Dev Technology
Ashburn, Virginia
Job Description Job Description Information Security Specialist Officer, Technical Lead, AWS Security • RMF & ATO • NIST 800-53 • Cloud Application Security Clearance: Active CBP, DHS, or Top Secret Clearance required Work Arrangement: Hybrid - onsite 3 days/week during standard business hours in Ashburn, VA About the Role Dev Technology Group is seeking a Senior Information Security Specialist to lead and develop a mid-sized team of ISSOs supporting the security, compliance, and authorization of mission-critical federal applications and information systems hosted in AWS. This is a hands-on technical leadership role combining people leadership, federal cybersecurity expertise, and direct collaboration with government and technical stakeholders. You will mentor junior and mid-level ISSOs while partnering with system owners, developers, architects, cloud/infrastructure engineers, security professionals, and government stakeholders throughout the system development lifecycle. You will provide practical security guidance for AWS-hosted applications, lead Risk Management Framework (RMF) and Authority to Operate (ATO) activities, oversee vulnerability management and continuous monitoring, and translate federal cybersecurity requirements into actionable guidance for technical teams. What You'll Do Lead, mentor, and develop a team of ISSOs by establishing priorities, providing technical direction and coaching, and promoting accountability and consistent security practices. Lead and oversee RMF, ATO, security authorization, compliance, vulnerability management, and continuous monitoring activities across a portfolio of federal systems and applications. Partner with ISSMs, system owners, assessors, developers, architects, engineers, and government stakeholders to maintain authorizations, identify risks, and address security requirements. Lead vulnerability management efforts, prioritizing remediation, developing mitigation strategies, and tracking corrective actions through resolution. Develop, assess, document, and support implementation of security controls aligned with FISMA, NIST 800-53, DHS, and client requirements . Prepare and maintain security and authorization documentation, including SSPs, ISAs, audit artifacts, and RMF documentation . Provide cybersecurity guidance for applications and systems deployed in AWS and integrate security throughout the software development lifecycle. Validate security implementation through technical reviews, discussions, interviews, assessments, and tabletop exercises. Support security audits, assessments, compliance reviews, and reviews of information systems and network connections. Interpret federal and client security policies and translate requirements into practical guidance for technical and development teams. Identify and escalate security risks, communicate priorities and remediation status, and provide clear visibility to Dev Technology leadership and government stakeholders. Develop and present security metrics, status reports, risk assessments, and executive briefings . Establish and improve security processes, procedures, templates, dashboards, and workflows to improve consistency, accountability, and efficiency across the ISSO team. Build trusted relationships with government clients through proactive communication, collaboration, and face-to-face engagement. Required Education, Experience & Skills Bachelor's degree and 7+ years of experience securing federal information systems. Demonstrated experience leading and mentoring information security professionals , including junior and mid-level ISSOs. Experience leading cybersecurity activities in a federal government client environment and working directly with government stakeholders.' Strong working knowledge of NIST Risk Management Framework (RMF) and experience supporting federal systems through security authorization and ATO activities . Experience developing, implementing, assessing, or documenting security controls aligned with FISMA and NIST 800-53 . Experience with vulnerability management, continuous monitoring, security assessments, audits, or compliance reviews for federal systems. Experience providing cybersecurity guidance for AWS-hosted applications and systems . Strong understanding of modern information systems and their technical security considerations. Ability to work effectively with developers, architects, engineers, government stakeholders, and technical and non-technical audiences. Strong written and verbal communication skills, including the ability to communicate security risks and technical findings and develop/present security documentation and executive briefings. Ability to establish priorities, manage competing demands, independently manage security activities, and escalate issues appropriately. Proactive, solutions-oriented approach to identifying risks and improving security practices. Current CBP, DHS, or Top Secret Clearance. Ability to work onsite 3 days per week in Ashburn, VA during standard business hours. Cybersecurity certification such as CISSP, CISM, GIAC, Security+, or another recognized cybersecurity certification. Preferred Education, Experience & Skills Experience developing or supporting RMF and authorization artifacts, including SSPs, ISAs, PTAs, ATTs, POA&Ms , and related documentation. Experience partnering with application development, cloud engineering, and DevSecOps teams to integrate security throughout the SDLC. Experience working in an Agile software development environment using Jira or similar platforms. Experience with GRC tools such as CSAM or similar platforms supporting authorization, compliance, vulnerability management, and security activities. Understanding of AI concepts and practical applications of AI for cybersecurity operations, risk analysis, compliance, or security program management. Our estimated salary range for this position is $88,000 - $ 150,000. This presented salary range is not a guarantee of compensation or salary. Offered salary is based on experience, geographic location, and possibly contractual requirements as appropriate to the role. Salary could fall outside of this range. Who We Are Dev Technology is a growing IT company with an employee-centric culture that works on mission-critical projects for the federal government. We partner with our federal customers to deliver technology services and solutions, and to drive our client's missions forward through innovation. We use Agile and DevSecOps principles to provide services including application development, biometrics and identity management, cloud and infrastructure optimization, IT and legacy modernization, and data management. As a Washington Post Top Workplace award winner for the past THIRTEEN years in a row, the Top Workplaces USA for the past five years, and a recipient of the Companies As Responsive Employers (CARE) Award for the past six years, Dev Technology employees enjoy: Generous and flexible time-off policy Flexible work schedules and telework options, including remote work availability for eligible projects Career development opportunities including a mentorship program, technical and management training through Dev University, hands-on learning through DevLab, tuition reimbursement, and paid training opportunities Industry-leading benefits including a choice of two health plans that include dental and vision, flexible spending account, commuter benefits, life insurance, and more 401K matching with a 5% matching contribution Regular team and company social events including our annual party, happy hours, fitness challenges, and more A focus on community engagement including company wide support activities, employer match for donations, and time off for volunteer efforts To learn more about working at Dev Technology, visit Working At Dev Technology Group Equal Opportunity Employer / Individuals with Disabilities / Protected Veterans Dev Technology Group operates in the following states: AL, AR, AZ, CO, DC, FL, GA, ID, IL, IN, MD, MA, ME, MI, MN, MO, MS, NC, NJ, OH, OR, PA, SC, TN, TX, VA, WV.
Job Description Job Description Information Security Specialist Officer, Technical Lead, AWS Security • RMF & ATO • NIST 800-53 • Cloud Application Security Clearance: Active CBP, DHS, or Top Secret Clearance required Work Arrangement: Hybrid - onsite 3 days/week during standard business hours in Ashburn, VA About the Role Dev Technology Group is seeking a Senior Information Security Specialist to lead and develop a mid-sized team of ISSOs supporting the security, compliance, and authorization of mission-critical federal applications and information systems hosted in AWS. This is a hands-on technical leadership role combining people leadership, federal cybersecurity expertise, and direct collaboration with government and technical stakeholders. You will mentor junior and mid-level ISSOs while partnering with system owners, developers, architects, cloud/infrastructure engineers, security professionals, and government stakeholders throughout the system development lifecycle. You will provide practical security guidance for AWS-hosted applications, lead Risk Management Framework (RMF) and Authority to Operate (ATO) activities, oversee vulnerability management and continuous monitoring, and translate federal cybersecurity requirements into actionable guidance for technical teams. What You'll Do Lead, mentor, and develop a team of ISSOs by establishing priorities, providing technical direction and coaching, and promoting accountability and consistent security practices. Lead and oversee RMF, ATO, security authorization, compliance, vulnerability management, and continuous monitoring activities across a portfolio of federal systems and applications. Partner with ISSMs, system owners, assessors, developers, architects, engineers, and government stakeholders to maintain authorizations, identify risks, and address security requirements. Lead vulnerability management efforts, prioritizing remediation, developing mitigation strategies, and tracking corrective actions through resolution. Develop, assess, document, and support implementation of security controls aligned with FISMA, NIST 800-53, DHS, and client requirements . Prepare and maintain security and authorization documentation, including SSPs, ISAs, audit artifacts, and RMF documentation . Provide cybersecurity guidance for applications and systems deployed in AWS and integrate security throughout the software development lifecycle. Validate security implementation through technical reviews, discussions, interviews, assessments, and tabletop exercises. Support security audits, assessments, compliance reviews, and reviews of information systems and network connections. Interpret federal and client security policies and translate requirements into practical guidance for technical and development teams. Identify and escalate security risks, communicate priorities and remediation status, and provide clear visibility to Dev Technology leadership and government stakeholders. Develop and present security metrics, status reports, risk assessments, and executive briefings . Establish and improve security processes, procedures, templates, dashboards, and workflows to improve consistency, accountability, and efficiency across the ISSO team. Build trusted relationships with government clients through proactive communication, collaboration, and face-to-face engagement. Required Education, Experience & Skills Bachelor's degree and 7+ years of experience securing federal information systems. Demonstrated experience leading and mentoring information security professionals , including junior and mid-level ISSOs. Experience leading cybersecurity activities in a federal government client environment and working directly with government stakeholders.' Strong working knowledge of NIST Risk Management Framework (RMF) and experience supporting federal systems through security authorization and ATO activities . Experience developing, implementing, assessing, or documenting security controls aligned with FISMA and NIST 800-53 . Experience with vulnerability management, continuous monitoring, security assessments, audits, or compliance reviews for federal systems. Experience providing cybersecurity guidance for AWS-hosted applications and systems . Strong understanding of modern information systems and their technical security considerations. Ability to work effectively with developers, architects, engineers, government stakeholders, and technical and non-technical audiences. Strong written and verbal communication skills, including the ability to communicate security risks and technical findings and develop/present security documentation and executive briefings. Ability to establish priorities, manage competing demands, independently manage security activities, and escalate issues appropriately. Proactive, solutions-oriented approach to identifying risks and improving security practices. Current CBP, DHS, or Top Secret Clearance. Ability to work onsite 3 days per week in Ashburn, VA during standard business hours. Cybersecurity certification such as CISSP, CISM, GIAC, Security+, or another recognized cybersecurity certification. Preferred Education, Experience & Skills Experience developing or supporting RMF and authorization artifacts, including SSPs, ISAs, PTAs, ATTs, POA&Ms , and related documentation. Experience partnering with application development, cloud engineering, and DevSecOps teams to integrate security throughout the SDLC. Experience working in an Agile software development environment using Jira or similar platforms. Experience with GRC tools such as CSAM or similar platforms supporting authorization, compliance, vulnerability management, and security activities. Understanding of AI concepts and practical applications of AI for cybersecurity operations, risk analysis, compliance, or security program management. Our estimated salary range for this position is $88,000 - $ 150,000. This presented salary range is not a guarantee of compensation or salary. Offered salary is based on experience, geographic location, and possibly contractual requirements as appropriate to the role. Salary could fall outside of this range. Who We Are Dev Technology is a growing IT company with an employee-centric culture that works on mission-critical projects for the federal government. We partner with our federal customers to deliver technology services and solutions, and to drive our client's missions forward through innovation. We use Agile and DevSecOps principles to provide services including application development, biometrics and identity management, cloud and infrastructure optimization, IT and legacy modernization, and data management. As a Washington Post Top Workplace award winner for the past THIRTEEN years in a row, the Top Workplaces USA for the past five years, and a recipient of the Companies As Responsive Employers (CARE) Award for the past six years, Dev Technology employees enjoy: Generous and flexible time-off policy Flexible work schedules and telework options, including remote work availability for eligible projects Career development opportunities including a mentorship program, technical and management training through Dev University, hands-on learning through DevLab, tuition reimbursement, and paid training opportunities Industry-leading benefits including a choice of two health plans that include dental and vision, flexible spending account, commuter benefits, life insurance, and more 401K matching with a 5% matching contribution Regular team and company social events including our annual party, happy hours, fitness challenges, and more A focus on community engagement including company wide support activities, employer match for donations, and time off for volunteer efforts To learn more about working at Dev Technology, visit Working At Dev Technology Group Equal Opportunity Employer / Individuals with Disabilities / Protected Veterans Dev Technology Group operates in the following states: AL, AR, AZ, CO, DC, FL, GA, ID, IL, IN, MD, MA, ME, MI, MN, MO, MS, NC, NJ, OH, OR, PA, SC, TN, TX, VA, WV.
KPMG
Washington, Washington DC
The KPMG Advisory practice is at the forefront of transformation, offering excellent opportunities for individuals to advance their careers and expertise with KPMG. Looking ahead, we anticipate continued evolution and success within the practice, fostering both personal and professional development, thereby creating new pathways for growth. In this ever-changing market environment, our professionals must be adaptable and thrive in a collaborative, team-driven culture. At KPMG, our people are our number one priority. With a wealth of learning and career development opportunities, a world-class training facility, and leading market tools, we help our people continue to grow both professionally and personally. If you're looking for a firm with a strong team connection where you can be your whole self, have an impact, advance your skills, deepen your experiences, and have the flexibility and access to constantly find new areas of inspiration and expand your capabilities, then consider a career in Advisory. KPMG is currently seeking a Specialist Director to join our Federal Advisory practice. Responsibilities: Assist in the design, engineering, and implementation of Zero Trust architectures (ZTA) across enterprise environments, ensuring alignment with CISA Zero Trust Maturity Models and federal mandates Collaborate with senior architects to integrate security controls into systems design, evaluating new tools / technologies to support a comprehensive defense-in-depth strategy Integrate security controls into the software development lifecycle (DevSecOps), perform application vulnerability assessments, and establish secure application onboarding processes for enterprise environments Support secure cloud migration initiatives, ensuring on-premise infrastructures and applications are safely transitioned to cloud environments (AWS, Azure, GCP) without compromising security postures or compliance requirements Implement / manage robust identity solutions, focusing on Identity, Credential, and Access Management (ICAM), Multi-Factor Authentication (MFA), and least-privilege access frameworks Ensure all security architectures and implementations comply with federal frameworks / standards, including NIST SP 800-53, NIST SP 800-207, Risk Management Framework (RMF), and Dod Cloud Computing Security Requirements Guide (SRG) Develop and tune use cases for Security Information and Event Management (SIEM) platforms and automate incident response workflows using Security Orchestration, Automation, and Response (SOAR) tools Monitor enterprise environments for anomalous activity, analyze security alerts, and assist in incident remediation efforts Qualifications: A minimum of eight years of cyber security engineering / solutions architecture experience; U.S. Federal government consulting experience preferred Bachelor's degree from an accredited college/university Preferred Certifications: CISSP (Certified Information Systems Security Professional), other relevant certifications (e.g. - CCSP, AWS Certified Security, Azure Security Engineer) Experience working within federal, DoD, or highly regulated environments with a strong understanding of federal compliance frameworks (NIST, RMF, FedRAMP) Experience planning and executing secure cloud migrations and managing native cloud security controls Experience / knowledge implementing and managing SIEM and SOAR platforms (e.g. - Splunk, Sentinel, Cortex XSOAR) Strong background in Identity and Access Management (e.g. - Okta, CyberArk, Microsoft Entra ID) Ability to travel as required to support firm engagements Applicant must possess a U.S. Government Secret clearance KPMG LLP and its affiliates and subsidiaries ("KPMG") complies with all local/state regulations regarding displaying salary ranges. If required, the ranges displayed below or via the URL below are specifically for those potential hires who will work in the location(s) listed. Any offered salary is determined based on relevant factors such as applicant's skills, job responsibilities, prior relevant experience, certain degrees and certifications and market considerations. In addition, KPMG is proud to offer a comprehensive, competitive benefits package, with options designed to help you make the best decisions for yourself, your family, and your lifestyle. Available benefits are based on eligibility. Our Total Rewards package includes a variety of medical and dental plans, vision coverage, disability and life insurance, 401(k) plans, and a robust suite of personal well-being benefits to support your mental health. Depending on job classification, standard work hours, and years of service, KPMG provides Personal Time Off per fiscal year. Additionally, each year KPMG publishes a calendar of holidays to be observed during the year and provides eligible employees two breaks each year where employees will not be required to use Personal Time Off; one is at year end and the other is around the July 4th holiday. Additional details about our benefits can be found towards the bottom of our KPMG US Careers site at Benefits & How We Work . Follow this link to obtain salary ranges by city outside of CA: KPMG offers a comprehensive compensation and benefits package. KPMG is an equal opportunity employer. KPMG complies with all applicable federal, state and local laws regarding recruitment and hiring. All qualified applicants are considered for employment without regard to race, color, religion, age, sex, sexual orientation, gender identity, national origin, citizenship status, disability, protected veteran status, or any other category protected by applicable federal, state or local laws. The attached link contains further information regarding KPMG's compliance with federal, state and local recruitment and hiring laws. No phone calls or agencies please. KPMG recruits on a rolling basis. Candidates are considered as they apply, until the opportunity is filled. Candidates are encouraged to apply expeditiously to any role(s) for which they are qualified that is also of interest to them. Los Angeles County applicants: Material job duties for this position are listed above. Criminal history may have a direct, adverse, and negative relationship with some of the material job duties of this position. These include the duties and responsibilities listed above, as well as the abilities to adhere to company policies, exercise sound judgment, effectively manage stress and work safely and respectfully with others, exhibit trustworthiness, and safeguard business operations and company reputation. Pursuant to the California Fair Chance Act, Los Angeles County Fair Chance Ordinance for Employers, Fair Chance Initiative for Hiring Ordinance, and San Francisco Fair Chance Ordinance, we will consider for employment qualified applicants with arrest and conviction records.
The KPMG Advisory practice is at the forefront of transformation, offering excellent opportunities for individuals to advance their careers and expertise with KPMG. Looking ahead, we anticipate continued evolution and success within the practice, fostering both personal and professional development, thereby creating new pathways for growth. In this ever-changing market environment, our professionals must be adaptable and thrive in a collaborative, team-driven culture. At KPMG, our people are our number one priority. With a wealth of learning and career development opportunities, a world-class training facility, and leading market tools, we help our people continue to grow both professionally and personally. If you're looking for a firm with a strong team connection where you can be your whole self, have an impact, advance your skills, deepen your experiences, and have the flexibility and access to constantly find new areas of inspiration and expand your capabilities, then consider a career in Advisory. KPMG is currently seeking a Specialist Director to join our Federal Advisory practice. Responsibilities: Assist in the design, engineering, and implementation of Zero Trust architectures (ZTA) across enterprise environments, ensuring alignment with CISA Zero Trust Maturity Models and federal mandates Collaborate with senior architects to integrate security controls into systems design, evaluating new tools / technologies to support a comprehensive defense-in-depth strategy Integrate security controls into the software development lifecycle (DevSecOps), perform application vulnerability assessments, and establish secure application onboarding processes for enterprise environments Support secure cloud migration initiatives, ensuring on-premise infrastructures and applications are safely transitioned to cloud environments (AWS, Azure, GCP) without compromising security postures or compliance requirements Implement / manage robust identity solutions, focusing on Identity, Credential, and Access Management (ICAM), Multi-Factor Authentication (MFA), and least-privilege access frameworks Ensure all security architectures and implementations comply with federal frameworks / standards, including NIST SP 800-53, NIST SP 800-207, Risk Management Framework (RMF), and Dod Cloud Computing Security Requirements Guide (SRG) Develop and tune use cases for Security Information and Event Management (SIEM) platforms and automate incident response workflows using Security Orchestration, Automation, and Response (SOAR) tools Monitor enterprise environments for anomalous activity, analyze security alerts, and assist in incident remediation efforts Qualifications: A minimum of eight years of cyber security engineering / solutions architecture experience; U.S. Federal government consulting experience preferred Bachelor's degree from an accredited college/university Preferred Certifications: CISSP (Certified Information Systems Security Professional), other relevant certifications (e.g. - CCSP, AWS Certified Security, Azure Security Engineer) Experience working within federal, DoD, or highly regulated environments with a strong understanding of federal compliance frameworks (NIST, RMF, FedRAMP) Experience planning and executing secure cloud migrations and managing native cloud security controls Experience / knowledge implementing and managing SIEM and SOAR platforms (e.g. - Splunk, Sentinel, Cortex XSOAR) Strong background in Identity and Access Management (e.g. - Okta, CyberArk, Microsoft Entra ID) Ability to travel as required to support firm engagements Applicant must possess a U.S. Government Secret clearance KPMG LLP and its affiliates and subsidiaries ("KPMG") complies with all local/state regulations regarding displaying salary ranges. If required, the ranges displayed below or via the URL below are specifically for those potential hires who will work in the location(s) listed. Any offered salary is determined based on relevant factors such as applicant's skills, job responsibilities, prior relevant experience, certain degrees and certifications and market considerations. In addition, KPMG is proud to offer a comprehensive, competitive benefits package, with options designed to help you make the best decisions for yourself, your family, and your lifestyle. Available benefits are based on eligibility. Our Total Rewards package includes a variety of medical and dental plans, vision coverage, disability and life insurance, 401(k) plans, and a robust suite of personal well-being benefits to support your mental health. Depending on job classification, standard work hours, and years of service, KPMG provides Personal Time Off per fiscal year. Additionally, each year KPMG publishes a calendar of holidays to be observed during the year and provides eligible employees two breaks each year where employees will not be required to use Personal Time Off; one is at year end and the other is around the July 4th holiday. Additional details about our benefits can be found towards the bottom of our KPMG US Careers site at Benefits & How We Work . Follow this link to obtain salary ranges by city outside of CA: KPMG offers a comprehensive compensation and benefits package. KPMG is an equal opportunity employer. KPMG complies with all applicable federal, state and local laws regarding recruitment and hiring. All qualified applicants are considered for employment without regard to race, color, religion, age, sex, sexual orientation, gender identity, national origin, citizenship status, disability, protected veteran status, or any other category protected by applicable federal, state or local laws. The attached link contains further information regarding KPMG's compliance with federal, state and local recruitment and hiring laws. No phone calls or agencies please. KPMG recruits on a rolling basis. Candidates are considered as they apply, until the opportunity is filled. Candidates are encouraged to apply expeditiously to any role(s) for which they are qualified that is also of interest to them. Los Angeles County applicants: Material job duties for this position are listed above. Criminal history may have a direct, adverse, and negative relationship with some of the material job duties of this position. These include the duties and responsibilities listed above, as well as the abilities to adhere to company policies, exercise sound judgment, effectively manage stress and work safely and respectfully with others, exhibit trustworthiness, and safeguard business operations and company reputation. Pursuant to the California Fair Chance Act, Los Angeles County Fair Chance Ordinance for Employers, Fair Chance Initiative for Hiring Ordinance, and San Francisco Fair Chance Ordinance, we will consider for employment qualified applicants with arrest and conviction records.
Dark Wolf Solutions
Melbourne, Florida
Job Description Job Description Dark Wolf Solutions is seeking a motivated and experienced Tenant Onboarding Specialist to join our collaborative team that supports a growing, multi-tenant cloud platform for our Space Force customer. As the platform scales, we are adding team members to manage the increasing volume of compliance documentation and continuous monitoring activities. In this role, you will be instrumental in planning, implementing, managing, monitoring, and upgrading our information system cybersecurity posture in accordance with industry-leading standards. You will play a critical part in ensuring our organization's data, infrastructure, and processes are protected by enabling appropriate security controls. Ideal candidates should have a strong sense of process development, organization, and communication skills. This role can be supported from any Dark Wolf Location from a hybrid capacity. Contract is based out of Melbourne, FL. Responsibilities: Work collaboratively to plan, implement, manage, monitor, and upgrade information system cybersecurity posture in accordance with NIST 800-53, NIST 800-160 v1 & v2, and NIST 800-207. Ensure the organization's data, infrastructure, and processes are protected by enabling appropriate security controls. Conducting regular risk assessments and vulnerability scans to identify potential security gaps and recommend appropriate mitigation strategies. Configure and manage compliance scanning and vulnerability tools to perform regular assessments and generate reports. Assisting in the development, implementation, and enforcement of information security policies and procedures. Research and document network and system vulnerabilities, providing clear and actionable recommendations. Participate in security incident response activities, providing technical expertise and support. Contribute to the DevSecOps cycle and change management process, ensuring security is integrated throughout the software development lifecycle. Effectively communicate security requirements, best practices, and remediation strategies to stakeholders across the organization. Qualifications: Bachelor's Degree or equivalent experience in Computer Science, Information Systems, Engineering, or a related technical discipline. Minimum of 2 years of experience in cybersecurity. Experience working with cloud environments (AWS, Azure, GCP) including cloud security control mechanisms (AWS IAM, Azure AD). Experience working with Commercial and Open-Source security tools, methods, and techniques. Experience with DevSecOps, continuous monitoring strategies, and knowledge of Risk Management Framework. Basic understanding of industry best practices related to the implementation of cybersecurity tools, information security policy, NIST, and FISMA controls. Demonstrated experience researching, analyzing, and applying cybersecurity mitigation strategies to address vulnerabilities. Experience working with Department of Defense security standards and tools (e.g., STIGs, SRGs, SCC, CIS). US Citizenship and an active Secret security clearance. Desired Qualifications: Experience implementing and using vulnerability scanning tools (e.g. Nessus, Tenable.sc, AWS Inspector, etc.). Experience implementing and using SIEM tools (e.g., Splunk, Elastic, etc.). Experience with various compliance tools, frameworks, and standards used in the DoD (e.g., NIST 800-53 Rev. 4/5, FedRAMP). Ability to identify basic coding flaws and apply secure code documentation. Knowledge of Software Development models including quality assurance processes. Security+ and/or DoD 8570 IAT II-level certification or ability to attain within 6 months of hire. This position will be a remote/hybrid role based out of Melbourne, FL or other Dark Wolf office locations. The estimated compensation range is $100,000.00 - $120,000.00, commensurate on experience and technical interview. We are proud to be an EEO/AA employer Minorities/Women/Veterans/Disabled and other protected categories. In compliance with federal law, all persons hired will be required to verify identity, confirm US Citizenship, and complete the required employment eligibility verification upon hire.
Job Description Job Description Dark Wolf Solutions is seeking a motivated and experienced Tenant Onboarding Specialist to join our collaborative team that supports a growing, multi-tenant cloud platform for our Space Force customer. As the platform scales, we are adding team members to manage the increasing volume of compliance documentation and continuous monitoring activities. In this role, you will be instrumental in planning, implementing, managing, monitoring, and upgrading our information system cybersecurity posture in accordance with industry-leading standards. You will play a critical part in ensuring our organization's data, infrastructure, and processes are protected by enabling appropriate security controls. Ideal candidates should have a strong sense of process development, organization, and communication skills. This role can be supported from any Dark Wolf Location from a hybrid capacity. Contract is based out of Melbourne, FL. Responsibilities: Work collaboratively to plan, implement, manage, monitor, and upgrade information system cybersecurity posture in accordance with NIST 800-53, NIST 800-160 v1 & v2, and NIST 800-207. Ensure the organization's data, infrastructure, and processes are protected by enabling appropriate security controls. Conducting regular risk assessments and vulnerability scans to identify potential security gaps and recommend appropriate mitigation strategies. Configure and manage compliance scanning and vulnerability tools to perform regular assessments and generate reports. Assisting in the development, implementation, and enforcement of information security policies and procedures. Research and document network and system vulnerabilities, providing clear and actionable recommendations. Participate in security incident response activities, providing technical expertise and support. Contribute to the DevSecOps cycle and change management process, ensuring security is integrated throughout the software development lifecycle. Effectively communicate security requirements, best practices, and remediation strategies to stakeholders across the organization. Qualifications: Bachelor's Degree or equivalent experience in Computer Science, Information Systems, Engineering, or a related technical discipline. Minimum of 2 years of experience in cybersecurity. Experience working with cloud environments (AWS, Azure, GCP) including cloud security control mechanisms (AWS IAM, Azure AD). Experience working with Commercial and Open-Source security tools, methods, and techniques. Experience with DevSecOps, continuous monitoring strategies, and knowledge of Risk Management Framework. Basic understanding of industry best practices related to the implementation of cybersecurity tools, information security policy, NIST, and FISMA controls. Demonstrated experience researching, analyzing, and applying cybersecurity mitigation strategies to address vulnerabilities. Experience working with Department of Defense security standards and tools (e.g., STIGs, SRGs, SCC, CIS). US Citizenship and an active Secret security clearance. Desired Qualifications: Experience implementing and using vulnerability scanning tools (e.g. Nessus, Tenable.sc, AWS Inspector, etc.). Experience implementing and using SIEM tools (e.g., Splunk, Elastic, etc.). Experience with various compliance tools, frameworks, and standards used in the DoD (e.g., NIST 800-53 Rev. 4/5, FedRAMP). Ability to identify basic coding flaws and apply secure code documentation. Knowledge of Software Development models including quality assurance processes. Security+ and/or DoD 8570 IAT II-level certification or ability to attain within 6 months of hire. This position will be a remote/hybrid role based out of Melbourne, FL or other Dark Wolf office locations. The estimated compensation range is $100,000.00 - $120,000.00, commensurate on experience and technical interview. We are proud to be an EEO/AA employer Minorities/Women/Veterans/Disabled and other protected categories. In compliance with federal law, all persons hired will be required to verify identity, confirm US Citizenship, and complete the required employment eligibility verification upon hire.