What are the responsibilities and job description for the DevSecOps Software Assurance Specialist position at Sabel Systems Technology Solutions Llc?
Who We Are
Sabel Systems Technology Solutions, LLC is a leading solution provider and rapidly growing Information and Communications Technology Company specializing in innovative and agile Digital Engineering and Acquisition Technical Stack design, implementation, and support, Strategy and Policy Development, Financial Management, Software Solutions Development, Requirements Analysis and Training, to name a few. Our client base is mostly in the DoD Federal Government Contracting space and we also partner with prime Government Contractors such as Siemens, Booze Allen, McKinsey and have work in the commercial space as well. We provide clients with large business opportunities and training within our small business agility and people first culture. You will be joining a dynamic and highly motivated team with one goal: "Get quality and secure solutions in the customers hands as soon as possible.
Who We Need
Sabel Systems has the technology solutions to support cloud-based processes for Digital Engineering, enabling Digital Threads for, and Digital Twins of, complex weapon systems. Our DoD customers have urgent and persistent needs to address new capabilities of near-peer strategic competitors, and asymmetric threats from disruptive actors. We are seeking talented professionals to make real these engineering solutions, keeping our nation's security capabilities well ahead of all threats.
What Youll Do
Reasonable accommodations may be made to enable individuals with disabilities to perform the essential functions of this position.
As a DevSecOps Software Assurance Expert, you will play a pivotal role in ensuring the security and integrity of a CI/CD pipeline for Department of Defense (DoD) applications throughout their lifecycle. You will leverage your expertise in automated testing, secure development practices, and security mitigation to ensure that applications meet stringent DoD security requirements. You will work directly with development, testing, and security teams to automate security testing processes and ensure that DoD applications are fully compliant with the latest security standards and policies. This role requires experience in both software assurance and automated testing, with a deep understanding of DoD regulations and security frameworks.
Key Responsibilities:
Automated Security Testing and Integration:
o Implement and automate security testing frameworks within CI/CD pipelines to ensure security vulnerabilities are detected early in the development process.
o Design and configure automated tools for static and dynamic code analysis, vulnerability scanning, and penetration testing for DoD applications.
o Ensure that automated security tests are comprehensive and address specific security
risks related to DoD environments, such as confidentiality, integrity, and availability.
2. Compliance and Security Standards:
o Ensure compliance with DoD security standards and frameworks, such as the Risk Management Framework (RMF), NIST 800-53, and DISA STIGs.
o Develop security test plans and strategies to verify that applications meet specific security requirements and are compliant with federal regulations and DoD policies.
o Conduct security audits and assessments to validate the security posture of DoD applications.
3. Consulting and Collaboration:
o Collaborate closely with development teams, security experts, and project stakeholders to define and implement security testing requirements and best practices.
o Advise on secure software development practices and guide teams on implementing secure coding standards, code reviews, and vulnerability management.
o Provide expert advice on risk assessments, vulnerability remediation, and incident response strategies specific to DoD applications.
4. Continuous Improvement and Automation:
o Lead the automation of security testing processes to increase efficiency, reduce risk, and speed up development cycles.
o Identify and implement new tools and methodologies for enhancing automated security testing in DoD environments.
o Continuously monitor the security landscape and make improvements to automated testing frameworks based on emerging threats and vulnerabilities.
5. Documentation and Reporting:
o Create and maintain detailed documentation of security testing processes, test results, risk assessments, and compliance reports.
o Present findings, vulnerabilities, and remediation recommendations to technical and non-technical stakeholders, ensuring transparency and alignment with DoD objectives.
o Develop and deliver security awareness training for development teams on secure coding and automated security testing practices.
6. Security Tool Management:
o Manage and optimize security tools for automated testing, vulnerability scanning, and compliance monitoring, ensuring they meet DoD security and performance requirements.
o Stay up-to-date with new security testing technologies, frameworks, and industry trends that could benefit DoD application security assurance.
Job Qualifications
Required Qualifications
Bachelors degree in Computer Science, Cybersecurity, or a related field.
Proven experience in automated security testing for complex applications, preferably in DoD or government environments.
Expertise with security tools such as Fortify, SonarQube, Anchore, OWASP ZAP, and Nessus for static and dynamic analysis.
In-depth knowledge of DoD security standards (RMF, NIST 800-53, DISA STIGs) and experience with security compliance processes within DoD projects.
Strong understanding of secure coding practices and the ability to guide development teams in identifying and mitigating security vulnerabilities.
Experience with DevSecOps tools and practices, including CI/CD pipeline integration, Jenkins, GitLab, and container security.
Strong analytical and problem-solving skills with the ability to translate complex security challenges into practical solutions.
Excellent communication skills with the ability to engage with cross-functional teams, management, and external stakeholders to drive security initiatives.
Experience working in highly regulated environments and a strong understanding of the security and compliance requirements unique to the DoD.
Security certifications such as SEC , CISSP, CISM, or CEH are a plus.
Working Conditions:
Fast-paced, dynamic environment with frequent interactions with cross-functional teams.
Self-motivated for team engagement via a remote work environment.
Personal Development
Demonstrates the Sabel Values through own behaviors; sets clear priorities and aligns all activities; sets/achieves high personal standards for performance/conduct.
Communicates effectively in all directions; encourages innovation.
Recognizes and celebrates accomplishment; helps the team lead and/or adapt to change; encourages teaming/networking across the company.
Assists with defining project team requirements for projects within solution area.
Supervision: No direct reports
Career Path:
Opportunities for career growth into senior business analyst roles, product management, or project management for digital engineering solutions.
Minimum Qualifications
To perform this job successfully, an individual must be able to perform each essential duty satisfactorily. The requirements listed below are representative of the minimum knowledge, skill, and/or ability required.
- Problem Solving: Identifies and resolves problems in a timely manner; gathers and analyzes information skillfully; develops alternative solutions; works well in group problem solving situations; uses reason even when dealing with emotional topics.
- Written Communication: Writes clearly and informatively; edits work for spelling and grammar; varies writing style to meet needs; presents numerical data effectively; able to read and interpret written information.
- Ethics: Treats people with respect; keeps commitments; inspires the trust of others; works with integrity and ethically; upholds organizational values.
- Strategic Thinking: Develops strategies to achieve organizational goals; understands organization's strengths & weaknesses; analyzes market and competition; identifies external threats and opportunities; adapts strategy to changing conditions.
- Planning/Organizing: Prioritize and plans work activities; uses time efficiently; plans for additional resources; sets goals and objectives; organizes or schedules other people and their tasks; develops realistic action plans.
- Professionalism: Approaches others in a tactful manner; reacts well under pressure; treats others with respect and consideration regardless of their status or position; accepts responsibility for own actions; follows through on commitments.
- Innovation: Displays original thinking and creativity; meets challenges with resourcefulness; generates suggestions for improving work; develops innovative approaches and ideas; presents ideas and information in a manner that gets others' attention.
- Language Skills: Ability to read, analyze and interpret general business periodicals, professional journals, technical procedures, or governmental regulations. Ability to write reports, proposals, business correspondence, and procedure manuals. Ability to effectively present information and respond to questions from groups of managers, clients, customers and general public.
- Mathematical Skills: Ability to apply concepts such as fractions, percentages, ratios, and proportions to practical situations.
- Reasoning Ability: Ability to define problems, collect data, establish facts, and draw valid conclusions. Ability to question activities and issues in all functional areas and make sound business decisions based on that data.
- Physical Demands: The physical demands described here are representative of those that must be met by an employee to successfully perform the essential functions of this job. Reasonable accommodations may be made to enable individuals with disabilities to perform the essential functions. While performing the duties of this Job, the employee is regularly required to sit, talk, type or hear. The employee is frequently required to walk; use hands to finger, handle, or feel and reach with hands and arms.
- Work Environment: The work environment characteristics described here are representative of those an employee encounters while performing the essential functions of this job. The employee will normally work in a temperature-controlled office environment, with frequent exposure to electronic office equipment.
Salary and Benefits
The range for this position is between $120,000 and $160,000. Actual salary will be negotiated with this positions Hiring Manager and can vary depending on the following factors: Billable contract and labor category, experience, skills, education /certifications/ licenses & geographic location.
Sabel Systems is committed to offering all employees a competitive benefits and compensation package that is comprehensive enough to meet their goals and needs. Our employees are our most valuable asset, and one of Sabel Systems largest financial investments is our benefits program. As a valued member of the organization, employees are provided with a host of benefits to include healthcare; financial assistance in the event of illness, injury, disability, loss of work, or death; health savings accounts; retirement plans; paid time off; paid holidays; education and training program reimbursement, to name a few.
EEO Statement
Sabel Systems is an equal opportunity employer. Our hiring decisions are based solely on qualifications, merit, and business need. We prohibit discrimination and harassment of any kind across all employment practices within our organization. Sabel Systems participates in the E-Verify Employment Verification Program.
Salary : $120,000 - $160,000