Cydecor, Inc

Cybersecurity Engineer - Clearance Required

Cydecor, Inc Norfolk, Virginia, United States · $120K–$145K/yr

Business Consulting and Services · 501-1,000 employees

4 h ago
security Senior (5-10 yrs) Full-time United States
Log in to apply, save this posting, or score it against your profile with AI.

About the role

The Cybersecurity Engineer will integrate security into the software development lifecycle by running security testing, triaging vulnerabilities, and collaborating with developers on remediation. They will also ensure compliance with Navy and DoD cybersecurity directives and maintain alignment with the Risk Management Framework.

What they look for

Cybersecurity Engineering Vulnerability Management CI/CD Pipeline Security SAST DAST Software Composition Analysis STIG ACAS Nessus Secure Code Review Risk Management Framework Azure DevOps DoD Cybersecurity Patch Management Container Security Information Assurance

Requirements

Candidates must have at least 5 years of cybersecurity engineering experience, specifically within software development and vulnerability management. A bachelor's degree in a technical field and an IAM Level II certification are required, along with an active or interim DOD Secret clearance.

Benefits

Health Insurance Dental Insurance Vision Insurance Life Insurance Short-term Disability Long-term Disability 401(k) Paid Time Off Paid Company Holidays Tuition Assistance Professional Development Assistance

Full description

Cydecor is a premier Federal Government solutions provider, delivering differentiated innovations in mission systems and business platforms.  We leverage leading-edge secure systems and software development, backed by industry-leading subject matter expertise, and business intelligence to enable decision-support and remain ahead of ever-evolving national security challenges.  Our success rests squarely on three bedrock principles: People, our center of gravity; Mission, what inspires us; and an unyielding commitment to Excellence, what separates us.

Job Description:  

We’re looking for a cybersecurity engineer to work the security side of software delivery on a large Navy readiness reporting program. You’ll work shoulder-to-shoulder with the development teams - finding vulnerabilities early, driving fixes into the code and the pipeline, and helping build security into how software gets designed, built, tested, and deployed. This is a hands-on engineering role. You’ll run and tune the security testing, chase findings to closure, and help keep the codebase and its dependencies clean. You’ll work under the Cybersecurity Lead Engineer and should have a strong understanding of the Risk Management Framework (RMF) to ensure your work remains aligned with the program’s security posture, while the Cybersecurity Lead Engineer retains ownership of the ATO packages.

Responsibilities include:

  • Run security testing across the development pipeline, SAST, DAST, software composition analysis, and container/image scanning - and keep it tuned so it catches what matters.
  • Triage and prioritize security findings, distinguish actionable issues from false positives or low-risk items, and collaborate with developers to implement remediation throughout the code and CI/CD pipeline. Track findings through resolution and ensure timely closure.
  • Review code and dependencies for security issues and give developers clear, specific remediation guidance they can act on.
  • Apply STIGs and hardening baselines, track vulnerability response and patching cadence, and keep the codebase and its dependencies current.
  • Enforce secure change management processes by performing Security Impact Analyses for proposed information system changes to authorized Navy systems.
  • Review DoW and Navy Cyber Tasking Orders and other related Cyber Directives to determine applicability to the NRRE family of systems and coordinate with applicable stakeholders to achieve compliance.
  • Ensure cybersecurity activities remain aligned with the program’s Risk Management Framework (RMF) posture and provide the Cybersecurity Lead Engineer with the documentation, evidence, and technical inputs required to support accreditation and continuous monitoring.

Additional duties and Responsibilities of the Cybersecurity Engineer include, but are not limited to the following:

  • Stay current on DoD cybersecurity guidance, tools, technologies, and best practices, incorporating relevant updates and improvements into team and program activities.
  • Effectively communicate cybersecurity posture, risk, and recommendations to technical and non-technical stakeholders, translating complex security concepts into clear, actionable information.
  • Establish and contribute to team standards, best practices, and reusable solutions that improve efficiency, promote consistency, and prevent duplication of effort.
  • Take ownership of issues and gaps, proactively driving solutions and coordinating with appropriate stakeholders to ensure timely and effective resolution.

Here’s what you need:

  • 5+ years in cybersecurity engineering, with a focus on the software development life cycle and vulnerability management.
  • Demonstrated experience with security testing in CI/CD pipelines using tools like SonarQube, Fortify, Checkmarx, or Snyk in Azure DevOps or comparable platforms.
  • Comfortable with vulnerability scanning and remediation: STIG application (focused expertise regarding Application Security Development), scan analysis (ACAS/Nessus or equivalent), secure code review, and dependency/patch management.
  • Working knowledge of RMF for DoD systems, enough to keep your work aligned with the program’s security posture.
  • IAM Level II Information Assurance Certification (per DoDI 8570.01-M and SECNAV M-5239.2), or equivalent under DoDM 8140.03 at Basic or Intermediate proficiency.

Bonus Points If You Have:

  • CSSLP, GWAPT, GWEB, CySA+, or similar secure-coding/vulnerability credentials; CISSP; prior work on DoD or Navy software programs; experience with cloud-hosted workloads and container security.

Security Clearance:

  • Interim or Active DOD Secret

Education:

  • Bachelor’s degree in computer science, cybersecurity, engineering, or a related technical field. Additional relevant experience can substitute for the degree.

Work Schedule:  

  • Monday - Friday, 8 hours

Compensation and Benefits: The projected compensation range for this position is $120,000-145,000. There are numerous factors that can impact a final salary/hourly rate including, but not limited to, relevant work experience, skills and competencies that align to the role, work location, education/certifications, and a contract's Labor Categories.

Cydecor offers a comprehensive compensation package including Health and Dental Insurance, Vision and Life Insurance, Short-Term & Long-Term Disability, 401(K) + company match, Paid Time Off (PTO), Paid Company Holidays, Tuition and Professional Development Assistance and more. 

What We Believe  We have an unwavering commitment to diversity with the aim that every one of our people has a full sense of belonging within our organization. As a business imperative, every person at Cydecor has the responsibility to create and sustain an inclusive environment.

Equal Employment Opportunity Statement Cydecor is an Equal Employment Opportunity/Affirmative Action Employer (EEO/AA). All employment and hiring decisions are based on qualifications, merit, and business needs without regard to race, religion, color, sexual orientation, nationality, gender, ethnic origin, disability, age, sex, gender identity & expression, veteran status, marital status, or any other characteristic protected by applicable law.

If you are a qualified individual with a disability and/or a disabled veteran, you may request a reasonable accommodation if you are unable or limited in your ability to access job openings or apply for a job on this site because of your disability. You can request assistance by contacting HR@cydecor.com or calling 703-884-2105. 

Key words: Cybersecurity, DevSecOps, Secure SDLC, Vulnerability Management, CI/CD, Pipeline Security, SAST, DAST, SCA, Software Composition Analysis, SonarQube, Fortify, Checkmarx, Snyk, Container Security, Image Scanning, STIG, Vulnerability Scanning, ACAS, Nessus, Secure Coding, Secure Code Review, Remediation, Patching, Azure DevOps, ADO, RMF, Risk Management Framework, IAM Level II, DoDM 8140.03, Security+, CSSLP, GWAPT, CISSP, Navy, Secret Clearance

Similar roles