System Engineer II - SBOM

Fort Meade, MD, US • Posted 1 day ago • Updated 9 hours ago
Full Time
On-site
USD $128,000.00 - 185,000.00 per year
Fitment

Dice Job Match Score™

🔢 Crunching numbers...

Job Details

Skills

  • Collaboration
  • Partnership
  • Authorization
  • FOCUS
  • Risk Analysis
  • Bill Of Materials
  • Database
  • Threat Analysis
  • Due Diligence
  • Research
  • Vendor Development
  • Continuous Integration
  • Continuous Delivery
  • Patch Management
  • Regulatory Compliance
  • Reporting
  • Technical Analysis
  • Computer Science
  • Information Systems
  • Science
  • Engineering Management
  • Systems Engineering
  • Risk Management
  • Billing
  • Operations Support Systems
  • SCA
  • Vulnerability Management
  • Software Development
  • Evaluation
  • Apache Maven
  • NuGet
  • GitHub
  • Analytical Skill
  • Information Assurance
  • Impact Analysis
  • Information Architecture
  • Cyber Security
  • DoD
  • IC
  • Integrated Circuit
  • Internal Communications
  • Strategic Planning
  • CISSP
  • Security+
  • SaaS
  • Nexus
  • IO
  • Software Security
  • Testing
  • Malware Analysis
  • Reverse Engineering
  • Supply Chain Management
  • Open Source
  • Software Development Methodology
  • Cloud Computing

Summary

Job Description

SALARY RANGE $128,000 - $185,000/year.

DUTIES As a successful candidate for the Systems Engineer II (Software Analyst) role, you will support the mission of the National Information Assurance Partnership (NIAP) by conducting in-depth software assurance and Software Bill of Materials (SBOM) analysis for commercial technologies seeking evaluation, authorization, or deployment within National Security Systems (NSS) and sensitive U.S. Government environments. In this capacity, you will focus heavily on software supply chain transparency, software provenance, open-source software (OSS) risk analysis, vulnerability identification, and vendor cybersecurity practices. You will evaluate software components, dependencies, development practices, and third-party supplier risks to mitigate potential threats to system confidentiality, integrity, and availability, leveraging strong technical analysis and cybersecurity knowledge to assess software ecosystems across the full lifecycle.

Required Skills

SKILLS

  • SBOM Analysis & Standards: Conduct Software Bill of Materials (SBOM) analysis on commercial software products, platforms, and applications; analyze dependencies, transitive dependencies, and third-party libraries; validate SBOM formats and standards including SPDX, CycloneDX, and SWID tags.
  • Vulnerability & Provenance Assessment: Assess software provenance, code lineage, package integrity, and component authenticity; identify known vulnerabilities and weaknesses through CVE analysis, KEV review, vulnerability databases, and threat intelligence sources.
  • Supply Chain & Open-Source Risk Evaluation: Evaluate security risks associated with open-source software (OSS), foreign-developed components, end-of-life dependencies, unmaintained libraries, and software obfuscation; conduct due diligence research on vendors, developers, maintainers, and ecosystems.
  • Secure Development & Architecture Review: Analyze vendor development practices (secure coding, build pipeline security, CI/CD protections, dependency/patch management, code signing); review deployment architectures for attack vectors and support Common Criteria evaluations.
  • Compliance, Reporting & Threat Monitoring: Perform supply chain assessments aligned with NIST SSDF, Executive Order 14028, federal software assurance guidance, and NIAP protection profiles; produce technical reports and briefings; monitor emerging supply chain threats, malware campaigns, and malicious package activity.

QUALIFICATIONS Fourteen (14) years of experience as a System Engineer supporting systems engineering, analytical engineering, or technical analysis activities on programs and contracts of similar scope, type, and complexity within complex enterprise or mission systems environments. Requires a Bachelor's degree in System Engineering, Computer Science, Information Systems, Engineering Science, Engineering Management, or a related discipline from an accredited college or university; five (5) years of additional systems engineering experience may be substituted for the bachelor's degree.

Demonstrated experience in:

  • Software supply chain security, cybersecurity analysis, application security, or Supply Chain Risk Management (SCRM).
  • Strong understanding of Software Bills of Materials (SBOMs), open-source software (OSS) ecosystems, Software Composition Analysis (SCA), vulnerability management, and secure software development practices.
  • Familiarity with Common Criteria, NIAP evaluation concepts, NIST cybersecurity guidance, and federal software security initiatives.
  • Working knowledge of software package managers and code repositories, including npm, PyPI, Maven, NuGet, and GitHub.
  • Analyzing complex software dependency structures to identify risk indicators and supply chain vulnerabilities.
  • Authoring technical analytical reports and communicating complex security findings to both technical and non-technical audiences.
  • Information Assurance (IA) and cybersecurity architectures, concepts, and standards, alongside relevant DoD, IC, and federal (e.g., NIST) policies, directives, and strategic planning instructions.

Desired Skills

  • Certifications: Preferred industry certifications such as CISSP, CSSLP, Security+, GIAC, Certified SCRM Professional, or specialized cloud/application security certifications.
  • SBOM & Analysis Tooling: Hands-on experience with SBOM and software composition analysis tools including Dependency-Track, Syft, Grype, Black Duck, Snyk, Sonatype Nexus, Mend.io, and Anchore.
  • Application Security Testing: Familiarity with Static Application Security Testing (SAST), Dynamic Application Security Testing (DAST), malware analysis, reverse engineering, and code signing validation.
  • Supply Chain Threat Vectors: In-depth understanding of supply chain attacks, dependency confusion, typosquatting, build system compromise, and malicious open-source package activity.
  • Vendor Security & Architecture: Experience evaluating software vendor security maturity and secure development lifecycle (SDLC) practices, along with knowledge of cloud-native software architectures and container security.
Employers have access to artificial intelligence language tools (“AI”) that help generate and enhance job descriptions and AI may have been used to create this description. The position description has been reviewed for accuracy and Dice believes it to correctly reflect the job opportunity.
  • Dice Id: 91130336
  • Position Id: d7e6a9619d123ab52cad836d5efabbe2
  • Posted 1 day ago
Create job alert
Set job alertNever miss an opportunity! Create an alert based on the job you applied for.

Similar Jobs

Annapolis, Maryland

•

Today

Full-time

USD 140,000.00 - 155,000.00 per year

Fort Meade, Maryland

•

Today

Full-time

USD 128,000.00 - 185,000.00 per year

Annapolis, Maryland

•

Today

Full-time

USD 120,000.00 - 145,000.00 per year

Annapolis, Maryland

•

Today

Full-time

USD 160,000.00 - 215,000.00 per year

Search all similar jobs