At least 5 years of experience serving as an Information Systems Security Engineer (ISSE) for United States Department of Defense (DoD) software projects.
Proven experience generating and submitting System Security Packages (SSPs), Plans of Action and Milestones (POA&Ms;), and other artifacts required for DoD Risk Management Framework (RMF) and Security Technical Implementation Guide (STIG) processes.
Hands-on experience applying DoD cybersecurity tools such as eMASS and STIG Viewer to develop and manage security packages.
Demonstrated success obtaining and maintaining at least one DoD Authorization to Operate (ATO) for an AWS-deployed container-based workload.
Strong background in cyber security, including threat modeling, vulnerability management, security monitoring, and data protection for deployed workloads.
Experience informing software mitigation requirements based on output from static application security testing (SAST) tools such as SonarQube.
Experience using container scanning tools such as Trivy to identify and remediate vulnerabilities in containerized workloads.
Demonstrated expertise in recommending and validating data protections and testing security controls for complex systems.
Track record of effective communication and collaboration throughout the RMF cybersecurity lifecycle with engineering, cybersecurity, business, and customer stakeholders.
Possession of one or more relevant cybersecurity certifications, such as CISSP, CASP, or Security+.
Experience with United States Intelligence Community (IC) system cybersecurity processes and tools.
Background in establishing or operating Security Operations Center (SOC) functions, including use of tools such as Splunk or CloudWatch.
Hands-on experience with AWS security services, such as Security Hub and GuardDuty, to enhance cloud security monitoring and compliance.
Experience serving as an ISSE on a DevSecOps team through multiple software releases, integrating security into continuous delivery pipelines.
Familiarity with system security tools such as Wiz or eMASSter for posture assessment and compliance tracking.
Knowledge of CIS benchmarks and other industry security standards, and the ability to apply them to system hardening and configuration.
Exposure to penetration testing, fuzz testing, and dynamic application security testing (DAST) tools and techniques, with the ability to interpret results and support remediation.