NewSat North America LLC
Colorado Springs, Colorado
Job Description Job Description POSITION SUMMARY NewSat is seeking an Intermediate-level Vulnerability Assessment Analyst to support our U.S. Space Force (USSF) customer. This position performs vulnerability assessment and remediation-tracking activities across a platform spanning more than 42 deployed environments across approximately 900 servers at multiple classification levels. Working with only periodic high-level guidance, the Intermediate VAA executes recurring and ad hoc assessments, validates findings, and supports remediation and continuous monitoring activities in non-routine and sometimes complicated situations. This role supports the task order's Continuous Cyber Monitoring, Threat Assessment and Risk Mitigation, and Body of Evidence artifact management service areas. KEY RESPONSIBILITIES • Execute scheduled and ad hoc vulnerability scans across the existing environment and during assessment of new connections using ACAS/Nessus and DoD-approved assessment tooling. • Apply DISA STIGs and SCAP benchmarks; validate compliance results and research findings to confirm or dismiss false positives. • Analyze scan output, correlate findings across environments, and document results in standardized assessment reports. • Track remediation actions to closure with system owners; support POA&M entry, updates, and supporting evidence. • Assemble Body of Evidence (BoE) artifacts supporting Certificate to Field (CtF), Authority to Connect (ATC) and continuous monitoring requirements. • Support assessment of cloud and container workloads, including AWS tenant spaces and EKS-hosted services. • Escalate complex, high-risk, or disputed findings to the Advanced VAA or Security Architect for adjudication. • Maintain assessment documentation, scan configurations, and reporting cadence in accordance with program procedures. REQUIRED QUALIFICATIONS • Active TS clearance with SCI eligibility; ability to meet program-directed access requirements. • Minimum 4 years of cybersecurity experience with direct vulnerability assessment or vulnerability management responsibility. • Security+ CE or equivalent DoD 8140 / 8570 baseline certification current at time of hire. • Hands-on experience with ACAS/Nessus or comparable scanning platforms and with STIG/SCAP compliance checking. • Familiarity with RMF, NIST SP 800-53 control families, and POA&M processes. • Ability to work non-routine assessment tasks with only periodic high-level supervision. PREFERRED QUALIFICATIONS • Bachelor's degree in Computer Science, Cybersecurity, Information Systems, or a related field. • Experience supporting DoD, IC, or space ground system programs. • Certifications such as CySA+, CEH, GCIH, or GSEC. • Exposure to containerized or cloud environments (Kubernetes/EKS, AWS). • Scripting familiarity (Python, PowerShell, Bash) for reporting and data reduction. Company Description NewSat provides cost-competitive, best-of-breed, global C5ISR solutions to ensure mission success for our customers. Our small business provides solutions to many industry partners, both as a prime contractor and value-added subcontractor. Company Description NewSat provides cost-competitive, best-of-breed, global C5ISR solutions to ensure mission success for our customers. Our small business provides solutions to many industry partners, both as a prime contractor and value-added subcontractor.
Job Description Job Description POSITION SUMMARY NewSat is seeking an Intermediate-level Vulnerability Assessment Analyst to support our U.S. Space Force (USSF) customer. This position performs vulnerability assessment and remediation-tracking activities across a platform spanning more than 42 deployed environments across approximately 900 servers at multiple classification levels. Working with only periodic high-level guidance, the Intermediate VAA executes recurring and ad hoc assessments, validates findings, and supports remediation and continuous monitoring activities in non-routine and sometimes complicated situations. This role supports the task order's Continuous Cyber Monitoring, Threat Assessment and Risk Mitigation, and Body of Evidence artifact management service areas. KEY RESPONSIBILITIES • Execute scheduled and ad hoc vulnerability scans across the existing environment and during assessment of new connections using ACAS/Nessus and DoD-approved assessment tooling. • Apply DISA STIGs and SCAP benchmarks; validate compliance results and research findings to confirm or dismiss false positives. • Analyze scan output, correlate findings across environments, and document results in standardized assessment reports. • Track remediation actions to closure with system owners; support POA&M entry, updates, and supporting evidence. • Assemble Body of Evidence (BoE) artifacts supporting Certificate to Field (CtF), Authority to Connect (ATC) and continuous monitoring requirements. • Support assessment of cloud and container workloads, including AWS tenant spaces and EKS-hosted services. • Escalate complex, high-risk, or disputed findings to the Advanced VAA or Security Architect for adjudication. • Maintain assessment documentation, scan configurations, and reporting cadence in accordance with program procedures. REQUIRED QUALIFICATIONS • Active TS clearance with SCI eligibility; ability to meet program-directed access requirements. • Minimum 4 years of cybersecurity experience with direct vulnerability assessment or vulnerability management responsibility. • Security+ CE or equivalent DoD 8140 / 8570 baseline certification current at time of hire. • Hands-on experience with ACAS/Nessus or comparable scanning platforms and with STIG/SCAP compliance checking. • Familiarity with RMF, NIST SP 800-53 control families, and POA&M processes. • Ability to work non-routine assessment tasks with only periodic high-level supervision. PREFERRED QUALIFICATIONS • Bachelor's degree in Computer Science, Cybersecurity, Information Systems, or a related field. • Experience supporting DoD, IC, or space ground system programs. • Certifications such as CySA+, CEH, GCIH, or GSEC. • Exposure to containerized or cloud environments (Kubernetes/EKS, AWS). • Scripting familiarity (Python, PowerShell, Bash) for reporting and data reduction. Company Description NewSat provides cost-competitive, best-of-breed, global C5ISR solutions to ensure mission success for our customers. Our small business provides solutions to many industry partners, both as a prime contractor and value-added subcontractor. Company Description NewSat provides cost-competitive, best-of-breed, global C5ISR solutions to ensure mission success for our customers. Our small business provides solutions to many industry partners, both as a prime contractor and value-added subcontractor.
NewSat North America LLC
Colorado Springs, Colorado
Job Description Job Description POSITION SUMMARY NewSat is seeking an Advanced-level Vulnerability Assessment Analyst (VAA) to support our U.S. Space Force (USSF) customer. This position leads vulnerability assessment and threat analysis activities supporting both existing infrastructure and platform growth through the Authority to Connect (ATC) process to protect a platform spanning more than 42 deployed environments across approximately 900 servers, operating at multiple classification levels. Operating with little to no guidance, the Advanced VAA plans and executes assessments against the environment to include multiple Amazon Elastic Kubernetes Service (EKS) clusters and numerous non-containerized assets. The analyst prioritizes findings by mission risk, drives remediation with system owners, and provides technical direction to junior assessment staff in complex, unstructured situations. This role directly supports the task order's Threat Assessment and Risk Mitigation and Continuous Cyber Monitoring service areas. KEY RESPONSIBILITIES • Plan, execute, and report on vulnerability assessments across multiple environments spanning CUI, Secret Collateral, and TS/SCI-SAP enclaves. • Lead scanning, credentialed assessment, and manual validation activities using ACAS/Nessus, STIG/SCAP tooling, and equivalent DoD-approved capabilities. • Apply DISA STIGs and SRGs to operating systems, containers, and applications; validate compliance and adjudicate false positives. • Prioritize findings by exploitability and mission impact; develop and track remediation and mitigation plans with system owners and the ISSM/ISSO. • Support Plan of Action and Milestones (POA&M) development, currency, and closure evidence as part of continuous monitoring. • Produce Body of Evidence (BoE) artifacts supporting Certificate to Field (CtF), Authority to Connect (ATC) and Authorization to Operate (ATO) activities. • Assess vulnerabilities in hybrid cloud and container environments, including AWS tenant spaces, EKS clusters, and master-image-provisioned server fleets. • Provide technical guidance to Basic and Intermediate assessment analysts; review their findings and resolve complex or disputed results. • Brief assessment results and risk posture to government technical leadership and program stakeholders. REQUIRED QUALIFICATIONS • Active TS clearance with SCI eligibility; ability to meet program-directed access requirements. • Bachelor's degree in Computer Science, Cybersecurity, Information Systems, Engineering, or a related field. Additional relevant experience may be substituted for degree. • Minimum 9 years of progressive cybersecurity experience with substantial focus on vulnerability assessment and management. • CISSP, CISM, CySA+ or equivalent DoD 8140 / 8570 baseline certification current at time of hire. • Demonstrated hands-on expertise with ACAS/Nessus, STIG/SCAP compliance tooling, and enterprise vulnerability management workflows. • Working knowledge of RMF, NIST SP 800-53, and continuous monitoring processes on DoD or IC systems. • Demonstrated ability to work independently and provide technical direction to other analysts. PREFERRED QUALIFICATIONS • Prior experience supporting USSF, Space RCO, or satellite ground system programs. • Advanced degree in Computer Science, Cybersecurity, Information Systems, Engineering, or a related field. • Experience assessing containerized and cloud-native workloads (Kubernetes/EKS, AWS). • Familiarity with penetration testing, red team support, or adversary emulation. • Scripting proficiency (Python, PowerShell, Bash) for assessment automation and data reduction. Company Description NewSat provides cost-competitive, best-of-breed, global C5ISR solutions to ensure mission success for our customers. Our small business provides solutions to many industry partners, both as a prime contractor and value-added subcontractor. Company Description NewSat provides cost-competitive, best-of-breed, global C5ISR solutions to ensure mission success for our customers. Our small business provides solutions to many industry partners, both as a prime contractor and value-added subcontractor.
Job Description Job Description POSITION SUMMARY NewSat is seeking an Advanced-level Vulnerability Assessment Analyst (VAA) to support our U.S. Space Force (USSF) customer. This position leads vulnerability assessment and threat analysis activities supporting both existing infrastructure and platform growth through the Authority to Connect (ATC) process to protect a platform spanning more than 42 deployed environments across approximately 900 servers, operating at multiple classification levels. Operating with little to no guidance, the Advanced VAA plans and executes assessments against the environment to include multiple Amazon Elastic Kubernetes Service (EKS) clusters and numerous non-containerized assets. The analyst prioritizes findings by mission risk, drives remediation with system owners, and provides technical direction to junior assessment staff in complex, unstructured situations. This role directly supports the task order's Threat Assessment and Risk Mitigation and Continuous Cyber Monitoring service areas. KEY RESPONSIBILITIES • Plan, execute, and report on vulnerability assessments across multiple environments spanning CUI, Secret Collateral, and TS/SCI-SAP enclaves. • Lead scanning, credentialed assessment, and manual validation activities using ACAS/Nessus, STIG/SCAP tooling, and equivalent DoD-approved capabilities. • Apply DISA STIGs and SRGs to operating systems, containers, and applications; validate compliance and adjudicate false positives. • Prioritize findings by exploitability and mission impact; develop and track remediation and mitigation plans with system owners and the ISSM/ISSO. • Support Plan of Action and Milestones (POA&M) development, currency, and closure evidence as part of continuous monitoring. • Produce Body of Evidence (BoE) artifacts supporting Certificate to Field (CtF), Authority to Connect (ATC) and Authorization to Operate (ATO) activities. • Assess vulnerabilities in hybrid cloud and container environments, including AWS tenant spaces, EKS clusters, and master-image-provisioned server fleets. • Provide technical guidance to Basic and Intermediate assessment analysts; review their findings and resolve complex or disputed results. • Brief assessment results and risk posture to government technical leadership and program stakeholders. REQUIRED QUALIFICATIONS • Active TS clearance with SCI eligibility; ability to meet program-directed access requirements. • Bachelor's degree in Computer Science, Cybersecurity, Information Systems, Engineering, or a related field. Additional relevant experience may be substituted for degree. • Minimum 9 years of progressive cybersecurity experience with substantial focus on vulnerability assessment and management. • CISSP, CISM, CySA+ or equivalent DoD 8140 / 8570 baseline certification current at time of hire. • Demonstrated hands-on expertise with ACAS/Nessus, STIG/SCAP compliance tooling, and enterprise vulnerability management workflows. • Working knowledge of RMF, NIST SP 800-53, and continuous monitoring processes on DoD or IC systems. • Demonstrated ability to work independently and provide technical direction to other analysts. PREFERRED QUALIFICATIONS • Prior experience supporting USSF, Space RCO, or satellite ground system programs. • Advanced degree in Computer Science, Cybersecurity, Information Systems, Engineering, or a related field. • Experience assessing containerized and cloud-native workloads (Kubernetes/EKS, AWS). • Familiarity with penetration testing, red team support, or adversary emulation. • Scripting proficiency (Python, PowerShell, Bash) for assessment automation and data reduction. Company Description NewSat provides cost-competitive, best-of-breed, global C5ISR solutions to ensure mission success for our customers. Our small business provides solutions to many industry partners, both as a prime contractor and value-added subcontractor. Company Description NewSat provides cost-competitive, best-of-breed, global C5ISR solutions to ensure mission success for our customers. Our small business provides solutions to many industry partners, both as a prime contractor and value-added subcontractor.