Software Security Engineer
Sherpa 6About the role
Description
Job Title: Software Security Engineer
Job Location: Onsite (Hybrid) - Ft. Belvoir, VA
Job Type: Full time 40 hours
Travel Requirement: Up to 25%
Secret: Ability to Obtain and Maintain Top Secret
Job Description:
Sherpa 6 is seeking a talented Software Security Engineer to join our team and play a crucial role in maintaining the security and integrity of our systems and data. We build mission-critical systems for the Department of Defense (DoD) and other commercial customers.
The ideal candidate will have extensive experience managing security compliance, leading security assurance efforts, and developing and implementing robust security controls. They will possess a deep understanding of security documentation and accreditation workflows, with the ability to identify vulnerabilities and recommend effective remediation strategies. Additionally, they will have hands-on experience with software vulnerability scanning tools and integrating them into build pipelines, as well as a strong interest in staying up to date on emerging security threats and best practices.
Responsibilities:
- Manage security compliance efforts and ensure adherence to accreditation standards and regulatory requirements.
- Develop, configure, and integrate automation solutions for dynamic security validation and reporting.
- Lead security assurance activities, including risk assessments, security audits, and penetration testing.
- Interface with partner security teams and attend security events to understand and communicate current security posture.
- Develop and maintain security documentation, artifacts, and accreditation materials as required.
- Understand and navigate accreditation workflows to ensure compliance with relevant security frameworks.
- Identify security flaws and weaknesses in systems and applications and recommend appropriate mitigating controls or remediation measures.
- Conduct software vulnerability scans, analyze results, and prioritize/address security vulnerabilities.
- Stay informed about the latest security threats, vulnerabilities, and industry trends, and provide timely updates and recommendations.
- Collaborate with cross-functional teams to integrate automated security tasks, such as scans and documentation, into existing workflows and processes.
- Perform topical tracking of security matters, including vulnerability reports, security advisories, and patch management activities.
- Experience with the NIST Risk Management Framework (RMF)/ATO process, including developing and maintaining artifacts and providing expertise in strategies to meet compliance.
- Experience securing and monitoring cloud environments and cloud-hosted applications.
Requirements
Qualifications:
- 3+ years of experience managing security compliance efforts or developing security validation tools.
- Bachelor of Science Degree in Software Engineering, Computer Science, IT, or a related field.
- Experience developing and maintaining security documentation, accreditation artifacts, and compliance reports.
- Expertise in the NIST Risk Management Framework (RMF) and Authorization to Operate (ATO) processes, including developing and maintaining required artifacts.
- Proven ability to provide strategic guidance and expertise to ensure compliance with RMF/ATO requirements.
- Experience in leveraging innovative solutions to meet operational and regulatory standards.
- Hands-on experience with software vulnerability scanning tools.
- Ability to identify security vulnerabilities and recommend effective remediation strategies.
- Excellent analytical and problem-solving skills, with a keen attention to detail.
- Strong communication and interpersonal skills, with the ability to effectively collaborate with cross-functional teams.
- Must be a US citizen.
- Must pass a background check and drug screening.
Qualities of Exceptional Candidates:
- Certification(s) in relevant areas (e.g., CISSP, CISM, CEH).
- Experience developing and configuring solutions for integrating automated security tasks, such as scans and documentation, into CI/CD pipelines or IT workflows.
- Familiarity with penetration testing methodologies and tools.
- Knowledge of Linux operating systems and/or software development/programming skills.
- Azure cloud experience.
- Experience securing and monitoring cloud environments and cloud-hosted applications.
Apply for this role
Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.
Apply Now →Generate Application KitFree account required — sign up in 30s