> Markdown version of [/jobs/ext/262997-cybersecurity-assessment-engineer](https://www.wearedevelopers.com/jobs/ext/262997-cybersecurity-assessment-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Cybersecurity Assessment Engineer - **Company:** Second Front Systems, Inc. - **Location:** Washington, DC, United States (Remote available) - **Experience:** Expert - **Salary:** $90,000.0 - $130,000.0 - **Contract:** Permanent contract - **Skills:** Amazon Web Services, Microsoft Azure, Bash Shell, Cloud Computing, Cyber Security, DevOps, Python (Programming Language), Platform as a Service (PAAS), SAP (Applications), Web Application Security, Software Engineering, Tripwire, Web Applications, Cloud Platform System, DevOps Tools - Open-source, Gitlab, Kubernetes, Tenable Nessus, CIS Benchmarks, Devsecops, Docker, Vulnerability Analysis - **Published:** May 29, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=18e5b369f5b6d7a1 ## About the Role Do you have experience in Web Application Security Testing?, * Experience solving complex and sometimes ill-defined problems * Intermediate knowledge of DevSecOps tools and software development * Ability to create and implement incident response plans * Background in cybersecurity and understanding of vulnerability risk analysis * Hands-on experience assessing or securing services within AWS, Azure, or GCP, particularly within PaaS or Kubernetes-based environments. * Proficient knowledge of NIST SP 800-37 (RMF) and NIST SP 800-53 rev 5 security controls * Deep understanding of the FedRAMP authorization process and Department of Defense (DoD) security standards. * 3-5 years of relevant experience * Secret Level Clearance (or above) * Ability to attain DOD 8570 Baseline Certification for IAT II within 6 months of hire date (preferably CYSA+), * Extensive experience with Department of Defense DevSecOps practices, policies, and security. * Experience with Docker, Gitlab, Kubernetes, Anchore, or other container scanning tools. * Ability to write basic scripts (Python, Bash, etc.) to automate evidence collection or data parsing. * Have a strong interest in matters of national security. ## Description Second Front Systems (2F) is seeking a motivated Cybersecurity Assessment Engineer to support our team. We are a fast-growing entrepreneurial team working at the convergence of technology and national security. The work will be dynamic and wide-ranging with cybersecurity, DevSecOps, and cloud infrastructure roles supporting the deployment and scale of our Game Warden platform. As a Cybersecurity Assessment Engineer at Second Front Systems, you will help ensure that Game Warden maintains a strong security posture. You will work hand-in-hand with the DevOps Engineering and Mission Success teams to oversee the software vulnerability scanning process, review vulnerability scan results, assist the customers in understanding those results, and make approval recommendations for vulnerabilities that can't be immediately resolved. This role will require learning new things like researching identified vulnerabilities, assessing risk, solving big problems, speaking your mind, and contributing to a culture of diversity, innovation, and excellence. This role is key to the security of our cloud platform and of the customer applications running on it. Note: This role requires U.S. citizenship due to government contract requirements. Additionally, candidates must reside in one of our approved hiring hubs: * DC/Maryland/Virginia * Raleigh/Durham/Chapel Hill, NC * Denver/Colorado Springs, CO * Dallas/Fort Worth, TX What You'll Do You will coordinate activities with the Principal Security Engineer, Platform team, and Customer Operations team. Specific tasks include: * Review web application artifacts of customer developed applications and provide customer feedback * Primary face of the cybersecurity team to software development and mission success teams * Assist with incident response plans to respond to application outages or downtime * Technical Security Validation: Conduct comprehensive assessments of cloud infrastructure, applications, and containerized environments to verify compliance with DISA STIGs, SRGs, and CIS Benchmarks. * Authorization Lifecycle Management: Author, review, and maintain high-quality security artifacts, including System Security Plans (SSP), Security Assessment Plans (SAP), and Security Assessment Reports (SAR). * Continuous Monitoring (ConMon): Monitor and report on the ongoing effectiveness of security controls, ensuring the platform maintains a robust and authorized security posture. * Vulnerability & Risk Analysis: Utilize automated scanning suites (e.g., Anchore, Trivy, Tenable) to identify vulnerabilities, distinguish true positives, and provide actionable remediation guidance to dev teams. * Supply Chain Security: Implement and manage technical workflows for SBOMs (Software Bill of Materials) to support modern, continuous authorization standards. * Cross-Functional Collaboration: Partner with DevOps and Software Engineering teams to translate complex NIST 800-53 controls into implementable technical requirements. ## Related Videos - [WeAreDevelopers LIVE - Modern DevOps for IoT Devices and More](https://www.wearedevelopers.com/videos/1805-wearedevelopers-live-modern-devops-for-iot-devices-and-more) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Docker Compose: Rediscovered](https://www.wearedevelopers.com/videos/1978-docker-compose-rediscovered) - [From DevOps to Scaled DevOps: How We’re Rebuilding Continuous Delivery as a Platform](https://www.wearedevelopers.com/videos/100018-from-devops-to-scaled-devops-how-we-re-rebuilding-continuous-delivery-as-a-platform) - [Enabling automated 1-click customer deployments with built-in quality and security](https://www.wearedevelopers.com/videos/83-enabling-automated-1-click-customer-deployments-with-built-in-quality-and-security) - [You can’t hack what you can’t see](https://www.wearedevelopers.com/videos/41-you-can-t-hack-what-you-can-t-see) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks) - [Dev Digest 138 - Are you secure about this?](https://www.wearedevelopers.com/magazine/486-dev-digest-138-are-you-secure-about-this)