Cybersecurity and Compliance for Aerospace & Defense (CMMC), Financial Services, Healthcare and Manufacturing Companies
Cyber Security Intern – SkillBridge
Location
Texas
Posted
82 days ago
Salary
0
Seniority
Entry Level
Job Description
Cyber Security Intern – SkillBridge
InfoDefense
• Participate in industry-related activities and customer meetings. • Author three 1,000-word articles/blogs on cyber security-related topics. • Provide exposure to private sector business, as well as a flexible schedule to accommodate out-processing. • Engage in core elements of the cyber security discipline including Network Security, Identity & Access Management, Security Operations Center, Endpoint Threat Protection Technologies, Cyber Incident Response, Governance, Risk and Compliance, Security Awareness, Threat and Vulnerability Management, Security Audit and Assessment, Social Engineering and Red Team Exercises, Security Metrics and Reporting.
Job Requirements
- The desire and ability to learn quickly, a great attitude, and good work ethic are required.
- Must be currently serving in the United State military.
- Eligible for the SkillBridge program.
- Exposure to core information security functions including network and application vulnerability testing.
- Proficient in Linux.
- Exposure to three or more of the following security technologies: Linux Bash and Python Scripting, Networking, Microsoft Windows (including Active Directory and Azure), NIST SP 800-171, SP 800-53, RMF, or CSF, Firewalls, intrusion prevention systems (IPS), and malware protection technology, Network vulnerability testing, Encryption technologies such as IPSEC, SIEM technologies such as Splunk, LogRhythm or Elasticsearch.
- Network+, CCNA, Security+ or other cyber security related certifications are desired.
Benefits
- Cyber security interns are provided with a laptop computer, docking station, monitors, keyboard and mouse, camera, and headset for remote working.
- Most hands-on instruction and on-the-job training is delivered using Microsoft Teams, although the opportunity for interacting on-site may also be provided.
- Interns must have a home office environment and sufficient Internet connectivity to enable remote work.
Related Guides
Related Categories
Related Job Pages
More Security Engineer Jobs
Company Overview Docusign brings agreements to life. Over 1.5 million customers and more than a billion people in over 180 countries use Docusign solutions to accelerate the process of doing business and simplify people’s lives. With intelligent agreement management, Docusign unleashes business-critical data that is trapped inside of documents. Until now, these were disconnected from business systems of record, costing businesses time, money, and opportunity. Using Docusign’s Intelligent Agreement Management platform, companies can create, commit, and manage agreements with solutions created by the #1 company in e-signature and contract lifecycle management (CLM). What you'll do As a core member of our Product Security Team, you will be responsible for embedding security practices within Docusign’s SDLC. Your work will empower all product teams to build secure applications from the ground up. You will act as a subject matter expert on secure application design, secure coding practices, systems integrations, and embedding security into automated testing/validation; driving a secure-by-design mindset across product development. The individual must be a U.S. Citizen, U.S. National or U.S. Person. Individuals outside of these categories are generally barred from having logical access to IL5 data or infrastructure This position is an individual contributor role reporting to the Director of Product Security. Responsibility - Collaborate with product engineers and product teams to gather requirements, provide expert consultation on securing the entire SDLC process within numerous environments, including those complying with DoD IL5 - Identify architectural flaws and security concerns in application designs early in the SDLC process - Threat Model and design security controls and mitigations in collaboration with product engineering teams - Verify/validate secure code interactions with other dependent and integrated services/systems - Ensure testing automation addresses security goals and concerns - Review and verify identified/reported vulnerabilities, perform root cause analysis, and partner with developers to drive corrections - Stay up-to-date with emerging security threats, trends, and new technologies to continuously improve the security posture of our code and shared development resources - Contribute to technical requirements, architecture, and interface design documents and educational resources Job Designation Remote: Employee is not required to be in or near an office frequently and works from a designated remote work location for the majority of the time. Positions at Docusign are assigned a job designation of either In Office, Hybrid or Remote and are specific to the role/job. Preferred job designations are not guaranteed when changing positions within Docusign. Docusign reserves the right to change a position's job designation depending on business needs and as permitted by local law. What you bring Basic - BS/BA degree or equivalent in relevant coding experience. - 5+ years of overall experience in Application Development, with at least 2 years focused in the Product Application Security discipline - Experience in designing, implementing, and maintaining secure software system - Experience with C# and .NET Framework/Core - Fluent in one or more other programming languages relevant to the organization (e.g., Python, Java, JavaScript) and the ability to quickly learn new languages - Experience with common security vulnerabilities (e.g. OWASP Top 10 and API Security Top 10) and their mitigations/remediations - Experience with development and build pipelines and associate best practices - Experience performing threat modeling and security analysis of application components to identify and mitigate potential vulnerabilities - Experience in secure source code audit/analysis and reporting - Experience with static and dynamic analysis tools, including vulnerability scanning suites - Experience in application security within cloud environments (e.g. AWS, Azure, GCP) - Experience developing and implementing security APIs and associated tooling against threats, such as unauthorized access and data breaches - Experience operating within and discovering the security implications of pre-existing code environments Preferred - Excellent analytical, problem-solving, and communication skills - Ability to work collaboratively across multiple teams Wage Transparency Pay for this position is based on a number of factors including geographic location and may vary depending on job-related knowledge, skills, and experience. Based on applicable legislation, the below details pay ranges in the following locations: California: $141,700.00 - $227,825.00 base salary Illinois, Colorado, Massachusetts and Minnesota: $137,100.00 - $193,725.00 base salary Washington, Maryland, New Jersey and New York (including NYC metro area): $137,100.00 - $200,125.00 base salary Washington DC: $141,700.00 - $200,125.00 base salary Ohio: $120,600.00 - $170,325.00 base salary This role is also eligible for the following: - Bonus: Sales personnel are eligible for variable incentive pay dependent on their achievement of pre-established sales goals. Non-Sales roles are eligible for a company bonus plan, which is calculated as a percentage of eligible wages and dependent on company performance. Global benefits provide options for the following: - Paid Time Off: earned time off, as well as paid company holidays based on region - Paid Parental Leave: take up to six months off with your child after birth, adoption or foster care placement - Full Health Benefits Plans: options for 100% employer paid and minimum employee contribution health plans from day one of employment - Retirement Plans: select retirement and pension programs with potential for employer contributions - Learning and Development: options for coaching, online courses and education reimbursements - Compassionate Care Leave: paid time off following the loss of a loved one and other life-changing events Life at Docusign Working here Docusign is committed to building trust and making the world more agreeable for our employees, customers and the communities in which we live and work. You can count on us to listen, be honest, and try our best to do what’s right, every day. At Docusign, everything is equal. We each have a responsibility to ensure every team member has an equal opportunity to succeed, to be heard, to exchange ideas openly, to build lasting relationships, and to do the work of their life. Best of all, you will be able to feel deep pride in the work you do, because your contribution helps us make the world better than we found it. And for that, you’ll be loved by us, our customers, and the world in which we live. Accommodation Docusign is committed to providing reasonable accommodations for qualified individuals with disabilities in our job application procedures. If you need such an accommodation, or a religious accommodation, during the application process, please contact us at accommodations@docusign.com. If you experience any issues, concerns, or technical difficulties during the application process please get in touch with our Talent organization at taops@docusign.com for assistance. Applicant and Candidate Privacy Notice States Not Eligible for Employment This position is not eligible for employment in the following states: Alaska, Hawaii, Maine, Mississippi, North Dakota, South Dakota, Vermont, West Virginia and Wyoming. Equal Opportunity Employer It's important to us that we build a talented team that is as diverse as our customers and where all employees feel a deep sense of belonging and thrive. We encourage great talent who bring a range of perspectives to apply for our open positions. Docusign is an Equal Opportunity Employer and makes hiring decisions based on experience, skill, aptitude and a can-do approach. We will not discriminate based on race, ethnicity, color, age, sex, religion, national origin, ancestry, pregnancy, sexual orientation, gender identity, gender expression, genetic information, physical or mental disability, registered domestic partner status, caregiver status, marital status, veteran or military status, or any other legally protected category. EEO Know Your Rights poster #LI-Remote
Security Engineer – Mid-Level
DMI (Digital Management, LLC)At the Intersection of Public and Private Sectors
• Supports security engineering for TSA systems • Involves control implementation/validation • Handles POA&M remediation and compliance evidence • Provides transition support and remediation tracking
Application Security Engineer
VivSoft TechnologiesFounded in 2011 and based in Ashburn, Virginia, VivSoft Technologies is a small business IT systems integrator specializing in open-source solutions, emerging technologies, and pro
Title: Application Security Engineer Clearance Required: Public Trust Location: Remote, USA Position Type: Full-Time About the company: At VivSoft, we aim to solve complex federal problems using emerging and open technologies in a collaborative and rewarding environment. VivSoft is a diverse team of strategists, engineers, designers, and creators experienced in building high performance effective softwares, with impactful organizational design and organizational dynamics for software delivery. We build secure Software Factories based on DoD reference designs and NIST Frameworks for Cloud and DevSecOps. These factories deliver AI/ML Applications, Data Science Platforms, Blockchain and Microservices for DoD, Healthcare and Civilian Agencies Job Summary: We are seeking an Application Security Engineer to support the modernization of a large-scale enterprise software development platform. This role focuses on securing CI/CD pipelines, enforcing DevSecOps best practices, and implementing automated security testing throughout the SDLC. The engineer will work closely with development and platform engineering teams to embed security into reusable templates, GitHub Actions, and deployment workflows, ensuring applications are built and deployed securely across environments. Key Responsibilities: - Using GitHub Advanced security, review security findings of the organization. - Review, validate, and approve request to remediate security findings. - Review, validate, and approve request to dismiss security findings. - Collaborate with Federal POC and FDIC security team to create and implement application security processes and standards. - Identify gaps and design solutions to improve application security at the FDIC. - Provide guidance to FDIC developers in regard to remediating findings when needed. Required Skills: - Bachelor’s degree in Computer Science, Engineering, Information Technology, or related field, or equivalent professional experience. - Proficiency in at least one or two major enterprise languages (e.g., Java, .Net, C#, JavaScript) to effectively review code and understand development context. - Experience integrating security tools (SAST/DAST/SCA) into CI/CD pipelines to automate vulnerability scanning. - Proficient in conducting and interpreting results from - SAST (Static Analysis Security Testing) - DAST (Dynamic Analysis Security Testing) - Manual Code Review for security flaws - Deep understanding of the OWASP Top 10 and other common application security attack vectors (e.g., injection, XSS, broken access control). - Knowledge of security considerations for large, complex enterprise architectures, which may include Cloud Security (AWS, Azure, or GCP), API security, and microservices. Benefits: - Comprehensive Medical, Dental, and Vision Plans (Healthcare benefits are 100% employer-paid for employees only) - Life Insurance - Paid Time Off (Flexible/Combined PTO, Bereavement Leave, 11 Company Paid Holidays) - 401K Retirement Plan with employer match - Professional Development Training Reimbursement
cFocus Software seeks a Sr. Cybersecurity Engineer / Architect to join our program supporting the National Institutes of Health (NIH). This position is remote. This position requires a Public Trust clearance. Qualifications: - Bachelor’s degree in Computer Science, Cyber Security, or related field. - 10+ years of cybersecurity engineering or security architecture experience. - Experience designing and implementing security controls in federal or regulated environments. - Security architecture and engineering practices - NIST Risk Management Framework (RMF) - NIST SP 800‑53 security controls - FISMA compliance - Security authorization / ATO processes - Incident response and threat analysis - Network security architecture and firewall management Duties: - Lead security engineering and architecture activities - Implement NIST 800-53 controls - Advise development teams on secure SDLC practices - Support incident response analysis - Implement security controls and network protections - Design, review, and implement secure architectures supporting hybrid scientific and IT environments across NCATS infrastructure. - Provide technical leadership on security engineering solutions supporting secure system development and infrastructure modernization. - Ensure architectures align with NIST SP 800‑53, NIST SP 800‑37, NIST SP 800‑160, FISMA, and NIH security policies. - Integrate security engineering practices across the system development lifecycle (SDLC) using DevSecOps and security‑by‑design principles. - Provide technical cybersecurity consulting to developers, engineers, and project stakeholders implementing NIST SP 800‑53 Rev. 5 security and privacy controls throughout system development. - Participate in architecture discussions, sprint reviews, and design reviews to ensure security requirements are integrated into system design and implementation. - Map system functionality to applicable security controls and develop control baselines aligned with system FIPS‑199 categorizations. - Provide implementation guidance on encryption, identity management, logging, secure API management, and other security technologies. - Assist with development of RMF artifacts including SSPs, SAPs, SARs, POA&Ms, Continuous Monitoring Strategies, and PIAs. - Serve as a technical lead supporting incident response coordination, analysis, and remediation across NCATS systems. - Coordinate with NCATS IT teams, security stakeholders, and the NIH Cyber Security Operations team. - Perform incident triage, containment, analysis, escalation, and remediation activities. - Conduct forensic analysis, malware review, and technical investigations supporting incident response activities. - Develop incident reports documenting root cause, impact, remediation steps, and lessons learned. - Support system authorization and assessment readiness activities for NCATS information systems. - Conduct pre‑assessment reviews and security control validation to prepare systems for compliance with federal security requirements. - Develop and maintain Authority to Operate (ATO) documentation and supporting artifacts. - Support FedRAMP authorization activities where applicable. - Assist with independent security assessments and remediation of identified vulnerabilities. - Provide engineering support for network security architecture and firewall management across the NCATS environment. - Design and maintain network segmentation strategies and security zones based on risk and sensitivity. - Implement firewall rules based on least privilege and default‑deny principles. - Conduct firewall configuration management, rule validation, and change control. - Validate logging configurations across network devices to support federal logging and monitoring requirements.



