Cybersecurity Engineer in Fairfax, Virginia at Xenon Innovations, Inc
Explore Related Opportunities
Job Description
This is an engineering position, not a scanning position. This position is not here to run ACAS sweeps and transcribe findings into spreadsheets. This role is about building the automation that makes hardening, evidence generation, and supply chain assurance a property of the build system. If a control can be enforced by code and proven by an artifact, your job is to make that happen and to make it repeatable across every baseline we deliver.
You will own the security engineering layer across our development and delivery environments, working alongside the embedded, firmware, and platform teams.
STIG and SRG automation
- Design and maintain automated hardening for RHEL, Windows, container, network device, and application baselines against applicable DISA STIGs and SRGs
- Author, tailor, and validate SCAP and OpenSCAP content; build and maintain idempotent Ansible-based roles
- Automate STIG checklist (CKL) generation, deviation documentation, and evidence packaging so that compliance state is a build output rather than a manual exercise
- Engineer tailoring decisions for embedded and real-time targets where stock STIG guidance breaks the mission and document the technical rationale and compensating controls that makes those deviations defensible in review
Software bill of materials
- Stand up automated SBOM generation (CycloneDX or SPDX) across firmware, embedded, and application build pipelines, including for cross-compiled and constrained targets
- Integrate SBOM production into CI so every delivered artifact ships with an accurate, signed component inventory
- Produce and maintain VEX documentation to communicate real exploitability rather than raw CVE counts
- Ensure SBOM output satisfies customer and NDAA/EO supply chain delivery requirements
Supply chain security and remediation
- Triage dependency and component vulnerabilities on technical merit and drive remediation with the engineering teams
- Implement artifact signing, provenance, and build attestation (Sigstore/cosign, SLSA-aligned practices) across the delivery chain
- Track upstream advisories and patch availability; own the engineering response when a component goes unmaintained or a fix does not exist
Pipeline and platform
- Build security gates into CI/CD across both unclassified and accredited enclaves, including air-gapped environments
- Implement policy-as-code, IaC scanning, and secrets management within the build system
- Automate the production of RMF evidence artifacts to shorten the ATO path
- BS in Computer Science, Computer Engineering, Cybersecurity, or equivalent hands-on experience
- 5+ years in security engineering, DevSecOps, or platform engineering, with demonstrable automation work
- Strong scripting and automation skills in Python and Bash
- Production experience with Ansible or equivalent configuration management
- Direct experience implementing DISA STIGs or SRGs in an automated fashion, including SCAP content work
- Working knowledge of CI/CD systems (Bitbucket, GitLab CI, or equivalent), containerization, and artifact repository management
- Familiarity with RMF, NIST SP 800-53, and NIST SP 800-171
- Ability to obtain a TS/SCI clearance
- Experience with SBOM tooling (JFrog Xray, Syft, Trivy, Grype, cdxgen, or similar) in embedded or cross-compiled build environments
- Prior work in air-gapped or classified development enclaves
- Experience hardening embedded Linux or RTOS targets where standard STIG automation does not apply cleanly
- Exposure to Navy accreditation processes
- Relevant certification (CISSP, GSEC, or DoD 8570 IAT/IAM Level II+)
- Active TS/SCI
Estimated Salary Range: $135,000-$230,000 per year
The salary range noted is intended as a general guide. Actual base salary offers from Xenon Innovations are determined based on several factors, including the position's scope and responsibilities, along with the candidate's experience, education, skill set, and prevailing market conditions.
Xenon Innovations, Inc. is an equal opportunity employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, national origin, age, disability, genetic information, or protected veteran status.