About this role
company
About Zaden Technologies, Inc.
Join Zaden Technologies on our mission to simplify the delivery and improve the utility of software products for our customers. At Zaden, we believe that our employees are our greatest assets. We hire the right candidates with the right skill sets who fit our culture of customer obsession, innovation, and continuous learning. We are our customer’s biggest advocate and we are looking for like-minded individuals who encompass these same ideals. It is important to us to offer you competitive pay and comprehensive benefits with opportunities that match your life and propel your career!
role
Zaden Technologies is looking for a Cybersecurity Engineer with a strong ISSO background who's ready to grow into the DevOps side of security. You'll keep the systems you support secure and authorized by managing RMF packages, running continuous monitoring, hardening environments and driving vulnerabilities to closure. You'll also work alongside our DevSecOps engineers to learn how security gets built into pipelines, containers and cloud infrastructure, and you'll help us replace manual compliance work with automation. If you're a hands-on security professional who's curious about automation and excited to expand your technical toolkit, we'd love to help you grow as we automate a smarter future.
Role Responsibilities:
- Perform ISSO duties for assigned systems, maintaining their security posture throughout the RMF lifecycle
- Develop and maintain authorization artifacts, including System Security Plans, POA&Ms, risk assessments and incident response plans
- Implement and validate security controls, and support assessors through the authorization process
- Conduct vulnerability scanning, audit log review and STIG compliance checks, and work with system owners to remediate findings
- Harden operating systems, applications and network components to STIG and SRG baselines
- Collaborate with DevSecOps engineers to integrate security tooling into CI/CD pipelines and translate control requirements into technical solutions
- Learn and apply DevOps practices such as containerization, Infrastructure-as-Code and scripting to automate compliance evidence collection
- Identify repeatable manual security tasks and work with the team to automate them
- Investigate and document security incidents, and report findings to leadership and stakeholders
- Keep up with emerging threats and evolving cybersecurity policy, and recommend improvements to Zaden's security practices
Required Qualifications:
- U.S. Citizenship and active security clearance (minimum secret)
- 3+ years of cybersecurity experience, including hands-on work as an ISSO or in an equivalent information assurance role
- Working knowledge of the Risk Management Framework (RMF) and NIST SP 800-53 security controls
- Experience preparing and maintaining authorization packages, including SSPs and POA&Ms
- Experience with vulnerability scanning and compliance tools such as ACAS/Nessus, SCAP Compliance Checker or STIG Viewer
- Hands-on experience hardening Linux or Windows systems
- Strong written communication skills for security documentation and reporting
- A genuine interest in learning DevOps tools and practices, and the motivation to build those skills on the job
- DoD 8140/8570 IAT Level II certification (e.g., CompTIA Security+) or ability to obtain within 6 months of hire
Preferred Qualifications:
- Experience with eMASS or similar GRC platforms
- Exposure to CI/CD tools such as GitLab CI, GitHub Actions or Jenkins
- Exposure to containers or orchestration tools such as Docker or Kubernetes
- Basic scripting experience in Bash, Python or PowerShell
- Familiarity with cloud platforms such as AWS or Azure and their native security services
- Experience with SIEM platforms such as Splunk or Elastic
- Familiarity with zero trust architecture principles
- Advanced certification such as CISSP, CISM or CASP+
