yoinka

Cybersecurity Software Engineer

General Dynamics

Scottsdale, AZMid$112.9k – $125.3k/yrClearance required
Sign in to applyVerified 1h ago
Location
Scottsdale, AZ
Work model
On-Site
Level
Mid
Salary
$112.9k – $125.3k/yr

Skills

AnsibleCI/CDCybersecurityDockerGitJavaKubernetesLinuxPythonRust

About this role

Basic Qualifications Bachelor's degree in Software Engineering, or related Science, Technology, Engineering or Mathematics field, plus a minimum of 5 years of relevant experience; or Master's degree, plus 3 years relevant experience.

CLEARANCE REQUIREMENTS: Ability to obtain a Department of Defense Secret security clearance is required at time of hire. Applicants selected will be subject to a U.S. Government security investigation and must meet eligibility requirements for access to classified information. Due to the nature of work performed within our facilities, U.S. citizenship is required. Responsibilities for this Position What You’ll Do

Own the current development and execution of the program vulnerability management process across the entire program and integrating AI into each step of the way

Execute and analyze vulnerability scan results using DISA ACAS and Anchore Grype

Conduct remediation efforts and verifying vulnerabilities are addressed in patched systems

Conduct static and dynamic code analysis using industry standard tools to detect security weaknesses and inform remediation efforts

Perform software dependency management, including tracking, updating, and assessing third-party components for known vulnerabilities

Generate and maintain software bills of materials (SBOM) for supporting supply chain risk management and vulnerability tracking

Recommend and implement configuration and hardening remediation for systems and applications to comply with US Govt, Industry, or Vendor guidance

Produce and maintain the program’s Plan of Action and Milestones (POAM) to include vulnerabilities and compliance findings

Produce & deliver security artifacts (Body of Evidence) that directly support the assessment of systems and applications being accredited

Build and maintain security tools through scripting, containers, CI/CD pipelines, and other automation

Produce and deliver security artifacts of findings with concise description of the issue, supporting evidence, reference material, and recommended mitigations

Monitor emerging threats, CVEs, and evolving security best practices and apply findings to supported technologies and program security posture

Develop and execute of security test plans, automated security tests, and verification and validation activities

Develop technical skills and cybersecurity expertise through on-the-job experience, mentorship, and cross-training with senior engineers

Skills you’ll bring

Proficiency in one or more languages such as C/C++, Java, Python, or Rust.

Practical experience working in Linux environments (preferably PitBull), including command-line proficiency and familiarity with OS-level security controls

Proficiency in DISA Security Technical Implementation Guides (STIGs) including nomenclature, tooling, and hardening

Proficiency with security testing and vulnerability management tooling including SAST, DAST, SCA, and container scanning, with hands-on experience using tools such as SonarQube, Fortify, OpenSCAP, Syft, Grype, ACAS

Proficiency of secure software development lifecycle (SSDLC) principles, practices, and common application-security vulnerabilities

Experience utilizing security frameworks and standards such as NIST, RMF, OWASP, CWE, CVE, STIGs, OVAL, CVSS, or secure coding standards

Experience supporting system accreditation and authorization activities for RMF and NCDSMO assessments

Proficiency applying NIST SP 800-53 Security Controls, overlays, and tailoring guidance to support system security plans and authorization packages

Experience using agentic or generative AI tools to develop, analyze, or automate solutions for cybersecurity problems

Experience with containers such as Podman (preferred), Docker, Kubernetes.

Experience with Gitlab and CI/CD pipelines ISC² CISSP desired; willing to pursue certification over time

Preferred Qualifications

Familiarity with Cross Domain Solutions, NCDSMO Raise the Bar, and other NCDSMO CDS

Listing verified 1h ago. Applications go through the company's official careers site.

← Back to Yoinka

Cybersecurity Software Engineer at General Dynamics, Scottsdale, AZ | Yoinka