Senior Security Engineer
Listed on 2026-03-01
-
Engineering
Cybersecurity
Overview
Readiness Delivered. Kratos is a leader in assured aerospace communication solutions and services. We are cutting-edge innovators and creative problem solvers working collaboratively to solve our customers’ toughest challenges. Our culture is fast-paced and innovative. We are a trusted partner-driven by doing the right thing and achieving maximum success for our customers, our partners and ourselves. Come join a dynamic and engaging work environment as a Senior Security Consultant supporting our Continuous Monitoring capabilities and team within the Kratos Dev Sec Ops organization.
Collaborate with engineering and high-profile customers to provide vulnerability scan analysis & validation, Plan of Actions & Milestones (POA&M) review, Risk Exposure Table (RET) analysis, and support in creation / validation of vulnerability deviation requests.
In this role, you will be conducting detailed analysis on operating system, web application, database, virtualization, container, virtual-storage, and driver vulnerability scans. Analysis will be based on validating accuracy of scanning scope based on documented inventories, scan authentication, and determination of the latest vulnerability tool signatures. Reporting will capture gaps in the analysis, and fully compiled vulnerabilities to present the customers complete risk posture.
The ideal candidate is highly organized, detail oriented, and able to trouble shoot data anomalies. Success in this growth position will allow for opportunities to assist in furthering the services and capabilities of the Kratos Dev Sec Ops Team including automation creation and support for a variety of vulnerability scanners, security tools, and administrative tasks.
Experience and Skills- Expert knowledge MS Excel
- Experience with Power Shell, GO, and/or Python
- Experience with various vulnerability scanners and SBOM Generation tools such as Sonar Qube, Syft, Grype, NPM Audit, Artifactory xRay, Tenable, Qualys, Burp Suite, etc.
- Validate Vulnerability Scan Quality (Authentication, Signature Updates, Configuration, etc.)
- Ability to validate scans against an inventory & ensure all hosts within a boundary are scanned. (Host Inventory Management)
- Familiarity and ability to differentiate different asset types such as containers, operating systems, databases, web scans, etc.
- Familiarity and ability to differentiate different types of audit checks such as CIS Benchmark / SITG checks and vulnerability checks.
Review & Verify Data Structures / Report Outputs from Vulnerability Scanners
- Ability to understand and verify data structures such as XML, JSON, YAML, etc.
- Ability to identify required data fields for reports and utilize them accordingly
- Ability to correlate potentially complex data structures and consolidate the data into a single format for analysis
Experience with configuration / compliance checks such as CIS Benchmarks and STIGs
- Ability to identify & verify authenticated & non-authenticated scans and agent-based scans.
- Ability to validate that vulnerability tool signatures are updated to the latest version and maintain a consistent update schedule.
- Ability to validate the scope of the audit checks enabled by the scanner are properly executing on the applicable assets
Strong Communication with the customer & fellow team members.
- Actively communicate issues or concerns to the customer & team
- Actively listens and participates in meetings
Strong Writing & Editing skills to assist in writing, developing, and editing Con Mon processes & documentation.
- Ability to write, edit, review, and assemble documents utilizing Microsoft Office & Markdown formatting syntax
- Ability to effectively write and clearly convey information
- Familiarity with code layout and able to extract comments to document functionality
- Familiarity with documentation styles that identify tasks that need to be accomplished & their required resources. Examples include:
- Plan of Action and Milestones (POA&M)
- Deviation Requests
- Project Plans
- Communication Plans
Ability to effectively accomplish complex tasks with minor guidance from team leadership.
- Ability to sequence and execute work efficiently with set timelines.
- Seek understanding and…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).