Cybersecurity Assessment Engineer

Second Front SystemsWashington, DC
$125,000 - $140,000Remote

About The Position

Second Front Systems (2F) is seeking a Cybersecurity Assessment Engineer to build a modern, resilient operations function from the ground up. This role involves protecting the infrastructure and platforms that power mission-critical software for national security, ensuring a secure environment for defenders. The position requires learning new skills, researching vulnerabilities, assessing risk, solving problems, and contributing to a culture of diversity, innovation, and excellence. This role is crucial for the security of the cloud platform and customer applications. Note: Candidates must reside in one of our approved hiring hubs: DC/Maryland/Virginia, Raleigh/Durham/Chapel Hill, NC, Denver/Colorado Springs, CO, Dallas/Fort Worth, TX.

Requirements

  • Experience solving complex and sometimes ill-defined problems
  • Intermediate knowledge of DevSecOps tools and software development
  • Ability to create and implement incident response plans
  • Background in cybersecurity and understanding of vulnerability risk analysis
  • Hands-on experience assessing or securing services within AWS, Azure, or GCP, particularly within PaaS or Kubernetes-based environments
  • Proficient knowledge of NIST SP 800-37 (RMF) and NIST SP 800-53 rev 5 security controls
  • Deep understanding of the FedRAMP authorization process and Department of Defense (DoD) security standards
  • 3-5 years of relevant experience
  • Ability to attain DOD 8570 Baseline Certification for IAT II within 6 months of hire date (preferably CYSA+)

Nice To Haves

  • Extensive experience with Department of Defense DevSecOps practices, policies, and security
  • Experience with Docker, Gitlab, Kubernetes, Anchore, or other container scanning tools
  • Ability to write basic scripts (Python, Bash, etc.) to automate evidence collection or data parsing
  • Strong interest in matters of national security
  • Having a Secret clearance is preferred

Responsibilities

  • Review web application artifacts of customer developed applications and provide customer feedback
  • Serve as the primary cybersecurity team representative to software development and mission success teams
  • Assist with incident response plans for application outages or downtime
  • Conduct comprehensive assessments of cloud infrastructure, applications, and containerized environments to verify compliance with DISA STIGs, SRGs, and CIS Benchmarks
  • Author, review, and maintain security artifacts, including System Security Plans (SSP), Security Assessment Plans (SAP), and Security Assessment Reports (SAR)
  • Monitor and report on the ongoing effectiveness of security controls to ensure the platform maintains a robust and authorized security posture
  • Utilize automated scanning suites (e.g., Anchore, Trivy, Tenable) to identify vulnerabilities, distinguish true positives, and provide actionable remediation guidance to dev teams
  • Implement and manage technical workflows for SBOMs (Software Bill of Materials) to support modern, continuous authorization standards
  • Partner with DevOps and Software Engineering teams to translate complex NIST 800-53 controls into implementable technical requirements

Benefits

  • Competitive Salary
  • 100% Healthcare, vision and dental coverage
  • 401(k) + 3% company contribution
  • Wellness perks (Fitness classes, mental health resources)
  • Equity incentive plan
  • Tech + office supplies stipend
  • Annual professional development stipend
  • Flexible paid time off + federal holidays off
  • Parental leave
  • Work from anywhere
  • Referral Bonus
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service