Cybersecurity Engineer - DSOP

Posted Yesterday
Be an Early Applicant
2 Locations
In-Office
Expert/Leader
Security
The Role
Build and operate secure DevSecOps pipelines using SAST, DAST, container scanning, SBOM/SCA, artifact validation, and vulnerability gates. Produce RMF/cATO evidence, support secure coding compliance, drive CWE/CVE remediation, validate rollback readiness, and help developers adopt secure-by-default CI/CD automation across cloud and mission environments.
Summary Generated by Built In

SAIC is a trusted leader in delivering advanced command and control capabilities across the Department of the Air Force. We bring deep expertise in engineering, securing, and deploying cutting-edge technologies that support mission-critical operations. In partnership with the Assistant Secretary of the Air Force for Acquisition, Technology, and Logistics, SAIC supports programs that unify data, sensors, mission applications, cloud-based services, and emerging AI-enabled automation. These efforts empower warfighters with a decisive edge, transforming complex, multidomain information into fast, clear, and actionable decisions when it matters most. As part of this team, you will help accelerate the integration, testing, security, and transition of new capabilities into operational use. You will work side by side with operators, engineers, Capability Providers, and government teams to ensure every delivery strengthens mission readiness. This role offers the opportunity to directly shape how the Air Force sees, decides, and acts across all domains—making a tangible and immediate impact on warfighter effectiveness.
The Cybersecurity Engineer (DSOP) builds and operates a secure DSOP pipeline to enable rapid, safe development and onboarding of Capability Provider applications. This role integrates automated SAST/DAST/container security and SBOM/SCA scanning, enforces secure coding gates, validates cyber artifacts, and ensures all pipeline evidence is routed to Infrastructure TO for Operational Baseline updates. The DSOP Engineer provides direct developer support, jointly participates in early DSOP/cloud design, and lays the foundation for secure-by-default CI/CD automation.

Job Duties include:

  • Build, enhance, and operate DSOP cyber pipeline stages (SAST, DAST, container scanning, SBOM/SCA).
  • Implement pipeline blocking rules for Critical/High vulnerabilities.
  • Integrate cyber validation tasks into CI/CD for multiple  environments.
  • Perform functional validation of CP/External artifacts when possible; deliver validated cyber outputs to Infrastructure TO.
  • Produce RMF/cATO‑ready cyber evidence (scan results, mitigation records, SBOM/SCA, logs).
  • Validate artifact integrity (image signing, checksum enforcement, provenance tracking).
  • Provide direct developer enablement: onboarding into DSOP tools, secure coding guidance, WHY‑based mentorship.
  • Review, categorize, and drive remediation of CWE/CVE findings across DSOPS, Cloud, CE, and CP teams.
  • Validate rollback readiness when cyber gates block promotion.
  • Partner with Cloud engineers on early pipeline/environment design and promote secure-by-default automation.  
Qualifications
  • Bachelors and nine (9) years or more experience; Masters and seven (7) years or more experience; PhD or JD and four (4) years or more experience.
  • US Citizenship.

Required Qualifications & Experience:

  • Hands on experience running automated SAST/DAST/container scans using Fortify, ZAP, Grype/Trivy or similar tools.
  • Experience documenting mitigations, reviewing CWE/CVE outputs, and validating secure coding practices. 
  • Proficiency with DevSecOps tooling (GitLab CI/CD, container registries, SBOM/SCA tools). 
  • Experience supporting secure coding compliance and vulnerability remediation. 
  • 8140 aligned certifications such as Security+, CISSP, CCSP, CASP+, or equivalent.

Desired Qualifications and Experience:

  • Experience supporting RMF/cATO pipelines—producing cyber evidence, aligning pipeline scans with SSP/POA&M updates. 
  • Background integrating secure DevSecOps automation across multi classification environments. 
  • Experience enabling developers by creating training, guidance, and best practice workflows.

Desired Skills and Certifications:

  • Deep experience with GitLab CI/CD, image signing, SBOM/SCA creation, and pipeline compliance validation. 
  • Familiarity with secure by design and shift left security principles embedded across DSOP automation. 
  • Strong communication habits—providing timely vector checks, developer friendly guidance, and clear evidence trails.
About UsSAIC® is a premier mission integrator focused on advancing the power of technology and innovation to serve and protect our world. Our robust portfolio of offerings across the defense, space, intelligence, and civilian markets includes secure high-end solutions in mission IT, enterprise IT, engineering services, and professional services. We integrate emerging technology, rapidly and securely, into mission critical operations that modernize and enable critical national imperatives.

We are approximately 23,000 strong; driven by mission, united by purpose, and inspired by opportunities. SAIC is an Equal Opportunity Employer. Headquartered in Reston, Virginia, SAIC has annual revenues of approximately $7.3 billion. For more information, visit saic.com. For ongoing news, please visit our newsroom.

Skills Required

  • Bachelor's degree and nine or more years of experience
  • Master's degree and seven or more years of experience
  • PhD or JD and four or more years of experience
  • US citizenship
  • Hands-on experience running automated SAST, DAST, and container scans using Fortify, ZAP, Grype, Trivy, or similar tools
  • Experience documenting mitigations, reviewing CWE/CVE outputs, and validating secure coding practices
  • Proficiency with DevSecOps tooling, GitLab CI/CD, container registries, and SBOM/SCA tools
  • Experience supporting secure coding compliance and vulnerability remediation
  • 8140-aligned certification such as Security+, CISSP, CCSP, CASP+, or equivalent
  • Experience supporting RMF/cATO pipelines and producing cyber evidence aligned with SSP/POA&M updates
  • Experience integrating secure DevSecOps automation across multi-classification environments
  • Experience creating developer training, guidance, and best-practice workflows
  • Deep experience with GitLab CI/CD, image signing, SBOM/SCA creation, and pipeline compliance validation
  • Familiarity with secure-by-design and shift-left security principles
  • Strong communication skills for developer guidance and clear evidence trails
Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
HQ: Stamford, CT
34,000 Employees

What We Do

Spectrum San Diego is a high tech security innovator, specializing in ultra-low-dose X-ray screening systems.

Similar Jobs

DFIN Logo DFIN

Service Delivery Associate

Fintech • Software
Remote or Hybrid
United States
1750 Employees

DFIN Logo DFIN

Service Delivery Associate

Fintech • Software
Remote or Hybrid
United States
1750 Employees

Comcast Logo Comcast

Account Executive

Digital Media • Information Technology • News + Entertainment
Remote or Hybrid
Virginia, USA
115000 Employees
52K-86K Annually

Samsara Logo Samsara

Mid-market Account Executive

Artificial Intelligence • Cloud • Computer Vision • Hardware • Internet of Things • Software
Easy Apply
Remote or Hybrid
United States
4000 Employees
152K-190K Annually

Similar Companies Hiring

Closinglock Thumbnail
Fintech • Real Estate • Security • Software • Financial Services • Cybersecurity • PropTech
Austin, TX
110 Employees
Credal.ai Thumbnail
Software • Security • Productivity • Machine Learning • Artificial Intelligence
Brooklyn, NY
Milestone Systems Thumbnail
Artificial Intelligence • Security • Software • Analytics • Big Data Analytics
Lake Oswego, OR
1500 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account