Cybersecurity Engineer - DSOP

SAICChantilly, VA

About The Position

The Cybersecurity Engineer (DSOP) builds and operates CMCC’s secure DSOP pipeline to enable rapid, safe development and onboarding of Capability Provider applications. This role integrates automated SAST/DAST/container security and SBOM/SCA scanning, enforces secure coding gates, validates cyber artifacts, and ensures all pipeline evidence is routed to Infrastructure TO for Operational Baseline updates. The DSOP Engineer provides direct developer support, jointly participates in early DSOP/cloud design, and lays the foundation for secure-by-default CI/CD automation.

Requirements

  • Build, enhance, and operate DSOP cyber pipeline stages (SAST, DAST, container scanning, SBOM/SCA).
  • Implement pipeline blocking rules for Critical/High vulnerabilities.
  • Integrate cyber validation tasks into CI/CD for multiple environments.
  • Perform functional validation of CP/External artifacts when possible; deliver validated cyber outputs to Infrastructure TO.
  • Produce RMF/cATO‑ready cyber evidence (scan results, mitigation records, SBOM/SCA, logs).
  • Validate artifact integrity (image signing, checksum enforcement, provenance tracking).
  • Provide direct developer enablement: onboarding into DSOP tools, secure coding guidance, WHY‑based mentorship.
  • Review, categorize, and drive remediation of CWE/CVE findings across DSOPS, Cloud, CE, and CP teams.
  • Validate rollback readiness when cyber gates block promotion.
  • Partner with Cloud engineers on early pipeline/environment design and promote secure-by-default automation.

Responsibilities

  • Build, enhance, and operate DSOP cyber pipeline stages (SAST, DAST, container scanning, SBOM/SCA).
  • Implement pipeline blocking rules for Critical/High vulnerabilities.
  • Integrate cyber validation tasks into CI/CD for multiple environments.
  • Perform functional validation of CP/External artifacts when possible; deliver validated cyber outputs to Infrastructure TO.
  • Produce RMF/cATO‑ready cyber evidence (scan results, mitigation records, SBOM/SCA, logs).
  • Validate artifact integrity (image signing, checksum enforcement, provenance tracking).
  • Provide direct developer enablement: onboarding into DSOP tools, secure coding guidance, WHY‑based mentorship.
  • Review, categorize, and drive remediation of CWE/CVE findings across DSOPS, Cloud, CE, and CP teams.
  • Validate rollback readiness when cyber gates block promotion.
  • Partner with Cloud engineers on early pipeline/environment design and promote secure-by-default automation.
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service