> Markdown version of [/jobs/ext/184728-software-systems-engineer-iii](https://www.wearedevelopers.com/jobs/ext/184728-software-systems-engineer-iii). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Software Systems Engineer III - **Company:** Altron Inc. - **Location:** Manassas, VA, United States - **Experience:** Experienced - **Salary:** $110,000.0 - $150,000.0 - **Contract:** Permanent contract - **Skills:** Kubernetes Security, Agile Methodology, Amazon Web Services, Systems Engineering, Cyber Security, Information Systems, Computer Networks, Databases, Network Diagrams, OpenShift, Software Systems, Data Streaming, Systems Architecture, Trusted Systems, Software Vulnerability Management, SARS Software Products, SC Clearance, Navsea, Kubernetes, Information Technology, Nessus, Scap Compliance Checker, Devsecops, Vulnerability Analysis - **Published:** May 23, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=6c5f658298ea2233 ## About the Role Do you have experience in Vuls?, Do you have a Bachelor's degree?, The ideal candidate will bring expertise in RMF implementation, NIST SP 800-53 security controls, vulnerability management, and secure systems engineering principles. This position is ideal for a cybersecurity professional who enjoys solving complex security challenges, managing concurrent authorization efforts, and collaborating across technical and program teams in fast-paced Agile environments., * Must be a U.S. Citizen with the ability to obtain and maintain a DoD Secret security clearance; active Secret clearance preferred. * Bachelor's degree in Cybersecurity, Computer Science, Systems Engineering, Information Technology, or related technical field; equivalent experience may be considered in lieu of a degree. * 3-8 years of experience supporting RMF, cybersecurity engineering, information assurance, or systems security engineering activities within DoD environments. * Experience executing the full RMF lifecycle in accordance with NIST SP 800-37 for DoD or Navy information systems. * Strong knowledge of NIST SP 800-53 Rev 4 and/or Rev 5 security controls and control assessment methodologies. * Experience developing RMF artifacts including SSPs, SAPs, SARs, RARs, and POA&Ms. * Proficiency with ACAS/Nessus, SCAP Compliance Checker, STIG Viewer, and vulnerability management processes. * Familiarity with system architectures, authorization boundaries, network diagrams, and secure systems engineering concepts. * Ability to communicate technical security findings and risk determinations to technical and non-technical stakeholders. * Experience supporting multiple concurrent authorization efforts in Agile or fast-paced engineering environments. Preferred Skills: * Experience supporting Navy RMF implementations, NAVSEA processes, or Navy-specific authorization workflows. * Proficiency with eMASS and VRAM. * Experience supporting DoD cloud authorization efforts including IL4-IL6 or FedRAMP environments. * Familiarity with Kubernetes, OpenShift, container security, or DevSecOps CI/CD pipelines. * Relevant certifications such as Security+, CISSP, CAP, CISM, or AWS Security certifications. * Experience supporting SCA evaluations or serving as an ISSE or ISSM. * Strong organizational skills with the ability to independently manage multiple priorities and concurrent efforts. * Effective collaboration, analytical thinking, and problem-solving skills. ## Description We are seeking a Software Systems Engineer - RMF to join our cybersecurity engineering team supporting U.S. Navy programs. In this role, you will lead the end-to-end Risk Management Framework (RMF) lifecycle for multiple Navy information systems, supporting authorization efforts from categorization through authorization and continuous monitoring. You will play a critical role in developing, maintaining, and defending Authorization to Operate (ATO) packages while ensuring systems meet evolving cybersecurity and compliance requirements., * Develop, submit and maintain complete authorization packages including SSPs, SAPs, SARs, RARs, POA&Ms, architectural diagrams, and hardware/software inventories. * Assess and validate NIST SP 800-53 security controls and develop defensible control implementation narratives to support SCA and AO reviews. * Implement and validate STIG compliance across operating systems, databases, applications, and network components. * Conduct vulnerability scanning and analysis using ACAS/Nessus, SCAP Compliance Checker, and related cybersecurity assessment tools. * Manage POA&M activities including risk characterization, remediation tracking, milestone management, and evidence validation through closure. * Collaborate with system owners, ISSMs, ISSOs, SCAs, AOs, developers, and engineers to support authorization decisions and continuous monitoring activities. * Develop and maintain authorization boundary diagrams, system architectures, data flow mappings, and security documentation. * Support change impact analysis, ongoing authorization activities, and continuous monitoring strategies across multiple systems. * Integrate cybersecurity and assessment activities into Agile development and DevSecOps workflows where applicable. ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [DevSecOps: Injecting Security into Mobile CI/CD Pipelines](https://www.wearedevelopers.com/videos/273-devsecops-injecting-security-into-mobile-ci-cd-pipelines) - [Organizational Change Through The Power Of Why - DevSecOps Enablement](https://www.wearedevelopers.com/videos/478-organizational-change-through-the-power-of-why-devsecops-enablement) - [DevSecOps culture](https://www.wearedevelopers.com/videos/783-devsecops-culture) - [You can’t hack what you can’t see](https://www.wearedevelopers.com/videos/41-you-can-t-hack-what-you-can-t-see) - [DevSecOps: Security in DevOps](https://www.wearedevelopers.com/videos/36-devsecops-security-in-devops) ## Related Articles - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Highest Paying Tech Companies for Developers](https://www.wearedevelopers.com/magazine/220-highest-paying-tech-companies-for-developers) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks) - [Is Software Engineering Over-Saturated?](https://www.wearedevelopers.com/magazine/418-is-software-engineering-over-saturated) - [Dev Digest 121 - AI goes offline](https://www.wearedevelopers.com/magazine/456-dev-digest-121-ai-goes-offline)