Security Engineer II

Paragon Technology Group, IncScott AFB, IL
$80,000 - $85,000Onsite

About The Position

Paragon is recruiting for a Security Engineer II to work on the PEO-T contract for USTRANSCOM. This role involves reviewing evolving NIST requirements to support risk assessment activities, preparing detailed specifications for cybersecurity remediation, and collaborating with government customers on POA&Ms and risk acceptance. The engineer will ensure secure coding practices are implemented and followed.

Requirements

  • 1-3 years relevant experience
  • Experience reviewing vulnerability scans using SAST (Static Application Security Testing) tools, analyze outputs to identify vulnerabilities, and recommend mitigation and remediation actions
  • Knowledge of multiple programming languages (e.g., Java, C#, Python, .NET, SQL)
  • Experience with threat modeling and presenting findings/recommendations to lead stakeholders.
  • Thorough understanding of CI/CD pipeline components, containerization technologies (e.g., Kubernetes, Docker, etc.,) and microservices architecture.
  • In-depth knowledge of critical application security vulnerabilities and OWASP Top 10
  • Experience with following static code analysis tools: SonarSource, OpenText SAST, and TruffleHog.
  • In-depth knowledge of DevSecOps practices and principles
  • Solid understanding of system and network security, authentication protocols, and cryptography.
  • Ability to communicate with development teams on mitigation and remediation of vulnerabilities and security control implementation.
  • Ability to work in a fast-paced environment and possess excellent communication skills.
  • Experience with security lockdown and/or hardening of servers and network devices
  • Possess skills to conduct Technical Reviews of Development Contractor produced security deliverables
  • Ability to coordinate with developers, vendors, and other government organizations/agencies to assess security engineering issues
  • Experience participating in Technical Interchange Meetings on a wide range of PMO security engineering topics
  • Experience providing support to ensure PMO systems are designed, developed, and deployed in accordance with applicable Executive Orders, Federal Policy, DOW regulations, USTRANSCOM requirements, and commercial best practice
  • Experience recommending changes to network and security architecture to improve security posture and meet operational performance requirements
  • Experience supporting operational security activities (e.g., researching coding languages, vulnerabilities associated with secure coding practices, etc.)
  • Experience supporting the Customer through critical review of documented DISA STIG/SRGs (e.g., Application Security and Development) and ingesting them in the government-supplied tools to support risk assessment of the NIST controls.
  • Active Secret Clearance
  • Active IAM II Certification in Good Standing (e.g., CGRC (formerly CAP), Security X (formerly CASP+CE), CISM, CISSP (or associate), GSLC, CCISO)
  • Bachelor’s in Computer Science or Cybersecurity or equivalent

Nice To Haves

  • Success in this role is demonstrated by clearly defined, traceable requirements that reflect validated operational needs; well-facilitated stakeholder forums that drive timely decisions; and functional designs that enable development teams to deliver compliant, mission-aligned capabilities.
  • The Analyst is trusted by government leadership as a reliable integrator across Services, Agencies, and functional domains.

Responsibilities

  • Reviews evolving NIST requirements to support risk assessment activities associated with the affiliated system requirements and specifications.
  • Prepares detailed specifications from which cybersecurity deficiencies identified during risk assessment will be mitigated/remediated and conducts follow-up risk assessment to ensure proper secure coding practices are being built-in/enforced to the greatest extent possible.
  • Collaborates closely with government customers to develop appropriate POA&Ms and support risk acceptance activities as needed to support risk management processes.
  • Conducts Technical Reviews of Development Contractor produced security deliverables.
  • Coordinates with developers, vendors, and other government organizations/agencies to assess security engineering issues.
  • Participates in Technical Interchange Meetings on a wide range of PMO security engineering topics.
  • Provides support to ensure PMO systems are designed, developed, and deployed in accordance with applicable Executive Orders, Federal Policy, DOW regulations, USTRANSCOM requirements, and commercial best practice.
  • Recommends changes to network and security architecture to improve security posture and meet operational performance requirements.
  • Supports operational security activities (e.g., researching coding languages, vulnerabilities associated with secure coding practices, etc.).
  • Supports the Customer through critical review of documented DISA STIG/SRGs (e.g., Application Security and Development) and ingesting them in the government-supplied tools to support risk assessment of the NIST controls.
  • Reviews vulnerability scans using SAST (Static Application Security Testing) tools, analyze outputs to identify vulnerabilities, and recommend mitigation and remediation actions.
  • Conducts threat modeling and presenting findings/recommendations to lead stakeholders.
  • Communicates with development teams on mitigation and remediation of vulnerabilities and security control implementation.
  • Performs security lockdown and/or hardening of servers and network devices.
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service