation, NIST SP 800-53 security controls, vulnerability management, and secure systems engineering principles. This position is ideal for a cybersecurity professional who enjoys solving complex security challenges, managing concurrent authorization efforts, and collaborating across technical and program teams in fast-paced Agile environments., * Must be a U.S. Citizen with the ability to obtain and maintain a DoD Secret security clearance; active Secret clearance preferred.

  • Bachelor’s degree in Cybersecurity, Computer Science, Systems Engineering, Information Technology, or related technical field; equivalent experience may be considered in lieu of a degree.
  • 3-8 years of experience supporting RMF, cybersecurity engineering, information assurance, or systems security engineering activities within DoD environments.
  • Experience executing the full RMF lifecycle in accordance with NIST SP 800-37 for DoD or Navy information systems.
  • Strong knowledge of NIST SP 800-53 Rev 4 and/or Rev 5 security controls and control assessment methodologies.
  • Experience developing RMF artifacts including SSPs, SAPs, SARs, RARs, and POA&Ms.
  • Proficiency with ACAS/Nessus, SCAP Compliance Checker, STIG Viewer, and vulnerability management processes.
  • Familiarity with system architectures, authorization boundaries, network diagrams, and secure systems engineering concepts.
  • Ability to communicate technical security findings and risk determinations to technical and non-technical stakeholders.
  • Experience supporting multiple concurrent authorization efforts in Agile or fast-paced engineering environments.

Preferred Skills:

  • Experience supporting Navy RMF implementations, NAVSEA processes, or Navy-specific authorization workflows.
  • Proficiency with eMASS and VRAM.
  • Experience supporting DoD cloud authorization efforts including IL4-IL6 or FedRAMP environments.
  • Familiarity with Kubernetes, OpenShift, container security, or DevSecOps CI/CD pipelines.
  • Relevant certifications such as Security+, CISSP, CAP, CISM, or AWS Security certifications.
  • Experience supporting SCA evaluations or serving as an ISSE or ISSM.
  • Strong organizational skills with the ability to independently manage multiple priorities and concurrent efforts.
  • Effective collaboration, analytical thinking, and problem-solving skills.

Benefits & conditions

Pulled from the full job description

  • Health insurance
  • 401(k) matching
  • Paid time off
  • Vision insurance
  • Dental insurance
  • Flexible spending account
  • Life insurance, This is a full-time position based in Manassas. U.S. citizenship is required to obtain and maintain a DoD Secret Clearance. The annual base salary is $110,00 - $150,000 with final compensation based on experience and skills. Candidates will be paid within this range based on their work experience and skills.

In addition to a competitive base salary, this position is eligible for a sign-on bonus and a comprehensive benefits package including healthcare benefits (medical, dental, and vision), Flexible Spending Accounts, Life Insurance, 401(k) plan with matching company contributions, paid time off, holidays, and tuition and training reimbursement.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on indeed.com

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

1:15 min

Key lessons learned from implementing automated mobile DevSecOps

Moataz Nabil Moataz Nabil · LIVE

3:22 min

Transitioning from software engineering to security roles

Anna Oliveira · Coffee With Developers

2:09 min

Shifting security left using the DevSecOps approach

Aarno Aukia · LIVE

1:45 min

Transitioning from software development to security roles

Stefania Chaplin · World Congress 2022

5:25 min

Shifting left and creating internal security champion programs

Vandana Verma Sehgal · LIVE

2:07 min

Integrating security practices for devsecops adoption

Nevelina Aleksandrova · LIVE

Videos

See all

Related articles

See all