Cybersecurity Software Engineer

General Dynamics Mission Systems, Inc.
Scottsdale, AZ, United States
7 days ago
Apply on justjobs.com
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Experienced
Experience required
3 years minimum
Compensation
$112,924.0 - $125,275.0
Working hours
Regular working hours
Job source

Tech stack

Java (Programming Language) Artificial Intelligence C++ (Programming Language) Command-Line Interface Static Program Analysis Cyber Security Continuous Integration VMware ESX Servers Python (Programming Language) Linux System Administration Open Web Application Security Ansible
+16 more
Fortify (Software) Secure Coding Security Software Software Engineering Verification and Validation (Software) SonarQube Test Management Software Vulnerability Management Gitlab Kubernetes Devsecops Docker Plan of Action and Milestones Static Application Security Testing Vulnerability Analysis Dynamic Application Security Testing

Job description

What You’ll Do

  • Own the current development and execution of the program vulnerability management process across the entire program and integrating AI into each step of the way

  • Execute and analyze vulnerability scan results using DISA ACAS and Anchore Grype

  • Conduct remediation efforts and verifying vulnerabilities are addressed in patched systems

  • Conduct static and dynamic code analysis using industry standard tools to detect security weaknesses and inform remediation efforts

  • Perform software dependency management, including tracking, updating, and assessing third-party components for known vulnerabilities

  • Generate and maintain software bills of materials (SBOM) for supporting supply chain risk management and vulnerability tracking

  • Recommend and implement configuration and hardening remediation for systems and applications to comply with US Govt, Industry, or Vendor guidance

  • Produce and maintain the program’s Plan of Action and Milestones (POAM) to include vulnerabilities and compliance findings

  • Produce & deliver security artifacts (Body of Evidence) that directly support the assessment of systems and applications being accredited

  • Build and maintain security tools through scripting, containers, CI/CD pipelines, and other automation

  • Produce and deliver security artifacts of findings with concise description of the issue, supporting evidence, reference material, and recommended mitigations

  • Monitor emerging threats, CVEs, and evolving security best practices and apply findings to supported technologies and program security posture

  • Develop and execute of security test plans, automated security tests, and verification and validation activities

  • Develop technical skills and cybersecurity expertise through on-the-job experience, mentorship, and cross-training with senior engineers

Requirements

Bachelor’s degree in Software Engineering, or related Science, Technology, Engineering or Mathematics field, plus a minimum of 5 years of relevant experience; or Master’s degree, plus 3 years relevant experience., Ability to obtain a Department of Defense Secret security clearance is required at time of hire. Applicants selected will be subject to a U.S. Government security investigation and must meet eligibility requirements for access to classified information. Due to the nature of work performed within our facilities, U.S. citizenship is required., * Proficiency in one or more languages such as C/C++, Java, Python, or Rust.

  • Practical experience working in Linux environments (preferably PitBull), including command-line proficiency and familiarity with OS-level security controls

  • Proficiency in DISA Security Technical Implementation Guides (STIGs) including nomenclature, tooling, and hardening

  • Proficiency with security testing and vulnerability management tooling including SAST, DAST, SCA, and container scanning, with hands-on experience using tools such as SonarQube, Fortify, OpenSCAP, Syft, Grype, ACAS

  • Proficiency of secure software development lifecycle (SSDLC) principles, practices, and common application-security vulnerabilities

  • Experience utilizing security frameworks and standards such as NIST, RMF, OWASP, CWE, CVE, STIGs, OVAL, CVSS, or secure coding standards

  • Experience supporting system accreditation and authorization activities for RMF and NCDSMO assessments

  • Proficiency applying NIST SP 800-53 Security Controls, overlays, and tailoring guidance to support system security plans and authorization packages

  • Experience using agentic or generative AI tools to develop, analyze, or automate solutions for cybersecurity problems

  • Experience with containers such as Podman (preferred), Docker, Kubernetes.

  • Experience with Gitlab and CI/CD pipelines
  • ISC CISSP desired; willing to pursue certification over time

Preferred Qualifications

  • Familiarity with Cross Domain Solutions, NCDSMO Raise the Bar, and other NCDSMO CDS guidance

  • Experience with Ansible test management framework.

  • Experience with virtualization infrastructure and containers, ESXi preferred

  • Experience in DevSecOps environments and securing CI/CD pipeline

  • Experience using Anchore Syft and Anchor Grype

  • Current SIPR access

About the company

General Dynamics Mission Systems (GDMS) engineers a diverse portfolio of high technology solutions, products and services that enable customers to successfully execute missions across all domains of operation. With a global team of 12,000+ top professionals, we partner with the best in industry to expand the bounds of innovation in the defense and scientific arenas. Given the nature of our work and who we are, we value trust, honesty, alignment and transparency. We offer highly competitive benefits and pride ourselves in being a great place to work with a shared sense of purpose. You will also enjoy a flexible work environment where contributions are recognized and rewarded. If who we are and what we do resonates with you, we invite you to join our high-performance team!

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on justjobs.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

6:14 min

Structuring CI/CD pipelines with integrated security and quality checks

Christoph Ruggenthaler · LIVE

2:07 min

Inspecting default bridge architectures and custom Docker networks

Oliver Seitz Oliver Seitz · World Congress 2025

1:42 min

Automating Skupper deployments using Ansible

Alex Soto Alex Soto · World Congress 2024

1:45 min

Transitioning from software development to security roles

Stefania Chaplin · World Congress 2022

4:54 min

Implementing geographic salary tiers for compensation equity and fairness

Rudi Bauer Rudi Bauer +1 · Cappuccino with HR

3:22 min

Transitioning from software engineering to security roles

Anna Oliveira · Coffee With Developers

Videos

See all

Related articles

See all