Jobs and Careers
AG
Software Assurance Engineer
Agile DefenseAlexandria, United Statesfull_timeVerifiedPosted 25 Oct 2024
About the role
At Agile Defense we know that action defines the outcome and new challenges require new solutions. That’s why we always look to the future and embrace change with an unmovable spirit and the courage to build for what comes next.
Our vision is to bring adaptive innovation to support our nation's most important missions through the seamless integration of advanced technologies, elite minds, and unparalleled agility—leveraging a foundation of speed, flexibility, and ingenuity to strengthen and protect our nation’s vital interests.
Requisition #: 642Job Title: Software Assurance EngineerLocation: REMOTE - Alexandria, VAClearance Level: Active DoD - Public Trust
Required Certification(s): · CISSP (or equivalent), GCSA or possess a willingness to pursue certifications after hire
SUMMARY The United States Patent and Trademark Office (USPTO), Cybersecurity Division, has a requirement to establish a white-box testing capability within USPTO by adding contractor expertise to engage with existing system and product owners with the goal of supplementing companion effort penetration testing services. This effort will enhance data security protections by evaluating USPTO systems, with a specific focus on sensitive Business Impact Information (BII) systems that contain Intellectual Property (IP) and PII.
A successful candidate will have verifiable experience in white-box testing, secure coding, static code analysis, dynamic application security testing, architecture security, Application Programmatic Interface (API) validation and communication skills. Strong technical capabilities, and an understanding of in-scope systems to the organization with respect to operational impact, is important as a key function of the role is to work closely with defensive partners.
JOB DUTIES AND RESPONSIBILITIES · Perform code reviews to identify flaws in the development of custom applications that handle sensitive IP data, particularly those involving complex data transformations, encryption, or proprietary algorithms. · Drive configuration auditing through review of system and network configurations for misconfigurations or insecure settings that could lead to exploitation. · Execute access controls to validate and assess whether internal access controls effectively enforce the principle of least privilege and prevent unauthorized access to IP data. · Generate reports that highlight security weaknesses uncovered during white-box testing and provide actionable remediation steps. · Ensure that critical issues are resolved before new software releases or system updates go live, especially if they affect data-sharing processes or BII systems. · Research, test, build, and coordinate the conversion and/or continuous integration pipelines and toolchains based on client requirements. · Design and develop new software products or major enhancements to existing software to support security operations. · Address problems of systems integration, compatibility, automation and orchestrations. · Assesses cloud security architectures and provide recommendations to improve overall infrastructure security and methods to automate security testing of applications moving through the CI/CD pipeline.
QUALIFICATIONS Required Certifications · CISSP (or equivalent), GCSA or possess a willingness to pursue certifications after hire
Education, Background, and Years of Experience · Bachelor’s degree/University degree or equivalent experience
ADDITIONAL SKILLS & QUALIFICATIONS Required Skills · 1+ years of relevant experience with most of the requirements below · Security Architecture reviews · DevSecOps CI/CI pipelines standards and best practices · Application Programming Interface (API) development and testing · Extensive experience working with White-Box testing methodologies and techniques · Static Application Security Testing tools. e.g., SonarQube, Veracode, Fortify · Dynamic Application Security Testing tools. e.g., OpenText Fortify WebInspect, Veracode, Invicti · Experience leveraging the MITRE ATT&CK Framework · Vulnerability Assessment tools. e.g., Nessus, Qualys, Rapid7 · Exploitation frameworks, e.g., Metasploit, CANVAS, Core Impact · Deep understanding of OSI model · Security devices, i.e. Firewalls, VPN, AAA systems · OS Security. e.g. Unix/Linux, Windows, OSX · Understanding of common protocols. e.g. HTTP, LDAP, SMTP, DNS · Web application infrastructure. e.g. Application Servers, Web Servers, Databases · Demonstrated ability to collaborate with a variety of analytical groups and service delivery organizations · Advanced analytical and problem-solving skills · Consistently demonstrates clear and concise written and verbal communication · Proficient in interpreting and applying policies, standards and procedures · Demonstrated ability to remain unbiased in a diverse working environment
Preferred Skills · Web development and programming languages. e.g. Python, Perl, Ruby,
Our vision is to bring adaptive innovation to support our nation's most important missions through the seamless integration of advanced technologies, elite minds, and unparalleled agility—leveraging a foundation of speed, flexibility, and ingenuity to strengthen and protect our nation’s vital interests.
Requisition #: 642Job Title: Software Assurance EngineerLocation: REMOTE - Alexandria, VAClearance Level: Active DoD - Public Trust
Required Certification(s): · CISSP (or equivalent), GCSA or possess a willingness to pursue certifications after hire
SUMMARY The United States Patent and Trademark Office (USPTO), Cybersecurity Division, has a requirement to establish a white-box testing capability within USPTO by adding contractor expertise to engage with existing system and product owners with the goal of supplementing companion effort penetration testing services. This effort will enhance data security protections by evaluating USPTO systems, with a specific focus on sensitive Business Impact Information (BII) systems that contain Intellectual Property (IP) and PII.
A successful candidate will have verifiable experience in white-box testing, secure coding, static code analysis, dynamic application security testing, architecture security, Application Programmatic Interface (API) validation and communication skills. Strong technical capabilities, and an understanding of in-scope systems to the organization with respect to operational impact, is important as a key function of the role is to work closely with defensive partners.
JOB DUTIES AND RESPONSIBILITIES · Perform code reviews to identify flaws in the development of custom applications that handle sensitive IP data, particularly those involving complex data transformations, encryption, or proprietary algorithms. · Drive configuration auditing through review of system and network configurations for misconfigurations or insecure settings that could lead to exploitation. · Execute access controls to validate and assess whether internal access controls effectively enforce the principle of least privilege and prevent unauthorized access to IP data. · Generate reports that highlight security weaknesses uncovered during white-box testing and provide actionable remediation steps. · Ensure that critical issues are resolved before new software releases or system updates go live, especially if they affect data-sharing processes or BII systems. · Research, test, build, and coordinate the conversion and/or continuous integration pipelines and toolchains based on client requirements. · Design and develop new software products or major enhancements to existing software to support security operations. · Address problems of systems integration, compatibility, automation and orchestrations. · Assesses cloud security architectures and provide recommendations to improve overall infrastructure security and methods to automate security testing of applications moving through the CI/CD pipeline.
QUALIFICATIONS Required Certifications · CISSP (or equivalent), GCSA or possess a willingness to pursue certifications after hire
Education, Background, and Years of Experience · Bachelor’s degree/University degree or equivalent experience
ADDITIONAL SKILLS & QUALIFICATIONS Required Skills · 1+ years of relevant experience with most of the requirements below · Security Architecture reviews · DevSecOps CI/CI pipelines standards and best practices · Application Programming Interface (API) development and testing · Extensive experience working with White-Box testing methodologies and techniques · Static Application Security Testing tools. e.g., SonarQube, Veracode, Fortify · Dynamic Application Security Testing tools. e.g., OpenText Fortify WebInspect, Veracode, Invicti · Experience leveraging the MITRE ATT&CK Framework · Vulnerability Assessment tools. e.g., Nessus, Qualys, Rapid7 · Exploitation frameworks, e.g., Metasploit, CANVAS, Core Impact · Deep understanding of OSI model · Security devices, i.e. Firewalls, VPN, AAA systems · OS Security. e.g. Unix/Linux, Windows, OSX · Understanding of common protocols. e.g. HTTP, LDAP, SMTP, DNS · Web application infrastructure. e.g. Application Servers, Web Servers, Databases · Demonstrated ability to collaborate with a variety of analytical groups and service delivery organizations · Advanced analytical and problem-solving skills · Consistently demonstrates clear and concise written and verbal communication · Proficient in interpreting and applying policies, standards and procedures · Demonstrated ability to remain unbiased in a diverse working environment
Preferred Skills · Web development and programming languages. e.g. Python, Perl, Ruby,
Apply for this role
Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.
Apply Now →Generate Application KitFree account required — sign up in 30s