> Markdown version of [/jobs/ext/2148951-cybersecurity-software-engineer](https://www.wearedevelopers.com/jobs/ext/2148951-cybersecurity-software-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Cybersecurity Software Engineer - **Company:** General Dynamics Mission Systems, Inc. - **Location:** Scottsdale, AZ, United States - **Experience:** Experienced - **Salary:** $112,924.0 - $125,275.0 - **Contract:** Permanent contract - **Skills:** Java (Programming Language), Artificial Intelligence, C++ (Programming Language), Command-Line Interface, Static Program Analysis, Cyber Security, Continuous Integration, VMware ESX Servers, Python (Programming Language), Linux System Administration, Open Web Application Security, Ansible, Fortify (Software), Secure Coding, Security Software, Software Engineering, Verification and Validation (Software), SonarQube, Test Management, Software Vulnerability Management, Gitlab, Kubernetes, Devsecops, Docker, Plan of Action and Milestones, Static Application Security Testing, Vulnerability Analysis, Dynamic Application Security Testing - **Published:** August 20, 2026 - **Apply:** https://justjobs.com/main/sendform/8/8/28176/1/18011239?backUrl=%2Fcareer%2F18011239%2FCybersecurity-Software-Engineer-Arizona-Scottsdale ## About the Role Bachelor's degree in Software Engineering, or related Science, Technology, Engineering or Mathematics field, plus a minimum of 5 years of relevant experience; or Master's degree, plus 3 years relevant experience., Ability to obtain a Department of Defense Secret security clearance is required at time of hire. Applicants selected will be subject to a U.S. Government security investigation and must meet eligibility requirements for access to classified information. Due to the nature of work performed within our facilities, U.S. citizenship is required., * Proficiency in one or more languages such as C/C++, Java, Python, or Rust. * Practical experience working in Linux environments (preferably PitBull), including command-line proficiency and familiarity with OS-level security controls * Proficiency in DISA Security Technical Implementation Guides (STIGs) including nomenclature, tooling, and hardening * Proficiency with security testing and vulnerability management tooling including SAST, DAST, SCA, and container scanning, with hands-on experience using tools such as SonarQube, Fortify, OpenSCAP, Syft, Grype, ACAS * Proficiency of secure software development lifecycle (SSDLC) principles, practices, and common application-security vulnerabilities * Experience utilizing security frameworks and standards such as NIST, RMF, OWASP, CWE, CVE, STIGs, OVAL, CVSS, or secure coding standards * Experience supporting system accreditation and authorization activities for RMF and NCDSMO assessments * Proficiency applying NIST SP 800-53 Security Controls, overlays, and tailoring guidance to support system security plans and authorization packages * Experience using agentic or generative AI tools to develop, analyze, or automate solutions for cybersecurity problems * Experience with containers such as Podman (preferred), Docker, Kubernetes. * Experience with Gitlab and CI/CD pipelines * ISC CISSP desired; willing to pursue certification over time Preferred Qualifications * Familiarity with Cross Domain Solutions, NCDSMO Raise the Bar, and other NCDSMO CDS guidance * Experience with Ansible test management framework. * Experience with virtualization infrastructure and containers, ESXi preferred * Experience in DevSecOps environments and securing CI/CD pipeline * Experience using Anchore Syft and Anchor Grype * Current SIPR access ## Description What You'll Do * Own the current development and execution of the program vulnerability management process across the entire program and integrating AI into each step of the way * Execute and analyze vulnerability scan results using DISA ACAS and Anchore Grype * Conduct remediation efforts and verifying vulnerabilities are addressed in patched systems * Conduct static and dynamic code analysis using industry standard tools to detect security weaknesses and inform remediation efforts * Perform software dependency management, including tracking, updating, and assessing third-party components for known vulnerabilities * Generate and maintain software bills of materials (SBOM) for supporting supply chain risk management and vulnerability tracking * Recommend and implement configuration and hardening remediation for systems and applications to comply with US Govt, Industry, or Vendor guidance * Produce and maintain the program's Plan of Action and Milestones (POAM) to include vulnerabilities and compliance findings * Produce & deliver security artifacts (Body of Evidence) that directly support the assessment of systems and applications being accredited * Build and maintain security tools through scripting, containers, CI/CD pipelines, and other automation * Produce and deliver security artifacts of findings with concise description of the issue, supporting evidence, reference material, and recommended mitigations * Monitor emerging threats, CVEs, and evolving security best practices and apply findings to supported technologies and program security posture * Develop and execute of security test plans, automated security tests, and verification and validation activities * Develop technical skills and cybersecurity expertise through on-the-job experience, mentorship, and cross-training with senior engineers ## Related Videos - [Enabling automated 1-click customer deployments with built-in quality and security](https://www.wearedevelopers.com/videos/83-enabling-automated-1-click-customer-deployments-with-built-in-quality-and-security) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Dev & Test in the Cloud? Deploy your cloud environments with Ansible & Terraform](https://www.wearedevelopers.com/videos/1607-dev-test-in-the-cloud-deploy-your-cloud-environments-with-ansible-terraform) - [Docker Compose: Rediscovered](https://www.wearedevelopers.com/videos/1978-docker-compose-rediscovered) - [WeAreDevelopers LIVE - Modern DevOps for IoT Devices and More](https://www.wearedevelopers.com/videos/1805-wearedevelopers-live-modern-devops-for-iot-devices-and-more) - [Securing Your Web Application Pipeline From Intruders](https://www.wearedevelopers.com/videos/53-securing-your-web-application-pipeline-from-intruders) ## Related Articles - [Highest Paying Tech Companies for Developers](https://www.wearedevelopers.com/magazine/220-highest-paying-tech-companies-for-developers) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again](https://www.wearedevelopers.com/magazine/751-how-we-built-a-worry-free-system-that-runs-for-10-years-and-what-we-d-do-again) - [Best Countries for Software Engineers](https://www.wearedevelopers.com/magazine/267-best-countries-for-software-engineers) - [Is Software Engineering Over-Saturated?](https://www.wearedevelopers.com/magazine/418-is-software-engineering-over-saturated) - [Now is the time for industrialized software development](https://www.wearedevelopers.com/magazine/601-now-is-the-time-for-industrialized-software-development)