Cybersecurity Assessment Engineer
Second Front Systems · Remote · United States · Remote
Pay: USD 155,000 – 175,000 a year
Posted Jul 17, 2026
Sign up free: we match you to jobs like this, tailor your application and fill the form. 2 free applications every day.
Cybersecurity Assessment Engineer
Second Front Systems (2F) is seeking a Cybersecurity Assessment Engineer to perform hands-on security assessments of software deployed through the Game Warden platform.
This is not a scan-operator or checklist-only position. We are looking for someone who can investigate technical findings, understand how an application is built and deployed, distinguish meaningful risk from scanner noise, and give engineering teams practical guidance they can act on.
Reporting to the Head of Product Security & Compliance, you will assess customer applications, container images, cloud configurations, software dependencies, and supporting artifacts before and after deployment. You will work directly with Product, Platform Engineering, DevOps, Mission Success, and customer development teams to identify vulnerabilities, evaluate their actual risk, and determine whether an application is ready to operate within Game Warden.
Your work will directly influence deployment decisions, vulnerability remediation, continuous monitoring, and the security posture of a platform supporting mission-critical government software.
Note: Candidates must reside in one of our approved hiring hubs:
• DC/Maryland/Virginia
• Raleigh/Durham/Chapel Hill, NC
• Denver/Colorado Springs, CO
• Dallas/Fort Worth, TX
This is a full-time position.
What You'll Do
• Perform technical security assessments of customer applications and services seeking deployment through the Game Warden platform.
• Review application artifacts, container images, software dependencies, infrastructure configurations, data flows, APIs, and deployment documentation to identify security weaknesses.
• Analyze results from SAST, DAST, software composition analysis, container scanning, infrastructure-as-code scanning, secrets detection, and vulnerability management tools.
• Serve as a trusted technical security partner to Mission Success, Platform Engineering, DevOps, and customer development teams.
• Partner with Security Authorization Specialists to ensure technical assessment results and supporting evidence can be used for RMF, FedRAMP, and continuous monitoring activities.
• Provide developers with clear remediation guidance that identifies the vulnerable component, explains the risk, and recommends specific corrective actions.
• Evaluate requests for vulnerability exceptions or delayed remediation. Validate the stated rationale, examine compensating controls, and provide a documented risk recommendation to the appropriate approving authority.
• Support recurring continuous monitoring reviews by identifying new vulnerabilities, configuration drift, outdated dependencies, and changes affecting previously assessed applications.
• Communicate assessment results directly to technical and nontechnical stakeholders, including customers who may need help understanding findings and remediation expectations.
• Produce clear assessment records that document the scope, methodology, evidence…