Job Description Job Description We are seeking a Senior Network Security Engineer for an operations-first role supporting enterprise network security infrastructure across on-premises, remote-access, hybrid-cloud, and cloud-connected environments. This is not primarily an architecture/design role. The priority is a hands-on engineer who can administer, configure, maintain, troubleshoot, patch, upgrade, back up, validate, document, and operate production security platforms with minimal ramp-up. Firewall operations: hands-on Cisco and Palo Alto firewall administration, rule changes, NAT, troubleshooting, policy cleanup, upgrades, backups, logging, and production support. VPN / remote access: support for remote-access VPN, site-to-site VPN, user connectivity issues, certificates, authentication flows, and after-hours troubleshooting. RSA / MFA administration: RSA SecurID or equivalent MFA operations, token support, server administration, user troubleshooting, VPN integration, certificates, patching, backups, logs, and monitoring. Day-to-day operations: ticket resolution, monitoring alerts, health checks, change requests, incident support, maintenance windows, operational reporting, and customer support. Configuration and administration: installing, configuring, maintaining, patching, upgrading, backing up, validating, and troubleshooting assigned security platforms. Production troubleshooting: strong TCP/IP, DNS, routing, firewall logs, packet captures, VPN authentication, certificate, and connectivity troubleshooting. Documentation and process discipline: SOPs, runbooks, diagrams, change records, rollback plans, evidence collection, knowledge transfer, and formal change management. Federal/customer environment maturity: Public Trust eligibility, regulated-environment documentation, customer support, cross-team coordination, and comfort working with government stakeholders. The best candidate can credibly say: "I have operated enterprise Cisco and Palo Alto firewalls in production, handled firewall rule changes and troubleshooting, supported VPN users and site-to-site tunnels, administered or supported RSA/MFA tied to VPN access, followed formal change-management processes, maintained documentation and backups, and can step into daily operational support with minimal ramp-up." Scope and Role Boundaries Primary platforms include Cisco ASA/Firepower/FTD/FMC, Palo Alto NGFW/Panorama/GlobalProtect, remote-access and site-to-site VPN, RSA SecurID Authentication Manager or comparable MFA, monitoring/logging/SIEM integrations, and related network security controls. Coordinate with SOC/NOC, cloud, identity/directory, wireless/LAN, server, endpoint, system owner, application, governance, and vendor teams during changes, incidents, troubleshooting, compliance, and audit support. Cloudflare, Cisco ISE/NAC, secure web/email gateways, packet visibility tools, SD-WAN/SASE/ZTNA, AWS/Azure security, and F5/application-delivery awareness are useful where they intersect with assigned operational support, but the core need is firewall, VPN, RSA/MFA, and production operations. Key Responsibilities Provide daily, weekly, monthly, and annual operational support for assigned security systems, including tickets, alerts, health checks, email/phone support, metrics, status reporting, and operational validation. Administer and troubleshoot enterprise firewalls, including rule bases, NAT, segmentation, high availability, threat prevention, VPN integration, logging, secure baselines, rule reviews, recertification, cleanup, and decommissioning. Install, configure, maintain, patch, upgrade, back up, and validate firewall, VPN, MFA, and related network security systems in production environments. Support remote-access VPN, site-to-site VPN, partner connectivity, cloud connectivity, mobile/remote users, certificates, authentication policies, availability, utilization, and user access issues. Maintain and troubleshoot RSA SecurID Authentication Manager or equivalent MFA services, including servers/appliances, agents, certificates, HA, backups, logs, monitoring, directory integration, VPN authentication, and token lifecycle support. Respond to incidents, vulnerability notices, urgent requests, vendor advisories, PSIRT notices, system alerts, and emergency troubleshooting while minimizing service disruption. Use firewall logs, VPN logs, packet captures, SIEM data, monitoring tools, DNS/routing checks, and standard diagnostics to resolve complex connectivity, authentication, TLS/certificate, and application-flow issues. Create and maintain topology diagrams, equipment inventories, configurations, SOPs, runbooks, implementation plans, rollback plans, build/upgrade procedures, troubleshooting notes, and knowledge articles. Follow approved change, release, incident, problem, and configuration-management processes; prepare change records, peer-review materials, validation evidence, root-cause analysis, metrics, and audit artifacts. Support vulnerability remediation, POA&M tracking, continuous monitoring, compliance reviews, audit evidence collection, and coordination with ISSO, system owner, and security governance teams. Requirements 7+ years of experience in network security engineering, network infrastructure, cybersecurity infrastructure, or a closely related role. 5+ years of hands-on experience administering, maintaining, and troubleshooting enterprise firewall platforms in production environments. Hands-on experience with Cisco security technologies such as Cisco ASA, Firepower, FTD, FMC, AnyConnect/Secure Client, or equivalent Cisco firewall/VPN platforms. Hands-on experience with Palo Alto Networks technologies such as NGFW, Panorama, GlobalProtect, security profiles, App-ID/User-ID, logging, and policy optimization. Experience administering or supporting RSA SecurID Authentication Manager or comparable enterprise MFA/two-factor authentication platforms, including token support, server operations, patching/upgrades, backups, certificates, monitoring, and directory/VPN integration. Strong knowledge of firewall policy, NAT, VPNs, routing, DNS, DHCP, BGP, TLS/certificates, packet captures, log analysis, segmentation, high availability, and common network diagnostic tools. Experience with enterprise monitoring, logging, SIEM, alerting, vulnerability management, incident response, formal change management, and regulated-environment documentation. Ability to create clear technical documentation, support customers and stakeholders, prioritize operational work, communicate clearly, and coordinate across technical teams. Ability to obtain and maintain a Public Trust background investigation. Desired Certifications Relevant certifications are helpful but should not replace demonstrated hands-on experience. Examples include CCNP Security, CCIE Security, PCNSE, PCCSE, CISSP, CCSP, AWS Certified Security - Specialty, AWS Advanced Networking - Specialty, Microsoft Certified: Azure Security Engineer Associate, Microsoft Certified: Azure Network Engineer Associate, CompTIA Security+, CompTIA CySA+, GIAC certifications, or equivalent vendor/cloud certifications. Core Competencies Enterprise firewall engineering and policy lifecycle management VPN, remote access, RSA/MFA, and token lifecycle operations Cloudflare, edge security, secure access, and Zero Trust support Content filtering, secure web/email gateway, and NAC operations Hybrid-cloud network security and secure connectivity Monitoring, logging, SIEM integration, and incident response support Security visibility, packet analysis, and advanced troubleshooting Vulnerability remediation, compliance evidence, and POA&M support Change management, documentation, reporting, and operational metrics Technical leadership, customer support, and cross-team collaboration Benefits 401(k) 401(k) matching Dental insurance Flexible schedule Flexible spending account Health insurance Health savings account Life insurance Paid time off Professional development assistance Referral program Retirement plan Tuition reimbursement Vision insurance
09/28/2026
Full time
Job Description Job Description We are seeking a Senior Network Security Engineer for an operations-first role supporting enterprise network security infrastructure across on-premises, remote-access, hybrid-cloud, and cloud-connected environments. This is not primarily an architecture/design role. The priority is a hands-on engineer who can administer, configure, maintain, troubleshoot, patch, upgrade, back up, validate, document, and operate production security platforms with minimal ramp-up. Firewall operations: hands-on Cisco and Palo Alto firewall administration, rule changes, NAT, troubleshooting, policy cleanup, upgrades, backups, logging, and production support. VPN / remote access: support for remote-access VPN, site-to-site VPN, user connectivity issues, certificates, authentication flows, and after-hours troubleshooting. RSA / MFA administration: RSA SecurID or equivalent MFA operations, token support, server administration, user troubleshooting, VPN integration, certificates, patching, backups, logs, and monitoring. Day-to-day operations: ticket resolution, monitoring alerts, health checks, change requests, incident support, maintenance windows, operational reporting, and customer support. Configuration and administration: installing, configuring, maintaining, patching, upgrading, backing up, validating, and troubleshooting assigned security platforms. Production troubleshooting: strong TCP/IP, DNS, routing, firewall logs, packet captures, VPN authentication, certificate, and connectivity troubleshooting. Documentation and process discipline: SOPs, runbooks, diagrams, change records, rollback plans, evidence collection, knowledge transfer, and formal change management. Federal/customer environment maturity: Public Trust eligibility, regulated-environment documentation, customer support, cross-team coordination, and comfort working with government stakeholders. The best candidate can credibly say: "I have operated enterprise Cisco and Palo Alto firewalls in production, handled firewall rule changes and troubleshooting, supported VPN users and site-to-site tunnels, administered or supported RSA/MFA tied to VPN access, followed formal change-management processes, maintained documentation and backups, and can step into daily operational support with minimal ramp-up." Scope and Role Boundaries Primary platforms include Cisco ASA/Firepower/FTD/FMC, Palo Alto NGFW/Panorama/GlobalProtect, remote-access and site-to-site VPN, RSA SecurID Authentication Manager or comparable MFA, monitoring/logging/SIEM integrations, and related network security controls. Coordinate with SOC/NOC, cloud, identity/directory, wireless/LAN, server, endpoint, system owner, application, governance, and vendor teams during changes, incidents, troubleshooting, compliance, and audit support. Cloudflare, Cisco ISE/NAC, secure web/email gateways, packet visibility tools, SD-WAN/SASE/ZTNA, AWS/Azure security, and F5/application-delivery awareness are useful where they intersect with assigned operational support, but the core need is firewall, VPN, RSA/MFA, and production operations. Key Responsibilities Provide daily, weekly, monthly, and annual operational support for assigned security systems, including tickets, alerts, health checks, email/phone support, metrics, status reporting, and operational validation. Administer and troubleshoot enterprise firewalls, including rule bases, NAT, segmentation, high availability, threat prevention, VPN integration, logging, secure baselines, rule reviews, recertification, cleanup, and decommissioning. Install, configure, maintain, patch, upgrade, back up, and validate firewall, VPN, MFA, and related network security systems in production environments. Support remote-access VPN, site-to-site VPN, partner connectivity, cloud connectivity, mobile/remote users, certificates, authentication policies, availability, utilization, and user access issues. Maintain and troubleshoot RSA SecurID Authentication Manager or equivalent MFA services, including servers/appliances, agents, certificates, HA, backups, logs, monitoring, directory integration, VPN authentication, and token lifecycle support. Respond to incidents, vulnerability notices, urgent requests, vendor advisories, PSIRT notices, system alerts, and emergency troubleshooting while minimizing service disruption. Use firewall logs, VPN logs, packet captures, SIEM data, monitoring tools, DNS/routing checks, and standard diagnostics to resolve complex connectivity, authentication, TLS/certificate, and application-flow issues. Create and maintain topology diagrams, equipment inventories, configurations, SOPs, runbooks, implementation plans, rollback plans, build/upgrade procedures, troubleshooting notes, and knowledge articles. Follow approved change, release, incident, problem, and configuration-management processes; prepare change records, peer-review materials, validation evidence, root-cause analysis, metrics, and audit artifacts. Support vulnerability remediation, POA&M tracking, continuous monitoring, compliance reviews, audit evidence collection, and coordination with ISSO, system owner, and security governance teams. Requirements 7+ years of experience in network security engineering, network infrastructure, cybersecurity infrastructure, or a closely related role. 5+ years of hands-on experience administering, maintaining, and troubleshooting enterprise firewall platforms in production environments. Hands-on experience with Cisco security technologies such as Cisco ASA, Firepower, FTD, FMC, AnyConnect/Secure Client, or equivalent Cisco firewall/VPN platforms. Hands-on experience with Palo Alto Networks technologies such as NGFW, Panorama, GlobalProtect, security profiles, App-ID/User-ID, logging, and policy optimization. Experience administering or supporting RSA SecurID Authentication Manager or comparable enterprise MFA/two-factor authentication platforms, including token support, server operations, patching/upgrades, backups, certificates, monitoring, and directory/VPN integration. Strong knowledge of firewall policy, NAT, VPNs, routing, DNS, DHCP, BGP, TLS/certificates, packet captures, log analysis, segmentation, high availability, and common network diagnostic tools. Experience with enterprise monitoring, logging, SIEM, alerting, vulnerability management, incident response, formal change management, and regulated-environment documentation. Ability to create clear technical documentation, support customers and stakeholders, prioritize operational work, communicate clearly, and coordinate across technical teams. Ability to obtain and maintain a Public Trust background investigation. Desired Certifications Relevant certifications are helpful but should not replace demonstrated hands-on experience. Examples include CCNP Security, CCIE Security, PCNSE, PCCSE, CISSP, CCSP, AWS Certified Security - Specialty, AWS Advanced Networking - Specialty, Microsoft Certified: Azure Security Engineer Associate, Microsoft Certified: Azure Network Engineer Associate, CompTIA Security+, CompTIA CySA+, GIAC certifications, or equivalent vendor/cloud certifications. Core Competencies Enterprise firewall engineering and policy lifecycle management VPN, remote access, RSA/MFA, and token lifecycle operations Cloudflare, edge security, secure access, and Zero Trust support Content filtering, secure web/email gateway, and NAC operations Hybrid-cloud network security and secure connectivity Monitoring, logging, SIEM integration, and incident response support Security visibility, packet analysis, and advanced troubleshooting Vulnerability remediation, compliance evidence, and POA&M support Change management, documentation, reporting, and operational metrics Technical leadership, customer support, and cross-team collaboration Benefits 401(k) 401(k) matching Dental insurance Flexible schedule Flexible spending account Health insurance Health savings account Life insurance Paid time off Professional development assistance Referral program Retirement plan Tuition reimbursement Vision insurance
Job Description Job Description Important Notice for Applicants: At Bixal, we want to ensure a transparent and secure application process for all candidates. Official communication will come from an email address ending or from Messages from other sources may be fraudulent, and you should exercise care to avoid any links or attachments included. Bixal will ensure that individuals with disabilities are provided reasonable accommodation to participate in the job application or interview process, to perform essential job functions, and to receive other benefits and privileges of employment. Need Assistance or a Reasonable Accommodation? If you need assistance or a reasonable accommodation to complete your application, we're here to help. Please reach out to us at and let us know how we can support you. You do not need to share personal details or disclose the nature of your request. You can expect a response from a team member within 24 hours during the regular work week and on the next operating day during the weekend or holidays. Why Bixal? Bixal is a consulting company headquartered in Fairfax, VA, working alongside governments and organizations to help them deliver better services and experiences to the communities they serve. Using evidence-based knowledge and technology, Bixal empowers clients to deliver on their missions more effectively by fostering a culture of learning and continuous improvement. Our values: People-First : Emphasizing the importance of people in all aspects of work. Collaboration and Transparency : Valuing teamwork and open communication. Growth Mindset : Encouraging innovation and continuous improvement. Creating Lasting Impact : Focusing on meaningful outcomes and positive change. About the role: Bixal is seeking a Senior Records Information Management Specialist for a project that supports a large-scale outreach and engagement effort, delivering strategic communications, content and creative services, digital strategy, and audience engagement across public-facing websites, applications, and social media platforms. The work is paired with the IT, cybersecurity, and data operations needed to keep that digital presence secure, reliable, and available around the clock. The program's mission is to ensure the intended audience receives timely, accurate, and accessible information about the programs, services, and policies that affect them - with content and platforms built to scale, adapt to changing needs, and hold up to federal compliance and security standards. The Senior Records Information Management Specialist will lead the design, governance, and day-to-day administration of the program's records management function, ensuring that electronic records generated across public-facing websites, applications, and social media platforms are properly captured, controlled, archived, and preserved in accordance with federal recordkeeping law and DoD policy. This role serves as the primary bridge between the content operation and the Government Records Manager, translating recordkeeping requirements into practical, user-centric processes that content and digital teams can execute consistently. This is a full-time position contingent on contract award by our client, with a defined performance period of one year with two one-year option periods. This role offers you a unique opportunity to make a meaningful impact on a project that aligns with Bixal's mission of delivering innovative, human-centered solutions. While the role has a fixed duration, we are committed to transparency and collaboration, keeping you informed about contract updates and new opportunities. At Bixal, we support your professional journey, ensuring your experience reflects our inclusive, purpose-driven culture and prepares you for future success. Location This role can work remotely from anywhere in the USA. You must be legally authorized to work in the US. Bixal does not provide visa sponsorship. Compensation: The salary range for this role is $92,000 - $95,000. In the spirit of transparency, most offers tend to land near the midpoint of the range. We make compensation decisions thoughtfully, considering your experience, the skills you bring, and our commitment to internal equity. Fairness and transparency are core to how we operate. Responsibilities: Administer the organization's records management program, ensuring records of business and mission activity are properly identified, scheduled, captured, and preserved in compliance with federal recordkeeping law and DoD records management policy. Develop, implement, and annually update records management SOPs and guidance, keeping pace with evolving Federal, DoD, and program-specific policy. Develop and maintain a records management plan governing the transfer, accessioning, and eventual disposition of permanent electronic records to the appropriate federal archival authority, and lead execution of related transfer activities. Conduct periodic compliance reviews and risk assessments of the records program, documenting gaps and recommending corrective actions to leadership. Partner with the Government Records Manager and content stakeholders to design intuitive, user-centric records management systems and workflows; conduct user research to identify pain points and streamline compliance. Direct archiving and digital preservation activities, including secure storage, metadata tagging and indexing, and backup/disaster-recovery practices that ensure long-term accountability, availability, and integrity of records. Ensure archived and published content remains tamper-proof, verifiable, and retained per applicable records schedules, conducting regular audits of archiving, access-control, and publishing workflows. Establish and enforce access-control, permissions, and audit-trail practices across content systems to maintain a defensible chain of custody. Ensure records considerations are reflected in broader digital strategy planning, content governance, and reporting. Deliver required records-related compliance and status reporting on established schedules, and brief findings and recommendations to Government stakeholders. Provide subject-matter guidance and training to content and digital teams on records identification, tagging, and retention responsibilities. Other relevant duties as qualified/trained to perform Qualifications: This position requires an active Secret Clearance. BA/BS in Information Science, Library/Archival Studies, Records Management, or a related field. Minimum 10 years of experience in records information management, including electronic records management within a federal or DoD environment. Demonstrated working knowledge of federal records management law, DoD recordkeeping policy, and archival transfer/accessioning processes. Experience developing and maintaining records management SOPs, retention schedules, and compliance reporting. Experience working within a content management system (CMS) environment and coordinating with cross-functional content/digital teams. Strong written communication skills, with experience producing compliance and governance reporting for government stakeholders. Nice to Have Skills and Experience: Certified Records Manager (CRM) or Information Governance Professional (IGP) certification. Familiarity with cloud-hosted content environments and associated backup and disaster-recovery controls. How We Support Our Team: Flex hours 401K with matching incentive Parental Leave Medical/dental/vision benefits Flex Spending Account Company provided short-term disability and life insurance Commuter benefits Paid Time Off (PTO) 11 Paid holidays Our company is committed to providing equal employment opportunities for all individuals and complies with all applicable federal, state, and local anti-discrimination laws. Employment decisions are based on merit, qualifications, and business needs.
09/28/2026
Full time
Job Description Job Description Important Notice for Applicants: At Bixal, we want to ensure a transparent and secure application process for all candidates. Official communication will come from an email address ending or from Messages from other sources may be fraudulent, and you should exercise care to avoid any links or attachments included. Bixal will ensure that individuals with disabilities are provided reasonable accommodation to participate in the job application or interview process, to perform essential job functions, and to receive other benefits and privileges of employment. Need Assistance or a Reasonable Accommodation? If you need assistance or a reasonable accommodation to complete your application, we're here to help. Please reach out to us at and let us know how we can support you. You do not need to share personal details or disclose the nature of your request. You can expect a response from a team member within 24 hours during the regular work week and on the next operating day during the weekend or holidays. Why Bixal? Bixal is a consulting company headquartered in Fairfax, VA, working alongside governments and organizations to help them deliver better services and experiences to the communities they serve. Using evidence-based knowledge and technology, Bixal empowers clients to deliver on their missions more effectively by fostering a culture of learning and continuous improvement. Our values: People-First : Emphasizing the importance of people in all aspects of work. Collaboration and Transparency : Valuing teamwork and open communication. Growth Mindset : Encouraging innovation and continuous improvement. Creating Lasting Impact : Focusing on meaningful outcomes and positive change. About the role: Bixal is seeking a Senior Records Information Management Specialist for a project that supports a large-scale outreach and engagement effort, delivering strategic communications, content and creative services, digital strategy, and audience engagement across public-facing websites, applications, and social media platforms. The work is paired with the IT, cybersecurity, and data operations needed to keep that digital presence secure, reliable, and available around the clock. The program's mission is to ensure the intended audience receives timely, accurate, and accessible information about the programs, services, and policies that affect them - with content and platforms built to scale, adapt to changing needs, and hold up to federal compliance and security standards. The Senior Records Information Management Specialist will lead the design, governance, and day-to-day administration of the program's records management function, ensuring that electronic records generated across public-facing websites, applications, and social media platforms are properly captured, controlled, archived, and preserved in accordance with federal recordkeeping law and DoD policy. This role serves as the primary bridge between the content operation and the Government Records Manager, translating recordkeeping requirements into practical, user-centric processes that content and digital teams can execute consistently. This is a full-time position contingent on contract award by our client, with a defined performance period of one year with two one-year option periods. This role offers you a unique opportunity to make a meaningful impact on a project that aligns with Bixal's mission of delivering innovative, human-centered solutions. While the role has a fixed duration, we are committed to transparency and collaboration, keeping you informed about contract updates and new opportunities. At Bixal, we support your professional journey, ensuring your experience reflects our inclusive, purpose-driven culture and prepares you for future success. Location This role can work remotely from anywhere in the USA. You must be legally authorized to work in the US. Bixal does not provide visa sponsorship. Compensation: The salary range for this role is $92,000 - $95,000. In the spirit of transparency, most offers tend to land near the midpoint of the range. We make compensation decisions thoughtfully, considering your experience, the skills you bring, and our commitment to internal equity. Fairness and transparency are core to how we operate. Responsibilities: Administer the organization's records management program, ensuring records of business and mission activity are properly identified, scheduled, captured, and preserved in compliance with federal recordkeeping law and DoD records management policy. Develop, implement, and annually update records management SOPs and guidance, keeping pace with evolving Federal, DoD, and program-specific policy. Develop and maintain a records management plan governing the transfer, accessioning, and eventual disposition of permanent electronic records to the appropriate federal archival authority, and lead execution of related transfer activities. Conduct periodic compliance reviews and risk assessments of the records program, documenting gaps and recommending corrective actions to leadership. Partner with the Government Records Manager and content stakeholders to design intuitive, user-centric records management systems and workflows; conduct user research to identify pain points and streamline compliance. Direct archiving and digital preservation activities, including secure storage, metadata tagging and indexing, and backup/disaster-recovery practices that ensure long-term accountability, availability, and integrity of records. Ensure archived and published content remains tamper-proof, verifiable, and retained per applicable records schedules, conducting regular audits of archiving, access-control, and publishing workflows. Establish and enforce access-control, permissions, and audit-trail practices across content systems to maintain a defensible chain of custody. Ensure records considerations are reflected in broader digital strategy planning, content governance, and reporting. Deliver required records-related compliance and status reporting on established schedules, and brief findings and recommendations to Government stakeholders. Provide subject-matter guidance and training to content and digital teams on records identification, tagging, and retention responsibilities. Other relevant duties as qualified/trained to perform Qualifications: This position requires an active Secret Clearance. BA/BS in Information Science, Library/Archival Studies, Records Management, or a related field. Minimum 10 years of experience in records information management, including electronic records management within a federal or DoD environment. Demonstrated working knowledge of federal records management law, DoD recordkeeping policy, and archival transfer/accessioning processes. Experience developing and maintaining records management SOPs, retention schedules, and compliance reporting. Experience working within a content management system (CMS) environment and coordinating with cross-functional content/digital teams. Strong written communication skills, with experience producing compliance and governance reporting for government stakeholders. Nice to Have Skills and Experience: Certified Records Manager (CRM) or Information Governance Professional (IGP) certification. Familiarity with cloud-hosted content environments and associated backup and disaster-recovery controls. How We Support Our Team: Flex hours 401K with matching incentive Parental Leave Medical/dental/vision benefits Flex Spending Account Company provided short-term disability and life insurance Commuter benefits Paid Time Off (PTO) 11 Paid holidays Our company is committed to providing equal employment opportunities for all individuals and complies with all applicable federal, state, and local anti-discrimination laws. Employment decisions are based on merit, qualifications, and business needs.
Job Description Job Description Job Title: Security Control Assessor Location: On Site in Arlington, VA Department: Cyber Security Services Reports To: Management FLSA Status: Full Time/Non-exempt Clearance: Top Secret clearance with the ability to obtain SCI with CI Polygraph Job Purpose: The security control assessor (SCAs) supports a critical, objective role to evaluate the effectiveness of implemented controls in mitigating security risks. The SCA will support a critical mission within the intelligence community. In the role as a SCA, you are expected to use automated scanning tools, manual techniques, and specialized testing methodologies to identify weaknesses and vulnerabilities. The SCA is expected to be a collaborative member of the RMF program of the organization, to provide intelligent input to system security architectures in order to align with RMF principles and guidelines. This includes ensuring to guide the RMF process so that security controls are integrated seamlessly into system designs to provide comprehensive protection against threats and vulnerabilities. Duties & Responsibilities: The SCA's specific duties include: Advise the Information System Owner (ISO) concerning the impact levels for Confidentiality, Integrity, and Availability for the information on systems. Ensure security assessments are completed for each IS. Initiate a POA&M with identified weaknesses and suspense dates for each IS based on findings and recommendations from the SAR. Evaluate security assessment documentation and provide written recommendations for security authorization to the CISO and AO. Assess proposed changes to Information Systems, their environment of operation, and mission needs that could affect system authorization. Serve as a cybersecurity technical advisor to the CISO and AO under their purview. Be integral to the development of the monitoring strategy. The system-level continuous monitoring strategy must conform to all applicable published DoD enterprise-level or DoD Component-level continuous monitoring strategies. Determine and document in the SAR a risk level for every noncompliant security control in the system baseline. Determine and document in the SAR an aggregate level of risk to the system and identify the key drivers for the assessment. The SCA's risk assessment considers threats, vulnerabilities, and potential impacts as well as existing and planned risk mitigation. Develop the continuous monitoring plan specific to the information system. The SCA is responsible for the RMF deliverables associated with Step 4 of DOD and IC RMF Policies for assigned systems. This includes, but is not limited to: Security Assessment Plans tailored to specific systems control requirements Security control assessment input, which includes narratives for the review of controls and artifacts Security Assessment Reports ATO recommendations or ATO with Condition Memorandums Conduct initial remediation actions once a security assessment has been completed to ensure proper hand off to the ISSM and ISSOs. Assessment of selected controls IAW continuous monitoring strategy The SCA is expected to have additional duties as assigned in support of corporate cyber security services. Additional details are reviewed in accordance with company policies. Requirements Required Skills & Experience: Strong knowledge of Risk Management Framework (RMF) 800-37 and continuous monitoring 800-137 Expert knowledge and hands-on experience with FISMA Systems, NIST 800-series guidelines, FIPS, Security Assessment & Authorization (SA&A) requirements and processes, Continuous Monitoring Framework experience and its tools, Plan of Action & Milestones (POA&M) policies, and vulnerability/patch management, risk management, project management, proficient with Microsoft products - Word, Excel, PowerPoint. Proficient with vulnerability and scanning tools and well-versed in interpreting risk posture resulting from assessment reports. Experience in project management and tracking, and the Microsoft suite of office products Experience of assessing cloud-based security authorizations (FedRamp, AWS & Azure) as well as the NIST control responsibilities Experience with SAP/JSIG Expert with documenting and or reviewing of security materials such as; system security plans (SSP), Security Assessment Report (SAR), and Security Assessment Plan (SAP), and other documents per NIST 800 guidelines. Experience supporting cloud-based security authorizations (FedRamp, AWS, & Azure) Experience creating Security Assessment Plans, Security Assessment Reports, and Executive-level briefings Qualifications: Bachelor's Degree in Computer Science or a related technical discipline Master's Degree preferred. Minimum 6-10 years of experience. Must currently possess an active Top Secret clearance with the ability to obtain SCI with CI Polygraph. DOD 8140 IAM Level II (CAP, CASP, CISM, CISSP, GSLC, CCISO) is required Systems Security Engineering background preferred. Effective communication skills to collaborate with cross-functional teams and stakeholders on implementing security measures organization-wide. Strong analytical skills for identifying system vulnerabilities and documenting control remediation recommendations through collaboration on System Impact Analysis and Documented Risk Acceptance. Detail-oriented with the ability to manage multiple tasks and prioritize effectively. Comprehensive knowledge of RMF activities at a senior level (ability to articulate to Executive audiences preferred). Familiarity with federal regulatory requirements, contractual obligations, and industry standards related to information security. Evaluate adherence to standards such as Privacy, GDPR, and HIPAA Powered by JazzHR I48iVzr4Ds
09/26/2026
Full time
Job Description Job Description Job Title: Security Control Assessor Location: On Site in Arlington, VA Department: Cyber Security Services Reports To: Management FLSA Status: Full Time/Non-exempt Clearance: Top Secret clearance with the ability to obtain SCI with CI Polygraph Job Purpose: The security control assessor (SCAs) supports a critical, objective role to evaluate the effectiveness of implemented controls in mitigating security risks. The SCA will support a critical mission within the intelligence community. In the role as a SCA, you are expected to use automated scanning tools, manual techniques, and specialized testing methodologies to identify weaknesses and vulnerabilities. The SCA is expected to be a collaborative member of the RMF program of the organization, to provide intelligent input to system security architectures in order to align with RMF principles and guidelines. This includes ensuring to guide the RMF process so that security controls are integrated seamlessly into system designs to provide comprehensive protection against threats and vulnerabilities. Duties & Responsibilities: The SCA's specific duties include: Advise the Information System Owner (ISO) concerning the impact levels for Confidentiality, Integrity, and Availability for the information on systems. Ensure security assessments are completed for each IS. Initiate a POA&M with identified weaknesses and suspense dates for each IS based on findings and recommendations from the SAR. Evaluate security assessment documentation and provide written recommendations for security authorization to the CISO and AO. Assess proposed changes to Information Systems, their environment of operation, and mission needs that could affect system authorization. Serve as a cybersecurity technical advisor to the CISO and AO under their purview. Be integral to the development of the monitoring strategy. The system-level continuous monitoring strategy must conform to all applicable published DoD enterprise-level or DoD Component-level continuous monitoring strategies. Determine and document in the SAR a risk level for every noncompliant security control in the system baseline. Determine and document in the SAR an aggregate level of risk to the system and identify the key drivers for the assessment. The SCA's risk assessment considers threats, vulnerabilities, and potential impacts as well as existing and planned risk mitigation. Develop the continuous monitoring plan specific to the information system. The SCA is responsible for the RMF deliverables associated with Step 4 of DOD and IC RMF Policies for assigned systems. This includes, but is not limited to: Security Assessment Plans tailored to specific systems control requirements Security control assessment input, which includes narratives for the review of controls and artifacts Security Assessment Reports ATO recommendations or ATO with Condition Memorandums Conduct initial remediation actions once a security assessment has been completed to ensure proper hand off to the ISSM and ISSOs. Assessment of selected controls IAW continuous monitoring strategy The SCA is expected to have additional duties as assigned in support of corporate cyber security services. Additional details are reviewed in accordance with company policies. Requirements Required Skills & Experience: Strong knowledge of Risk Management Framework (RMF) 800-37 and continuous monitoring 800-137 Expert knowledge and hands-on experience with FISMA Systems, NIST 800-series guidelines, FIPS, Security Assessment & Authorization (SA&A) requirements and processes, Continuous Monitoring Framework experience and its tools, Plan of Action & Milestones (POA&M) policies, and vulnerability/patch management, risk management, project management, proficient with Microsoft products - Word, Excel, PowerPoint. Proficient with vulnerability and scanning tools and well-versed in interpreting risk posture resulting from assessment reports. Experience in project management and tracking, and the Microsoft suite of office products Experience of assessing cloud-based security authorizations (FedRamp, AWS & Azure) as well as the NIST control responsibilities Experience with SAP/JSIG Expert with documenting and or reviewing of security materials such as; system security plans (SSP), Security Assessment Report (SAR), and Security Assessment Plan (SAP), and other documents per NIST 800 guidelines. Experience supporting cloud-based security authorizations (FedRamp, AWS, & Azure) Experience creating Security Assessment Plans, Security Assessment Reports, and Executive-level briefings Qualifications: Bachelor's Degree in Computer Science or a related technical discipline Master's Degree preferred. Minimum 6-10 years of experience. Must currently possess an active Top Secret clearance with the ability to obtain SCI with CI Polygraph. DOD 8140 IAM Level II (CAP, CASP, CISM, CISSP, GSLC, CCISO) is required Systems Security Engineering background preferred. Effective communication skills to collaborate with cross-functional teams and stakeholders on implementing security measures organization-wide. Strong analytical skills for identifying system vulnerabilities and documenting control remediation recommendations through collaboration on System Impact Analysis and Documented Risk Acceptance. Detail-oriented with the ability to manage multiple tasks and prioritize effectively. Comprehensive knowledge of RMF activities at a senior level (ability to articulate to Executive audiences preferred). Familiarity with federal regulatory requirements, contractual obligations, and industry standards related to information security. Evaluate adherence to standards such as Privacy, GDPR, and HIPAA Powered by JazzHR I48iVzr4Ds
Job Description Job Description On our expert team, you'll perform work focused on implementing and operating next generation security solutions for government and commercial clients. You'll perform hands-on evaluation, implementation, and operation of leading security cyber defense tools and technologies, and apply in-depth defense strategies to large and complex networks to rapidly identify vulnerabilities and threats, prioritize response actions, and develop effective countermeasures. You'll apply thought leadership in a highly collaborative and innovative work environment to solve complex security challenges. You will lead a team as they engineer solutions to complex challenges for customers using knowledge network engineering, Active Directory, and system administration. In this role, you'll closely impact mission success, protecting data and networks from malicious payloads and actors. With mentoring, challenging hands-on problem-solving, and opportunities to learn new tools and skills, we focus on growing as a team to make the best solutions for our customers. Work with us as we secure and protect our nation's most sensitive capabilities. What You'll Work On: Develop relationships quickly and easily with other teams, communicating the complexities of security with a wide variety of audiences, including senior management. Manage infrastructure and cybersecurity controls, including enhanced detection and vulnerability capabilities and improved event correlation in large enterprises. Contribute to risk and vulnerability assessments in network, system, and application areas, and leverage big data analytics and traditional security event types to identify advanced threats or indicators of compromise. Requirements Experience with the deployment or daily maintenance of Forescout CounterACT appliances 5+ years of experience performing systems administration for Windows or Linux, including performing basic troubleshooting and installation or configuration, monitoring system performance or availability, and performing security upgrades Experience architecting and designing IP networks, including developing and documenting network topologies Experience with network engineering, including physical or logical such as installation and activation of ports, configuration of switches, and LANS, VLANS, and network FW, or appliances or network administration services such as Active Directory, Guests LANS, and domain management Knowledge of multi-domain architectures, including data center, WAN, and LAN in virtualized architectures Active TS/SCI clearance; willingness to take a polygraph exam Associate's degree and 10+ years of experience supporting IT projects and activities, Bachelor's degree and 8+ years of experience supporting IT projects and activities, or Master's degree and 6+ years of experience supporting IT projects and activities DoD 8570 IAT Level II Certification such as Security+ CE, CCNA-Security, GSEC, SSCP, CySA+, GICSP, or CND Certification Ability to obtain a DoD 8570 Cybersecurity Service Provider - Infrastructure Support Certification such as CEH, CySA+, GICSP, SSCP, CHFI, CFR, Cloud+, or CND Certification, within 30 days of start date Nice If You Have: Knowledge of federal information security policies, standards, procedures, directives, frameworks, federal security authorizations, assessment, and risk management processes for enterprise systems Ability to install and deploy Forescout in a customer environment Ability to integrate cybersecurity data using enterprise or custom tools data aggregation and analysis tools, including Splunk Ability to provide support in a Tier II IT operations and maintenance role, including ticket work information updates, issue responses, and remediation Ability to be a self-starter, work without considerable direction, and work with a team Possession of excellent verbal and written communication skills, including for coordinating efforts and establishing customer relations Benefits Essential Network Security (ENS) Solutions, LLC is a service-disabled veteran owned, highly regarded IT consulting and management firm. ENS consults for the Department of Defense (DoD) and Intelligence Community (IC) providing innovative solutions in the core competency area of Identity, Credential and Access Management (ICAM), Software Development, Cyber and Network Security, System Engineering, Program/Project Management, IT support, Solutions, and Services that yield enduring results. Our strong technical and management experts have been able to maintain a standard of excellence in their relationships while delivering innovative, scalable and collaborative infrastructure to our clients. Why ENS? Free Platinum-Level Medical/Dental/Vision coverage, 100% paid for by ENS 401k Contribution from Day 1 PTO + 11 Paid Federal Holidays Long & Short Term Disability Insurance Group Term Life Insurance Tuition, Certification & Professional Development Assistance Workers' Compensation Relocation Assistance Candidate AI Usage Policy AI tools are an important part of daily work at ENS Solutions, and we are committed to their responsible and ethical use. To ensure a fair and equitable candidate evaluation based on individual skills, knowledge, and experience, candidates are not permitted to use artificial intelligence or other assistive tools during interviews, whether in person or virtual, unless explicit permission has been granted in advance.
09/26/2026
Full time
Job Description Job Description On our expert team, you'll perform work focused on implementing and operating next generation security solutions for government and commercial clients. You'll perform hands-on evaluation, implementation, and operation of leading security cyber defense tools and technologies, and apply in-depth defense strategies to large and complex networks to rapidly identify vulnerabilities and threats, prioritize response actions, and develop effective countermeasures. You'll apply thought leadership in a highly collaborative and innovative work environment to solve complex security challenges. You will lead a team as they engineer solutions to complex challenges for customers using knowledge network engineering, Active Directory, and system administration. In this role, you'll closely impact mission success, protecting data and networks from malicious payloads and actors. With mentoring, challenging hands-on problem-solving, and opportunities to learn new tools and skills, we focus on growing as a team to make the best solutions for our customers. Work with us as we secure and protect our nation's most sensitive capabilities. What You'll Work On: Develop relationships quickly and easily with other teams, communicating the complexities of security with a wide variety of audiences, including senior management. Manage infrastructure and cybersecurity controls, including enhanced detection and vulnerability capabilities and improved event correlation in large enterprises. Contribute to risk and vulnerability assessments in network, system, and application areas, and leverage big data analytics and traditional security event types to identify advanced threats or indicators of compromise. Requirements Experience with the deployment or daily maintenance of Forescout CounterACT appliances 5+ years of experience performing systems administration for Windows or Linux, including performing basic troubleshooting and installation or configuration, monitoring system performance or availability, and performing security upgrades Experience architecting and designing IP networks, including developing and documenting network topologies Experience with network engineering, including physical or logical such as installation and activation of ports, configuration of switches, and LANS, VLANS, and network FW, or appliances or network administration services such as Active Directory, Guests LANS, and domain management Knowledge of multi-domain architectures, including data center, WAN, and LAN in virtualized architectures Active TS/SCI clearance; willingness to take a polygraph exam Associate's degree and 10+ years of experience supporting IT projects and activities, Bachelor's degree and 8+ years of experience supporting IT projects and activities, or Master's degree and 6+ years of experience supporting IT projects and activities DoD 8570 IAT Level II Certification such as Security+ CE, CCNA-Security, GSEC, SSCP, CySA+, GICSP, or CND Certification Ability to obtain a DoD 8570 Cybersecurity Service Provider - Infrastructure Support Certification such as CEH, CySA+, GICSP, SSCP, CHFI, CFR, Cloud+, or CND Certification, within 30 days of start date Nice If You Have: Knowledge of federal information security policies, standards, procedures, directives, frameworks, federal security authorizations, assessment, and risk management processes for enterprise systems Ability to install and deploy Forescout in a customer environment Ability to integrate cybersecurity data using enterprise or custom tools data aggregation and analysis tools, including Splunk Ability to provide support in a Tier II IT operations and maintenance role, including ticket work information updates, issue responses, and remediation Ability to be a self-starter, work without considerable direction, and work with a team Possession of excellent verbal and written communication skills, including for coordinating efforts and establishing customer relations Benefits Essential Network Security (ENS) Solutions, LLC is a service-disabled veteran owned, highly regarded IT consulting and management firm. ENS consults for the Department of Defense (DoD) and Intelligence Community (IC) providing innovative solutions in the core competency area of Identity, Credential and Access Management (ICAM), Software Development, Cyber and Network Security, System Engineering, Program/Project Management, IT support, Solutions, and Services that yield enduring results. Our strong technical and management experts have been able to maintain a standard of excellence in their relationships while delivering innovative, scalable and collaborative infrastructure to our clients. Why ENS? Free Platinum-Level Medical/Dental/Vision coverage, 100% paid for by ENS 401k Contribution from Day 1 PTO + 11 Paid Federal Holidays Long & Short Term Disability Insurance Group Term Life Insurance Tuition, Certification & Professional Development Assistance Workers' Compensation Relocation Assistance Candidate AI Usage Policy AI tools are an important part of daily work at ENS Solutions, and we are committed to their responsible and ethical use. To ensure a fair and equitable candidate evaluation based on individual skills, knowledge, and experience, candidates are not permitted to use artificial intelligence or other assistive tools during interviews, whether in person or virtual, unless explicit permission has been granted in advance.
Job Description Job Description On our expert team, you'll perform work focused on implementing and operating next generation security solutions for government and commercial clients. You'll perform hands-on evaluation, implementation, and operation of leading security cyber defense tools and technologies, and apply in-depth defense strategies to large and complex networks to rapidly identify vulnerabilities and threats, prioritize response actions, and develop effective countermeasures. You'll apply thought leadership in a highly collaborative and innovative work environment to solve complex security challenges. You will lead a team as they engineer solutions to complex challenges for customers using knowledge network engineering, Active Directory, and system administration. In this role, you'll closely impact mission success, protecting data and networks from malicious payloads and actors. With mentoring, challenging hands-on problem-solving, and opportunities to learn new tools and skills, we focus on growing as a team to make the best solutions for our customers. Work with us as we secure and protect our nation's most sensitive capabilities. What You'll Work On: Develop relationships quickly and easily with other teams, communicating the complexities of security with a wide variety of audiences, including senior management. Manage infrastructure and cybersecurity controls, including enhanced detection and vulnerability capabilities and improved event correlation in large enterprises. Contribute to risk and vulnerability assessments in network, system, and application areas, and leverage big data analytics and traditional security event types to identify advanced threats or indicators of compromise. Requirements Experience with the deployment or daily maintenance of Forescout CounterACT appliances 5+ years of experience performing systems administration for Windows or Linux, including performing basic troubleshooting and installation or configuration, monitoring system performance or availability, and performing security upgrades Experience architecting and designing IP networks, including developing and documenting network topologies Experience with network engineering, including physical or logical such as installation and activation of ports, configuration of switches, and LANS, VLANS, and network FW, or appliances or network administration services such as Active Directory, Guests LANS, and domain management Knowledge of multi-domain architectures, including data center, WAN, and LAN in virtualized architectures Active TS/SCI clearance; willingness to take a polygraph exam Associate's degree and 10+ years of experience supporting IT projects and activities, Bachelor's degree and 8+ years of experience supporting IT projects and activities, or Master's degree and 6+ years of experience supporting IT projects and activities DoD 8570 IAT Level II Certification such as Security+ CE, CCNA-Security, GSEC, SSCP, CySA+, GICSP, or CND Certification Ability to obtain a DoD 8570 Cybersecurity Service Provider - Infrastructure Support Certification such as CEH, CySA+, GICSP, SSCP, CHFI, CFR, Cloud+, or CND Certification, within 30 days of start date Nice If You Have: Knowledge of federal information security policies, standards, procedures, directives, frameworks, federal security authorizations, assessment, and risk management processes for enterprise systems Ability to install and deploy Forescout in a customer environment Ability to integrate cybersecurity data using enterprise or custom tools data aggregation and analysis tools, including Splunk Ability to provide support in a Tier II IT operations and maintenance role, including ticket work information updates, issue responses, and remediation Ability to be a self-starter, work without considerable direction, and work with a team Possession of excellent verbal and written communication skills, including for coordinating efforts and establishing customer relations Benefits Essential Network Security (ENS) Solutions, LLC is a service-disabled veteran owned, highly regarded IT consulting and management firm. ENS consults for the Department of Defense (DoD) and Intelligence Community (IC) providing innovative solutions in the core competency area of Identity, Credential and Access Management (ICAM), Software Development, Cyber and Network Security, System Engineering, Program/Project Management, IT support, Solutions, and Services that yield enduring results. Our strong technical and management experts have been able to maintain a standard of excellence in their relationships while delivering innovative, scalable and collaborative infrastructure to our clients. Why ENS? Free Platinum-Level Medical/Dental/Vision coverage, 100% paid for by ENS 401k Contribution from Day 1 PTO + 11 Paid Federal Holidays Long & Short Term Disability Insurance Group Term Life Insurance Tuition, Certification & Professional Development Assistance Workers' Compensation Relocation Assistance Candidate AI Usage Policy AI tools are an important part of daily work at ENS Solutions, and we are committed to their responsible and ethical use. To ensure a fair and equitable candidate evaluation based on individual skills, knowledge, and experience, candidates are not permitted to use artificial intelligence or other assistive tools during interviews, whether in person or virtual, unless explicit permission has been granted in advance.
09/26/2026
Full time
Job Description Job Description On our expert team, you'll perform work focused on implementing and operating next generation security solutions for government and commercial clients. You'll perform hands-on evaluation, implementation, and operation of leading security cyber defense tools and technologies, and apply in-depth defense strategies to large and complex networks to rapidly identify vulnerabilities and threats, prioritize response actions, and develop effective countermeasures. You'll apply thought leadership in a highly collaborative and innovative work environment to solve complex security challenges. You will lead a team as they engineer solutions to complex challenges for customers using knowledge network engineering, Active Directory, and system administration. In this role, you'll closely impact mission success, protecting data and networks from malicious payloads and actors. With mentoring, challenging hands-on problem-solving, and opportunities to learn new tools and skills, we focus on growing as a team to make the best solutions for our customers. Work with us as we secure and protect our nation's most sensitive capabilities. What You'll Work On: Develop relationships quickly and easily with other teams, communicating the complexities of security with a wide variety of audiences, including senior management. Manage infrastructure and cybersecurity controls, including enhanced detection and vulnerability capabilities and improved event correlation in large enterprises. Contribute to risk and vulnerability assessments in network, system, and application areas, and leverage big data analytics and traditional security event types to identify advanced threats or indicators of compromise. Requirements Experience with the deployment or daily maintenance of Forescout CounterACT appliances 5+ years of experience performing systems administration for Windows or Linux, including performing basic troubleshooting and installation or configuration, monitoring system performance or availability, and performing security upgrades Experience architecting and designing IP networks, including developing and documenting network topologies Experience with network engineering, including physical or logical such as installation and activation of ports, configuration of switches, and LANS, VLANS, and network FW, or appliances or network administration services such as Active Directory, Guests LANS, and domain management Knowledge of multi-domain architectures, including data center, WAN, and LAN in virtualized architectures Active TS/SCI clearance; willingness to take a polygraph exam Associate's degree and 10+ years of experience supporting IT projects and activities, Bachelor's degree and 8+ years of experience supporting IT projects and activities, or Master's degree and 6+ years of experience supporting IT projects and activities DoD 8570 IAT Level II Certification such as Security+ CE, CCNA-Security, GSEC, SSCP, CySA+, GICSP, or CND Certification Ability to obtain a DoD 8570 Cybersecurity Service Provider - Infrastructure Support Certification such as CEH, CySA+, GICSP, SSCP, CHFI, CFR, Cloud+, or CND Certification, within 30 days of start date Nice If You Have: Knowledge of federal information security policies, standards, procedures, directives, frameworks, federal security authorizations, assessment, and risk management processes for enterprise systems Ability to install and deploy Forescout in a customer environment Ability to integrate cybersecurity data using enterprise or custom tools data aggregation and analysis tools, including Splunk Ability to provide support in a Tier II IT operations and maintenance role, including ticket work information updates, issue responses, and remediation Ability to be a self-starter, work without considerable direction, and work with a team Possession of excellent verbal and written communication skills, including for coordinating efforts and establishing customer relations Benefits Essential Network Security (ENS) Solutions, LLC is a service-disabled veteran owned, highly regarded IT consulting and management firm. ENS consults for the Department of Defense (DoD) and Intelligence Community (IC) providing innovative solutions in the core competency area of Identity, Credential and Access Management (ICAM), Software Development, Cyber and Network Security, System Engineering, Program/Project Management, IT support, Solutions, and Services that yield enduring results. Our strong technical and management experts have been able to maintain a standard of excellence in their relationships while delivering innovative, scalable and collaborative infrastructure to our clients. Why ENS? Free Platinum-Level Medical/Dental/Vision coverage, 100% paid for by ENS 401k Contribution from Day 1 PTO + 11 Paid Federal Holidays Long & Short Term Disability Insurance Group Term Life Insurance Tuition, Certification & Professional Development Assistance Workers' Compensation Relocation Assistance Candidate AI Usage Policy AI tools are an important part of daily work at ENS Solutions, and we are committed to their responsible and ethical use. To ensure a fair and equitable candidate evaluation based on individual skills, knowledge, and experience, candidates are not permitted to use artificial intelligence or other assistive tools during interviews, whether in person or virtual, unless explicit permission has been granted in advance.
Job Description Job Description Business Technology Integrators (BTI) is a Service-Disabled Veteran-Owned Small Business (SDVOSB) with more than 25 years of experience delivering innovative and reliable IT and engineering solutions to the Federal Government. BTI supports mission-critical programs across defense and civilian agencies, with core expertise in cybersecurity, program management, enterprise IT, and technical oversight services. Position Overview The Intermediate AV/VTC Specialist will provide audiovisual, video teleconferencing, collaboration-platform, and multimedia production support for the Equal Employment Opportunity Commission. This position supports the configuration, operation, maintenance, and troubleshooting of AV/VTC systems within a distributed enterprise environment similar in size and complexity to the EEOC. The ideal candidate will have at least six years of relevant experience supporting audiovisual technologies, video production equipment, conferencing platforms, and integrated multimedia systems. The specialist will support live meetings, virtual conferences, presentations, broadcasts, and other mission-related events while ensuring high-quality audio, video, and collaboration services. Key Responsibilities Configure, operate, maintain, and troubleshoot audiovisual, video teleconferencing, and multimedia production equipment. Provide technical and operational support for Microsoft Teams, Zoom, Poly RealPresence, and Cisco video conferencing systems and endpoints. Set up and support virtual meetings, hybrid meetings, executive conferences, presentations, live events, and video teleconferences. Perform pre-event system checks and confirm that cameras, microphones, displays, speakers, conferencing platforms, and network connections are operating correctly. Monitor live meetings and events, quickly identifying and resolving audio, video, connectivity, or equipment issues. Provide video editing and post-production services for recorded meetings, training materials, presentations, and organizational communications. Operate video switchers, professional cameras, recording equipment, and related production technologies. Support camera placement, framing, lighting, recording, and live video production activities. Develop and edit graphics, animations, motion graphics, presentation materials, and other visual media. Perform audio mixing and configure microphones, speakers, amplifiers, and other sound-reinforcement equipment. Configure and support digital signal processing systems used for audio routing, optimization, and control. Operate and maintain AV control systems, projection systems, video walls, digital displays, and LED display technologies. Diagnose and resolve hardware, software, signal-routing, audio-quality, video-quality, and platform-integration issues. Perform preventive maintenance, firmware updates, equipment testing, and routine system inspections. Coordinate with IT, networking, facilities, communications, and event-support personnel to ensure reliable service delivery. Assist end users, presenters, executives, and meeting organizers with the proper use of AV/VTC systems. Maintain equipment inventories, system configurations, maintenance records, technical documentation, and standard operating procedures. Escalate complex technical issues to senior AV/VTC personnel, vendors, or appropriate support teams. Follow EEOC security, accessibility, operational, and information-technology policies and procedures. Minimum Qualifications A minimum of six years of experience providing AV/VTC support in an enterprise or federal environment similar in size, scope, and complexity to the EEOC. Demonstrated experience configuring, operating, maintaining, and troubleshooting AV and multimedia production equipment. Hands-on experience supporting Microsoft Teams, Zoom, Poly RealPresence, and Cisco video conferencing technologies. Experience with video editing, post-production, video switching, and camera operations. Experience with graphic design, animation, and motion-graphics development. Knowledge of professional audio mixing, microphone systems, signal routing, and sound-reinforcement technologies. Experience with digital signal processing, AV control systems, projection systems, video displays, and LED display technologies. Ability to support live, virtual, and hybrid meetings in a time-sensitive environment. Strong troubleshooting, customer-service, organization, and communication skills. Ability to communicate technical information clearly to both technical and nontechnical users. Ability to work independently and collaboratively with IT teams, government personnel, vendors, and other stakeholders. Ability to lift, move, install, and position AV equipment as required. Preferred Qualifications Associate's or bachelor's degree in Audiovisual Technology, Broadcast Production, Communications, Information Technology, Multimedia Production, or a related discipline. Experience supporting a federal government agency or a geographically distributed organization. Experience with enterprise conference rooms, executive briefing rooms, training rooms, auditoriums, and live-event environments. AVIXA Certified Technology Specialist certification, such as CTS, CTS-I, or CTS-D. Manufacturer certifications involving Poly, Cisco, Crestron, Extron, QSC, Biamp, or similar AV technologies. Familiarity with Section 508 accessibility requirements and federal information-security standards. Core Competencies AV/VTC system operation and troubleshooting Microsoft Teams, Zoom, Poly, and Cisco support Live and hybrid meeting support Video editing and post-production Video switching and camera operation Graphic design and motion graphics Professional audio mixing Digital signal processing AV control and projection systems LED and digital display technologies Preventive maintenance and documentation Customer and executive-level support Choose a Description from the Library LocationCountry - Multiple Countries -AfghanistanAland IslandsAlbaniaAlbertaAlgeriaAndorraAngolaAnguillaAntarcticaAntigua and BarbudaArgentinaArmeniaArubaAustraliaAustriaAzerbaijanBahamasBahrainBangladeshBarbadosBelarusBelgiumBelizeBeninBermudaBhutanBoliviaBosnia and HerzegovinaBotswanaBouvet IslandBrazilBritish ColumbiaBritish Indian Ocean TerritoryBrunei DarussalamBulgariaBurkina FasoBurundiCambodiaCameroonCanadaCape VerdeCayman IslandsCentral African RepublicChadChileChinaChristmas IslandCocos (Keeling) IslandsColombiaComorosCongoCongo, The Democratic Republic of theCook IslandsCosta RicaCôte d' IvoireCroatiaCubaCyprusCzech RepublicDenmarkDjiboutiDominicaDominican RepublicEcuadorEgyptEl SalvadorEquatorial GuineaEritreaEstoniaEthiopiaFalkland Islands (Malvinas)Faroe IslandsFederated States Of MicronesiaFijiFinlandFranceFrench GuianaFrench PolynesiaFrench Southern TerritoriesGabonGambiaGeorgiaGermanyGhanaGibraltarGreat BritainGreeceGreenlandGrenadaGuadeloupeGuamGuatemalaGuernseyGuineaGuinea - BissauGuyanaHaitiHeard Island and McDonald IslandsHoly See (Vatican City State)HondurasHong KongHungaryIcelandIndiaIndonesiaIran, Islamic Republic ofIraqIrelandIsle of ManIsraelItalyJamaicaJapanJerseyJordanKazakhstanKenyaKiribatiKorea, Democratic People's Republic ofKosovoKuwaitKyrgyzstanLao People's Democratic RepublicLatviaLebanonLesothoLiberiaLibyaLiechtensteinLithuaniaLuxembourgMacaoMacedonia, Republic ofMadagascarMalawiMalaysiaMaldivesMaliMaltaManitobaMarshall IslandsMartiniqueMauritaniaMauritiusMayotteMexicoMoldovaMonacoMongoliaMontenegroMontserratMoroccoMozambiqueMyanmarNamibiaNauruNepalNetherlandsNetherlands AntillesNew BrunswickNew CaledoniaNew ZealandNewfoundland and LabradorNicaraguaNigerNigeriaNiueNorfolk IslandNorthern Mariana IslandsNorthwest TerritoriesNorwayNova ScotiaNunavutOmanOntarioPakistanPalauPalestinian Territory, OccupiedPanamaPapua New GuineaParaguayPeruPhilippinesPitcairnPolandPortugalPrince Edward IslandPuerto RicoQatarQuebecReunionRomaniaRussian FederationRwandaSaint BarthélemySaint HelenaSaint Kitts and NevisSaint LuciaSaint Martin (French part)Saint Pierre and MiquelonSaint Vincent and the GrenadinesSamoaSan MarinoSao Tome and PrincipeSaskatchewanSaudi ArabiaSenegalSerbiaSeychellesSierra LeoneSingaporeSlovakiaSloveniaSolomon IslandsSomaliaSouth AfricaSouth Georgia and the South Sandwich IslandsSouth KoreaSouth SudanSpainSri LankaSudanSurinameSvalbard and Jan MayenSwazilandSwedenSwitzerlandSyrian Arab RepublicTaiwanTajikistanTanzania, United Republic ofThailandTimor- LesteTogoTokelauTongaTrinidad and TobagoTunisiaTurkeyTurkmenistanTurks and Caicos IslandsTuvaluUgandaUkraineUnited Arab EmiratesUnited KingdomUnited StatesUnited States Minor Outlying IslandsUruguayUzbekistanVanuatuVenezuelaViet NamVirgin IslandsWallis and FutunaWestern SaharaYemenYukonZambiaZimbabwe Street Address Powered by JazzHR ktfBlmglPp
09/26/2026
Full time
Job Description Job Description Business Technology Integrators (BTI) is a Service-Disabled Veteran-Owned Small Business (SDVOSB) with more than 25 years of experience delivering innovative and reliable IT and engineering solutions to the Federal Government. BTI supports mission-critical programs across defense and civilian agencies, with core expertise in cybersecurity, program management, enterprise IT, and technical oversight services. Position Overview The Intermediate AV/VTC Specialist will provide audiovisual, video teleconferencing, collaboration-platform, and multimedia production support for the Equal Employment Opportunity Commission. This position supports the configuration, operation, maintenance, and troubleshooting of AV/VTC systems within a distributed enterprise environment similar in size and complexity to the EEOC. The ideal candidate will have at least six years of relevant experience supporting audiovisual technologies, video production equipment, conferencing platforms, and integrated multimedia systems. The specialist will support live meetings, virtual conferences, presentations, broadcasts, and other mission-related events while ensuring high-quality audio, video, and collaboration services. Key Responsibilities Configure, operate, maintain, and troubleshoot audiovisual, video teleconferencing, and multimedia production equipment. Provide technical and operational support for Microsoft Teams, Zoom, Poly RealPresence, and Cisco video conferencing systems and endpoints. Set up and support virtual meetings, hybrid meetings, executive conferences, presentations, live events, and video teleconferences. Perform pre-event system checks and confirm that cameras, microphones, displays, speakers, conferencing platforms, and network connections are operating correctly. Monitor live meetings and events, quickly identifying and resolving audio, video, connectivity, or equipment issues. Provide video editing and post-production services for recorded meetings, training materials, presentations, and organizational communications. Operate video switchers, professional cameras, recording equipment, and related production technologies. Support camera placement, framing, lighting, recording, and live video production activities. Develop and edit graphics, animations, motion graphics, presentation materials, and other visual media. Perform audio mixing and configure microphones, speakers, amplifiers, and other sound-reinforcement equipment. Configure and support digital signal processing systems used for audio routing, optimization, and control. Operate and maintain AV control systems, projection systems, video walls, digital displays, and LED display technologies. Diagnose and resolve hardware, software, signal-routing, audio-quality, video-quality, and platform-integration issues. Perform preventive maintenance, firmware updates, equipment testing, and routine system inspections. Coordinate with IT, networking, facilities, communications, and event-support personnel to ensure reliable service delivery. Assist end users, presenters, executives, and meeting organizers with the proper use of AV/VTC systems. Maintain equipment inventories, system configurations, maintenance records, technical documentation, and standard operating procedures. Escalate complex technical issues to senior AV/VTC personnel, vendors, or appropriate support teams. Follow EEOC security, accessibility, operational, and information-technology policies and procedures. Minimum Qualifications A minimum of six years of experience providing AV/VTC support in an enterprise or federal environment similar in size, scope, and complexity to the EEOC. Demonstrated experience configuring, operating, maintaining, and troubleshooting AV and multimedia production equipment. Hands-on experience supporting Microsoft Teams, Zoom, Poly RealPresence, and Cisco video conferencing technologies. Experience with video editing, post-production, video switching, and camera operations. Experience with graphic design, animation, and motion-graphics development. Knowledge of professional audio mixing, microphone systems, signal routing, and sound-reinforcement technologies. Experience with digital signal processing, AV control systems, projection systems, video displays, and LED display technologies. Ability to support live, virtual, and hybrid meetings in a time-sensitive environment. Strong troubleshooting, customer-service, organization, and communication skills. Ability to communicate technical information clearly to both technical and nontechnical users. Ability to work independently and collaboratively with IT teams, government personnel, vendors, and other stakeholders. Ability to lift, move, install, and position AV equipment as required. Preferred Qualifications Associate's or bachelor's degree in Audiovisual Technology, Broadcast Production, Communications, Information Technology, Multimedia Production, or a related discipline. Experience supporting a federal government agency or a geographically distributed organization. Experience with enterprise conference rooms, executive briefing rooms, training rooms, auditoriums, and live-event environments. AVIXA Certified Technology Specialist certification, such as CTS, CTS-I, or CTS-D. Manufacturer certifications involving Poly, Cisco, Crestron, Extron, QSC, Biamp, or similar AV technologies. Familiarity with Section 508 accessibility requirements and federal information-security standards. Core Competencies AV/VTC system operation and troubleshooting Microsoft Teams, Zoom, Poly, and Cisco support Live and hybrid meeting support Video editing and post-production Video switching and camera operation Graphic design and motion graphics Professional audio mixing Digital signal processing AV control and projection systems LED and digital display technologies Preventive maintenance and documentation Customer and executive-level support Choose a Description from the Library LocationCountry - Multiple Countries -AfghanistanAland IslandsAlbaniaAlbertaAlgeriaAndorraAngolaAnguillaAntarcticaAntigua and BarbudaArgentinaArmeniaArubaAustraliaAustriaAzerbaijanBahamasBahrainBangladeshBarbadosBelarusBelgiumBelizeBeninBermudaBhutanBoliviaBosnia and HerzegovinaBotswanaBouvet IslandBrazilBritish ColumbiaBritish Indian Ocean TerritoryBrunei DarussalamBulgariaBurkina FasoBurundiCambodiaCameroonCanadaCape VerdeCayman IslandsCentral African RepublicChadChileChinaChristmas IslandCocos (Keeling) IslandsColombiaComorosCongoCongo, The Democratic Republic of theCook IslandsCosta RicaCôte d' IvoireCroatiaCubaCyprusCzech RepublicDenmarkDjiboutiDominicaDominican RepublicEcuadorEgyptEl SalvadorEquatorial GuineaEritreaEstoniaEthiopiaFalkland Islands (Malvinas)Faroe IslandsFederated States Of MicronesiaFijiFinlandFranceFrench GuianaFrench PolynesiaFrench Southern TerritoriesGabonGambiaGeorgiaGermanyGhanaGibraltarGreat BritainGreeceGreenlandGrenadaGuadeloupeGuamGuatemalaGuernseyGuineaGuinea - BissauGuyanaHaitiHeard Island and McDonald IslandsHoly See (Vatican City State)HondurasHong KongHungaryIcelandIndiaIndonesiaIran, Islamic Republic ofIraqIrelandIsle of ManIsraelItalyJamaicaJapanJerseyJordanKazakhstanKenyaKiribatiKorea, Democratic People's Republic ofKosovoKuwaitKyrgyzstanLao People's Democratic RepublicLatviaLebanonLesothoLiberiaLibyaLiechtensteinLithuaniaLuxembourgMacaoMacedonia, Republic ofMadagascarMalawiMalaysiaMaldivesMaliMaltaManitobaMarshall IslandsMartiniqueMauritaniaMauritiusMayotteMexicoMoldovaMonacoMongoliaMontenegroMontserratMoroccoMozambiqueMyanmarNamibiaNauruNepalNetherlandsNetherlands AntillesNew BrunswickNew CaledoniaNew ZealandNewfoundland and LabradorNicaraguaNigerNigeriaNiueNorfolk IslandNorthern Mariana IslandsNorthwest TerritoriesNorwayNova ScotiaNunavutOmanOntarioPakistanPalauPalestinian Territory, OccupiedPanamaPapua New GuineaParaguayPeruPhilippinesPitcairnPolandPortugalPrince Edward IslandPuerto RicoQatarQuebecReunionRomaniaRussian FederationRwandaSaint BarthélemySaint HelenaSaint Kitts and NevisSaint LuciaSaint Martin (French part)Saint Pierre and MiquelonSaint Vincent and the GrenadinesSamoaSan MarinoSao Tome and PrincipeSaskatchewanSaudi ArabiaSenegalSerbiaSeychellesSierra LeoneSingaporeSlovakiaSloveniaSolomon IslandsSomaliaSouth AfricaSouth Georgia and the South Sandwich IslandsSouth KoreaSouth SudanSpainSri LankaSudanSurinameSvalbard and Jan MayenSwazilandSwedenSwitzerlandSyrian Arab RepublicTaiwanTajikistanTanzania, United Republic ofThailandTimor- LesteTogoTokelauTongaTrinidad and TobagoTunisiaTurkeyTurkmenistanTurks and Caicos IslandsTuvaluUgandaUkraineUnited Arab EmiratesUnited KingdomUnited StatesUnited States Minor Outlying IslandsUruguayUzbekistanVanuatuVenezuelaViet NamVirgin IslandsWallis and FutunaWestern SaharaYemenYukonZambiaZimbabwe Street Address Powered by JazzHR ktfBlmglPp
Job Description Job Description ZERO TRUST PROJECT LEAD POSITION DESCRIPTION General Description Zermount Inc. is seeking a Zero Trust (ZT) Technical Project Lead with demonstrated experience in providing enterprise support services while leveraging industry-standard service management best practices. We are looking for a team lead that is able to withstand even the most complex environments for our ZT enterprise initiative. The Project Lead will lead, plan, and manage Information Technology (IT) projects as well as provide leadership and guiding technical staff. They will integrate business and technical aspects of projects that are a part of the implementation of ZT principles across all pillars of ZT (identity, device, network, application and workload and data) to assist the client in meeting the requirements set forth by EO 14028 and OMB M 22-09. The Project Lead will also assess business implications, monitor progress in meeting deadlines, standards, and customer cost targets. They will establish goals and plans that meet project objectives and have expert technical knowledge. In addition, they will direct and control activities for a client, having overall responsibility for financial management, methods, and staffing to ensure all technical requirements are met. This position also includes client reporting and interfacing with senior management to communicate a program's progress and achievements. Decision-making and domain knowledge may have a critical impact on project implementation. The Project Lead will supervise others. Duties & Responsibilities: The ZT Project Lead will lead the Zermount ZT Team to ensure we are designing and implementing solutions and services that secure federal networks and provide leadership required to meet the objectives of EO 14028 and other Federal requirements. Additionally, the ZT Project Lead will provide support and services to include: Analyze, plan, and develop scheduled project plans. Responsible for program Integrated Master Scheduler (IMS) updates, health, and accuracy. Responsible for quality management and control. Provide SME support and technical guidance to information system stakeholders on the implementation of ZTA requirements and participate in design reviews upon request. Ensure alignment of the ZTA program to organizational strategies and deliver anticipated benefits of ZT as outlined in EO 14028, the CISA ZT Maturity Model, and the NIST SP 800-207. Creating month status reports (progression week 1 through week 4 buildup). Perform risk management to include: (1) managing risk across the ZTA program as the landscape evolves; and (2) integrating ZTA into the existing TSA and DHS Cybersecurity Risk Management framework and CISA's ZT maturity model with the goal of the solution reaching the optimal state of maturity. Draft Program Management Report (PMR). Responsible for streamlining and automating enterprise-level performance reporting for all components within ZT, aligned with existing and planned reporting and analytics structures and tools, such as the Continuous Diagnostics and Mitigation (CDM) dashboards, FISMA reporting, and Information Security Continuous Monitoring (ISCM) dashboards Establishing and implementing training processes for all technical personnel. Assisting the TSA in its ultimate goal of meeting or exceeding the "managed and measurable" IG CIGIE FISMA maturity metrics as amended, for all applicable security functions for ZT. Develop, implement, and maintain enterprise-wide performance metrics and measures for the ZT initiative Determine and define clear deliverables, roles, and responsibilities for all resources. Create performance measures for all resources. Managing, updating and maintaining all ZTA program governance documents including but not limited to the ZTA roadmap; which articulates the programs vision, scope, and direction Responsible for development of all management artifacts (PMP, IMP, CP, RMP, QAP, etc.). Ensure program integration and operational processes and procedures. Establishing and maintaining relationships among all stakeholders. Design Dashboard/Briefings to measure program performance, schedule, etc. Responsible for mapping ZTA capabilities outlined throughout this PWS, existing capabilities within the department, and new capabilities the Contractor recommends be added to the Pillars of Zero Trust (currently 5 Pillars) as outlined by CISA, M-21-31, M-22-01, M-22-09, EO 14028, NIST 800-207, and any future memoranda, executive orders, and standards. The Contractor must also map new ZTA capabilities that the Government approves Mentor Team Leads Review and ensure all deliverables are submitted in accordance with the SOW and in a timely manner. Cross task area support as required. Qualifications: A minimum of 10 years of IT cybersecurity management experience including 3 years of direct support for the US Government OR a relevant Bachelor's degree in IT, computer science, business or engineering and 10+ years of IT cybersecurity management experience including 3 years of direct support for the US Government. Experience communicating effectively, both oral and written, with technical, non-technical, and executive-level customers. Understanding and experience with Agile Principles, processes and methodologies. Knowledge of EO 14028, OMB M 22-09, Federal, DoD, and CISA Zero Trust Architecture, Maturity Model, and Technical Reference Architectures. Excellent communication, collaboration, and problem-solving skills. Ability to work independently and as part of a team. Demonstrated ability to effectively engage and manage relationships with highly political clients while maintaining a professional demeanor, exhibiting patience, and navigating sensitive situations with tact. Ability to navigate complex and politically sensitive client environments with professionalism, patience, and tact. Zero Trust Specific Qualifications: System Maturity Model Expertise in the implementation, strategy, roadmap, and analysis with regard to TSA systems and the TSA Enterprise and meet the requirements outlined in M-21-31, M-22-09, EO 14028, and NIST SP 800-207. Working experience associated with implementing all of the Zero Trust requirements based off of the CISA Zero Trust Maturity Model 2.0 and any upcoming versions. SME level knowledge within at least one of the five Zero Trust Maturity Model pillars as defined by the CISA Maturity Model. Possess a deep understanding and proficiency in the principles, technologies, and best practices associated with the pillars. Provide strategic guidance and expertise in implementing Zero Trust within their assigned pillar, ensuring alignment with industry standards and organizational objectives. Deep understanding of the criteria needed to meet the Federal Governments intended, optimal, maturity level. Ability to develop a Zero Trust Maturity Roadmap to achieve optimal maturity level. Education: Minimum of a Bachelor of Science (or higher) in one of the following: computer engineering, computer science, IT, cyber security, or a related field. Relevant years of experience may be used in substitution for situations where the candidate does not have a Bachelor's degree in the required field. Clearance level: Minimum of an active Secret Clearance. Work Location: Hybrid - Primarily Remote. Required onsite work at the client location in Springfield, VA and Zermount HQ in Arlington, VA., will be occasionally required. Hours of Operation: Business Hours: 8:00 am EST - 4:30 pm EST.
09/26/2026
Full time
Job Description Job Description ZERO TRUST PROJECT LEAD POSITION DESCRIPTION General Description Zermount Inc. is seeking a Zero Trust (ZT) Technical Project Lead with demonstrated experience in providing enterprise support services while leveraging industry-standard service management best practices. We are looking for a team lead that is able to withstand even the most complex environments for our ZT enterprise initiative. The Project Lead will lead, plan, and manage Information Technology (IT) projects as well as provide leadership and guiding technical staff. They will integrate business and technical aspects of projects that are a part of the implementation of ZT principles across all pillars of ZT (identity, device, network, application and workload and data) to assist the client in meeting the requirements set forth by EO 14028 and OMB M 22-09. The Project Lead will also assess business implications, monitor progress in meeting deadlines, standards, and customer cost targets. They will establish goals and plans that meet project objectives and have expert technical knowledge. In addition, they will direct and control activities for a client, having overall responsibility for financial management, methods, and staffing to ensure all technical requirements are met. This position also includes client reporting and interfacing with senior management to communicate a program's progress and achievements. Decision-making and domain knowledge may have a critical impact on project implementation. The Project Lead will supervise others. Duties & Responsibilities: The ZT Project Lead will lead the Zermount ZT Team to ensure we are designing and implementing solutions and services that secure federal networks and provide leadership required to meet the objectives of EO 14028 and other Federal requirements. Additionally, the ZT Project Lead will provide support and services to include: Analyze, plan, and develop scheduled project plans. Responsible for program Integrated Master Scheduler (IMS) updates, health, and accuracy. Responsible for quality management and control. Provide SME support and technical guidance to information system stakeholders on the implementation of ZTA requirements and participate in design reviews upon request. Ensure alignment of the ZTA program to organizational strategies and deliver anticipated benefits of ZT as outlined in EO 14028, the CISA ZT Maturity Model, and the NIST SP 800-207. Creating month status reports (progression week 1 through week 4 buildup). Perform risk management to include: (1) managing risk across the ZTA program as the landscape evolves; and (2) integrating ZTA into the existing TSA and DHS Cybersecurity Risk Management framework and CISA's ZT maturity model with the goal of the solution reaching the optimal state of maturity. Draft Program Management Report (PMR). Responsible for streamlining and automating enterprise-level performance reporting for all components within ZT, aligned with existing and planned reporting and analytics structures and tools, such as the Continuous Diagnostics and Mitigation (CDM) dashboards, FISMA reporting, and Information Security Continuous Monitoring (ISCM) dashboards Establishing and implementing training processes for all technical personnel. Assisting the TSA in its ultimate goal of meeting or exceeding the "managed and measurable" IG CIGIE FISMA maturity metrics as amended, for all applicable security functions for ZT. Develop, implement, and maintain enterprise-wide performance metrics and measures for the ZT initiative Determine and define clear deliverables, roles, and responsibilities for all resources. Create performance measures for all resources. Managing, updating and maintaining all ZTA program governance documents including but not limited to the ZTA roadmap; which articulates the programs vision, scope, and direction Responsible for development of all management artifacts (PMP, IMP, CP, RMP, QAP, etc.). Ensure program integration and operational processes and procedures. Establishing and maintaining relationships among all stakeholders. Design Dashboard/Briefings to measure program performance, schedule, etc. Responsible for mapping ZTA capabilities outlined throughout this PWS, existing capabilities within the department, and new capabilities the Contractor recommends be added to the Pillars of Zero Trust (currently 5 Pillars) as outlined by CISA, M-21-31, M-22-01, M-22-09, EO 14028, NIST 800-207, and any future memoranda, executive orders, and standards. The Contractor must also map new ZTA capabilities that the Government approves Mentor Team Leads Review and ensure all deliverables are submitted in accordance with the SOW and in a timely manner. Cross task area support as required. Qualifications: A minimum of 10 years of IT cybersecurity management experience including 3 years of direct support for the US Government OR a relevant Bachelor's degree in IT, computer science, business or engineering and 10+ years of IT cybersecurity management experience including 3 years of direct support for the US Government. Experience communicating effectively, both oral and written, with technical, non-technical, and executive-level customers. Understanding and experience with Agile Principles, processes and methodologies. Knowledge of EO 14028, OMB M 22-09, Federal, DoD, and CISA Zero Trust Architecture, Maturity Model, and Technical Reference Architectures. Excellent communication, collaboration, and problem-solving skills. Ability to work independently and as part of a team. Demonstrated ability to effectively engage and manage relationships with highly political clients while maintaining a professional demeanor, exhibiting patience, and navigating sensitive situations with tact. Ability to navigate complex and politically sensitive client environments with professionalism, patience, and tact. Zero Trust Specific Qualifications: System Maturity Model Expertise in the implementation, strategy, roadmap, and analysis with regard to TSA systems and the TSA Enterprise and meet the requirements outlined in M-21-31, M-22-09, EO 14028, and NIST SP 800-207. Working experience associated with implementing all of the Zero Trust requirements based off of the CISA Zero Trust Maturity Model 2.0 and any upcoming versions. SME level knowledge within at least one of the five Zero Trust Maturity Model pillars as defined by the CISA Maturity Model. Possess a deep understanding and proficiency in the principles, technologies, and best practices associated with the pillars. Provide strategic guidance and expertise in implementing Zero Trust within their assigned pillar, ensuring alignment with industry standards and organizational objectives. Deep understanding of the criteria needed to meet the Federal Governments intended, optimal, maturity level. Ability to develop a Zero Trust Maturity Roadmap to achieve optimal maturity level. Education: Minimum of a Bachelor of Science (or higher) in one of the following: computer engineering, computer science, IT, cyber security, or a related field. Relevant years of experience may be used in substitution for situations where the candidate does not have a Bachelor's degree in the required field. Clearance level: Minimum of an active Secret Clearance. Work Location: Hybrid - Primarily Remote. Required onsite work at the client location in Springfield, VA and Zermount HQ in Arlington, VA., will be occasionally required. Hours of Operation: Business Hours: 8:00 am EST - 4:30 pm EST.
Job Description Job Description Description: Job Title: Security Control Assessor Location: On Site in Arlington, VA Department: Cyber Security Services Reports To: Management FLSA Status: Full Time/Non-exempt Job Purpose: The security control assessor (SCAs) supports a critical, objective role to evaluate the effectiveness of implemented controls in mitigating security risks. The SCA will support a critical mission within the intelligence community. In the role as a SCA, you are expected to use automated scanning tools, manual techniques, and specialized testing methodologies to identify weaknesses and vulnerabilities. The SCA is expected to be a collaborative member of the RMF program of the organization, to provide intelligent input to system security architectures in order to align with RMF principles and guidelines. This includes ensuring to guide the RMF process so that security controls are integrated seamlessly into system designs to provide comprehensive protection against threats and vulnerabilities. Duties & Responsibilities: The SCA's specific duties include: Advise the Information System Owner (ISO) concerning the impact levels for Confidentiality, Integrity, and Availability for the information on systems. Ensure security assessments are completed for each IS. Initiate a POA&M with identified weaknesses and suspense dates for each IS based on findings and recommendations from the SAR. Evaluate security assessment documentation and provide written recommendations for security authorization to the CISO and AO. Assess proposed changes to Information Systems, their environment of operation, and mission needs that could affect system authorization. Serve as a cybersecurity technical advisor to the CISO and AO under their purview. Be integral to the development of the monitoring strategy. The system-level continuous monitoring strategy must conform to all applicable published DoD enterprise-level or DoD Component-level continuous monitoring strategies. Determine and document in the SAR a risk level for every noncompliant security control in the system baseline. Determine and document in the SAR an aggregate level of risk to the system and identify the key drivers for the assessment. The SCA's risk assessment considers threats, vulnerabilities, and potential impacts as well as existing and planned risk mitigation. Develop the continuous monitoring plan specific to the information system. The SCA is responsible for the RMF deliverables associated with Step 4 of DOD and IC RMF Policies for assigned systems. This includes, but is not limited to: Security Assessment Plans tailored to specific systems control requirements Security control assessment input, which includes narratives for the review of controls and artifacts Security Assessment Reports ATO recommendations or ATO with Condition Memorandums Conduct initial remediation actions once a security assessment has been completed to ensure proper hand off to the ISSM and ISSOs. Assessment of selected controls IAW continuous monitoring strategy The SCA is expected to have additional duties as assigned in support of corporate cyber security services. Additional details are reviewed in accordance with company policies. Requirements: Required Skills & Experience: Strong knowledge of Risk Management Framework (RMF) 800-37 and continuous monitoring 800-137 Expert knowledge and hands-on experience with FISMA Systems, NIST 800-series guidelines, FIPS, Security Assessment & Authorization (SA&A) requirements and processes, Continuous Monitoring Framework experience and its tools, Plan of Action & Milestones (POA&M) policies, and vulnerability/patch management, risk management, project management, proficient with Microsoft products - Word, Excel, PowerPoint. Proficient with vulnerability and scanning tools and well-versed in interpreting risk posture resulting from assessment reports. Experience in project management and tracking, and the Microsoft suite of office products Experience of assessing cloud-based security authorizations (FedRamp, AWS & Azure) as well as the NIST control responsibilities Experience with SAP/JSIG Expert with documenting and or reviewing of security materials such as; system security plans (SSP), Security Assessment Report (SAR), and Security Assessment Plan (SAP), and other documents per NIST 800 guidelines. Experience supporting cloud-based security authorizations (FedRamp, AWS, & Azure) Experience creating Security Assessment Plans, Security Assessment Reports, and Executive-level briefings Qualifications: Bachelor's Degree in Computer Science or a related technical discipline Master's Degree preferred. Minimum 6-10 years of experience. Must currently possess an active TS/SCI with the ability to obtain and maintain a CI polygraph. DOD 8140 IAM Level II (CAP, CASP, CISM, CISSP, GSLC, CCISO) is required Systems Security Engineering background preferred. Effective communication skills to collaborate with cross-functional teams and stakeholders on implementing security measures organization-wide. Strong analytical skills for identifying system vulnerabilities and documenting control remediation recommendations through collaboration on System Impact Analysis and Documented Risk Acceptance. Detail-oriented with the ability to manage multiple tasks and prioritize effectively. Comprehensive knowledge of RMF activities at a senior level (ability to articulate to Executive audiences preferred). Familiarity with federal regulatory requirements, contractual obligations, and industry standards related to information security. Evaluate adherence to standards such as Privacy, GDPR, and HIPAA Other: This is typical office or administrative work, and there is no exposure to adverse environmental conditions. This position requires sedentary work. Sedentary work is defined as: Exerting up to 10 pounds of force occasionally and/or a negligible amount of force frequently or constantly to lift, carry, push, pull or otherwise move objects, including the human body. Sedentary work involves sitting most of the time. Jobs are sedentary if walking and standing are required only occasionally, and all other sedentary criteria are met.
09/26/2026
Full time
Job Description Job Description Description: Job Title: Security Control Assessor Location: On Site in Arlington, VA Department: Cyber Security Services Reports To: Management FLSA Status: Full Time/Non-exempt Job Purpose: The security control assessor (SCAs) supports a critical, objective role to evaluate the effectiveness of implemented controls in mitigating security risks. The SCA will support a critical mission within the intelligence community. In the role as a SCA, you are expected to use automated scanning tools, manual techniques, and specialized testing methodologies to identify weaknesses and vulnerabilities. The SCA is expected to be a collaborative member of the RMF program of the organization, to provide intelligent input to system security architectures in order to align with RMF principles and guidelines. This includes ensuring to guide the RMF process so that security controls are integrated seamlessly into system designs to provide comprehensive protection against threats and vulnerabilities. Duties & Responsibilities: The SCA's specific duties include: Advise the Information System Owner (ISO) concerning the impact levels for Confidentiality, Integrity, and Availability for the information on systems. Ensure security assessments are completed for each IS. Initiate a POA&M with identified weaknesses and suspense dates for each IS based on findings and recommendations from the SAR. Evaluate security assessment documentation and provide written recommendations for security authorization to the CISO and AO. Assess proposed changes to Information Systems, their environment of operation, and mission needs that could affect system authorization. Serve as a cybersecurity technical advisor to the CISO and AO under their purview. Be integral to the development of the monitoring strategy. The system-level continuous monitoring strategy must conform to all applicable published DoD enterprise-level or DoD Component-level continuous monitoring strategies. Determine and document in the SAR a risk level for every noncompliant security control in the system baseline. Determine and document in the SAR an aggregate level of risk to the system and identify the key drivers for the assessment. The SCA's risk assessment considers threats, vulnerabilities, and potential impacts as well as existing and planned risk mitigation. Develop the continuous monitoring plan specific to the information system. The SCA is responsible for the RMF deliverables associated with Step 4 of DOD and IC RMF Policies for assigned systems. This includes, but is not limited to: Security Assessment Plans tailored to specific systems control requirements Security control assessment input, which includes narratives for the review of controls and artifacts Security Assessment Reports ATO recommendations or ATO with Condition Memorandums Conduct initial remediation actions once a security assessment has been completed to ensure proper hand off to the ISSM and ISSOs. Assessment of selected controls IAW continuous monitoring strategy The SCA is expected to have additional duties as assigned in support of corporate cyber security services. Additional details are reviewed in accordance with company policies. Requirements: Required Skills & Experience: Strong knowledge of Risk Management Framework (RMF) 800-37 and continuous monitoring 800-137 Expert knowledge and hands-on experience with FISMA Systems, NIST 800-series guidelines, FIPS, Security Assessment & Authorization (SA&A) requirements and processes, Continuous Monitoring Framework experience and its tools, Plan of Action & Milestones (POA&M) policies, and vulnerability/patch management, risk management, project management, proficient with Microsoft products - Word, Excel, PowerPoint. Proficient with vulnerability and scanning tools and well-versed in interpreting risk posture resulting from assessment reports. Experience in project management and tracking, and the Microsoft suite of office products Experience of assessing cloud-based security authorizations (FedRamp, AWS & Azure) as well as the NIST control responsibilities Experience with SAP/JSIG Expert with documenting and or reviewing of security materials such as; system security plans (SSP), Security Assessment Report (SAR), and Security Assessment Plan (SAP), and other documents per NIST 800 guidelines. Experience supporting cloud-based security authorizations (FedRamp, AWS, & Azure) Experience creating Security Assessment Plans, Security Assessment Reports, and Executive-level briefings Qualifications: Bachelor's Degree in Computer Science or a related technical discipline Master's Degree preferred. Minimum 6-10 years of experience. Must currently possess an active TS/SCI with the ability to obtain and maintain a CI polygraph. DOD 8140 IAM Level II (CAP, CASP, CISM, CISSP, GSLC, CCISO) is required Systems Security Engineering background preferred. Effective communication skills to collaborate with cross-functional teams and stakeholders on implementing security measures organization-wide. Strong analytical skills for identifying system vulnerabilities and documenting control remediation recommendations through collaboration on System Impact Analysis and Documented Risk Acceptance. Detail-oriented with the ability to manage multiple tasks and prioritize effectively. Comprehensive knowledge of RMF activities at a senior level (ability to articulate to Executive audiences preferred). Familiarity with federal regulatory requirements, contractual obligations, and industry standards related to information security. Evaluate adherence to standards such as Privacy, GDPR, and HIPAA Other: This is typical office or administrative work, and there is no exposure to adverse environmental conditions. This position requires sedentary work. Sedentary work is defined as: Exerting up to 10 pounds of force occasionally and/or a negligible amount of force frequently or constantly to lift, carry, push, pull or otherwise move objects, including the human body. Sedentary work involves sitting most of the time. Jobs are sedentary if walking and standing are required only occasionally, and all other sedentary criteria are met.
Job Description Job Description Experienced assessor sought to lead rigorous, evidence-based security assessments of cloud and hybrid systems supporting federal missions. Who we are looking for: Spry Methods is seeking an experienced Senior Cloud Security Assessor to join our team in the Washington, DC area. The successful candidate will bring extensive hands-on experience conducting independent security control assessments of cloud and hybrid systems, with particular depth in federal cloud environments. This role requires sound professional judgment, strong analytical skills, and a practical, common-sense approach to applying security requirements to system data, technical evidence, mission context, and actual risk. Key Responsibilities: • Lead full-cycle Security Assessment and Authorization (SA&A) activities for cloud, hybrid, and enterprise systems as an independent assessor. • Assess Microsoft Azure and Amazon Web Services (AWS) environments, including the implementation and operating effectiveness of administrative, operational, and technical security controls. • Retrieve and review FedRAMP authorization packages and supporting documentation, then analyze the package for applicability, control inheritance, residual risk, gaps, and customer responsibilities. • Conduct detailed analysis of assessment artifacts, including system security plans, policies, procedures, architecture and data-flow diagrams, inventories, configurations, logs, scan results, test outputs, and other supporting evidence. • Develop Security Assessment Plans (SAPs), Security Assessment Reports (SARs), Risk Assessment Reports (RARs), Required Evidence Lists, and Plans of Action and Milestones (POA&Ms). • Perform network, system, application, and NIST security control testing from administrative, operational, and technical perspectives. • Analyze vulnerability scan results, interpret risk, and use manual validation and corroborating evidence to distinguish actionable findings from false positives or unsupported conclusions. • Apply security requirements using practical judgment and data context rather than relying solely on checklist compliance. Evaluate whether evidence is relevant, reliable, sufficient, and representative of the assessed environment. • Clearly communicate findings, risk, root cause, and feasible mitigation options to technical teams, system owners, executives, and other assessment stakeholders. • Coordinate evidence requests, interviews, test activities, and assessment schedules with customer personnel and Information Systems Security Analysts. • Support security assessment program operations and contribute to consistent assessment methods, quality reviews, and defensible reporting. Minimum Qualifications • Active Certified Information Systems Security Professional (CISSP) certification is required. • At least eight years of demonstrated, hands-on experience conducting security control assessments, including substantial experience serving as an independent assessor for cloud and hybrid systems. • Extensive experience conducting independent security assessments of federal systems hosted in Microsoft Azure and AWS environments, including evaluation of security controls, architecture, inherited controls, customer-configured controls, and cloud-specific risks. • Demonstrated experience retrieving, navigating, and analyzing FedRAMP authorization packages and associated security artifacts. • Strong knowledge of federal Risk Management Framework (RMF) processes and NIST security control assessment practices. • Ability to analyze large volumes of technical and governance evidence, connect information across artifacts, identify inconsistencies, and reach clear, supportable conclusions. • Strong understanding of IT security requirements, technical countermeasures, vulnerability management, risk management, contingency planning, secure data communications, and system security architecture. • Excellent technical writing and stakeholder communication skills, with the ability to explain risk and recommended mitigation in clear, decision-oriented language. • Bachelor's degree in cybersecurity, information technology, computer science, or a related field, or eight additional years of relevant specialized experience. • Experience using CSAM or a comparable governance, risk, and compliance platform. Preferred Qualifications • Certificate of Cloud Security Knowledge (CCSK), Certified Cloud Security Professional (CCSP), Certified Governance, Risk and Compliance (CGRC), or comparable cloud or assessment certification. • Experience supporting federal cybersecurity programs and conducting assessments, audits, or control implementation reviews in accordance with NIST Special Publications. • Experience assessing cloud service offerings that rely on FedRAMP-authorized services and documenting control inheritance and customer responsibility requirements. • DoD 8570/8140 IAM Level II eligibility or an equivalent qualification, when required by the customer environment. • Experience evaluating privacy and data protection considerations as part of security assessments. Success in this role: The successful assessor is technically credible, independent, and evidence-driven. They know when the data supports a finding, when additional validation is needed, and when a requirement must be interpreted in light of architecture, mission use, and actual exposure. They produce assessment results that are clear, consistent, defensible, and actionable. We may use artificial intelligence (AI) tools to support parts of the hiring process, such as reviewing applications, analyzing resumes, or assessing responses and identifying potential inconsistencies or verification signals in application materials based on available information. These tools assist our recruitment team but do not replace human judgment. Final hiring decisions are ultimately made by humans. If you would like more information about how your data is processed, please contact us.
09/26/2026
Full time
Job Description Job Description Experienced assessor sought to lead rigorous, evidence-based security assessments of cloud and hybrid systems supporting federal missions. Who we are looking for: Spry Methods is seeking an experienced Senior Cloud Security Assessor to join our team in the Washington, DC area. The successful candidate will bring extensive hands-on experience conducting independent security control assessments of cloud and hybrid systems, with particular depth in federal cloud environments. This role requires sound professional judgment, strong analytical skills, and a practical, common-sense approach to applying security requirements to system data, technical evidence, mission context, and actual risk. Key Responsibilities: • Lead full-cycle Security Assessment and Authorization (SA&A) activities for cloud, hybrid, and enterprise systems as an independent assessor. • Assess Microsoft Azure and Amazon Web Services (AWS) environments, including the implementation and operating effectiveness of administrative, operational, and technical security controls. • Retrieve and review FedRAMP authorization packages and supporting documentation, then analyze the package for applicability, control inheritance, residual risk, gaps, and customer responsibilities. • Conduct detailed analysis of assessment artifacts, including system security plans, policies, procedures, architecture and data-flow diagrams, inventories, configurations, logs, scan results, test outputs, and other supporting evidence. • Develop Security Assessment Plans (SAPs), Security Assessment Reports (SARs), Risk Assessment Reports (RARs), Required Evidence Lists, and Plans of Action and Milestones (POA&Ms). • Perform network, system, application, and NIST security control testing from administrative, operational, and technical perspectives. • Analyze vulnerability scan results, interpret risk, and use manual validation and corroborating evidence to distinguish actionable findings from false positives or unsupported conclusions. • Apply security requirements using practical judgment and data context rather than relying solely on checklist compliance. Evaluate whether evidence is relevant, reliable, sufficient, and representative of the assessed environment. • Clearly communicate findings, risk, root cause, and feasible mitigation options to technical teams, system owners, executives, and other assessment stakeholders. • Coordinate evidence requests, interviews, test activities, and assessment schedules with customer personnel and Information Systems Security Analysts. • Support security assessment program operations and contribute to consistent assessment methods, quality reviews, and defensible reporting. Minimum Qualifications • Active Certified Information Systems Security Professional (CISSP) certification is required. • At least eight years of demonstrated, hands-on experience conducting security control assessments, including substantial experience serving as an independent assessor for cloud and hybrid systems. • Extensive experience conducting independent security assessments of federal systems hosted in Microsoft Azure and AWS environments, including evaluation of security controls, architecture, inherited controls, customer-configured controls, and cloud-specific risks. • Demonstrated experience retrieving, navigating, and analyzing FedRAMP authorization packages and associated security artifacts. • Strong knowledge of federal Risk Management Framework (RMF) processes and NIST security control assessment practices. • Ability to analyze large volumes of technical and governance evidence, connect information across artifacts, identify inconsistencies, and reach clear, supportable conclusions. • Strong understanding of IT security requirements, technical countermeasures, vulnerability management, risk management, contingency planning, secure data communications, and system security architecture. • Excellent technical writing and stakeholder communication skills, with the ability to explain risk and recommended mitigation in clear, decision-oriented language. • Bachelor's degree in cybersecurity, information technology, computer science, or a related field, or eight additional years of relevant specialized experience. • Experience using CSAM or a comparable governance, risk, and compliance platform. Preferred Qualifications • Certificate of Cloud Security Knowledge (CCSK), Certified Cloud Security Professional (CCSP), Certified Governance, Risk and Compliance (CGRC), or comparable cloud or assessment certification. • Experience supporting federal cybersecurity programs and conducting assessments, audits, or control implementation reviews in accordance with NIST Special Publications. • Experience assessing cloud service offerings that rely on FedRAMP-authorized services and documenting control inheritance and customer responsibility requirements. • DoD 8570/8140 IAM Level II eligibility or an equivalent qualification, when required by the customer environment. • Experience evaluating privacy and data protection considerations as part of security assessments. Success in this role: The successful assessor is technically credible, independent, and evidence-driven. They know when the data supports a finding, when additional validation is needed, and when a requirement must be interpreted in light of architecture, mission use, and actual exposure. They produce assessment results that are clear, consistent, defensible, and actionable. We may use artificial intelligence (AI) tools to support parts of the hiring process, such as reviewing applications, analyzing resumes, or assessing responses and identifying potential inconsistencies or verification signals in application materials based on available information. These tools assist our recruitment team but do not replace human judgment. Final hiring decisions are ultimately made by humans. If you would like more information about how your data is processed, please contact us.
Vaco is hiring a Chief Information Officer (CIO) in Lombard, IL. Location: Lombard, IL (Chicago Area) On-Site About the Opportunity A leading transportation and mobility services organization is seeking a visionary and operationally focused Chief Information Officer (CIO) to lead enterprise-wide technology strategy, digital transformation, cybersecurity, and IT operations. Supporting a large-scale network of transportation services across hundreds of locations nationwide, this organization operates in a highly distributed, mission-critical environment where technology plays a central role in safety, service delivery, workforce productivity, and customer experience. Reporting directly to the Chief Executive Officer and serving as a member of the Executive Leadership Team, the CIO will be responsible for shaping the future technology landscape while ensuring operational excellence across all information technology functions. This executive will serve as a trusted business partner, driving innovation, modernization, and enterprise performance through strategic technology investment and disciplined execution. Position Overview The Chief Information Officer is responsible for developing and executing a comprehensive technology and digital strategy that supports business growth, operational efficiency, safety, and customer satisfaction. This leader will oversee all aspects of information technology, including enterprise applications, infrastructure, cybersecurity, data and analytics, field support services, project management, innovation, and vendor management. Success in this role requires a highly collaborative executive who combines strategic vision with hands-on leadership and a strong operational mindset. The ideal candidate will have experience leading technology organizations in complex, geographically dispersed environments where reliability, scalability, and service excellence are essential. Key Responsibilities Technology Strategy & Digital Transformation Define and execute a long-term technology roadmap aligned with business objectives and customer expectations. Lead enterprise-wide digital transformation initiatives that improve operational efficiency, safety, workforce effectiveness, and customer outcomes. Identify emerging technologies and innovation opportunities that create measurable business value. Serve as a strategic advisor to executive leadership on technology trends, risks, investments, and modernization priorities. Foster a culture that embraces innovation, continuous improvement, and digital adoption. IT Operations & Service Excellence Ensure the reliability, availability, and performance of technology systems supporting a large national operating network. Oversee IT service delivery and support functions, ensuring responsive and effective support for a 24/7 operational environment. Establish strong governance, service management disciplines, and performance metrics across the technology organization. Maintain operational continuity through resilient infrastructure, disaster recovery, and business continuity planning. Drive technology standardization and process optimization across multiple business locations. Enterprise Applications & Data Strategy Lead the strategy, optimization, and governance of enterprise technology platforms supporting operations, finance, human resources, scheduling, maintenance, safety, and customer-facing functions. Modernize legacy applications and streamline the overall technology architecture. Expand data analytics and reporting capabilities to support informed business decisions and operational performance. Promote the use of advanced analytics and business intelligence tools across the organization. Establish a strong data governance framework to ensure quality, consistency, accessibility, and security of enterprise data. Cybersecurity & Risk Management Develop and maintain a comprehensive cybersecurity strategy that protects critical systems, data, and operational assets. Strengthen security governance, risk management, and compliance capabilities. Oversee incident response, disaster recovery, and business continuity programs. Ensure technology practices meet applicable regulatory, legal, and industry requirements. Create a culture of security awareness and accountability throughout the organization. Leadership & Talent Development Build and lead a high-performing technology organization focused on collaboration, innovation, and results. Recruit, develop, and retain top technology talent. Partner closely with operational and corporate leaders to align technology solutions with business needs. Lead organizational change efforts that support successful technology adoption and business transformation. Encourage a customer-focused mindset and culture of accountability across the IT function. Financial, Vendor & Portfolio Management Manage technology budgets, capital investments, and resource allocation to maximize business value. Identify opportunities for cost optimization while maintaining high service levels. Oversee strategic technology vendors, contract negotiations, and supplier performance. Manage the enterprise technology project portfolio, ensuring prioritization, governance, and successful delivery. Establish clear ROI measures for technology investments and transformation initiatives. Qualifications Required Experience Executive-level technology leadership experience in a large, distributed, operationally intensive organization. Demonstrated success leading enterprise technology modernization and digital transformation programs. Significant experience managing mission-critical systems within complex, customer-facing operating environments. Proven track record of building high-performing teams and developing strong leadership benches. Strong business acumen with experience managing large budgets, strategic technology investments, and vendor ecosystems. Ability to influence senior stakeholders and lead effectively within a matrixed organizational structure. Preferred Experience Background in transportation, logistics, infrastructure, industrial services, utilities, field services, or similarly complex industries. Experience operating within multinational or globally integrated organizations. Familiarity with public-sector environments, regulatory compliance requirements, or transportation technologies. Experience overseeing cloud transformation, enterprise application modernization, and advanced analytics initiatives. Leadership Profile The successful candidate will demonstrate: Strategic thinking combined with disciplined execution. Strong business partnership and stakeholder management skills. Excellent communication and influencing capabilities. A pragmatic, hands-on leadership style. Strong operational awareness and customer focus. The ability to lead through change and transformation. High integrity, humility, accountability, and commitment to organizational success. By submitting to this position, you are agreeing to be included in our talent pool for future hiring for similarly qualified positions. EEO Notice Vaco by Highspring is an Equal Opportunity Employer and does not discriminate against any employee or applicant for employment because of race (including but not limited to traits historically associated with race such as hair texture and hair style), color, sex (includes pregnancy or related conditions), religion or creed, national origin, citizenship, age, disability, status as a veteran, union membership, ethnicity, gender, gender identity, gender expression, sexual orientation, marital status, political affiliation, or any other protected characteristics as required by federal, state or local law. Vaco by Highspring and its parents, affiliates, and subsidiaries are committed to the full inclusion of all qualified individuals. As part of this commitment, Vaco by Highspring and its parents, affiliates, and subsidiaries will ensure that persons with disabilities are provided reasonable accommodations. If reasonable accommodation is needed to participate in the job application or interview process, to perform essential job functions, and/or to receive other benefits and privileges of employment, please contact . Vaco by Highspring also wants all applicants to know their rights that workplace discrimination is illegal. Representation Notice By submitting to this position, you agree that you will be giving Vaco by Highspring the exclusive right to present your as a candidate for the foregoing employment opportunity. You further agree that you have represented information about yourself accurately and have not affirmatively misrepresented your qualifications. You also agree to maintain as confidential, to the fullest extent permitted by law, any information you learn from Vaco by Highspring about the position and you will limit disclosure of information about the position only to the extent necessary to perform any obligations in furtherance of your application. In exchange, Vaco by Highspring agrees to exercise reasonable efforts to represent you through all solicitation, job screening and resume dispersal. For residents of Ontario, Canada: Based on Highspring's discussions with its Client, Highspring's understanding is that this position for employment is a current vacancy (either through Highspring as a contractor or with the client directly). Privacy Notice Vaco by Highspring and its parents, affiliates, and subsidiaries ("we," "our," or "Vaco by Highspring") respects your privacy and are committed to providing transparent notice of our policies. California residents may access Vaco by Highspring HR Notice at Collection for California Applicants and Employees here. Virginia residents may access our state specific policies here. Residents of all other states may access our policies here . click apply for full job details
09/26/2026
Full time
Vaco is hiring a Chief Information Officer (CIO) in Lombard, IL. Location: Lombard, IL (Chicago Area) On-Site About the Opportunity A leading transportation and mobility services organization is seeking a visionary and operationally focused Chief Information Officer (CIO) to lead enterprise-wide technology strategy, digital transformation, cybersecurity, and IT operations. Supporting a large-scale network of transportation services across hundreds of locations nationwide, this organization operates in a highly distributed, mission-critical environment where technology plays a central role in safety, service delivery, workforce productivity, and customer experience. Reporting directly to the Chief Executive Officer and serving as a member of the Executive Leadership Team, the CIO will be responsible for shaping the future technology landscape while ensuring operational excellence across all information technology functions. This executive will serve as a trusted business partner, driving innovation, modernization, and enterprise performance through strategic technology investment and disciplined execution. Position Overview The Chief Information Officer is responsible for developing and executing a comprehensive technology and digital strategy that supports business growth, operational efficiency, safety, and customer satisfaction. This leader will oversee all aspects of information technology, including enterprise applications, infrastructure, cybersecurity, data and analytics, field support services, project management, innovation, and vendor management. Success in this role requires a highly collaborative executive who combines strategic vision with hands-on leadership and a strong operational mindset. The ideal candidate will have experience leading technology organizations in complex, geographically dispersed environments where reliability, scalability, and service excellence are essential. Key Responsibilities Technology Strategy & Digital Transformation Define and execute a long-term technology roadmap aligned with business objectives and customer expectations. Lead enterprise-wide digital transformation initiatives that improve operational efficiency, safety, workforce effectiveness, and customer outcomes. Identify emerging technologies and innovation opportunities that create measurable business value. Serve as a strategic advisor to executive leadership on technology trends, risks, investments, and modernization priorities. Foster a culture that embraces innovation, continuous improvement, and digital adoption. IT Operations & Service Excellence Ensure the reliability, availability, and performance of technology systems supporting a large national operating network. Oversee IT service delivery and support functions, ensuring responsive and effective support for a 24/7 operational environment. Establish strong governance, service management disciplines, and performance metrics across the technology organization. Maintain operational continuity through resilient infrastructure, disaster recovery, and business continuity planning. Drive technology standardization and process optimization across multiple business locations. Enterprise Applications & Data Strategy Lead the strategy, optimization, and governance of enterprise technology platforms supporting operations, finance, human resources, scheduling, maintenance, safety, and customer-facing functions. Modernize legacy applications and streamline the overall technology architecture. Expand data analytics and reporting capabilities to support informed business decisions and operational performance. Promote the use of advanced analytics and business intelligence tools across the organization. Establish a strong data governance framework to ensure quality, consistency, accessibility, and security of enterprise data. Cybersecurity & Risk Management Develop and maintain a comprehensive cybersecurity strategy that protects critical systems, data, and operational assets. Strengthen security governance, risk management, and compliance capabilities. Oversee incident response, disaster recovery, and business continuity programs. Ensure technology practices meet applicable regulatory, legal, and industry requirements. Create a culture of security awareness and accountability throughout the organization. Leadership & Talent Development Build and lead a high-performing technology organization focused on collaboration, innovation, and results. Recruit, develop, and retain top technology talent. Partner closely with operational and corporate leaders to align technology solutions with business needs. Lead organizational change efforts that support successful technology adoption and business transformation. Encourage a customer-focused mindset and culture of accountability across the IT function. Financial, Vendor & Portfolio Management Manage technology budgets, capital investments, and resource allocation to maximize business value. Identify opportunities for cost optimization while maintaining high service levels. Oversee strategic technology vendors, contract negotiations, and supplier performance. Manage the enterprise technology project portfolio, ensuring prioritization, governance, and successful delivery. Establish clear ROI measures for technology investments and transformation initiatives. Qualifications Required Experience Executive-level technology leadership experience in a large, distributed, operationally intensive organization. Demonstrated success leading enterprise technology modernization and digital transformation programs. Significant experience managing mission-critical systems within complex, customer-facing operating environments. Proven track record of building high-performing teams and developing strong leadership benches. Strong business acumen with experience managing large budgets, strategic technology investments, and vendor ecosystems. Ability to influence senior stakeholders and lead effectively within a matrixed organizational structure. Preferred Experience Background in transportation, logistics, infrastructure, industrial services, utilities, field services, or similarly complex industries. Experience operating within multinational or globally integrated organizations. Familiarity with public-sector environments, regulatory compliance requirements, or transportation technologies. Experience overseeing cloud transformation, enterprise application modernization, and advanced analytics initiatives. Leadership Profile The successful candidate will demonstrate: Strategic thinking combined with disciplined execution. Strong business partnership and stakeholder management skills. Excellent communication and influencing capabilities. A pragmatic, hands-on leadership style. Strong operational awareness and customer focus. The ability to lead through change and transformation. High integrity, humility, accountability, and commitment to organizational success. By submitting to this position, you are agreeing to be included in our talent pool for future hiring for similarly qualified positions. EEO Notice Vaco by Highspring is an Equal Opportunity Employer and does not discriminate against any employee or applicant for employment because of race (including but not limited to traits historically associated with race such as hair texture and hair style), color, sex (includes pregnancy or related conditions), religion or creed, national origin, citizenship, age, disability, status as a veteran, union membership, ethnicity, gender, gender identity, gender expression, sexual orientation, marital status, political affiliation, or any other protected characteristics as required by federal, state or local law. Vaco by Highspring and its parents, affiliates, and subsidiaries are committed to the full inclusion of all qualified individuals. As part of this commitment, Vaco by Highspring and its parents, affiliates, and subsidiaries will ensure that persons with disabilities are provided reasonable accommodations. If reasonable accommodation is needed to participate in the job application or interview process, to perform essential job functions, and/or to receive other benefits and privileges of employment, please contact . Vaco by Highspring also wants all applicants to know their rights that workplace discrimination is illegal. Representation Notice By submitting to this position, you agree that you will be giving Vaco by Highspring the exclusive right to present your as a candidate for the foregoing employment opportunity. You further agree that you have represented information about yourself accurately and have not affirmatively misrepresented your qualifications. You also agree to maintain as confidential, to the fullest extent permitted by law, any information you learn from Vaco by Highspring about the position and you will limit disclosure of information about the position only to the extent necessary to perform any obligations in furtherance of your application. In exchange, Vaco by Highspring agrees to exercise reasonable efforts to represent you through all solicitation, job screening and resume dispersal. For residents of Ontario, Canada: Based on Highspring's discussions with its Client, Highspring's understanding is that this position for employment is a current vacancy (either through Highspring as a contractor or with the client directly). Privacy Notice Vaco by Highspring and its parents, affiliates, and subsidiaries ("we," "our," or "Vaco by Highspring") respects your privacy and are committed to providing transparent notice of our policies. California residents may access Vaco by Highspring HR Notice at Collection for California Applicants and Employees here. Virginia residents may access our state specific policies here. Residents of all other states may access our policies here . click apply for full job details