IPTA is looking for a Software Assurance Security Analyst to administer and maintain security solutions, conduct secure code reviews, and ensure compliance with security benchmarks for enterprise and Directorate-level applications within the AvMC enterprise.
Requirements
- Experience with ASP.NET, C++, C-Sharp, CSS, JavaScript, and Python
- Experience with OpenText (Fortify) SAST and WebInspect DAST
- Experience using Docker Desktop, Visual Studio, and VMware Workspace One
- DoD 8500.01
- DoD 8510.01
- AR 25-2
- NIST 800-53A
Responsibilities
- Administer and maintain multiple Windows Server 2022 systems supporting the AvMC enterprise OpenText (Fortify) application security solution, including patch management, role-based access controls, and system hardening.
- Conduct secure code reviews and vulnerability assessments for enterprise and Directorate-level applications; provide mitigation strategies, integration/test support, and final disposition of identified issues in accordance with software assurance best practices.
- Apply and validate the Application Security and Development (ASD) STIG across multiple applications within the environment, ensuring compliance with DISA security benchmarks.
- Analyze vulnerability scan results (e.g., Fortify, SwAT) and correlate findings to application architecture, layered defense strategies, and DoD risk acceptance thresholds.
- Create and deliver user training, SOPs, and workflow guides aligned with DoD and Army Software Assurance and Cybersecurity standards.
- Maintain working knowledge of relevant cybersecurity and software development regulations, including DoD 8500.01, DoD 8510.01, AR 25-2, and NIST 800-53A.
- Perform full lifecycle application development IAW Army policies (AR 25-2), including secure coding practices, automated testing, and CI/CD pipeline integration.
Other
- Eight (8) years of prior experience in a similar role
- Strong communication and organizational skills
- DoD 8500.01, DoD 8510.01, AR 25-2, and NIST 800-53A
- DoD 8570 Level II/III certification desired
- Active security clearance required