Cybersecurity Software Engineer
General Dynamics
- Location
- Scottsdale, AZ
- Work model
- On-Site
- Level
- Mid
- Salary
- $112.9k – $125.3k/yr
Skills
About this role
Basic Qualifications Bachelor's degree in Software Engineering, or related Science, Technology, Engineering or Mathematics field, plus a minimum of 5 years of relevant experience; or Master's degree, plus 3 years relevant experience.
CLEARANCE REQUIREMENTS: Ability to obtain a Department of Defense Secret security clearance is required at time of hire. Applicants selected will be subject to a U.S. Government security investigation and must meet eligibility requirements for access to classified information. Due to the nature of work performed within our facilities, U.S. citizenship is required. Responsibilities for this Position What You’ll Do
Own the current development and execution of the program vulnerability management process across the entire program and integrating AI into each step of the way
Execute and analyze vulnerability scan results using DISA ACAS and Anchore Grype
Conduct remediation efforts and verifying vulnerabilities are addressed in patched systems
Conduct static and dynamic code analysis using industry standard tools to detect security weaknesses and inform remediation efforts
Perform software dependency management, including tracking, updating, and assessing third-party components for known vulnerabilities
Generate and maintain software bills of materials (SBOM) for supporting supply chain risk management and vulnerability tracking
Recommend and implement configuration and hardening remediation for systems and applications to comply with US Govt, Industry, or Vendor guidance
Produce and maintain the program’s Plan of Action and Milestones (POAM) to include vulnerabilities and compliance findings
Produce & deliver security artifacts (Body of Evidence) that directly support the assessment of systems and applications being accredited
Build and maintain security tools through scripting, containers, CI/CD pipelines, and other automation
Produce and deliver security artifacts of findings with concise description of the issue, supporting evidence, reference material, and recommended mitigations
Monitor emerging threats, CVEs, and evolving security best practices and apply findings to supported technologies and program security posture
Develop and execute of security test plans, automated security tests, and verification and validation activities
Develop technical skills and cybersecurity expertise through on-the-job experience, mentorship, and cross-training with senior engineers
Skills you’ll bring
Proficiency in one or more languages such as C/C++, Java, Python, or Rust.
Practical experience working in Linux environments (preferably PitBull), including command-line proficiency and familiarity with OS-level security controls
Proficiency in DISA Security Technical Implementation Guides (STIGs) including nomenclature, tooling, and hardening
Proficiency with security testing and vulnerability management tooling including SAST, DAST, SCA, and container scanning, with hands-on experience using tools such as SonarQube, Fortify, OpenSCAP, Syft, Grype, ACAS
Proficiency of secure software development lifecycle (SSDLC) principles, practices, and common application-security vulnerabilities
Experience utilizing security frameworks and standards such as NIST, RMF, OWASP, CWE, CVE, STIGs, OVAL, CVSS, or secure coding standards
Experience supporting system accreditation and authorization activities for RMF and NCDSMO assessments
Proficiency applying NIST SP 800-53 Security Controls, overlays, and tailoring guidance to support system security plans and authorization packages
Experience using agentic or generative AI tools to develop, analyze, or automate solutions for cybersecurity problems
Experience with containers such as Podman (preferred), Docker, Kubernetes.
Experience with Gitlab and CI/CD pipelines ISC² CISSP desired; willing to pursue certification over time
Preferred Qualifications
Familiarity with Cross Domain Solutions, NCDSMO Raise the Bar, and other NCDSMO CDS