At least 5 years of experience serving as an Information Systems Security Engineer (ISSE) for United States Department of Defense (DoD) software projects.
Proven experience generating and submitting System Security Packages (SSPs), Plans of Action and Milestones (POA&Ms;), and other artifacts required for DoD Risk Management Framework (RMF) and Security Technical Implementation Guide (STIG) processes.
Hands-on experience applying DoD cybersecurity tools such as eMASS and STIG Viewer to develop and manage security packages.
Demonstrated success obtaining and maintaining at least one DoD Authorization to Operate (ATO) for an AWS-deployed container-based workload.
Strong background in cyber security, including threat modeling, vulnerability management, security monitoring, and data protection for deployed workloads.
Experience informing software mitigation requirements based on output from static application security testing (SAST) tools such as SonarQube.
Experience using container scanning tools such as Trivy to identify and remediate vulnerabilities in containerized workloads.
Demonstrated expertise in recommending and validating data protections and testing security controls for complex systems.
Possession of one or more relevant cybersecurity certifications, such as CISSP, CASP, or Security+.