- Location
- Washington, DC, District of Columbia
- Workplace
- Remote
- Employment
- Full time
- Level
- Mid level
- Posted
- 2 months ago
About this role
Second Front Systems (2F) is looking for a battle-tested, high-agency Cybersecurity Assessment Engineer to support our team.. We sit at the high-stakes intersection of defense tech and national security, and this role is about building a modern, resilient operations function from the ground up. You’ll be protecting the infrastructure and platforms that power mission-critical software for the free world - ensuring our nation’s defenders have the secure environment they need to move fast.
At 2F, we pair a startup’s bias for action with a relentless sense of purpose. As a Cybersecurity Assessment Engineer at Second Front Systems, you will help ensure that Game Warden maintains a strong security posture. You will work hand-in-hand with the DevOps Engineering and Mission Success teams to oversee the software vulnerability scanning process, review vulnerability scan results, assist the customers in understanding those results, and make approval recommendations for vulnerabilities that can't be immediately resolved. This role will require learning new things like researching identified vulnerabilities, assessing risk, solving big problems, speaking your mind, and contributing to a culture of diversity, innovation, and excellence. This role is key to the security of our cloud platform and of the customer applications running on it.
Note: Candidates must reside in one of our approved hiring hubs:
DC/Maryland/Virginia
Raleigh/Durham/Chapel Hill, NC
Denver/Colorado Springs, CO
Dallas/Fort Worth, TX
What You'll Do
Review web application artifacts of customer developed applications and provide customer feedback
Primary face of the cybersecurity team to software development and mission success teams
Assist with incident response plans to respond to application outages or downtime
Technical Security Validation: Conduct comprehensive assessments of cloud infrastructure, applications, and containerized environments to verify compliance with DISA STIGs, SRGs, and CIS Benchmarks.
Authorization Lifecycle Management: Author, review, and maintain high-quality security artifacts, including System Security Plans (SSP), Security Assessment Plans (SAP), and Security Assessment Reports (SAR).
Continuous Monitoring (ConMon): Monitor and report on the ongoing effectiveness of security controls, ensuring the platform maintains a robust and authorized security posture.
Vulnerability & Risk Analysis: Utilize automated scanning suites (e.g., Anchore, Trivy, Tenable) to identify vulnerabilities, distinguish true positives, and provide actionable remediation guidance to dev teams.
Supply Chain Security: Implement and manage technical workflows for SBOMs (Software Bill of Materials) to support modern, continuous authorization standards.
Cross-Functional Collaboration: Partner with DevOps and Software Engineering teams to translate complex NIST 800-53 controls into implementable technical requirements.
What You Bring
Experience solving complex and sometimes ill-defined problems
Intermediate knowledge of DevSecOps tools and software development
Ability to create and implement incident response plans
Background in cybersecurity and understanding of vulnerability risk analysis
Hands-on experience assessing or securing services within AWS, Azure, or GCP, particularly within PaaS or Kubernetes-based environments.
Proficient knowledge of NIST SP 800-37 (RMF) and NIST SP 800-53 rev 5 security controls
Deep understanding of the FedRAMP authorization process and Department of Defense (DoD) security standards.
3-5 years of relevant experience
Ability to attain DOD 8570 Baseline Certification for IAT II within 6 months of hire date (preferably CYSA+)
Preferred
Extensive experience with Department of Defense DevSecOps practices, policies, and security
Experience with Docker, Gitlab, Kubernetes, Anchore, or other container scanning tools
Ability to write basic scripts (Python, Bash, etc.) to automate evidence collection or data parsing
Strong interest in matters of national security
Having a Secret clearance is preferred
The base salary for this position will fall between $125,000-140,000 Your ultimate compensation will be determined by professional background, technical proficiency, seniority, and regional cost factors. Furthermore, this opportunity includes potential eligibility for equity awards and discretionary bonuses, rounding out a comprehensive total rewards offering.
Success at 2F Looks Like:
Viewing obstacles as opportunities for growth
Having a bias toward action and tangible, measurable results
Striving to be both compassionate and direct with your feedback
Being team-oriented and inclusive with your action
Perks & Benefits:
This role is a full time position. As a public benefit corporation, we’re a team of purpose-driven trailblazers transforming the future of U.S. national security. We hire the best to do their best and, as such, we are committed to providing the perks and benefits you need to be successful - both in- and outside the workplace.
We offer you:
Competitive Salary
100% Healthcare, vision and dental coverage
401(k) + 3% company contribution
Wellness perks (Fitness classes, mental health resources)
Equity incentive plan
Tech + office supplies stipend
Annual professional development stipend
Flexible paid time off + federal holidays off
Parental leave
Work from anywhere
Referral Bonus
Visit our careers page to learn more.
Who We Are:
Second Front Systems (2F) is a public-benefit software company powering software for the free world. We eliminate the friction that slows innovation, enabling faster, more secure development and deployment of software across government and regulated networks. Built by national security veterans and backed by top-tier venture capital, our platform is trusted by the world’s leading organizations to cut deployment timelines from years to weeks. We move fast, solve hard problems, and deliver trusted capabilities where they’re needed most. Our work strengthens global security and gives the United States and its allies a lasting competitive advantage. Learn more at secondfront.com.
One last thing:
We are an equal opportunity employer and all qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity or expression, pregnancy, age, national origin, disability status, genetic information, protected veteran status, or any other characteristic protected by law.
State notices:
Colorado:
In accordance with Colorado law, applicants may redact their date of birth, dates of attendance, and dates of graduation from any uploaded documents.
Maryland:
Under Maryland law, an employer may not require or demand, as a condition of employment, prospective employment, or continued employment, that an individual submit to or take a polygraph examination or similar test. An employer who violates this law is guilty of a misdemeanor and subject to a fine not exceeding $100.
As published by Second Front Systems. Applications are handled on their site.
Skills this posting mentions
About Second Front Systems
Second Front is a public-benefit, venture-backed company delivering mission-critical software to the world’s democracies. We work with organizations to simplify and accelerate every step of software delivery to government and regulated networks, including development, accreditation, operation, and extensibility. Together with our customers and partners, we're powering software for the free world. Learn more at secondfront.com
All 17 openings at Second Front SystemsOne click, then it is written
Apply to Second Front Systems with a resume written for this role.
Queue Cybersecurity Assessment Engineer and I read the posting, rewrite your resume against it, draft the cover letter, and score the fit. Then you press send, or press one button and I fill in Second Front Systems’s form for you.
01Drop your resume
A PDF or a LinkedIn URL. About a minute, once.
02I rank the openings
Every weekday morning, the live catalog scored against your history. Up to 20 worth your time, not two hundred links.
03Each one is written up
Resume rewritten for the posting, a cover letter, a fit score. Press send, or let me fill in the form.
- 25 sent a week, free
- No card
- Nothing sent until you say so
More roles at Second Front Systems
See all- 5 weeks ago
- 5 weeks ago
- 5 weeks ago
Senior Technical Implementation Engineer (United Kingdom)
United KingdomRemote
£70k - £90k/yrSeniorEngineering - 7 weeks ago
- 2 months ago
- 2 months ago
Similar roles elsewhere
See more- Today
Engineering Manager, People Applications
DoorDashWashington, D.C. +8
$163k - $240k/yrManagerEngineering - 3 days ago
- 4 days ago
Put this to work
Paste your career in once. Every application after that is written for you.
Drop a resume or a LinkedIn URL. I rank the live openings against it, rewrite the resume and write a cover letter for the best of them, and fill in the employer's form when you press the button. You read, you decide what goes out.
01Drop your resume
A PDF or a LinkedIn URL. About a minute, once.
02I rank the openings
Every weekday morning, the live catalog scored against your history. Up to 20 worth your time, not two hundred links.
03Each one is written up
Resume rewritten for the posting, a cover letter, a fit score. Press send, or let me fill in the form.
- New matches ranked and written before you are up.
- Every bullet stays inside what your history supports. Nothing invented.
- Queued, submitted, interviewing, offer: one screen, not a spreadsheet.
500 free credits on sign-up. No card. Nothing is sent until you say so.
Listed from the job board Second Front Systems publishes. Refolk is not the employer and does not handle their hiring. Applications go to Second Front Systems directly.