SCAP / STIG Automation
- Build automated OpenSCAP pipelines to scan Ubuntu 24.04 LTS and other Linux hosts using DISA STIG benchmarks.
- Integrate XCCDF and OVAL results into OpenRMF using automated ingestion workflows.
- Develop hardened base images (VMs and containers) aligned to DISA STIG requirements.
Container Security
- Integrate RapidFort scans into CI/CD pipelines.
- Automate ingestion of SCAP JSON into OpenRMF.
- Ensure curated images remain compliant and low-CVE.
Compliance Operations (RMF/FedRAMP/CMMC)
- Support generation of automated DISA checklists (CKLs) and POA&M updates.
- Work with compliance and engineering teams to resolve findings and track remediation progress via OpenRMF.
Security Telemetry & SIEM Engineering
- Deploy/tune Wazuh agents across hosts and workloads.
- Configure pipelines from Wazuh → Elastic → Tines.
- Write and maintain Elastic SIEM detection rules.
SOAR Automation & AI SOC Buildout
- Develop Tines workflows to automate:
- SCAP ingestion
- RapidFort event processing
- Elastic SIEM alert enrichment
- Compliance notifications & ticketing
- Integrate LLMs to:
- Summarize alerts
- Draft POA&M entries
- Generate remediation guidance
- Produce daily/weekly SOC and compliance reports
Infrastructure & DevSecOps
- Contribute to secure CI/CD pipelines, secrets management, system hardening, logging, and access control aligned with DoD RMF.