Astrion logo

Cybersecurity Engineer (Software Assurance / ISSO Support)

Astrion

  • Boulder, Colorado
  • 1 day ago

    Highlights

    You will work closely with senior Cybersecurity Engineers and the Information Systems Security Manager ( ISSM ) to integrate security into the software development lifecycle (DevSecOps), conduct application security testing, and assist in maintaining Assessment and Authorization ( A&A ) documentation. Work with the ISSM and senior ISSOs to create, update, and maintain Assessment and Authorization ( A&A ) documentation, including the System Security Plan (SSP) and Security Controls Traceability Matrices (SCTMs).

    Numbers & Facts

    LocationBoulder, Colorado
    IndustryOther/Not Classified
    Company Size2,500 to 4,999 employees
    Websitehttps://astrion.us/about-us/

    Description

    Overview:

    Cybersecurity Engineer (Software Assurance / ISSO Support)

    : U.S. Space Force – Space Systems Command (SSC), Space Sensing (SN) Directorate
    LOCATION: Boulder Ground Innovation Facility (BGIF), Boulder, CO
    SALARY RANGE: Estimated $125,000 + annually*

    *depending on experience, certifications, and qualifications

    CLEARANCE: Active Secret / SCI Eligible

     

    Astrion is seeking an experienced Cybersecurity Engineer to support the Space Sensing Directorate at the Boulder Ground Innovation Facility (BGIF). This is a hands-on, onsite role safeguarding some of the nation’s most critical space and intelligence capabilities. In this role, you will focus primarily on Software Assurance (SwA) within our classified environments while providing supplemental Information Systems Security Officer (ISSO) support. You will work closely with senior Cybersecurity Engineers and the Information Systems Security Manager (ISSM) to integrate security into the software development lifecycle (DevSecOps), conduct application security testing, and assist in maintaining Assessment and Authorization (A&A) documentation. Your efforts will directly contribute to safeguarding valuable intelligence systems and ensuring positive mission outcomes.

     

     

    REQUIRED QUALIFICATIONS / SKILLS

    • Education: Bachelor's degree in Computer Science, Cybersecurity, Engineering, or a related technical field (Required).
    • Experience: 1 to 3 years of experience in cybersecurity, software engineering, or an IT security-related role. Internships and academic project experience in secure coding or cyber compliance will be considered. (Required)
    • Certification: Valid Security+ CE Certification. Must meet position and certification requirements outlined in DoD Directive 8570.01-M for Information Assurance Technical (IAT) Level II. (Required)
    • Software Assurance: Familiarity with secure coding principles, DevSecOps pipelines, and application security testing tools (e.g., SAST, DAST, SCA). Highly Desired.
    • Compliance: Basic understanding of the Risk Management Framework (RMF) and the Authorization to Operate (ATO) process. Desired.
    • System Configuration: Familiarity with Defense Information Systems Agency (DISA) Security Technical Implementation Guides (STIGs) and applying them to applications and operating systems. Desired.
    • Technical Familiarity: Basic understanding of cloud-based systems, Linux/Windows operating systems, and networking fundamentals. Desired.
    • Clearance: Must be capable of obtaining and maintaining the required security clearance for access to classified systems.

    RESPONSIBILITIES

    Software Assurance & DevSecOps

    • Assist in evaluating software architecture and design to ensure systems are functional and secure against cyber-attacks.
    • Support the integration of security tools and vulnerability checks into the continuous integration/continuous deployment (CI/CD) pipeline.
    • Analyze results from code scans and vulnerability assessments, working with development teams to remediate identified software flaws.
    • Apply Secure Technical Implementation Guide (STIG) best practices specifically targeted at software, applications, and databases.
    • Assist in developing and maintaining Defensive Cyberspace Operations tactics to monitor application-level security.

    ISSO & Compliance Support

    • Work with the ISSM and senior ISSOs to create, update, and maintain Assessment and Authorization (A&A) documentation, including the System Security Plan (SSP) and Security Controls Traceability Matrices (SCTMs).
    • Assist in tracking and updating the Plan of Action and Milestones (POA&M) for software and system vulnerabilities.
    • Support periodic reviews and evaluations of Information System (IS) policies and procedures.
    • Assist in preparing for and executing IS Security Inspections, tests, and reviews.
    • Contribute to vulnerability and risk assessment analysis to support ongoing authorization and accreditation efforts.

     

    #CJ

    About Company

    We are the transformative evolution of two prominent government services firms, ERC and Oasis Systems, each bringing with them a rich legacy of dedicated service to our nation’s Defense and Federal communities.

    The company brings together 2,800 employees focused on Cybersecurity, Digital Solutions, Mission Support, and Systems Engineering serving customers in more than 36 states across the U.S. with Centers of Excellence in Washington DC, Huntsville, AL and Burlington, MA.

    Our resources, deep expertise, and adaptable solutions will enable us to scale and expand development and engineering capabilities for Defense and Federal communities.

    Similar Jobs