> Markdown version of [/jobs/ext/2376319-software-cyber-isse-gitlab-rmf-focus](https://www.wearedevelopers.com/jobs/ext/2376319-software-cyber-isse-gitlab-rmf-focus). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Software Cyber ISSE (GitLab & RMF Focus) - **Company:** Parsons Corporation - **Location:** Aberdeen, MD, United States - **Experience:** Expert - **Salary:** $103,500.0 - $181,100.0 - **Contract:** Permanent contract - **Skills:** Kubernetes Security, Cloud Computing Security, Code Review, CompTIA Security+, Cyber Security, Continuous Integration, Secure Coding, Software Engineering, Software Systems, Software Vulnerability Management, SARS Software Products, DevOps Tools - Open-source, Infrastructure as Code (IaC), Gitlab, SC Clearance, Kubernetes, Information Technology, Devsecops, Docker, Jenkins, Plan of Action and Milestones - **Published:** August 19, 2026 - **Apply:** https://parsons.wd5.myworkdayjobs.com/Search/job/US---MD-Aberdeen/Software-Cyber-ISSE--GitLab---RMF-Focus-_R184925 ## About the Role * Bachelor's degree in Computer Science, Cybersecurity, Information Technology, or a related field (or equivalent experience). * 5+ years of experience in cybersecurity engineering, with a focus on software systems. * Demonstrated expertise in GitLab, including CI/CD pipeline security and DevSecOps integration. * In-depth knowledge and hands-on experience with the NIST Risk Management Framework (RMF). * Experience developing and maintaining RMF documentation (SSP, SAR, POA&M, etc.). * Strong understanding of secure software development lifecycle (SDLC) practices. * Familiarity with DoD/Federal cybersecurity requirements (e.g., NIST SP 800-53, CNSSI 1253). * Excellent communication and technical writing skills. * Must be a US citizen. What Desired Skills You'll Bring: * Relevant cybersecurity certifications (e.g., CISSP, CAP, CEH, Security+). * Experience with container security, cloud security, or infrastructure as code (IaC). * Familiarity with additional DevSecOps tools (e.g., Jenkins, Docker, Kubernetes). * Experience supporting Authorization to Operate (ATO) processes. * Active SECRET Clearance (or higher preferred). ## Description Parsons is seeking a highly skilled and motivated Software Cyber ISSE (Information Systems Security Engineer) to join our dynamic team! In this role, you will play a key part in integrating cybersecurity best practices throughout the software development lifecycle, supporting compliance activities, and ensuring the security posture of critical systems for our Department of Defense (DoD) and Federal clients. What You'll Be Doing: * Serve as the Information Systems Security Engineer (ISSE) for software development projects, ensuring security is embedded at every stage. * Integrate cybersecurity requirements into software design, development, and deployment processes. * Utilize GitLab for secure code management, CI/CD pipelines, and DevSecOps practices. * Develop and maintain Risk Management Framework (RMF) documentation, including System Security Plans (SSPs), Security Assessment Reports (SARs), and Plans of Action & Milestones (POA&Ms). * Conduct security risk assessments and vulnerability analyses to identify and mitigate potential threats. * Collaborate with cross-functional teams to ensure compliance with DoD and Federal cybersecurity policies and standards. * Support security control implementation, testing, and continuous monitoring activities. * Provide technical guidance on secure coding, code reviews, and vulnerability remediation. ## Related Videos - [Docker Compose: Rediscovered](https://www.wearedevelopers.com/videos/1978-docker-compose-rediscovered) - [WeAreDevelopers LIVE - Modern DevOps for IoT Devices and More](https://www.wearedevelopers.com/videos/1805-wearedevelopers-live-modern-devops-for-iot-devices-and-more) - [The Road to MLOps: How Verivox Transitioned to AWS](https://www.wearedevelopers.com/videos/1050-the-road-to-mlops-how-verivox-transitioned-to-aws) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Enabling automated 1-click customer deployments with built-in quality and security](https://www.wearedevelopers.com/videos/83-enabling-automated-1-click-customer-deployments-with-built-in-quality-and-security) - [Docker build without Docker](https://www.wearedevelopers.com/videos/100114-docker-build-without-docker) ## Related Articles - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks) - [Is Software Engineering Over-Saturated?](https://www.wearedevelopers.com/magazine/418-is-software-engineering-over-saturated) - [Now is the time for industrialized software development](https://www.wearedevelopers.com/magazine/601-now-is-the-time-for-industrialized-software-development)