user avatar

System Engineer II - SBOM

Black Eagle Defense

Posted today

Job Requirements

Fort Meade, MD
Top Secret/SCI Full Scope Polygraph
Career Level not specified
$128,000 - $185,000

Job Description

Job Description

SALARY RANGE $128,000 - $185,000/year.

DUTIES As a successful candidate for the Systems Engineer II (Software Analyst) role, you will support the mission of the National Information Assurance Partnership (NIAP) by conducting in-depth software assurance and Software Bill of Materials (SBOM) analysis for commercial technologies seeking evaluation, authorization, or deployment within National Security Systems (NSS) and sensitive U.S. Government environments. In this capacity, you will focus heavily on software supply chain transparency, software provenance, open-source software (OSS) risk analysis, vulnerability identification, and vendor cybersecurity practices. You will evaluate software components, dependencies, development practices, and third-party supplier risks to mitigate potential threats to system confidentiality, integrity, and availability, leveraging strong technical analysis and cybersecurity knowledge to assess software ecosystems across the full lifecycle.

Required Skills

SKILLS
  • SBOM Analysis & Standards: Conduct Software Bill of Materials (SBOM) analysis on commercial software products, platforms, and applications; analyze dependencies, transitive dependencies, and third-party libraries; validate SBOM formats and standards including SPDX, CycloneDX, and SWID tags.
  • Vulnerability & Provenance Assessment: Assess software provenance, code lineage, package integrity, and component authenticity; identify known vulnerabilities and weaknesses through CVE analysis, KEV review, vulnerability databases, and threat intelligence sources.
  • Supply Chain & Open-Source Risk Evaluation: Evaluate security risks associated with open-source software (OSS), foreign-developed components, end-of-life dependencies, unmaintained libraries, and software obfuscation; conduct due diligence research on vendors, developers, maintainers, and ecosystems.
  • Secure Development & Architecture Review: Analyze vendor development practices (secure coding, build pipeline security, CI/CD protections, dependency/patch management, code signing); review deployment architectures for attack vectors and support Common Criteria evaluations.
  • Compliance, Reporting & Threat Monitoring: Perform supply chain assessments aligned with NIST SSDF, Executive Order 14028, federal software assurance guidance, and NIAP protection profiles; produce technical reports and briefings; monitor emerging supply chain threats, malware campaigns, and malicious package activity.


QUALIFICATIONS Fourteen (14) years of experience as a System Engineer supporting systems engineering, analytical engineering, or technical analysis activities on programs and contracts of similar scope, type, and complexity within complex enterprise or mission systems environments. Requires a Bachelor's degree in System Engineering, Computer Science, Information Systems, Engineering Science, Engineering Management, or a related discipline from an accredited college or university; five (5) years of additional systems engineering experience may be substituted for the bachelor's degree.

Demonstrated experience in:
  • Software supply chain security, cybersecurity analysis, application security, or Supply Chain Risk Management (SCRM).
  • Strong understanding of Software Bills of Materials (SBOMs), open-source software (OSS) ecosystems, Software Composition Analysis (SCA), vulnerability management, and secure software development practices.
  • Familiarity with Common Criteria, NIAP evaluation concepts, NIST cybersecurity guidance, and federal software security initiatives.
  • Working knowledge of software package managers and code repositories, including npm, PyPI, Maven, NuGet, and GitHub.
  • Analyzing complex software dependency structures to identify risk indicators and supply chain vulnerabilities.
  • Authoring technical analytical reports and communicating complex security findings to both technical and non-technical audiences.
  • Information Assurance (IA) and cybersecurity architectures, concepts, and standards, alongside relevant DoD, IC, and federal (e.g., NIST) policies, directives, and strategic planning instructions.


Desired Skills

  • Certifications: Preferred industry certifications such as CISSP, CSSLP, Security+, GIAC, Certified SCRM Professional, or specialized cloud/application security certifications.
  • SBOM & Analysis Tooling: Hands-on experience with SBOM and software composition analysis tools including Dependency-Track, Syft, Grype, Black Duck, Snyk, Sonatype Nexus, Mend.io, and Anchore.
  • Application Security Testing: Familiarity with Static Application Security Testing (SAST), Dynamic Application Security Testing (DAST), malware analysis, reverse engineering, and code signing validation.
  • Supply Chain Threat Vectors: In-depth understanding of supply chain attacks, dependency confusion, typosquatting, build system compromise, and malicious open-source package activity.
  • Vendor Security & Architecture: Experience evaluating software vendor security maturity and secure development lifecycle (SDLC) practices, along with knowledge of cloud-native software architectures and container security.
group id: 91130336