Cybersecurity Assessment Engineer at Second Front Systems | Torre

Cybersecurity Assessment Engineer

You will secure mission-critical defense software by building resilient cybersecurity operations.
Emma highlights
This highlight was written by Emma’s AI. Ask Emma to edit it.
Full-time

Legal agreement: Employment

Compensation
USD125k - 140k/year
location_on
Remote (for United States residents)
Match
skeleton-gauges
You have opted out of job matches in .
To undo this, go to the 'Skills and Interests' section of your preferences.
Review preferences
Shared by
Emma of Torre.ai
2 days ago

Requirements and responsibilities


Second Front Systems (2F) is looking for a battle-tested, high-agency Cybersecurity Assessment Engineer to support our team.. We sit at the high-stakes intersection of defense tech and national security, and this role is about building a modern, resilient operations function from the ground up. You’ll be protecting the infrastructure and platforms that power mission-critical software for the free world—ensuring our nation’s defenders have the secure environment they need to move fast.At 2F, we pair a startup’s bias for action with a relentless sense of purpose. As a Cybersecurity Assessment Engineer at Second Front Systems, you will help ensure that Game Warden maintains a strong security posture. You will work hand-in-hand with the DevOps Engineering and Mission Success teams to oversee the software vulnerability scanning process, review vulnerability scan results, assist the customers in understanding those results, and make approval recommendations for vulnerabilities that can't be immediately resolved. This role will require learning new things like researching identified vulnerabilities, assessing risk, solving big problems, speaking your mind, and contributing to a culture of diversity, innovation, and excellence. This role is key to the security of our cloud platform and of the customer applications running on it.What You'll DoReview web application artifacts of customer developed applications and provide customer feedbackPrimary face of the cybersecurity team to software development and mission success teamsAssist with incident response plans to respond to application outages or downtimeTechnical Security Validation: Conduct comprehensive assessments of cloud infrastructure, applications, and containerized environments to verify compliance with DISA STIGs, SRGs, and CIS Benchmarks.Authorization Lifecycle Management: Author, review, and maintain high-quality security artifacts, including System Security Plans (SSP), Security Assessment Plans (SAP), and Security Assessment Reports (SAR).Continuous Monitoring (ConMon): Monitor and report on the ongoing effectiveness of security controls, ensuring the platform maintains a robust and authorized security posture.Vulnerability & Risk Analysis: Utilize automated scanning suites (e.g., Anchore, Trivy, Tenable) to identify vulnerabilities, distinguish true positives, and provide actionable remediation guidance to dev teams.Supply Chain Security: Implement and manage technical workflows for SBOMs (Software Bill of Materials) to support modern, continuous authorization standards.Cross-Functional Collaboration: Partner with DevOps and Software Engineering teams to translate complex NIST 800-53 controls into implementable technical requirements.What You BringExperience solving complex and sometimes ill-defined problemsIntermediate knowledge of DevSecOps tools and software developmentAbility to create and implement incident response plansBackground in cybersecurity and understanding of vulnerability risk analysisHands-on experience assessing or securing services within AWS, Azure, or GCP, particularly within PaaS or Kubernetes-based environments.Proficient knowledge of NIST SP 800-37 (RMF) and NIST SP 800-53 rev 5 security controlsDeep understanding of the FedRAMP authorization process and Department of Defense (DoD) security standards.3-5 years of relevant experienceAbility to attain DOD 8570 Baseline Certification for IAT II within 6 months of hire date (preferably CYSA+)PreferredExtensive experience with Department of Defense DevSecOps practices, policies, and securityExperience with Docker, Gitlab, Kubernetes, Anchore, or other container scanning toolsAbility to write basic scripts (Python, Bash, etc.) to automate evidence collection or data parsingStrong interest in matters of national securityHaving a Secret clearance is preferredThe base salary for this position will fall between $125,000-140,000 Your ultimate compensation will be determined by professional background, technical proficiency, seniority, and regional cost factors. Furthermore, this opportunity includes potential eligibility for equity awards and discretionary bonuses, rounding out a comprehensive total rewards offering.Success at 2F Looks Like:Viewing obstacles as opportunities for growthHaving a bias toward action and tangible, measurable resultsStriving to be both compassionate and direct with your feedbackBeing team-oriented and inclusive with your actionPerks & Benefits:This role is a full time position. As a public benefit corporation, we’re a team of purpose-driven trailblazers transforming the future of U.S. national security. We hire the best to do their best and, as such, we are committed to providing the perks and benefits you need to be successful—both in- and outside the workplace.We offer you:Competitive Salary100% Healthcare, vision and dental coverage401(k) + 3% company contributionWellness perks (Fitness classes, mental health resources)Equity incentive planTech + office supplies stipendAnnual professional development stipendFlexible paid time off + federal holidays offParental leaveWork from anywhereReferral BonusVisit our careers page to learn more.Who We Are:Second Front Systems (2F) is a public-benefit software company powering software for the free world. We eliminate the friction that slows innovation, enabling faster, more secure development and deployment of software across government and regulated networks. Built by national security veterans and backed by top-tier venture capital, our platform is trusted by the world’s leading organizations to cut deployment timelines from years to weeks. We move fast, solve hard problems, and deliver trusted capabilities where they’re needed most. Our work strengthens global security and gives the United States and its allies a lasting competitive advantage. Learn more at secondfront.com.