DARC Software Cyber Engineer
- Discuss this with your agent
- Open in Claude
- Open in ChatGPT
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Role details
Tech stack
+41 more
Job description
This role focuses on secure software engineering for a next-generation, ground-based radar system that provides 24/7, all-weather surveillance of deep space. You will design, develop, and secure Java/Spring applications within a DevSecOps environment, ensuring robust application security and vulnerability management across CI/CD pipelines. By working on DARC, you contribute directly to Space Domain Awareness and the protection of critical military and civilian space assets in geosynchronous orbit, supporting a mission that is vital to national and global security., * Design, develop, and maintain software using Java and the Spring Framework for mission-critical radar and space domain awareness applications.
- Debug existing software, identify root causes of defects, and implement effective and sustainable fixes.
- Participate in Agile development processes, including cross-functional scrum teams, sprint planning, daily stand-ups, reviews, and retrospectives.
- Analyze static and dynamic application security scan results, distinguish true security vulnerabilities from false positives or non-applicable findings, and document technical justifications.
- Draft and maintain technical remediation plans and Plans of Action and Milestones (POA&M) to address security findings.
- Apply secure coding practices during development and perform code reviews to identify and remediate common vulnerabilities.
- Integrate security gates into CI/CD pipelines and ensure that security checks are embedded in build and release processes.
- Read, interpret, and implement security requirements, translating them into clear developer-facing tasks and acceptance criteria.
- Use version control systems effectively, including branching and merging strategies, to support collaborative development in team environments.
- Work with multiple Linux distributions, particularly Red Hat Enterprise Linux and Ubuntu, to support development, deployment, and troubleshooting activities.
- Support application security and vulnerability management efforts across the software lifecycle, including identification, triage, remediation, and verification.
- Collaborate with DevSecOps teams to integrate security tooling such as SAST, SCA, and container scanning into automated pipelines.
- Contribute to the design and implementation of secure containerized environments using Docker and Kubernetes.
- Assist in maintaining software integrity and supply chain security, including dependency management, software bills of materials (SBOMs), and vendor assessment activities.
- Support compliance with relevant security frameworks and guidelines, including NIST SP 800-53 Risk Management Framework (RMF) and DISA Application Security and Development STIG.
- Participate in vulnerability lifecycle management and patching processes across development, test, and production environments.
- Help ensure appropriate handling and protection of sensitive data, including personally identifiable information (PII), classified information, and export-controlled data.
- Support or help obtain cross-domain solution (CDS) approvals for low-to-high data transfers and follow associated compliance workflows.
- Contribute to continuous improvement of security processes, tools, and standards within the software engineering organization., The role supports a highly advanced, next-generation radar system that provides continuous, all-weather surveillance of deep space and plays a critical role in Space Domain Awareness. You will work in a technology-driven environment that emphasizes cybersecurity, DevSecOps practices, and modern tooling such as CI/CD pipelines, SonarQube, Docker, Kubernetes, and Linux-based platforms including Red Hat Enterprise Linux and Ubuntu. The position follows a 9/80 work schedule, offering a compressed workweek with every other Friday off, and every Friday that is worked is performed remotely. The primary work location is in a modern facility near the Colorado Springs Airport in the COCO-1 building, with no on-base work required. The environment promotes collaboration, mission focus, and continuous improvement in both software engineering and security practices., Google IT Automation with Python Software Developer Leidos
Colorado Springs, CO*On-Site
Equities Code Review Data Mining Market Data Communication Data Analysis Microservices Software Design Product Testing Ancient History Data Integration Secret Clearance Data Visualization Portfolio Analysis Systems Engineering Software Development Predictive Analytics Decision Support Tools Agile Software Development C++ (Programming Language) Java (Programming Language) +0
Requirements
Triage Tooling Sonatype Debugging Hardening Visionary SonarQube DevSecOps Innovation Kubernetes Code Review NIST 800-53 Secure Coding Cyber Security Systems Design Export Control Version Control Sprint Planning Spring Framework Agile Methodology Docker (Software) Bill Of Materials Container Security Linux Distribution Development Testing, Time Off Management Software Engineering Software Development Lifecycle Management Application Security Programming Languages Branching And Merging Dependency Management Supply Chain Security Cross-Domain Solutions Red Hat Enterprise Linux Vulnerability Management Risk Management Framework Ubuntu (Operating System) Engineering Design Process C++ (Programming Language) Java (Programming Language) Scrum (Software Development) Python (Programming Language) Software Composition Analysis Security Requirements Analysis Continuous Improvement Process Software Development Life Cycle Troubleshooting (Problem Solving) Personally Identifiable Information Plan Of Action And Milestones (POA&M) Static Application Security Testing (SAST), * Proficiency in Java development with practical experience using the Spring Framework.
- Experience debugging existing software and correcting defects in complex applications.
- Familiarity with Agile development methodologies and experience working in cross-functional scrum teams.
- Ability to analyze static and dynamic security scan results and distinguish actionable security findings from false positives or non-applicable items.
- Experience drafting technical justifications and remediation plans (POA&M) for identified security issues.
- Practical experience applying secure coding practices and conducting code reviews to identify common vulnerabilities.
- Knowledge of CI/CD pipelines and how to integrate security gates into build and release processes.
- Ability to read, interpret, and implement security requirements and translate them into developer-facing tasks and acceptance criteria.
- Experience using version control systems and implementing branching strategies in team environments.
- Experience working with multiple Linux distributions, with emphasis on Red Hat Enterprise Linux and Ubuntu.
- Experience in application security and vulnerability management within software development environments.
- Experience with DevSecOps practices and CI/CD security integration.
- Familiarity with tools and concepts such as SonarQube, Docker, Kubernetes, and CI/CD pipelines.
- Active Secret clearance.
- Relevant cybersecurity certification such as Security+., * Experience overseeing software integrity and supply chain security, including dependency management, SBOMs, and vendor assessment.
- Familiarity with NIST SP 800-53 Risk Management Framework (RMF) and DISA Application Security and Development STIG.
- Hands-on experience with one or more static application security testing (SAST) tools, such as SonarQube or Fortify.
- Hands-on experience with one or more software composition analysis (SCA) tools, such as Sonatype Nexus.
- Professional certifications such as CISSP or CSSLP in addition to Security+.
- Familiarity with container security and orchestration hardening, including Docker and Kubernetes, as well as image scanning tools.
- Practical knowledge of vulnerability lifecycle management and patching processes across multiple environments.
- Understanding of data protection requirements and secure handling of sensitive data, including PII, classified information, and export-controlled data.
- Experience supporting or obtaining low-to-high (CDS) transfer approvals and working within established compliance workflows.
- Experience with Python and C++ as complementary programming languages in a multi-language environment.
- Knowledge of RMF and STIG processes in support of secure system design and accreditation., Individual compensation offered for this position within this range will depend on many factors, including qualifications, skills, relevant experience, job knowledge, geographic location, internal equity, and other pertinent job-related factors., Linux CI/CD Radar MATLAB Planning Debugging Visionary Management Innovation Algorithms Shift Work Reliability Algorithm Design Secret Clearance Agile Methodology Software Features Quality Assurance CompTIA Security+ Signal Processing Root Cause Analysis Systems Integration Software Development Atlassian Confluence Continuous Integration Security Configuration Red Hat Enterprise Linux Digital Signal Processing Engineering Design Process C++ (Programming Language) Java (Programming Language) Verbal Communication Skills Front End (Software Engineering) Troubleshooting (Problem Solving) JavaScript (Programming Language) +0, Linux CI/CD Triage Tooling Sonatype Debugging Hardening Visionary SonarQube DevSecOps Innovation Kubernetes Code Review NIST 800-53 Secure Coding Cyber Security Systems Design Export Control Version Control Sprint Planning Spring Framework Agile Methodology Docker (Software) Bill Of Materials Container Security Linux Distribution Development Testing, Time Off Management Software Engineering Software Development Lifecycle Management Application Security Programming Languages Branching And Merging Dependency Management Supply Chain Security Cross-Domain Solutions Red Hat Enterprise Linux Vulnerability Management Risk Management Framework Ubuntu (Operating System) Engineering Design Process C++ (Programming Language) Java (Programming Language) Scrum (Software Development) Python (Programming Language) Software Composition Analysis Security Requirements Analysis Continuous Improvement Process Software Development Life Cycle Troubleshooting (Problem Solving) Personally Identifiable Information Plan Of Action And Milestones (POA&M) Static Application Security Testing (SAST) Certified Secure Software Lifecycle Professional Certified Information Systems Security Professional +0
Benefits & conditions
Eligibility requirements apply to some benefits and may depend on your job classification and length of employment. Benefits are subject to change and may be subject to specific elections, plan, or program terms. This temporary role may be eligible for the following:
- Medical, Dental & Vision
- 401(k)/Roth
- Basic/Supplemental Life & AD&D
- Short and long-term disability
- HSA & DCFSA
- Transportation benefits
- Employee Assistance Program
- Company Paid Time off or State Sick Leave
Job Type & Location
This is a Contract position based out of Colorado Springs, CO. Pay and Benefits
The pay range for this position is $135000.00 - $160000.00/hr.
About the company
Actalent is a global leader in engineering and sciences services and talent solutions. We help visionary companies advance their engineering and science initiatives through access to specialized experts who drive scale, innovation and speed to market. With a network of almost 20,000 consultants and 5,000 clients across the U.S., Canada, Asia and Europe, Actalent serves many of the Fortune 500. We are proud to be an Engineering News-Record (ENR) Top 500 Design Firm for our engineering design services and a ClearlyRated Best of Staffing® winner for both client and talent service.
Apply for this position
This job is hosted externally. Click below to view the full posting and apply.
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Good distractions
Talks and stories from around this role — technically off-topic, practically not.
Moments
Explore playlistsVideos
See allRelated articles
See all
Résumé-Driven Development: How IT trends affect the job market for software developers
Now is the time for industrialized software development
Dev Digest 134 - Where pixels sing?
DevOps Engineer Salary [2023]