- Location
- San Antonio, TX, US
- Type
- Full-time
- Department
- IT
- Clearance
- Required
- Closing date
- Today
- Source
- iCIMS
Description
Description
- Providing support to a specialized team in the development of advanced analysts for the Joint Staff to be fielded in the next 2-5 years. Work will be at the 16th Air Force in San Antonio, Texas
- Designing, testing, and applying automated baseline hardening scripts (Ansible playbooks, Bash, Python) to enforce DISA Security Technical Implementation Guides and Security Requirements Guides across five on-premises RHEL Linux servers, PostgreSQL instances, and container platforms
- Partnering with Java/Python streaming analytics developers to embed automated security testing into Continuous Integration and Continuous Delivery or Deployment pipelines (Git, Gradle), implementing Static Application Security Testing (SAST) and Software Composition Analysis (SCA) via SonarQube or comparable tools
- Packaging, deploying, and securing application containers utilizing Docker and Kubernetes; validating container image provenance, eliminating baseline CVEs, and configure secure container runtimes
- Using experience in Assessment & Authorization (A&A) developing, maintaining, and updating core RMF security packages—including System Security Plans (SSP), Continuous Monitoring (ConMon) plans, and Security Assessment Plans (SAP)—within the Xacta eGRC portal
- Executing routine vulnerability scans using ACAS (Tenable Nessus) and Security Content Automation Protocol (SCAP) compliance benchmarks across the five-server enclave; analyzing findings, eliminating false positives, and coordinating patch cycles
- Required to formulate actionable Plan of Action & Milestones (POA&M) entries for identified non-compliant controls, working closely with system engineers to resolve findings and mitigate operational risk
#LI-DG1
Requirements
- Bachelor’s Degree in Cybersecurity, Computer Science, Information Technology, Software Engineering or STEM discipline with 4 years of additional equivalent professional experience
- CASP+ (SecurityX), CGRC (formerly CAP), CISSP, CISM, CCISO, or equivalent
- Red Hat Enterprise Linux (RHEL 8/9) administration, command-line operations, system service management, and SELinux configuration
- Ability to work independently while leveraging a team of diverse specialties
Desired Skills
- Direct hands-on experience running ACAS / Tenable Nessus vulnerability scans and interpreting STIG Viewer / SCAP results
- Experience drafting or maintaining System Security Plans (SSPs) and navigating Xacta or eMASS
- Working knowledge of Joint and USAF doctrine, specifically defensive cyber operations
- Experience in programming and system design
- Prior experience supporting AF-SCI or NSANet-connected systems.
- Active CASP+ (SecurityX) or CISSP certification
- Direct experience writing Ansible playbooks to automate DISA STIG remediation (e.g., automated STIG lockdown scripts)
- Familiarity with database administration, access controls, and STIG checklist validation for PostgreSQL
- Demonstrated familiarity with NIST SP 800-53 Rev. 5, NIST SP 800-37, and DoD/CNSSI security directives
- Demonstrated experience deploying and securing containerized applications using Docker and Kubernetes (or Podman)
Clearance Information
SRC IS A CONTRACTOR FOR THE U.S. GOVERNMENT, THIS POSITION WILL REQUIRE U.S. CITIZENSHIP AS WELL AS, A U.S. GOVERNMENT SECURITY CLEARANCE AT THE TOP SECRET / SCI LEVEL WITH Poly-CI ELIGIBILITY
Travel Requirements
- Yes, 10%
About Us
Scientific Research Corporation is an advanced information technology and engineering company that provides innovative products and services to government and private industry, as well as independent institutions. At the core of our capabilities is a seasoned team of highly skilled engineers and scientists with multidisciplinary backgrounds. This team is challenged daily to provide cutting edge technology solutions to our clients.
SRC offers a generous benefit package, including medical, dental, and vision plans, 401(k) with a company match, life insurance, vacation and sick paid time off accruals with amounts increasing based on role and years of service, 11 paid holidays, tuition reimbursement, and a work environment that encourages excellence and more. For positions requiring a security clearance, selected applicants will be subject to a government security investigation and must meet eligibility requirements for access to classified information.
EEO
Scientific Research Corporation is an equal opportunity employer that does not discriminate in employment.
All qualified applicants will receive consideration for employment without regard to their race, color, religion, sex, age, sexual orientation, gender identity, national origin, disability, protected veteran status, or any other protected characteristic under federal, state or local law.
Scientific Research Corporation endeavors to make www.scires.com accessible to any and all users. If you would like to contact us regarding the accessibility of our website or need assistance completing the application process, please contact [email protected] for assistance. This contact information is for accommodation requests only and cannot be used to inquire about the status of applications.