Who We Are
Sabel Systems Technology Solutions, LLC is a leading solution provider and rapidly growing Information and Communications Technology Company specializing in innovative and agile Digital Engineering and Acquisition Technical Stack design, implementation, and support, Strategy and Policy Development, Financial Management, Software Solutions Development, Requirements Analysis and Training, to name a few. Our client base is mostly in the DoD Federal Government Contracting space and we also partner with prime Government Contractors such as Siemens, Booz Allen, McKinsey and have work in the commercial space as well. We provide clients with large business opportunities and training within our small business agility and people first culture. You will be joining a dynamic and highly motivated team with one goal: "Get quality and secure solutions in the customers hands as soon as possible”.
Who We Need
Sabel Systems has the technology solutions to support cloud-based processes for Digital Engineering, enabling Digital Threads for, and Digital Twins of, complex weapon systems. Our DoD customers have urgent and persistent needs to address new capabilities of near-peer strategic competitors, and asymmetric threats from disruptive actors. We are seeking talented professionals to make real these engineering solutions, keeping our nation's security capabilities well ahead of all threats.
What You’ll Do
Reasonable accommodations may be made to enable individuals with disabilities to perform the essential functions of this position.
As a DevSecOps Software Assurance Expert, you will play a pivotal role in ensuring the security and integrity of a CI/CD pipeline for Department of Defense (DoD) applications throughout their lifecycle. You will leverage your expertise in automated testing, secure development practices, and security mitigation to ensure that applications meet stringent DoD security requirements. You will work directly with development, testing, and security teams to automate security testing processes and ensure that DoD applications are fully compliant with the latest security standards and policies. This role requires experience in both software assurance and automated testing, with a deep understanding of DoD regulations and security frameworks.
Key Responsibilities:
Automated Security Testing and Integration:
- Implement and automate security testing frameworks within CI/CD pipelines to ensure security vulnerabilities are detected early in the development process.
- Design and configure automated tools for static and dynamic code analysis, vulnerability scanning, and penetration testing for DoD applications.
- Ensure that automated security tests are comprehensive and address specific security risks related to DoD environments, such as confidentiality, integrity, and availability.
Compliance and Security Standards:
- Ensure compliance with DoD security standards and frameworks, such as the Risk Management Framework (RMF), NIST 800-53, and DISA STIGs.
- Develop security test plans and strategies to verify that applications meet specific security requirements and are compliant with federal regulations and DoD policies.
- Conduct security audits and assessments to validate the security posture of DoD applications.
Consulting and Collaboration:
- Collaborate closely with development teams, security experts, and project stakeholders to define and implement security testing requirements and best practices.
- Advise on secure software development practices and guide teams on implementing secure coding standards, code reviews, and vulnerability management.
- Provide expert advice on risk assessments, vulnerability remediation, and incident response strategies specific to DoD applications.
Continuous Improvement and Automation:
- Lead the automation of security testing processes to increase efficiency, reduce risk, and speed up development cycles.
- Identify and implement new tools and methodologies for enhancing automated security testing in DoD environments.
- Continuously monitor the security landscape and make improvements to automated testing frameworks based on emerging threats and vulnerabilities.
Documentation and Reporting:
- Create and maintain detailed documentation of security testing processes, test results, risk assessments, and compliance reports.
- Present findings, vulnerabilities, and remediation recommendations to technical and non-technical stakeholders, ensuring transparency and alignment with DoD objectives.
- Develop and deliver security awareness training for development teams on secure coding and automated security testing practices.
Security Tool Management:
- Manage and optimize security tools for automated testing, vulnerability scanning, and compliance monitoring, ensuring they meet DoD security and performance requirements.
- Stay up-to-date with new security testing technologies, frameworks, and industry trends that could benefit DoD application security assurance.