368,634open jobs
9,437companies
50,578added this week
Browse all
Salary
$125k – $140k per year
Location
Remote (Texas, Virginia, Maryland, North Carolina, District of Columbia, United States)
Seniority
Middle · 3+ years exp
Employment
Full-Time
Overview
Company
Impact
Profile match
Second Front Systems accelerates the accreditation of commercial software for government use. Its Game Warden platform hosts vendor applications inside approved secure environments. Defence agencies use it to adopt modern tools far faster than usual.

Second Front Systems (2F) is looking for a battle-tested, high-agency Cybersecurity Assessment Engineer to support our team.. We sit at the high-stakes intersection of defense tech and national security, and this role is about building a modern, resilient operations function from the ground up. You’ll be protecting the infrastructure and platforms that power mission-critical software for the free world-ensuring our nation’s defenders have the secure environment they need to move fast.

At 2F, we pair a startup’s bias for action with a relentless sense of purpose. As a Cybersecurity Assessment Engineer at Second Front Systems, you will help ensure that Game Warden maintains a strong security posture. You will work hand-in-hand with the DevOps Engineering and Mission Success teams to oversee the software vulnerability scanning process, review vulnerability scan results, assist the customers in understanding those results, and make approval recommendations for vulnerabilities that can't be immediately resolved. This role will require learning new things like researching identified vulnerabilities, assessing risk, solving big problems, speaking your mind, and contributing to a culture of diversity, innovation, and excellence. This role is key to the security of our cloud platform and of the customer applications running on it.

Note: Candidates must reside in one of our approved hiring hubs:

  • DC/Maryland/Virginia

  • Raleigh/Durham/Chapel Hill, NC

  • Denver/Colorado Springs, CO

  • Dallas/Fort Worth, TX

What You'll Do

  • Review web application artifacts of customer developed applications and provide customer feedback

  • Primary face of the cybersecurity team to software development and mission success teams

  • Assist with incident response plans to respond to application outages or downtime

  • Technical Security Validation: Conduct comprehensive assessments of cloud infrastructure, applications, and containerized environments to verify compliance with DISA STIGs, SRGs, and CIS Benchmarks.

  • Authorization Lifecycle Management: Author, review, and maintain high-quality security artifacts, including System Security Plans (SSP), Security Assessment Plans (SAP), and Security Assessment Reports (SAR).

  • Continuous Monitoring (ConMon): Monitor and report on the ongoing effectiveness of security controls, ensuring the platform maintains a robust and authorized security posture.

  • Vulnerability & Risk Analysis: Utilize automated scanning suites (e.g., Anchore, Trivy, Tenable) to identify vulnerabilities, distinguish true positives, and provide actionable remediation guidance to dev teams.

  • Supply Chain Security: Implement and manage technical workflows for SBOMs (Software Bill of Materials) to support modern, continuous authorization standards.

  • Cross-Functional Collaboration: Partner with DevOps and Software Engineering teams to translate complex NIST 800-53 controls into implementable technical requirements.

What You Bring

  • Experience solving complex and sometimes ill-defined problems

  • Intermediate knowledge of DevSecOps tools and software development

  • Ability to create and implement incident response plans

  • Background in cybersecurity and understanding of vulnerability risk analysis

  • Hands-on experience assessing or securing services within AWS, Azure, or GCP, particularly within PaaS or Kubernetes-based environments.

  • Proficient knowledge of NIST SP 800-37 (RMF) and NIST SP 800-53 rev 5 security controls

  • Deep understanding of the FedRAMP authorization process and Department of Defense (DoD) security standards.

  • 3-5 years of relevant experience

  • Ability to attain DOD 8570 Baseline Certification for IAT II within 6 months of hire date (preferably CYSA+)

Preferred

  • Extensive experience with Department of Defense DevSecOps practices, policies, and security

  • Experience with Docker, Gitlab, Kubernetes, Anchore, or other container scanning tools

  • Ability to write basic scripts (Python, Bash, etc.) to automate evidence collection or data parsing

  • Strong interest in matters of national security

  • Having a Secret clearance is preferred

The base salary for this position will fall between $125,000-140,000 Your ultimate compensation will be determined by professional background, technical proficiency, seniority, and regional cost factors. Furthermore, this opportunity includes potential eligibility for equity awards and discretionary bonuses, rounding out a comprehensive total rewards offering.

Success at 2F Looks Like:

  • Viewing obstacles as opportunities for growth

  • Having a bias toward action and tangible, measurable results

  • Striving to be both compassionate and direct with your feedback

  • Being team-oriented and inclusive with your action

Perks & Benefits:

This role is a full time position. As a public benefit corporation, we’re a team of purpose-driven trailblazers transforming the future of U.S. national security. We hire the best to do their best and, as such, we are committed to providing the perks and benefits you need to be successful-both in- and outside the workplace.

We offer you:

  • Competitive Salary

  • 100% Healthcare, vision and dental coverage

  • 401(k) + 3% company contribution

  • Wellness perks (Fitness classes, mental health resources)

  • Equity incentive plan

  • Tech + office supplies stipend

  • Annual professional development stipend

  • Flexible paid time off + federal holidays off

  • Parental leave

  • Work from anywhere

  • Referral Bonus

Visit our careers page to learn more.

Who We Are:

Second Front Systems (2F) is a public-benefit software company powering software for the free world. We eliminate the friction that slows innovation, enabling faster, more secure development and deployment of software across government and regulated networks. Built by national security veterans and backed by top-tier venture capital, our platform is trusted by the world’s leading organizations to cut deployment timelines from years to weeks. We move fast, solve hard problems, and deliver trusted capabilities where they’re needed most. Our work strengthens global security and gives the United States and its allies a lasting competitive advantage. Learn more at secondfront.com.

One last thing:

We are an equal opportunity employer and all qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity or expression, pregnancy, age, national origin, disability status, genetic information, protected veteran status, or any other characteristic protected by law.

State notices:

Colorado:

In accordance with Colorado law, applicants may redact their date of birth, dates of attendance, and dates of graduation from any uploaded documents.

Maryland:

Under Maryland law, an employer may not require or demand, as a condition of employment, prospective employment, or continued employment, that an individual submit to or take a polygraph examination or similar test. An employer who violates this law is guilty of a misdemeanor and subject to a fine not exceeding $100.

Free account
Stop reading job ads. Get the ones that fit.
One free account turns this page into a shortlist built around your stack, your level and your pay.
Match on every job. Stack, seniority, pay and location, scored against your profile.
368,634 open roles. Read straight off company career pages, refreshed every day.
Unlimited applications. Every one you send is tracked in one place, on-site or on a company board.
3 tailored CVs a month. Rewritten for the exact job you are applying to. Included free.
Create a free account
Free forever. No card. Under a minute.

Your match

How well do you fit this role?
Two answers are enough for a real match. No account needed.
Check my fit
Answers stay in this browser until you create an account.

Recommended for you based on this role

Similar stack
Same company
In your city
$20k – $49k per year (Estimated) • Remote • Full-Time • Bachelor's Degree
Python
Ruby
SQL
Databases
Amazon Neptune
Neo4j
AI/ML
Hallucination
LangChain
LangGraph
LLM
Model Context Protocol
Spark
AI Agents
LLM Guardrails
DevOps
Ansible
AWS
Azure
CI/CD
Docker
GCP
GitHub Actions
GitLab CI
Jenkins
Kubernetes
Rest API
Terraform
GitHub
GitLab
QA
Playwright
Postman
Selenium
Swagger
Apply
SOC Senior Analyst 2 days ago
In office • Full-Time • Bachelor's Degree • Riyadh
DevOps
AWS
Azure
GCP
Cybersecurity
MITRE ATT&CK
Apply
SOC Analyst L1 1 day ago
In office • Full-Time • Bachelor's Degree • Riyadh
DevOps
AWS
Azure
GCP
SLI/SLO/SLA
Cybersecurity
MITRE ATT&CK
Apply
$20k – $51k per year (Estimated) • Remote • Full-Time • 3+ years exp
DevOps
AWS
Azure
GCP
IAM
Apply
Remote • Full-Time • 3+ years exp • Cairo
C#
JavaScript
TypeScript
C#
.NET
AI/ML
Copilot
DevOps
Azure
Azure DevOps
CI/CD
Rest API
Analytics
ETL/ELT
Management
Power Apps
Power Automate
Apply
UX Designer 10 days ago
$120k – $145k per year • Equity • Remote • Full-Time • 3+ years exp
AI/ML
Claude
Claude Code
Cybersecurity
FedRAMP
NIST 800-53
Design
Figma
Apply
$160k – $200k per year • Equity • In office • Full-Time • 7+ years exp
Bash
Python
Rust
DevOps
AWS
Azure
CloudFormation
Docker
GCP
Grafana
Helm
Istio
Kubernetes
OpenShift
Platform Engineering
Prometheus
Red Hat
Splunk
Terraform
GitLab
Cybersecurity
FedRAMP
NIST 800-53
Zero Trust
Apply
$160k – $190k per year • Equity • Remote • Full-Time • 10+ years exp
DevOps
AWS
Azure
GCP
Platform Engineering
Apply
SOC Manager 21 day ago
$205k – $215k per year • Equity • Remote • Full-Time • 3+ years exp
Python
DevOps
AWS
Kubernetes
Terraform
Cybersecurity
FedRAMP
Apply
$149k – $176k per year • Equity • In office • Full-Time • 7+ years exp • London
Go
AI/ML
Claude
Gemini
DevOps
AWS
Azure
CI/CD
Docker
GCP
Kubernetes
Pulumi
Rest API
GitLab
Cybersecurity
NIST 800-53
Management
Google Workspace
Slack
Apply
See all jobs
This is one of many
368,634 more open roles from verified company boards, updated every day.