Senior Cyber Software Engineer

SAICHuntsville, AlabamaOn-siteFull-timeSenior, 5–8 yearsListed 49 minutes ago

Apply now

About this role

SAIC has an immediate need for a Senior Cyber Software Engineer to support the Combat Capabilities Development Command (DEVCOM) Aviation & Missile Center (AvMC) Software, Simulation, Systems Engineering & Integration Directorate (S3I) onsite at Redstone Arsenal in Huntsville, AL.

This role bridges the gap between software engineering and cybersecurity. The candidate will be responsible for the security architecture, secure coding, static/dynamic code analysis, and vulnerability remediation for embedded and application software across the full software development lifecycle. Working directly within an Agile/Scrum team, the candidate will ensure military systems meet rigorous DoD cybersecurity requirements (such as DISA STIGs/SRGs and RMF standards) while actively contributing to modern continuous integration and automated software delivery pipelines.

Key Responsibilities & Job Duties

- Secure Software Development & Engineering: Participate in the full lifecycle design, coding, testing, and integration of secure embedded and application software for military systems using C/C++ and Object-Oriented methodologies.
- Static & Dynamic Code Analysis: Perform, analyze, and track static and dynamic code analysis scan results (e.g., Parasoft, Coverity, Fortify) to identify vulnerabilities, eliminate security flaws, and guide development remediation efforts.
- Security Control Implementation & Hardening: Work with cross-functional software teams to implement and automate technical security controls, including DISA STIGs, SRGs, and industry best practice hardening guidelines across Linux, RTOS, and application baselines.
- Security Code & Architecture Reviews: Evaluate software requirements, system design changes, and proposed merge requests for security impact to determine authorization and risk mitigation.
- CI/CD & Pipeline Security (DevSecOps): Integrate automated security testing and compliance checks within CI/CD pipelines (e.g., Microsoft Azure DevOps, Git).
- Vulnerability Scanning & Remediation: Analyze vulnerability scan outputs (such as ACAS/Nessus) to develop and implement code- or configuration-level remediation plans.
- RMF & Artifact Support: Assist in updating Risk Management Framework (RMF) artifacts, including software/firmware inventories, interface specifications, and Ports, Protocols, and Services Management (PPSM) documentation.
- Cross-Discipline Collaboration: Actively participate in Agile/Scrum ceremonies, technical interchange meetings, and hardware/software design reviews alongside Systems, Cyber, Safety, Operations, and Test teams.

Education & Experience:

- Bachelor’s degree in Computer Science, Software Engineering, Cybersecurity, Computer Engineering, or a related technical discipline with five (5) to nine (9) years of related experience; Additional six(6) years’ equivalent experience may be considered in lieu of a degree per contract requirements.

Clearance Requirements:

- Clearance: Must possess an active DoD Secret security clearance.

Required Certifications:

- Certification: Must hold a current DoD 8570/8140 IAT Level II baseline certification (e.g., CompTIA Security+ CE , CySA+, or higher/equivalent).

Required Technical Skills:

- Strong hands-on programming experience with C/C++ or other Object-Oriented languages.
- Direct experience running and interpreting Static Code Analysis tools (e.g., Fortify, Coverity, Parasoft).
- Practical understanding of DISA STIGs/SRGs and application security hardening.
- Experience operating within an Agile/Scrum software development environment.
- Experience with source control, build systems, and CI/CD tools (e.g., Git, SVN, Microsoft Azure DevOps, Visual Studio ).
- Strong working knowledge of Linux operating environments.
- Strong written and verbal communication skills with the ability to interact effectively with customer stakeholders and multi-disciplinary teams.

Desired Skills & Experience:

- Experience with embedded systems, firmware, or Real-Time Operating Systems (RTOS) .
- Experience with Assured Compliance Assessment Solution ( ACAS ) or Nessus vulnerability scanners.
- Familiarity with DoD Risk Management Framework ( RMF ) processes and software accreditation artifact preparation.
- Experience writing unit tests, automated test fixtures, and security regression scripts.