it job board logo
  • Home
  • Find IT Jobs
  • Register CV
  • Register as Employer
  • Contact us
  • Career Advice
  • Recruiting? Post a job
  • Sign in
  • Sign up
  • Home
  • Find IT Jobs
  • Register CV
  • Register as Employer
  • Contact us
  • Career Advice
Sorry, that job is no longer available. Here are some results that may be similar to the job you were looking for.

666 jobs found

Email me jobs like this
Refine Search
Current Search
information system security engineer
Sr. Delivery Consultant, National Security (NatSec) Professional Services (ProServe)
Amazon Web Services, Inc. Jessup, Maryland
This position requires that the candidate selected be a US Citizen and must currently possess and maintain an active TS/SCI security clearance with polygraph. This is a hands-on technical role that requires an advanced software/systems engineering background. Coding/automation and design/architecture skills are required! The Amazon Web Services Professional Services (ProServe) team is seeking a skilled Delivery Consultant to join our team at AWS. ProServe is a global organization of experts that help customers realize their desired business outcomes when utilizing AWS. We work together with customer teams and the AWS Partner Network (APN) to execute enterprise cloud computing initiatives. Our team provides assistance through a collection of offerings which help customers achieve specific outcomes related to enterprise cloud adoption. We also deliver focused guidance through our global specialty practices, which cover a variety of solutions, technologies, and industries. As a Delivery Consultant, you will work closely with customers to design, implement, and manage AWS solutions that meet their technical requirements and business objectives. You'll be a key player in driving customer success throughout their cloud journey, providing technical expertise and best practices across the project lifecycle. You'll collaborate closely with stakeholders to gather requirements, assess current infrastructure, and propose effective migration strategies to AWS. As an experienced technology professional, you will be responsible for: • Designing and implementing complex, scalable, and secure AWS solutions tailored to customer needs • Providing technical guidance and troubleshooting support throughout project delivery • Collaborating with stakeholders to gather requirements and propose effective migration strategies • Acting as a trusted advisor to customers on industry trends and emerging technologies • Sharing knowledge within the organization through mentoring, training, and creating reusable artifacts About the team About AWS AWS values diverse experiences. Even if you do not meet all of the preferred qualifications and skills listed in the job description, we encourage candidates to apply. If your career is just starting, hasn't followed a traditional path, or includes alternative experiences, don't let it stop you from applying. Why AWS? Amazon Web Services (AWS) is the world's most comprehensive and broadly adopted cloud platform. We pioneered cloud computing and never stopped innovating - that's why customers from the most successful startups to Global 500 companies trust our robust suite of products and services to power their businesses. Inclusive Team Culture Here at AWS, it's in our nature to learn and be curious. Our employee-led affinity groups foster a culture of inclusion that empower us to be proud of our differences. Ongoing events and learning experiences, including our Conversations on Race and Ethnicity (CORE) and AmazeCon conferences, inspire us to never stop embracing our uniqueness. Mentorship & Career Growth We're continuously raising our performance bar as we strive to become Earth's Best Employer. That's why you'll find endless knowledge-sharing, mentorship and other career-advancing resources here to help you develop into a better-rounded professional. Work/Life Balance We value work-life harmony. Achieving success at work should never come at the expense of sacrifices at home, which is why we strive for flexibility as part of our working culture. When we feel supported in the workplace and at home, there's nothing we can't achieve in the cloud. BASIC QUALIFICATIONS- 7+ years of technical specialist, design and architecture experience - 5+ years of database (eg. SQL, NoSQL, Hadoop, Spark, Kafka, Kinesis) experience - 7+ years of consulting, design and implementation of serverless distributed solutions experience - 5+ years of software development with object oriented language experience - Current, active US Government Security Clearance of TS/SCI with Polygraph PREFERRED QUALIFICATIONS- degree in advanced technology, or AWS Professional level certification - Knowledge of AWS services including compute, storage, networking, security, databases, machine learning, and serverless technologies - Experience in performance optimization and cost management for cloud environments - Experience communicating technical concepts to diverse audiences in pre-sales environments Amazon is an equal opportunity employer and does not discriminate on the basis of protected veteran status, disability, or other legally protected status. Our inclusive culture empowers Amazonians to deliver the best results for our customers. If you have a disability and need a workplace accommodation or adjustment during the application and hiring process, including support for the interview or onboarding process, please visit for more information. If the country/region you're applying in isn't listed, please contact your Recruiting Partner. The base salary range for this position is listed below. Your Amazon package will include sign-on payments and restricted stock units (RSUs). Final compensation will be determined based on factors including experience, qualifications, and location. Amazon also offers comprehensive benefits including health insurance (medical, dental, vision, prescription, Basic Life & AD&D insurance and option for Supplemental life plans, EAP, Mental Health Support, Medical Advice Line, Flexible Spending Accounts, Adoption and Surrogacy Reimbursement coverage), 401(k) matching, paid time off, and parental leave. Learn more about our benefits at . USA, MD, Jessup - 153 800.00 USD annually
09/26/2026
Full time
This position requires that the candidate selected be a US Citizen and must currently possess and maintain an active TS/SCI security clearance with polygraph. This is a hands-on technical role that requires an advanced software/systems engineering background. Coding/automation and design/architecture skills are required! The Amazon Web Services Professional Services (ProServe) team is seeking a skilled Delivery Consultant to join our team at AWS. ProServe is a global organization of experts that help customers realize their desired business outcomes when utilizing AWS. We work together with customer teams and the AWS Partner Network (APN) to execute enterprise cloud computing initiatives. Our team provides assistance through a collection of offerings which help customers achieve specific outcomes related to enterprise cloud adoption. We also deliver focused guidance through our global specialty practices, which cover a variety of solutions, technologies, and industries. As a Delivery Consultant, you will work closely with customers to design, implement, and manage AWS solutions that meet their technical requirements and business objectives. You'll be a key player in driving customer success throughout their cloud journey, providing technical expertise and best practices across the project lifecycle. You'll collaborate closely with stakeholders to gather requirements, assess current infrastructure, and propose effective migration strategies to AWS. As an experienced technology professional, you will be responsible for: • Designing and implementing complex, scalable, and secure AWS solutions tailored to customer needs • Providing technical guidance and troubleshooting support throughout project delivery • Collaborating with stakeholders to gather requirements and propose effective migration strategies • Acting as a trusted advisor to customers on industry trends and emerging technologies • Sharing knowledge within the organization through mentoring, training, and creating reusable artifacts About the team About AWS AWS values diverse experiences. Even if you do not meet all of the preferred qualifications and skills listed in the job description, we encourage candidates to apply. If your career is just starting, hasn't followed a traditional path, or includes alternative experiences, don't let it stop you from applying. Why AWS? Amazon Web Services (AWS) is the world's most comprehensive and broadly adopted cloud platform. We pioneered cloud computing and never stopped innovating - that's why customers from the most successful startups to Global 500 companies trust our robust suite of products and services to power their businesses. Inclusive Team Culture Here at AWS, it's in our nature to learn and be curious. Our employee-led affinity groups foster a culture of inclusion that empower us to be proud of our differences. Ongoing events and learning experiences, including our Conversations on Race and Ethnicity (CORE) and AmazeCon conferences, inspire us to never stop embracing our uniqueness. Mentorship & Career Growth We're continuously raising our performance bar as we strive to become Earth's Best Employer. That's why you'll find endless knowledge-sharing, mentorship and other career-advancing resources here to help you develop into a better-rounded professional. Work/Life Balance We value work-life harmony. Achieving success at work should never come at the expense of sacrifices at home, which is why we strive for flexibility as part of our working culture. When we feel supported in the workplace and at home, there's nothing we can't achieve in the cloud. BASIC QUALIFICATIONS- 7+ years of technical specialist, design and architecture experience - 5+ years of database (eg. SQL, NoSQL, Hadoop, Spark, Kafka, Kinesis) experience - 7+ years of consulting, design and implementation of serverless distributed solutions experience - 5+ years of software development with object oriented language experience - Current, active US Government Security Clearance of TS/SCI with Polygraph PREFERRED QUALIFICATIONS- degree in advanced technology, or AWS Professional level certification - Knowledge of AWS services including compute, storage, networking, security, databases, machine learning, and serverless technologies - Experience in performance optimization and cost management for cloud environments - Experience communicating technical concepts to diverse audiences in pre-sales environments Amazon is an equal opportunity employer and does not discriminate on the basis of protected veteran status, disability, or other legally protected status. Our inclusive culture empowers Amazonians to deliver the best results for our customers. If you have a disability and need a workplace accommodation or adjustment during the application and hiring process, including support for the interview or onboarding process, please visit for more information. If the country/region you're applying in isn't listed, please contact your Recruiting Partner. The base salary range for this position is listed below. Your Amazon package will include sign-on payments and restricted stock units (RSUs). Final compensation will be determined based on factors including experience, qualifications, and location. Amazon also offers comprehensive benefits including health insurance (medical, dental, vision, prescription, Basic Life & AD&D insurance and option for Supplemental life plans, EAP, Mental Health Support, Medical Advice Line, Flexible Spending Accounts, Adoption and Surrogacy Reimbursement coverage), 401(k) matching, paid time off, and parental leave. Learn more about our benefits at . USA, MD, Jessup - 153 800.00 USD annually
Full Stack Developer
V15P1TALONNN Chicago, Illinois
About Company: At ADP we use the most comprehensive data in the industry to create workplace insights that help inform products, ideas, and decisions every day. For 75 years, ADP has been building a better world of work. Learn why more than 1,000,000 clients rely on ADP and why we're always designing for people. About the Role: As a Full Stack Developer, you will play a pivotal role in designing, developing, and maintaining both the front-end and back-end components of our web applications. Your work will directly impact the user experience and the overall performance of our software products, ensuring they are scalable, secure, and efficient. You will collaborate closely with cross-functional teams including product managers, designers, and other developers to translate business requirements into technical solutions. This role demands a strong understanding of modern web technologies and best practices to deliver high-quality code and innovative features. Ultimately, your contributions will drive the continuous improvement and success of our digital platforms within the information industry. Minimum Qualifications: Bachelor's degree in Computer Science, Software Engineering, or a related field, or equivalent practical experience. Proven experience as a Full Stack Developer or similar role in software development. Proficiency with front-end technologies such as HTML5, CSS3, JavaScript, and frameworks like React, Angular, or Vue.js. Strong knowledge of back-end programming languages such as Node.js, Python, Java, or Ruby. Experience with database systems including SQL and NoSQL databases. Familiarity with RESTful API design and integration. Understanding of version control systems, preferably Git. Ability to write unit and integration tests to ensure code quality. Preferred Qualifications: Experience with cloud platforms such as AWS, Azure, or Google Cloud. Knowledge of containerization and orchestration tools like Docker and Kubernetes. Familiarity with CI/CD pipelines and automated deployment processes. Experience working in Agile/Scrum development environments. Strong understanding of web security principles and best practices. Contributions to open-source projects or a personal portfolio demonstrating coding skills. Responsibilities: Develop and maintain responsive web applications using modern front-end frameworks and back-end technologies. Collaborate with product and design teams to implement user-friendly interfaces and seamless user experiences. Write clean, maintainable, and well-documented code following industry best practices and coding standards. Perform code reviews, testing, and debugging to ensure software quality and reliability. Optimize applications for maximum speed and scalability while ensuring security compliance. Participate in agile development processes including sprint planning, daily stand-ups, and retrospectives. Troubleshoot and resolve technical issues across the full technology stack. Stay current with emerging technologies and industry trends to continuously enhance development practices. Skills: The required skills enable you to build and maintain both client-side and server-side components of web applications, ensuring seamless integration and functionality. Front-end skills allow you to create intuitive and responsive user interfaces, while back-end expertise ensures robust server logic and database management. Your proficiency with APIs and version control supports collaborative development and integration with other systems. Preferred skills such as cloud platform knowledge and containerization enhance your ability to deploy and scale applications efficiently in modern environments. Together, these skills empower you to deliver high-quality, secure, and scalable software solutions that meet business needs and user expectations.
09/26/2026
Full time
About Company: At ADP we use the most comprehensive data in the industry to create workplace insights that help inform products, ideas, and decisions every day. For 75 years, ADP has been building a better world of work. Learn why more than 1,000,000 clients rely on ADP and why we're always designing for people. About the Role: As a Full Stack Developer, you will play a pivotal role in designing, developing, and maintaining both the front-end and back-end components of our web applications. Your work will directly impact the user experience and the overall performance of our software products, ensuring they are scalable, secure, and efficient. You will collaborate closely with cross-functional teams including product managers, designers, and other developers to translate business requirements into technical solutions. This role demands a strong understanding of modern web technologies and best practices to deliver high-quality code and innovative features. Ultimately, your contributions will drive the continuous improvement and success of our digital platforms within the information industry. Minimum Qualifications: Bachelor's degree in Computer Science, Software Engineering, or a related field, or equivalent practical experience. Proven experience as a Full Stack Developer or similar role in software development. Proficiency with front-end technologies such as HTML5, CSS3, JavaScript, and frameworks like React, Angular, or Vue.js. Strong knowledge of back-end programming languages such as Node.js, Python, Java, or Ruby. Experience with database systems including SQL and NoSQL databases. Familiarity with RESTful API design and integration. Understanding of version control systems, preferably Git. Ability to write unit and integration tests to ensure code quality. Preferred Qualifications: Experience with cloud platforms such as AWS, Azure, or Google Cloud. Knowledge of containerization and orchestration tools like Docker and Kubernetes. Familiarity with CI/CD pipelines and automated deployment processes. Experience working in Agile/Scrum development environments. Strong understanding of web security principles and best practices. Contributions to open-source projects or a personal portfolio demonstrating coding skills. Responsibilities: Develop and maintain responsive web applications using modern front-end frameworks and back-end technologies. Collaborate with product and design teams to implement user-friendly interfaces and seamless user experiences. Write clean, maintainable, and well-documented code following industry best practices and coding standards. Perform code reviews, testing, and debugging to ensure software quality and reliability. Optimize applications for maximum speed and scalability while ensuring security compliance. Participate in agile development processes including sprint planning, daily stand-ups, and retrospectives. Troubleshoot and resolve technical issues across the full technology stack. Stay current with emerging technologies and industry trends to continuously enhance development practices. Skills: The required skills enable you to build and maintain both client-side and server-side components of web applications, ensuring seamless integration and functionality. Front-end skills allow you to create intuitive and responsive user interfaces, while back-end expertise ensures robust server logic and database management. Your proficiency with APIs and version control supports collaborative development and integration with other systems. Preferred skills such as cloud platform knowledge and containerization enhance your ability to deploy and scale applications efficiently in modern environments. Together, these skills empower you to deliver high-quality, secure, and scalable software solutions that meet business needs and user expectations.
Configuration Manager
Omitron, Inc. Colorado Springs, Colorado
Job Description Job Description Omitron is seeking a Configuration Manager to support the CROWN effort in Colorado Springs, CO. This role owns configuration management across the CROWN lifecycle, from establishing CM planning and configuration identification through baseline management, change control, configuration status accounting, verification, and audit. The Configuration Manager is responsible for ensuring CROWN's hardware, software, network configurations, technical documentation, and associated configuration items remain controlled, traceable, reproducible, and auditable throughout the system lifecycle. This role requires someone capable of building and owning CM structure where it does not yet exist and maintaining that discipline within an evolving, Agile-driven technical environment. The ideal candidate can establish configuration baselines, operate a Change Control Board (CCB), maintain configuration status accounting, control changes across hardware and software components, and coordinate with Omitron and Government stakeholders to ensure configuration integrity throughout development, deployment, operations, and sustainment. The Configuration Manager will work closely with systems engineering, network engineering, software, cybersecurity, installation, operations, logistics, and program management personnel to ensure that the approved configuration accurately reflects what is designed, tested, deployed, and operating in the field. Key Responsibilities Develop and document the life cycle of CM planning, including program milestones and schedules to monitor CM status. Implement an internal CM system to manage all configuration documentation, physical media, and system components (hardware and software). Ensure CM practices cover engineering, implementation, and testing environments in accordance with evolving requirements. Implement change control guidelines for managing updates to project baselines and associated documentation. Establish and facilitate a Change Control Board (CCB) to review and approve changes. Track and maintain configuration baselines for each Prime Mission Product, including Commercial Off-The-Shelf (COTS) and Free and Open-Source Software (FOSS) components. Coordinate CM activities with Omitron and government stakeholders to ensure compliance with Agile product development processes and government requirements. Work closely with engineering, cybersecurity, and operations personnel to ensure configuration traceability, auditability, and consistent documentation across CROWN's lifecycle. Coordinate with installation and operations teams to ensure fielded system configurations accurately reflect approved baselines and as-built documentation. Conduct or support Functional Configuration Audits (FCA), Physical Configuration Audits (PCA), baseline reviews, and internal CM audits as applicable. Continuously improve CM processes as CROWN capabilities, deployments, and operational requirements evolve. Required Qualifications US citizenship required Security Clearance: Active TS/SCI clearance. Education: Bachelor's degree. Experience: 6+ years of relevant experience in configuration management, or an equivalent combination of education and experience. Demonstrated experience developing and implementing CM plans, baselines, and change control processes for a complex technical program. Experience establishing or facilitating a Change Control Board (CCB) or equivalent change management process. Strong coordination and documentation skills, with the ability to work across engineering, cybersecurity, and operations teams and with government stakeholders. Experience with version control, release management, or software configuration management concepts. Experience identifying and managing Configuration Items across hardware, software, firmware, and technical documentation. Preferred Qualifications Experience supporting DoD, Space Force, NRO, or other federal/IC programs. Familiarity with Agile product development processes and how CM practices adapt within an Agile environment. Industry certifications in configuration management (e.g., CMPIC, ITIL) or related disciplines. Familiarity with the CROWN program or similar network/systems delivery initiatives. Industry certification in configuration management or related disciplines, such as CMPIC, CM2, ITIL, or equivalent. Experience managing configuration for enterprise networks, distributed systems, mission systems, or other complex IT infrastructure. Compensation and Benefits: The salary range for this role is $120,000 to $160,000. Actual compensation will be determined based on factors including, but not limited to, relevant experience, education, technical expertise, certifications, security clearance, geographic location, internal equity, market conditions, contract requirements, and other factors. Benefits include: Health, Dental and Vision Insurance HSA or FSA accounts Company paid ST/LT Disability and AD&D insurance Paid Federal Holidays Paid Vacation Leave and Sick Leave Parental Leave 401k with company match Supplemental Insurance options like AFLAC Professional Development Reimbursement Voluntary Life Insurance Company Overview: Omitron is an Aerospace Engineering and Information Technology small business firm headquartered in Beltsville, Maryland with a field office located in Colorado Springs, Colorado. Since 1984, Omitron has provided excellence in engineering services and product development to government and industry customers for both civilian and military aerospace programs. Omitron recognizes that outstanding people are the key to our success. Our goal is to select highly qualified and motivated individuals and provide them with an environment necessary to stimulate and nurture engineering and business objectives. Omitron offers its employees competitive salaries, a full benefits package, and excellent career growth opportunities. We welcome talented professionals who wish to take advantage of the opportunities we offer. At Omitron, we believe that a workplace that fosters innovation and collaboration will be a successful one. We are committed to attracting, developing, and retaining top talent from a broad range of backgrounds, perspectives, and experiences. Per Title VII, our hiring decisions are made based on qualifications, skills, and experience, in accordance with our commitment to equal opportunity employment and nondiscrimination policies. We welcome all individuals who share our passion for excellence and encourage applicants from diverse backgrounds to apply. We also support a workplace where every employee feels valued, respected, and empowered to contribute their best work. Our workplace initiatives are open to all and designed to create a culture of belonging for everyone. E-Verify Participation. Powered by JazzHR KBcXtmP5bX
09/26/2026
Full time
Job Description Job Description Omitron is seeking a Configuration Manager to support the CROWN effort in Colorado Springs, CO. This role owns configuration management across the CROWN lifecycle, from establishing CM planning and configuration identification through baseline management, change control, configuration status accounting, verification, and audit. The Configuration Manager is responsible for ensuring CROWN's hardware, software, network configurations, technical documentation, and associated configuration items remain controlled, traceable, reproducible, and auditable throughout the system lifecycle. This role requires someone capable of building and owning CM structure where it does not yet exist and maintaining that discipline within an evolving, Agile-driven technical environment. The ideal candidate can establish configuration baselines, operate a Change Control Board (CCB), maintain configuration status accounting, control changes across hardware and software components, and coordinate with Omitron and Government stakeholders to ensure configuration integrity throughout development, deployment, operations, and sustainment. The Configuration Manager will work closely with systems engineering, network engineering, software, cybersecurity, installation, operations, logistics, and program management personnel to ensure that the approved configuration accurately reflects what is designed, tested, deployed, and operating in the field. Key Responsibilities Develop and document the life cycle of CM planning, including program milestones and schedules to monitor CM status. Implement an internal CM system to manage all configuration documentation, physical media, and system components (hardware and software). Ensure CM practices cover engineering, implementation, and testing environments in accordance with evolving requirements. Implement change control guidelines for managing updates to project baselines and associated documentation. Establish and facilitate a Change Control Board (CCB) to review and approve changes. Track and maintain configuration baselines for each Prime Mission Product, including Commercial Off-The-Shelf (COTS) and Free and Open-Source Software (FOSS) components. Coordinate CM activities with Omitron and government stakeholders to ensure compliance with Agile product development processes and government requirements. Work closely with engineering, cybersecurity, and operations personnel to ensure configuration traceability, auditability, and consistent documentation across CROWN's lifecycle. Coordinate with installation and operations teams to ensure fielded system configurations accurately reflect approved baselines and as-built documentation. Conduct or support Functional Configuration Audits (FCA), Physical Configuration Audits (PCA), baseline reviews, and internal CM audits as applicable. Continuously improve CM processes as CROWN capabilities, deployments, and operational requirements evolve. Required Qualifications US citizenship required Security Clearance: Active TS/SCI clearance. Education: Bachelor's degree. Experience: 6+ years of relevant experience in configuration management, or an equivalent combination of education and experience. Demonstrated experience developing and implementing CM plans, baselines, and change control processes for a complex technical program. Experience establishing or facilitating a Change Control Board (CCB) or equivalent change management process. Strong coordination and documentation skills, with the ability to work across engineering, cybersecurity, and operations teams and with government stakeholders. Experience with version control, release management, or software configuration management concepts. Experience identifying and managing Configuration Items across hardware, software, firmware, and technical documentation. Preferred Qualifications Experience supporting DoD, Space Force, NRO, or other federal/IC programs. Familiarity with Agile product development processes and how CM practices adapt within an Agile environment. Industry certifications in configuration management (e.g., CMPIC, ITIL) or related disciplines. Familiarity with the CROWN program or similar network/systems delivery initiatives. Industry certification in configuration management or related disciplines, such as CMPIC, CM2, ITIL, or equivalent. Experience managing configuration for enterprise networks, distributed systems, mission systems, or other complex IT infrastructure. Compensation and Benefits: The salary range for this role is $120,000 to $160,000. Actual compensation will be determined based on factors including, but not limited to, relevant experience, education, technical expertise, certifications, security clearance, geographic location, internal equity, market conditions, contract requirements, and other factors. Benefits include: Health, Dental and Vision Insurance HSA or FSA accounts Company paid ST/LT Disability and AD&D insurance Paid Federal Holidays Paid Vacation Leave and Sick Leave Parental Leave 401k with company match Supplemental Insurance options like AFLAC Professional Development Reimbursement Voluntary Life Insurance Company Overview: Omitron is an Aerospace Engineering and Information Technology small business firm headquartered in Beltsville, Maryland with a field office located in Colorado Springs, Colorado. Since 1984, Omitron has provided excellence in engineering services and product development to government and industry customers for both civilian and military aerospace programs. Omitron recognizes that outstanding people are the key to our success. Our goal is to select highly qualified and motivated individuals and provide them with an environment necessary to stimulate and nurture engineering and business objectives. Omitron offers its employees competitive salaries, a full benefits package, and excellent career growth opportunities. We welcome talented professionals who wish to take advantage of the opportunities we offer. At Omitron, we believe that a workplace that fosters innovation and collaboration will be a successful one. We are committed to attracting, developing, and retaining top talent from a broad range of backgrounds, perspectives, and experiences. Per Title VII, our hiring decisions are made based on qualifications, skills, and experience, in accordance with our commitment to equal opportunity employment and nondiscrimination policies. We welcome all individuals who share our passion for excellence and encourage applicants from diverse backgrounds to apply. We also support a workplace where every employee feels valued, respected, and empowered to contribute their best work. Our workplace initiatives are open to all and designed to create a culture of belonging for everyone. E-Verify Participation. Powered by JazzHR KBcXtmP5bX
Security Control Assessor (SME), Level III
OneZero Solutions Curtis Bay, Maryland
Job Description Job Description We are an employee-centric company that truly values our team members and the contributions they make to our customers and the missions they support. We pride ourselves on being forward-leaning thinkers and on building teams that are, and continue to be, technically proficient across a broad range of cyber mission areas. OneZero full-time employees receive a highly competitive benefits package, including health, dental, vision, and life insurance, a 401(k) with company matching, paid time off and holidays, an employee referral program, and educational assistance. Additional details are available on our website: Position Title : Security Control Assessor (SME), Level IIILocation: USCG Surface Forces Logistics Center, 2401 Hawkins Point Road, Baltimore, MD 21226. Work may also be performed at the SFLC satellite offices at 707 East Ordnance Road, approximately one mile from the primary site, and at other sites as determined necessary by the Contracting Officer's Representative (COR).Clearance:No security clearance required. This position does not involve access to classified information or classified IT systems.S. citizenship is required in accordance with HSAR 3052.204-71 Alternate I.Position SummaryThe Security Control Assessor (SCA) provides independent security control assessment and authorization support to the USCG SFLC Business Operations Division in support of Surface Domain Operational Technology (OT) and Platform IT systems. The role is the assessment authority on the team: it evaluates whether security and privacy controls are implemented correctly, operating as intended, and producing the intended outcome, and it provides the evidence the Authorizing Official relies on to make risk decisions.This is the senior assessment position on the task order and is distinct from the ISSO roles, which own and maintain the authorization packages. The SCA assesses; the ISSOs prepare and sustain. The position is expected to operate with a high degree of independence and to advise the OT Security Manager (ISSM) directly.Key ResponsibilitiesSupport the OT Security Manager (ISSM) and staff in establishing and maintaining the programs, procedures, and policies that protect Government Sensitive But Unclassified (SBU) information.Perform independent assessments of SFLC Operational Technology to verify that applicable security and privacy controls are implemented correctly, operating as intended, and producing the desired outcome.Provide security assessment and authorization consultation services to the ISSM, on site.Review existing policies, procedures, and guidelines for compliance with DHS, USCG, and DoD cybersecurity policy; draft or revise SFLC policy documentation for ISSM review, approval, and organizational implementation.Assist in preparing RMF security authorization documentation for submission to the Authorizing Official (AO).Maintain security assessment information and supporting documentation within Government-designated systems and repositories.Create and validate SFLC security assessment and authorization accounts within Government-designated systems and tools.Update and maintain assessment and authorization status within Government-designated tracking systems and databases.Upload, track, and update Plans of Action and Milestones (POA recommend POA&M updates based on assessment results and maintain traceability from identified vulnerabilities through to the applicable POA&M.Conduct vulnerability scans of SFLC OT, networks, devices, and associated components using Government-approved tools.Provide assistance to system administrators in remediating vulnerabilities identified through scanning.Provide vulnerability and risk management support in conjunction with assessment and authorization activities.Maintain the enterprise tracking log for electronic spillage activities in accordance with Government policy.Support the destruction of removable media generated during assessment activities in accordance with Government procedures.Support cybersecurity strategic planning and continuous monitoring activities, evaluating enterprise services through assessment of priorities and risk.Provide bi-weekly status reports to the SFLC OT Security Manager (ISSM).Conduct a monthly project status update briefing to the ISSM at SFLC Baltimore.Required QualificationsExperienceTen (10) or more years of progressive cybersecurity experience, including at least five (5) years performing security control assessments or independent A&A validation in a federal environment.Demonstrated experience executing NIST SP 800-37 RMF end to end, including control assessment against NIST SP 800-53A.Experience assessing systems to a formal authorization decision and producing assessment artifacts relied upon by an Authorizing Official.Experience conducting and interpreting vulnerability scans and translating findings into risk-based recommendations and POA&M entries.Experience drafting and revising organizational cybersecurity policy for Government review and adoption.CertificationMust hold and maintain at least one active certification approved for Information Assurance Management (IAM) Level II or Level III. Any one of the following satisfies the requirement:CISSP - Certified Information Systems Security Professional (or CISSP Associate)CISM - Certified Information Security ManagerCGRC - Governance, Risk and Compliance Certification (formerly CAP)CASP+ - CompTIA Advanced Security PractitionerGSLC - GIAC Security Leadership CertificationCCISO - EC-Council Certified Chief Information Security Officer (Level III only)Certification requirements are subject to confirmation against COMDTINST M2620.2 (series) Appendix D, the controlling USCG certification matrix. Verify the accepted certification list with the Program Manager before extending an offer.Evidence of active certification in good standing is required prior to onboarding. Waivers and exceptions to certification requirements will not be granted.Certifications must remain current, active, and in good standing throughout performance. Loss, lapse, or revocation of a required certification is grounds for removal from the contract. Continuing education required to maintain certification is at the employee's and company's expense.Ability to work independently and advise a Government security manager at the senior level.Strong written communication: the role produces bi-weekly written reporting and briefs the ISSM monthly.Ability to read, write, speak, and understand English fluently.Preferred QualificationsPrior USCG, DHS, or DoD assessment experience, particularly with Surface Domain OT or Platform IT systems.Familiarity with COMDTINST M2620.2 (series) and COMDTINST 5500.13 (series).Experience assessing OT/ICS or PIT systems where conventional endpoint tooling cannot be deployed.CGRC (formerly CAP), CISA, or GSNA in addition to the required baseline certification.Experience supporting DHS SELC-aligned programs.Master's degree in cybersecurity, information systems, or a related field.Technical SkillsNIST SP 800-37 (RMF), 800-53 / 53A / 53B, 800-137 (ISCM), FIPS 199 and FIPS 200DHS 4300A Sensitive Systems Handbook and the DHS Systems Engineering Life Cycle (SELC)Government-designated A&A repositories and tracking tools (e.g., eMASS or successor)DISA Security Technical Implementation Guides (STIGs) and Security Requirements Guides (SRGs)Government-approved vulnerability scanning and compliance tooling (e.g., ACAS/Nessus, SCAP-validated scanners)POA&M development, tracking, and closure, including waiver and risk acceptance packagesOperational Technology (OT), Platform IT (PIT), and industrial control system environments, including constraints on agent-based toolingNIST SP 800-30 risk assessment methodology and NIST SP 800-115 technical assessment techniquesElectronic spillage handling and removable media sanitization proceduresSecurity ClearanceNo security clearance required. This position does not involve access to classified information or classified IT systems.S. citizenship is required in accordance with HSAR 3052.204-71 Alternate I.A favorably adjudicated Tier 1 background investigation (or higher) is required. Candidates without an existing investigation on file must complete an Electronic Application (eApp) for investigation processing.Note to recruiting: per the task order, the position is not billable until the selected candidate is fully cleared, has a CAC in hand, and has reported to the work site. Fill timelines should assume 30-90 days for investigation and CAC issuance.EducationBachelor 's degree in cybersecurity, computer science, information systems, engineering, or a related field.Work EnvironmentPrimarily on-site at SFLC Baltimore. On-site presence is required for the monthly status briefing to the ISSM and for participation in change management boards, technical exchange meetings, and Government working groups.The Government furnishes workspace, telephone, a Standard Workstation, and copy/fax access.Remote work may be authorized at the sole discretion of the Government. If authorized, compliant hardware, software, and internet service are contractor- furnished.Occasional travel outside the local commuting area may be required for training and associated off-site meetings, subject to advance COR approval and reimbursed per the Federal Travel Regulations. The 707 East Ordnance Road satellite office is within the local commuting area.OneZero Solutions, LLC is an Equal Opportunity employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, age, pregnancy, genetic information, disability, status as a protected veteran, or any other protected category under applicable federal, state, and local laws.To request an accommodation . click apply for full job details
09/26/2026
Full time
Job Description Job Description We are an employee-centric company that truly values our team members and the contributions they make to our customers and the missions they support. We pride ourselves on being forward-leaning thinkers and on building teams that are, and continue to be, technically proficient across a broad range of cyber mission areas. OneZero full-time employees receive a highly competitive benefits package, including health, dental, vision, and life insurance, a 401(k) with company matching, paid time off and holidays, an employee referral program, and educational assistance. Additional details are available on our website: Position Title : Security Control Assessor (SME), Level IIILocation: USCG Surface Forces Logistics Center, 2401 Hawkins Point Road, Baltimore, MD 21226. Work may also be performed at the SFLC satellite offices at 707 East Ordnance Road, approximately one mile from the primary site, and at other sites as determined necessary by the Contracting Officer's Representative (COR).Clearance:No security clearance required. This position does not involve access to classified information or classified IT systems.S. citizenship is required in accordance with HSAR 3052.204-71 Alternate I.Position SummaryThe Security Control Assessor (SCA) provides independent security control assessment and authorization support to the USCG SFLC Business Operations Division in support of Surface Domain Operational Technology (OT) and Platform IT systems. The role is the assessment authority on the team: it evaluates whether security and privacy controls are implemented correctly, operating as intended, and producing the intended outcome, and it provides the evidence the Authorizing Official relies on to make risk decisions.This is the senior assessment position on the task order and is distinct from the ISSO roles, which own and maintain the authorization packages. The SCA assesses; the ISSOs prepare and sustain. The position is expected to operate with a high degree of independence and to advise the OT Security Manager (ISSM) directly.Key ResponsibilitiesSupport the OT Security Manager (ISSM) and staff in establishing and maintaining the programs, procedures, and policies that protect Government Sensitive But Unclassified (SBU) information.Perform independent assessments of SFLC Operational Technology to verify that applicable security and privacy controls are implemented correctly, operating as intended, and producing the desired outcome.Provide security assessment and authorization consultation services to the ISSM, on site.Review existing policies, procedures, and guidelines for compliance with DHS, USCG, and DoD cybersecurity policy; draft or revise SFLC policy documentation for ISSM review, approval, and organizational implementation.Assist in preparing RMF security authorization documentation for submission to the Authorizing Official (AO).Maintain security assessment information and supporting documentation within Government-designated systems and repositories.Create and validate SFLC security assessment and authorization accounts within Government-designated systems and tools.Update and maintain assessment and authorization status within Government-designated tracking systems and databases.Upload, track, and update Plans of Action and Milestones (POA recommend POA&M updates based on assessment results and maintain traceability from identified vulnerabilities through to the applicable POA&M.Conduct vulnerability scans of SFLC OT, networks, devices, and associated components using Government-approved tools.Provide assistance to system administrators in remediating vulnerabilities identified through scanning.Provide vulnerability and risk management support in conjunction with assessment and authorization activities.Maintain the enterprise tracking log for electronic spillage activities in accordance with Government policy.Support the destruction of removable media generated during assessment activities in accordance with Government procedures.Support cybersecurity strategic planning and continuous monitoring activities, evaluating enterprise services through assessment of priorities and risk.Provide bi-weekly status reports to the SFLC OT Security Manager (ISSM).Conduct a monthly project status update briefing to the ISSM at SFLC Baltimore.Required QualificationsExperienceTen (10) or more years of progressive cybersecurity experience, including at least five (5) years performing security control assessments or independent A&A validation in a federal environment.Demonstrated experience executing NIST SP 800-37 RMF end to end, including control assessment against NIST SP 800-53A.Experience assessing systems to a formal authorization decision and producing assessment artifacts relied upon by an Authorizing Official.Experience conducting and interpreting vulnerability scans and translating findings into risk-based recommendations and POA&M entries.Experience drafting and revising organizational cybersecurity policy for Government review and adoption.CertificationMust hold and maintain at least one active certification approved for Information Assurance Management (IAM) Level II or Level III. Any one of the following satisfies the requirement:CISSP - Certified Information Systems Security Professional (or CISSP Associate)CISM - Certified Information Security ManagerCGRC - Governance, Risk and Compliance Certification (formerly CAP)CASP+ - CompTIA Advanced Security PractitionerGSLC - GIAC Security Leadership CertificationCCISO - EC-Council Certified Chief Information Security Officer (Level III only)Certification requirements are subject to confirmation against COMDTINST M2620.2 (series) Appendix D, the controlling USCG certification matrix. Verify the accepted certification list with the Program Manager before extending an offer.Evidence of active certification in good standing is required prior to onboarding. Waivers and exceptions to certification requirements will not be granted.Certifications must remain current, active, and in good standing throughout performance. Loss, lapse, or revocation of a required certification is grounds for removal from the contract. Continuing education required to maintain certification is at the employee's and company's expense.Ability to work independently and advise a Government security manager at the senior level.Strong written communication: the role produces bi-weekly written reporting and briefs the ISSM monthly.Ability to read, write, speak, and understand English fluently.Preferred QualificationsPrior USCG, DHS, or DoD assessment experience, particularly with Surface Domain OT or Platform IT systems.Familiarity with COMDTINST M2620.2 (series) and COMDTINST 5500.13 (series).Experience assessing OT/ICS or PIT systems where conventional endpoint tooling cannot be deployed.CGRC (formerly CAP), CISA, or GSNA in addition to the required baseline certification.Experience supporting DHS SELC-aligned programs.Master's degree in cybersecurity, information systems, or a related field.Technical SkillsNIST SP 800-37 (RMF), 800-53 / 53A / 53B, 800-137 (ISCM), FIPS 199 and FIPS 200DHS 4300A Sensitive Systems Handbook and the DHS Systems Engineering Life Cycle (SELC)Government-designated A&A repositories and tracking tools (e.g., eMASS or successor)DISA Security Technical Implementation Guides (STIGs) and Security Requirements Guides (SRGs)Government-approved vulnerability scanning and compliance tooling (e.g., ACAS/Nessus, SCAP-validated scanners)POA&M development, tracking, and closure, including waiver and risk acceptance packagesOperational Technology (OT), Platform IT (PIT), and industrial control system environments, including constraints on agent-based toolingNIST SP 800-30 risk assessment methodology and NIST SP 800-115 technical assessment techniquesElectronic spillage handling and removable media sanitization proceduresSecurity ClearanceNo security clearance required. This position does not involve access to classified information or classified IT systems.S. citizenship is required in accordance with HSAR 3052.204-71 Alternate I.A favorably adjudicated Tier 1 background investigation (or higher) is required. Candidates without an existing investigation on file must complete an Electronic Application (eApp) for investigation processing.Note to recruiting: per the task order, the position is not billable until the selected candidate is fully cleared, has a CAC in hand, and has reported to the work site. Fill timelines should assume 30-90 days for investigation and CAC issuance.EducationBachelor 's degree in cybersecurity, computer science, information systems, engineering, or a related field.Work EnvironmentPrimarily on-site at SFLC Baltimore. On-site presence is required for the monthly status briefing to the ISSM and for participation in change management boards, technical exchange meetings, and Government working groups.The Government furnishes workspace, telephone, a Standard Workstation, and copy/fax access.Remote work may be authorized at the sole discretion of the Government. If authorized, compliant hardware, software, and internet service are contractor- furnished.Occasional travel outside the local commuting area may be required for training and associated off-site meetings, subject to advance COR approval and reimbursed per the Federal Travel Regulations. The 707 East Ordnance Road satellite office is within the local commuting area.OneZero Solutions, LLC is an Equal Opportunity employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, age, pregnancy, genetic information, disability, status as a protected veteran, or any other protected category under applicable federal, state, and local laws.To request an accommodation . click apply for full job details
Security Control Assessor/Representatives
Dark Wolf Solutions Arlington, Virginia
Job Description Job Description Dark Wolf Solutions is seeking Security Control Assessor/Representatives (SCA/Rs) to lead security control assessments across high-priority projects. Working at the intersection of cybersecurity engineering, cloud architecture, and DevSecOps prototyping, you will evaluate security controls for cutting-edge AI/LLM technologies across multiple classification levels. This position is ideal for a pragmatic cloud assessor or SCAR who excels in fast-paced DevSecOps environments, understands AWS cloud security, and is eager to shape the cybersecurity posture of next-generation DoD AI capabilities.This position will be based out of Arlington, VA. Additional responsibilities include: Key Responsibilities Execute formal SCA/R duties. Lead security assessment efforts, establishing reusable security playbooks and assessment frameworks for rapid AI deployment into enterprise workflows. Evaluate technical control effectiveness across AWS cloud infrastructure, DevSecOps pipelines, microservices, containerized workloads, and GenAI/LLM application stacks. Partner directly with cybersecurity engineering and DevSecOps prototyping teams to integrate security controls early in the development lifecycle. Review, author, and maintain assessment packages-including System Security Plans (SSPs), Security Assessment Plans (SAPs), Security Assessment Reports (SARs), and POA&Ms-tailored to rapid prototyping and AI systems. Assess technical security risks specific to AI/LLM implementations, such as API exposure, vector database access controls, model integration surface area, and software supply chain dependencies. Support continuous monitoring (ConMon), technical risk evaluations, and cloud architecture reviews across multi-tenant, multi-classification environments. Coordinate with Authorizing Officials (AOs), program managers, and engineering leads to deliver decision-ready risk briefings and ATO recommendations. Provide technical input and oversight for cybersecurity engineering and penetration testing activities across prototype projects. Required Qualifications Active Top Secret security clearance Current DoD 8570/8140 IAM Level II or Level III certification (e.g., Security+, CySA+, CISM, CISSP, CCISO, CAP/CISC) 3-5+ years of experience conducting security control assessments, compliance testing, or A&A/RMF activities for DoD or federal information systems Solid operational understanding of core AWS cloud services (EC2, S3, IAM, VPCs, Security Groups, Security Hub) and how security controls function within cloud-native and CI/CD pipeline environments. Strong working knowledge of NIST SP 800-53 (Rev. 4/5), NIST SP 800-37 (RMF), DoD Cloud Computing SRG, and FedRAMP baselines. Demonstrated experience writing and evaluating core RMF artifacts (SSPs, SAPs, SARs, POA&Ms) Exceptional written and verbal communication skills, with the ability to articulate technical risk clearly to executive stakeholders, Authorizing Officials, and engineering teams. Hands-on experience navigating government GRC repositories, such as eMASS or XACTA. Desired Qualifications Hands-on experience mapping security controls to the NIST AI Risk Management Framework (AI RMF), the OWASP Top 10 for LLM Applications, or the DoD Responsible AI (RAI) Guidelines. Familiarity evaluating secure design patterns for autonomous AI Agents (e.g., tool-calling permissions, sandboxing agent execution environments, prompt boundaries, and ReAct/LangGraph architectures). Experience assessing cloud-managed AI ecosystems and foundation model platforms (e.g., AWS Bedrock, AWS SageMaker, Hugging Face Enterprise, or self-hosted open-source models). Understanding of data protection, access controls, and boundary security for RAG pipelines and vector databases (e.g., OpenSearch Vector Engine, Pinecone, Milvus, or PostgreSQL pgvector). Familiarity evaluating risks unique to LLMs-including prompt injection, data poisoning, model inversion, insecure output handling, and open-source supply chain vulnerabilities in AI libraries (PyTorch, LangChain, LlamaIndex). Exposure to LLM guardrail platforms, evaluation frameworks, or AI security tools (e.g., Promptfoo, Garak, Giskard, NeMo Guardrails) used to test model robustness and output safety. Experience with cATO methodologies, Infrastructure as Code (IaC) templates (Terraform, CloudFormation), and container security (AWS EKS/ECS, Docker). Active AWS Certifications (e.g., AWS Certified Security - Specialty or AWS Certified Solutions Architect). Background or familiarity with offensive security, penetration testing The salary range for this position is estimated to be between $135,000.00 - $150,000.00, commensurate on experience and technical skillset. We are proud to be an EEO/AA employer Minorities/Women/Veterans/Disabled and other protected categories. In compliance with federal law, all persons hired will be required to verify identity, confirm US Citizenship, and complete the required employment eligibility verification upon hire. We are strictly looking for direct, full-time W2 employees. We do not engage with third-party staffing agencies, C2C, or 1099 independent contractors for this role.
09/26/2026
Full time
Job Description Job Description Dark Wolf Solutions is seeking Security Control Assessor/Representatives (SCA/Rs) to lead security control assessments across high-priority projects. Working at the intersection of cybersecurity engineering, cloud architecture, and DevSecOps prototyping, you will evaluate security controls for cutting-edge AI/LLM technologies across multiple classification levels. This position is ideal for a pragmatic cloud assessor or SCAR who excels in fast-paced DevSecOps environments, understands AWS cloud security, and is eager to shape the cybersecurity posture of next-generation DoD AI capabilities.This position will be based out of Arlington, VA. Additional responsibilities include: Key Responsibilities Execute formal SCA/R duties. Lead security assessment efforts, establishing reusable security playbooks and assessment frameworks for rapid AI deployment into enterprise workflows. Evaluate technical control effectiveness across AWS cloud infrastructure, DevSecOps pipelines, microservices, containerized workloads, and GenAI/LLM application stacks. Partner directly with cybersecurity engineering and DevSecOps prototyping teams to integrate security controls early in the development lifecycle. Review, author, and maintain assessment packages-including System Security Plans (SSPs), Security Assessment Plans (SAPs), Security Assessment Reports (SARs), and POA&Ms-tailored to rapid prototyping and AI systems. Assess technical security risks specific to AI/LLM implementations, such as API exposure, vector database access controls, model integration surface area, and software supply chain dependencies. Support continuous monitoring (ConMon), technical risk evaluations, and cloud architecture reviews across multi-tenant, multi-classification environments. Coordinate with Authorizing Officials (AOs), program managers, and engineering leads to deliver decision-ready risk briefings and ATO recommendations. Provide technical input and oversight for cybersecurity engineering and penetration testing activities across prototype projects. Required Qualifications Active Top Secret security clearance Current DoD 8570/8140 IAM Level II or Level III certification (e.g., Security+, CySA+, CISM, CISSP, CCISO, CAP/CISC) 3-5+ years of experience conducting security control assessments, compliance testing, or A&A/RMF activities for DoD or federal information systems Solid operational understanding of core AWS cloud services (EC2, S3, IAM, VPCs, Security Groups, Security Hub) and how security controls function within cloud-native and CI/CD pipeline environments. Strong working knowledge of NIST SP 800-53 (Rev. 4/5), NIST SP 800-37 (RMF), DoD Cloud Computing SRG, and FedRAMP baselines. Demonstrated experience writing and evaluating core RMF artifacts (SSPs, SAPs, SARs, POA&Ms) Exceptional written and verbal communication skills, with the ability to articulate technical risk clearly to executive stakeholders, Authorizing Officials, and engineering teams. Hands-on experience navigating government GRC repositories, such as eMASS or XACTA. Desired Qualifications Hands-on experience mapping security controls to the NIST AI Risk Management Framework (AI RMF), the OWASP Top 10 for LLM Applications, or the DoD Responsible AI (RAI) Guidelines. Familiarity evaluating secure design patterns for autonomous AI Agents (e.g., tool-calling permissions, sandboxing agent execution environments, prompt boundaries, and ReAct/LangGraph architectures). Experience assessing cloud-managed AI ecosystems and foundation model platforms (e.g., AWS Bedrock, AWS SageMaker, Hugging Face Enterprise, or self-hosted open-source models). Understanding of data protection, access controls, and boundary security for RAG pipelines and vector databases (e.g., OpenSearch Vector Engine, Pinecone, Milvus, or PostgreSQL pgvector). Familiarity evaluating risks unique to LLMs-including prompt injection, data poisoning, model inversion, insecure output handling, and open-source supply chain vulnerabilities in AI libraries (PyTorch, LangChain, LlamaIndex). Exposure to LLM guardrail platforms, evaluation frameworks, or AI security tools (e.g., Promptfoo, Garak, Giskard, NeMo Guardrails) used to test model robustness and output safety. Experience with cATO methodologies, Infrastructure as Code (IaC) templates (Terraform, CloudFormation), and container security (AWS EKS/ECS, Docker). Active AWS Certifications (e.g., AWS Certified Security - Specialty or AWS Certified Solutions Architect). Background or familiarity with offensive security, penetration testing The salary range for this position is estimated to be between $135,000.00 - $150,000.00, commensurate on experience and technical skillset. We are proud to be an EEO/AA employer Minorities/Women/Veterans/Disabled and other protected categories. In compliance with federal law, all persons hired will be required to verify identity, confirm US Citizenship, and complete the required employment eligibility verification upon hire. We are strictly looking for direct, full-time W2 employees. We do not engage with third-party staffing agencies, C2C, or 1099 independent contractors for this role.
Security Control Accessor
VIATEQ Corporation Washington, Washington DC
Job Description Job Description: VIATEQ Corporation is looking for a Security Control Assessor (SCA) to support a comprehensive enterprise cybersecurity services program for a federal government client. This position requires the ability to obtain and maintain a Minimum Background Investigation (MBI) or higher, PIV credentials, and all requisite IT access authorizations prior to performing work. Primary work will be performed at the client site in Washington, DC and approved remote/telework locations. This role serves as a key technical contributor responsible for the independent assessment and evaluation of security and privacy controls across the client's enterprise IT portfolio, spanning on-premises, cloud-hosted, and hybrid systems, in support of the agency's Federal Information Security Modernization Act (FISMA) compliance program, Risk Management Framework (RMF) activities, and Ongoing Authorization (OA) initiatives. The ideal candidate is a detail-oriented and technically proficient security assessment professional with demonstrated experience conducting NIST SP 800-53 security and privacy controls assessments, developing Security Assessment Reports (SARs), supporting Authority to Operate (ATO) activities, and executing continuous monitoring assessments across a diverse federal enterprise IT environment. This individual must possess the ability to work independently across complex, multi-technology system boundaries and deliver thorough, accurate, and well-written assessment artifacts that meet rigorous federal documentation standards. The Security Control Assessor will serve as an independent technical evaluator responsible for planning, executing, and reporting on security and privacy controls assessments for assigned systems and services across the client's enterprise IT portfolio. This individual is responsible for assessing the implementation and effectiveness of NIST SP 800-53 security and privacy controls, documenting assessment findings in accordance with NIST SP 800-53A methodologies, producing high-quality assessment artifacts, and supporting the full RMF assessment lifecycle from initial planning through final report delivery and POA&M development. The SCA works closely with ISSOs, system owners, security engineers, and Government stakeholders to ensure assessments are thorough, accurate, and completed within required timelines. Responsibilities: Security & Privacy Controls Assessment Plan, execute, and report on comprehensive security and privacy controls assessments for assigned federal information systems and services, including on-premises, IaaS, PaaS, and SaaS implementations, in accordance with NIST SP 800-53 Rev 5, NIST SP 800-53A Rev 5, and applicable agency implementation procedures. Conduct point-in-time full controls assessments, annual controls assessments, multi-year one-third assessments, and Ongoing Authorization (OA) evaluation assessments in accordance with the agency's assessment schedule and applicable implementation procedures. Develop and deliver draft Security Assessment Plans (SAPs) no less than ten (10) business days prior to beginning each assessment, clearly documenting the assessment scope, boundaries, sampling strategies, test methods, and schedule. Execute NIST SP 800-53A Determine If Statements (DISs) for all in-scope controls, documenting assessment findings to a level of detail sufficient to demonstrate that the implementation of each control objective is validated or not validated, avoiding high-level summary statements and ensuring technical depth across all technology types within the system boundary. Conduct technical controls assessments across all technology types within each system boundary, including Windows and UNIX servers, network devices (routers, switches, Cisco, F5 load balancers), web applications, databases, cloud platforms, and endpoint systems, applying appropriate sampling strategies approved by the Government prior to implementation. Develop Government-approved sampling strategies encompassing all asset types within each system boundary, typically between ten (10) and twenty (20) percent of applicable assets where appropriate, ensuring sampling covers all relevant device types, users, and services. Map identified vulnerabilities and assessment findings to applicable NIST SP 800-53 Rev 5 controls and control families, ensuring accurate and complete linkage between technical findings and corresponding control deficiencies. Produce comprehensive draft and final Security Assessment Reports (SARs) within required timelines, ensuring reports are comprehensive to the scope identified in the SAP, fully aligned to the agency's Governance, Risk, and Compliance (GRC) tool, include visual representation against the NIST Cybersecurity Framework (CSF), and are peer-reviewed for accuracy and grammar prior to submission. Develop draft Plans of Action and Milestones (POA&M) entries for identified control deficiencies, typically using the agency's GRC tool, delivering draft POA&Ms within thirty (30) calendar days from point-in-time assessment kickoff. Develop draft Annual Assessment Reports (AARs) per in-scope system within one-hundred-twenty (120) business days from point-in-time annual assessment kickoff, and deliver draft summary reports for multi-year assessment efforts no later than sixty (60) business days prior to the end of each Fiscal Year. Incorporate all Government feedback into assessment artifacts within five (5) business days of receipt of comments, delivering finalized deliverables that accurately reflect all Government-provided corrections, questions, and recommendations. Ongoing Authorization (OA) Evaluation Support Conduct Ongoing Authorization (OA) controls assessments for systems approved for OA, applying agency-specific OA test procedures that replace traditional NIST SP 800-53A test procedures for OA-approved systems. Execute OA Positive Testing monthly for OA-approved systems, using automated or semi-automated techniques to determine whether controls are operating effectively under normal circumstances, documenting results in the agency GRC tool in accordance with OA implementation procedures. Execute OA Negative Testing annually for OA-approved systems, using automated or semi-automated techniques to determine whether controls respond as expected under abnormal circumstances where misuse is injected to attempt to circumvent the control, coordinating as necessary with penetration testing purple team resources. Assist in the development and submission of OA Playbooks for Government approval, documenting the testing methodology for each OA core control including Test Strategy, Test Design, Test Execution, Results Evaluation, and Visualization components. Conduct OA testing comprehensively across all technology types within each target system's boundary, including sampling across in-scope devices, users, and services, documenting all test results in detail within the agency GRC tool in accordance with applicable OA implementation procedures. Ensure all OA Positive and Negative Testing documentation is peer-reviewed for accuracy and grammar prior to submission to the Government. ISSO Support & Collaboration Collaborate closely with assigned ISSOs to support their development of in-depth technical and operational knowledge about assigned systems, providing assessment expertise, technical guidance, and documentation support as needed. Provide technical support and expertise to ISSOs in the development and maintenance of all security documentation in the ATO package, including System Security Plans (SSPs), Configuration Management Plans (CMPs), Information System Contingency Plans (ISCPs), and other RMF artifacts, ensuring documentation aligns with applicable agency implementation procedures and template requirements. Support ISSOs in reviewing and validating system security documentation for technical accuracy, completeness, and alignment with the system boundary and technology stack, providing specific and actionable feedback to improve documentation quality. Assist ISSOs in ensuring control implementation descriptions within SSPs are written to the required level of technical detail, clearly explaining how each control is implemented across all technologies within the system boundary using specific naming conventions, configurations, and operational procedures rather than high-level general statements. Participate in Enterprise Change Control Board (ECCB) activities as needed, providing security assessment expertise to support the evaluation of proposed system changes and their potential impact on the system's security posture and ATO status. Audit & Compliance Support Support internal and external audit activities for assigned FISMA systems, facilitating meetings and walkthroughs of key cybersecurity capabilities, coordinating with system support personnel, and supplying auditors with requested artifacts and evidence within required timeframes. Ensure audit artifacts are complete, accurate, and delivered on time to avoid repeated requests from auditors, communicating any issues or problems to the Government immediately upon discovery. Support FISMA continuous monitoring activities, including the collection, validation, and submission of system-level FISMA metrics for assigned systems in alignment with federal CIO metrics requirements and agency reporting schedules. Assist in the development and maintenance of automated visualizations and dashboards that reflect the status and effectiveness of security controls for assigned systems, providing continuous visibility into the security posture and compliance status of assigned systems. Support High Value Asset (HVA) assessment activities for designated HVA systems, including vulnerability scanning and remediation validation, monitoring and analysis of relevant audit logs . click apply for full job details
09/26/2026
Full time
Job Description Job Description: VIATEQ Corporation is looking for a Security Control Assessor (SCA) to support a comprehensive enterprise cybersecurity services program for a federal government client. This position requires the ability to obtain and maintain a Minimum Background Investigation (MBI) or higher, PIV credentials, and all requisite IT access authorizations prior to performing work. Primary work will be performed at the client site in Washington, DC and approved remote/telework locations. This role serves as a key technical contributor responsible for the independent assessment and evaluation of security and privacy controls across the client's enterprise IT portfolio, spanning on-premises, cloud-hosted, and hybrid systems, in support of the agency's Federal Information Security Modernization Act (FISMA) compliance program, Risk Management Framework (RMF) activities, and Ongoing Authorization (OA) initiatives. The ideal candidate is a detail-oriented and technically proficient security assessment professional with demonstrated experience conducting NIST SP 800-53 security and privacy controls assessments, developing Security Assessment Reports (SARs), supporting Authority to Operate (ATO) activities, and executing continuous monitoring assessments across a diverse federal enterprise IT environment. This individual must possess the ability to work independently across complex, multi-technology system boundaries and deliver thorough, accurate, and well-written assessment artifacts that meet rigorous federal documentation standards. The Security Control Assessor will serve as an independent technical evaluator responsible for planning, executing, and reporting on security and privacy controls assessments for assigned systems and services across the client's enterprise IT portfolio. This individual is responsible for assessing the implementation and effectiveness of NIST SP 800-53 security and privacy controls, documenting assessment findings in accordance with NIST SP 800-53A methodologies, producing high-quality assessment artifacts, and supporting the full RMF assessment lifecycle from initial planning through final report delivery and POA&M development. The SCA works closely with ISSOs, system owners, security engineers, and Government stakeholders to ensure assessments are thorough, accurate, and completed within required timelines. Responsibilities: Security & Privacy Controls Assessment Plan, execute, and report on comprehensive security and privacy controls assessments for assigned federal information systems and services, including on-premises, IaaS, PaaS, and SaaS implementations, in accordance with NIST SP 800-53 Rev 5, NIST SP 800-53A Rev 5, and applicable agency implementation procedures. Conduct point-in-time full controls assessments, annual controls assessments, multi-year one-third assessments, and Ongoing Authorization (OA) evaluation assessments in accordance with the agency's assessment schedule and applicable implementation procedures. Develop and deliver draft Security Assessment Plans (SAPs) no less than ten (10) business days prior to beginning each assessment, clearly documenting the assessment scope, boundaries, sampling strategies, test methods, and schedule. Execute NIST SP 800-53A Determine If Statements (DISs) for all in-scope controls, documenting assessment findings to a level of detail sufficient to demonstrate that the implementation of each control objective is validated or not validated, avoiding high-level summary statements and ensuring technical depth across all technology types within the system boundary. Conduct technical controls assessments across all technology types within each system boundary, including Windows and UNIX servers, network devices (routers, switches, Cisco, F5 load balancers), web applications, databases, cloud platforms, and endpoint systems, applying appropriate sampling strategies approved by the Government prior to implementation. Develop Government-approved sampling strategies encompassing all asset types within each system boundary, typically between ten (10) and twenty (20) percent of applicable assets where appropriate, ensuring sampling covers all relevant device types, users, and services. Map identified vulnerabilities and assessment findings to applicable NIST SP 800-53 Rev 5 controls and control families, ensuring accurate and complete linkage between technical findings and corresponding control deficiencies. Produce comprehensive draft and final Security Assessment Reports (SARs) within required timelines, ensuring reports are comprehensive to the scope identified in the SAP, fully aligned to the agency's Governance, Risk, and Compliance (GRC) tool, include visual representation against the NIST Cybersecurity Framework (CSF), and are peer-reviewed for accuracy and grammar prior to submission. Develop draft Plans of Action and Milestones (POA&M) entries for identified control deficiencies, typically using the agency's GRC tool, delivering draft POA&Ms within thirty (30) calendar days from point-in-time assessment kickoff. Develop draft Annual Assessment Reports (AARs) per in-scope system within one-hundred-twenty (120) business days from point-in-time annual assessment kickoff, and deliver draft summary reports for multi-year assessment efforts no later than sixty (60) business days prior to the end of each Fiscal Year. Incorporate all Government feedback into assessment artifacts within five (5) business days of receipt of comments, delivering finalized deliverables that accurately reflect all Government-provided corrections, questions, and recommendations. Ongoing Authorization (OA) Evaluation Support Conduct Ongoing Authorization (OA) controls assessments for systems approved for OA, applying agency-specific OA test procedures that replace traditional NIST SP 800-53A test procedures for OA-approved systems. Execute OA Positive Testing monthly for OA-approved systems, using automated or semi-automated techniques to determine whether controls are operating effectively under normal circumstances, documenting results in the agency GRC tool in accordance with OA implementation procedures. Execute OA Negative Testing annually for OA-approved systems, using automated or semi-automated techniques to determine whether controls respond as expected under abnormal circumstances where misuse is injected to attempt to circumvent the control, coordinating as necessary with penetration testing purple team resources. Assist in the development and submission of OA Playbooks for Government approval, documenting the testing methodology for each OA core control including Test Strategy, Test Design, Test Execution, Results Evaluation, and Visualization components. Conduct OA testing comprehensively across all technology types within each target system's boundary, including sampling across in-scope devices, users, and services, documenting all test results in detail within the agency GRC tool in accordance with applicable OA implementation procedures. Ensure all OA Positive and Negative Testing documentation is peer-reviewed for accuracy and grammar prior to submission to the Government. ISSO Support & Collaboration Collaborate closely with assigned ISSOs to support their development of in-depth technical and operational knowledge about assigned systems, providing assessment expertise, technical guidance, and documentation support as needed. Provide technical support and expertise to ISSOs in the development and maintenance of all security documentation in the ATO package, including System Security Plans (SSPs), Configuration Management Plans (CMPs), Information System Contingency Plans (ISCPs), and other RMF artifacts, ensuring documentation aligns with applicable agency implementation procedures and template requirements. Support ISSOs in reviewing and validating system security documentation for technical accuracy, completeness, and alignment with the system boundary and technology stack, providing specific and actionable feedback to improve documentation quality. Assist ISSOs in ensuring control implementation descriptions within SSPs are written to the required level of technical detail, clearly explaining how each control is implemented across all technologies within the system boundary using specific naming conventions, configurations, and operational procedures rather than high-level general statements. Participate in Enterprise Change Control Board (ECCB) activities as needed, providing security assessment expertise to support the evaluation of proposed system changes and their potential impact on the system's security posture and ATO status. Audit & Compliance Support Support internal and external audit activities for assigned FISMA systems, facilitating meetings and walkthroughs of key cybersecurity capabilities, coordinating with system support personnel, and supplying auditors with requested artifacts and evidence within required timeframes. Ensure audit artifacts are complete, accurate, and delivered on time to avoid repeated requests from auditors, communicating any issues or problems to the Government immediately upon discovery. Support FISMA continuous monitoring activities, including the collection, validation, and submission of system-level FISMA metrics for assigned systems in alignment with federal CIO metrics requirements and agency reporting schedules. Assist in the development and maintenance of automated visualizations and dashboards that reflect the status and effectiveness of security controls for assigned systems, providing continuous visibility into the security posture and compliance status of assigned systems. Support High Value Asset (HVA) assessment activities for designated HVA systems, including vulnerability scanning and remediation validation, monitoring and analysis of relevant audit logs . click apply for full job details
Security Control Assessor
Omniscius Consulting Arlington, Virginia
Job Description Job Description Job Title: Security Control Assessor Location: On Site in Arlington, VA Department: Cyber Security Services Reports To: Management FLSA Status: Full Time/Non-exempt Clearance: Top Secret clearance with the ability to obtain SCI with CI Polygraph Job Purpose: The security control assessor (SCAs) supports a critical, objective role to evaluate the effectiveness of implemented controls in mitigating security risks. The SCA will support a critical mission within the intelligence community. In the role as a SCA, you are expected to use automated scanning tools, manual techniques, and specialized testing methodologies to identify weaknesses and vulnerabilities. The SCA is expected to be a collaborative member of the RMF program of the organization, to provide intelligent input to system security architectures in order to align with RMF principles and guidelines. This includes ensuring to guide the RMF process so that security controls are integrated seamlessly into system designs to provide comprehensive protection against threats and vulnerabilities. Duties & Responsibilities: The SCA's specific duties include: Advise the Information System Owner (ISO) concerning the impact levels for Confidentiality, Integrity, and Availability for the information on systems. Ensure security assessments are completed for each IS. Initiate a POA&M with identified weaknesses and suspense dates for each IS based on findings and recommendations from the SAR. Evaluate security assessment documentation and provide written recommendations for security authorization to the CISO and AO. Assess proposed changes to Information Systems, their environment of operation, and mission needs that could affect system authorization. Serve as a cybersecurity technical advisor to the CISO and AO under their purview. Be integral to the development of the monitoring strategy. The system-level continuous monitoring strategy must conform to all applicable published DoD enterprise-level or DoD Component-level continuous monitoring strategies. Determine and document in the SAR a risk level for every noncompliant security control in the system baseline. Determine and document in the SAR an aggregate level of risk to the system and identify the key drivers for the assessment. The SCA's risk assessment considers threats, vulnerabilities, and potential impacts as well as existing and planned risk mitigation. Develop the continuous monitoring plan specific to the information system. The SCA is responsible for the RMF deliverables associated with Step 4 of DOD and IC RMF Policies for assigned systems. This includes, but is not limited to: Security Assessment Plans tailored to specific systems control requirements Security control assessment input, which includes narratives for the review of controls and artifacts Security Assessment Reports ATO recommendations or ATO with Condition Memorandums Conduct initial remediation actions once a security assessment has been completed to ensure proper hand off to the ISSM and ISSOs. Assessment of selected controls IAW continuous monitoring strategy The SCA is expected to have additional duties as assigned in support of corporate cyber security services. Additional details are reviewed in accordance with company policies. Requirements Required Skills & Experience: Strong knowledge of Risk Management Framework (RMF) 800-37 and continuous monitoring 800-137 Expert knowledge and hands-on experience with FISMA Systems, NIST 800-series guidelines, FIPS, Security Assessment & Authorization (SA&A) requirements and processes, Continuous Monitoring Framework experience and its tools, Plan of Action & Milestones (POA&M) policies, and vulnerability/patch management, risk management, project management, proficient with Microsoft products - Word, Excel, PowerPoint. Proficient with vulnerability and scanning tools and well-versed in interpreting risk posture resulting from assessment reports. Experience in project management and tracking, and the Microsoft suite of office products Experience of assessing cloud-based security authorizations (FedRamp, AWS & Azure) as well as the NIST control responsibilities Experience with SAP/JSIG Expert with documenting and or reviewing of security materials such as; system security plans (SSP), Security Assessment Report (SAR), and Security Assessment Plan (SAP), and other documents per NIST 800 guidelines. Experience supporting cloud-based security authorizations (FedRamp, AWS, & Azure) Experience creating Security Assessment Plans, Security Assessment Reports, and Executive-level briefings Qualifications: Bachelor's Degree in Computer Science or a related technical discipline Master's Degree preferred. Minimum 6-10 years of experience. Must currently possess an active Top Secret clearance with the ability to obtain SCI with CI Polygraph. DOD 8140 IAM Level II (CAP, CASP, CISM, CISSP, GSLC, CCISO) is required Systems Security Engineering background preferred. Effective communication skills to collaborate with cross-functional teams and stakeholders on implementing security measures organization-wide. Strong analytical skills for identifying system vulnerabilities and documenting control remediation recommendations through collaboration on System Impact Analysis and Documented Risk Acceptance. Detail-oriented with the ability to manage multiple tasks and prioritize effectively. Comprehensive knowledge of RMF activities at a senior level (ability to articulate to Executive audiences preferred). Familiarity with federal regulatory requirements, contractual obligations, and industry standards related to information security. Evaluate adherence to standards such as Privacy, GDPR, and HIPAA Powered by JazzHR I48iVzr4Ds
09/26/2026
Full time
Job Description Job Description Job Title: Security Control Assessor Location: On Site in Arlington, VA Department: Cyber Security Services Reports To: Management FLSA Status: Full Time/Non-exempt Clearance: Top Secret clearance with the ability to obtain SCI with CI Polygraph Job Purpose: The security control assessor (SCAs) supports a critical, objective role to evaluate the effectiveness of implemented controls in mitigating security risks. The SCA will support a critical mission within the intelligence community. In the role as a SCA, you are expected to use automated scanning tools, manual techniques, and specialized testing methodologies to identify weaknesses and vulnerabilities. The SCA is expected to be a collaborative member of the RMF program of the organization, to provide intelligent input to system security architectures in order to align with RMF principles and guidelines. This includes ensuring to guide the RMF process so that security controls are integrated seamlessly into system designs to provide comprehensive protection against threats and vulnerabilities. Duties & Responsibilities: The SCA's specific duties include: Advise the Information System Owner (ISO) concerning the impact levels for Confidentiality, Integrity, and Availability for the information on systems. Ensure security assessments are completed for each IS. Initiate a POA&M with identified weaknesses and suspense dates for each IS based on findings and recommendations from the SAR. Evaluate security assessment documentation and provide written recommendations for security authorization to the CISO and AO. Assess proposed changes to Information Systems, their environment of operation, and mission needs that could affect system authorization. Serve as a cybersecurity technical advisor to the CISO and AO under their purview. Be integral to the development of the monitoring strategy. The system-level continuous monitoring strategy must conform to all applicable published DoD enterprise-level or DoD Component-level continuous monitoring strategies. Determine and document in the SAR a risk level for every noncompliant security control in the system baseline. Determine and document in the SAR an aggregate level of risk to the system and identify the key drivers for the assessment. The SCA's risk assessment considers threats, vulnerabilities, and potential impacts as well as existing and planned risk mitigation. Develop the continuous monitoring plan specific to the information system. The SCA is responsible for the RMF deliverables associated with Step 4 of DOD and IC RMF Policies for assigned systems. This includes, but is not limited to: Security Assessment Plans tailored to specific systems control requirements Security control assessment input, which includes narratives for the review of controls and artifacts Security Assessment Reports ATO recommendations or ATO with Condition Memorandums Conduct initial remediation actions once a security assessment has been completed to ensure proper hand off to the ISSM and ISSOs. Assessment of selected controls IAW continuous monitoring strategy The SCA is expected to have additional duties as assigned in support of corporate cyber security services. Additional details are reviewed in accordance with company policies. Requirements Required Skills & Experience: Strong knowledge of Risk Management Framework (RMF) 800-37 and continuous monitoring 800-137 Expert knowledge and hands-on experience with FISMA Systems, NIST 800-series guidelines, FIPS, Security Assessment & Authorization (SA&A) requirements and processes, Continuous Monitoring Framework experience and its tools, Plan of Action & Milestones (POA&M) policies, and vulnerability/patch management, risk management, project management, proficient with Microsoft products - Word, Excel, PowerPoint. Proficient with vulnerability and scanning tools and well-versed in interpreting risk posture resulting from assessment reports. Experience in project management and tracking, and the Microsoft suite of office products Experience of assessing cloud-based security authorizations (FedRamp, AWS & Azure) as well as the NIST control responsibilities Experience with SAP/JSIG Expert with documenting and or reviewing of security materials such as; system security plans (SSP), Security Assessment Report (SAR), and Security Assessment Plan (SAP), and other documents per NIST 800 guidelines. Experience supporting cloud-based security authorizations (FedRamp, AWS, & Azure) Experience creating Security Assessment Plans, Security Assessment Reports, and Executive-level briefings Qualifications: Bachelor's Degree in Computer Science or a related technical discipline Master's Degree preferred. Minimum 6-10 years of experience. Must currently possess an active Top Secret clearance with the ability to obtain SCI with CI Polygraph. DOD 8140 IAM Level II (CAP, CASP, CISM, CISSP, GSLC, CCISO) is required Systems Security Engineering background preferred. Effective communication skills to collaborate with cross-functional teams and stakeholders on implementing security measures organization-wide. Strong analytical skills for identifying system vulnerabilities and documenting control remediation recommendations through collaboration on System Impact Analysis and Documented Risk Acceptance. Detail-oriented with the ability to manage multiple tasks and prioritize effectively. Comprehensive knowledge of RMF activities at a senior level (ability to articulate to Executive audiences preferred). Familiarity with federal regulatory requirements, contractual obligations, and industry standards related to information security. Evaluate adherence to standards such as Privacy, GDPR, and HIPAA Powered by JazzHR I48iVzr4Ds
Configuration Manager
Tensley Consulting, Inc. Annapolis Junction, Maryland
Job Description Job Description Job Description Tensley Consulting is seeking a Configuration Manager Level 3 to support configuration management activities for developmental and operational systems. This role is responsible for maintaining system configuration baselines and ensuring proper version control across development, test, and production environments. The Configuration Manager will work with engineering and operational teams to implement configuration management policies, maintain system documentation, and support change control processes. This role also supports system build, staging, testing, and integration activities while ensuring configuration standards are followed throughout the system lifecycle. Education / Experience Eight (8) years of experience as a Configuration Manager supporting programs of similar scope and complexity is required. Bachelor's degree in a technical or business discipline from an accredited college or university. A Master's degree may substitute for two (2) years of experience. Four (4) additional years of CM experience may substitute for a bachelor's degree Salary: $123,000-$133,000. This represents the typical salary range for this position, but is not guaranteed. Salary is based on experience, location and contractual requirements which could fall outside of the range listed. , Required Skills Five (5) years of demonstrated experience supporting Information Assurance (IA) configuration management requirements, including CM aspects of physical and virtual access controls, labeling, and maintenance procedures as defined in System Security Plans (SSP) and related security documentation. Experience supporting configuration management (CM) for developmental and operational systems Experience maintaining configuration baselines across development, test, and production environments Experience implementing hardware and software version control processes Experience using configuration management tools Experience supporting system build, staging, testing, and integration environments Experience supporting change control processes and configuration audits Experience developing or maintaining configuration management policies and procedures , Desired Skills Experience supporting Department of Defense (DoD) or Intelligence Community (IC) programs Experience supporting large enterprise or mission systems Familiarity with System Security Plans (SSP) and related security documentation Experience working with source code control systems , About Tensley Consulting, Inc. About TensleyTensley Consulting is a Service-Disabled Veteran-Owned Small Business focused on mission engineering in support of the United States Intelligence Community and the Department of Defense. Our team consists of System Engineers, Software Engineers, Test Engineers, and Signals Analysts performing work throughout the Continental United States (CONUS) and Outside the Continental United States (OCONUS). Equal Opportunity, Diversity InclusionWe aim to build a team that represents a variety of backgrounds, perspectives, and skills. We embrace inclusion and ensure equal employment opportunity without discrimination or harassment based on race, color, religion, sex (including pregnancy, childbirth, or related medical conditions), sexual orientation, gender identity or expression, age, disability, national origin, marital or domestic/civil partnership status, genetic information, citizenship status, military or veteran status, or any other personal characteristic. Benefits Include 100% paid medical coverage with HSA and company contribution 100% paid vision, dental, short-term, and long-term premium 12% 401(k) contribution (not a match) Education and training budget 6 weeks and 3 days of PTO And much more! Come grow with us!
09/26/2026
Full time
Job Description Job Description Job Description Tensley Consulting is seeking a Configuration Manager Level 3 to support configuration management activities for developmental and operational systems. This role is responsible for maintaining system configuration baselines and ensuring proper version control across development, test, and production environments. The Configuration Manager will work with engineering and operational teams to implement configuration management policies, maintain system documentation, and support change control processes. This role also supports system build, staging, testing, and integration activities while ensuring configuration standards are followed throughout the system lifecycle. Education / Experience Eight (8) years of experience as a Configuration Manager supporting programs of similar scope and complexity is required. Bachelor's degree in a technical or business discipline from an accredited college or university. A Master's degree may substitute for two (2) years of experience. Four (4) additional years of CM experience may substitute for a bachelor's degree Salary: $123,000-$133,000. This represents the typical salary range for this position, but is not guaranteed. Salary is based on experience, location and contractual requirements which could fall outside of the range listed. , Required Skills Five (5) years of demonstrated experience supporting Information Assurance (IA) configuration management requirements, including CM aspects of physical and virtual access controls, labeling, and maintenance procedures as defined in System Security Plans (SSP) and related security documentation. Experience supporting configuration management (CM) for developmental and operational systems Experience maintaining configuration baselines across development, test, and production environments Experience implementing hardware and software version control processes Experience using configuration management tools Experience supporting system build, staging, testing, and integration environments Experience supporting change control processes and configuration audits Experience developing or maintaining configuration management policies and procedures , Desired Skills Experience supporting Department of Defense (DoD) or Intelligence Community (IC) programs Experience supporting large enterprise or mission systems Familiarity with System Security Plans (SSP) and related security documentation Experience working with source code control systems , About Tensley Consulting, Inc. About TensleyTensley Consulting is a Service-Disabled Veteran-Owned Small Business focused on mission engineering in support of the United States Intelligence Community and the Department of Defense. Our team consists of System Engineers, Software Engineers, Test Engineers, and Signals Analysts performing work throughout the Continental United States (CONUS) and Outside the Continental United States (OCONUS). Equal Opportunity, Diversity InclusionWe aim to build a team that represents a variety of backgrounds, perspectives, and skills. We embrace inclusion and ensure equal employment opportunity without discrimination or harassment based on race, color, religion, sex (including pregnancy, childbirth, or related medical conditions), sexual orientation, gender identity or expression, age, disability, national origin, marital or domestic/civil partnership status, genetic information, citizenship status, military or veteran status, or any other personal characteristic. Benefits Include 100% paid medical coverage with HSA and company contribution 100% paid vision, dental, short-term, and long-term premium 12% 401(k) contribution (not a match) Education and training budget 6 weeks and 3 days of PTO And much more! Come grow with us!
Configuration Manager 2
Columbia Technology Partners Annapolis Junction, Maryland
Job Description Job Description Description:Columbia Technology Partners is seeking a Configuration Manager to implement and maintain configuration management (CM) and version control processes for hardware and software systems throughout the full system lifecycle. This role ensures configuration integrity, traceability, and control by managing baselines, enforcing standardized CM processes, utilizing configuration tools, and supporting audits and change control activities.Key Responsibilities: Develop, implement, and enforce hardware and software configuration management and version control policies, processes, and proceduresEstablish, maintain, and control configuration baselines, ensuring accurate versioning and traceability of all configuration items (CIs)Manage end-to-end configuration control, including change tracking, impact analysis, approvals, and audit readinessUtilize CM tools (e.g., DOORS, Eclipse) to store, track, and manage configuration artifactsSupport build, integration, test, and release environments while maintaining configuration integrity across all phasesDevelop and document CM processes, including automated build and release procedures aligned with applicable standardsConduct configuration audits, support Change Control Board (CCB) activities, and ensure end-to-end configuration traceabilityQualifications: Six (6) years of experience in configuration management and version control on programs of similar scope, complexity, and technical requirementsBachelor 's degree in a technical or business-related discipline from an accredited institution, or four (4) additional years of relevant CM experience in lieu of a degreeDemonstrated experience implementing and managing hardware and software configuration baselines and version control systemsFor developmental programs, a minimum of one (1) year of experience using source code control systems such as Git, SVN, or equivalent toolsRequirements: U.S. Citizenship is required for all applicants. CTP is an equal opportunity employer and abides by applicable employment laws and regulations. All applicants and employees are subject to random drug testing in accordance with Executive Order 12564. Employment is contingent upon successful completion of a security background investigation and polygraph.Certification Requirements:DOD 8570 CertificationThis position requires an active Security Clearance with appropriate Polygraph.About us:Founded in 2007, Columbia Technology Partners is a Service-Disabled Veteran Owned Small Business with a specialization in technology and management consulting committed to solving intricate and sensitive technology issues facing corporations and federal agencies. Since its inception, CTP has been instrumental in the technical design, engineering development, operational deployment, and support of key systems. With a proven track record in information security, project management, systems/network engineering, security risk management, vulnerability assessments, and mobile security implementation; our employees have the experience, expertise, and innovative thinking our customers need for results that exceed expectations. CTP staff have worked closely with both government engineers and management to gather mission requirements, develop the architecture to deliver the needed functionality and assess tools available to meet or exceed the needs of the mission.At Columbia Technology Partners (CTP), we are united in being the best that we can be as individuals, but our core belief is that we can be better together. Together we will take on each mission with an execution process that authentically represents who we are. Our success relies on our team values, the foundation we built around them, and the Partners we become along the way.That's why our pay is competitive, our missions are critical, and our benefits represent what matters most to CTP: Our People.Salary Range TransparencyAt Columbia Technology Partners we are committed to transparency and fairness in our compensation practices. We believe in creating a work environment where employees feel valued, empowered, and rewarded for their contributions.How We Determine Salary RangesOur salary ranges are based on the following key factors:Job Role and Responsibilities: The specific duties and responsibilities associated with each role form the foundation of our compensation structure.Market Research and Industry Benchmarks: We conduct regular analysis of market trends and salaries across our industry, using reliable compensation data to ensure we stay competitive.Experience and Qualifications: An individual's experience, education, certifications, and specialized skills all contribute to determining their position within a salary range.Location: Salary ranges may be adjusted based on geographic cost of living, in accordance with local and national standards.Company Performance: Our compensation practices also take into account overall company performance and financial health, ensuring that we maintain sustainability while rewarding our team.Really good benefits, for really GREAT people:From our CTP Family to yours, we know how important these decisions are. Your benefits are about you, not us. Tell us what you need in order to see a future at CTP; let's get where you're going, together. Medical: CTP offers 3 superior plans, bringing our employees both in-network and out-of-network options.Vision + Dental: Both free to you + paid in full by CTP.Retirement: 401k - 6% company contributionPTO + Leave: A work life balance is extremely important to our team here at CTP, which is why our paid time off plans are so lucrative. Offering customizable leave plans to meet your needs is just one of our many perks! Jury Duty, Bereavement + Military Leave provided.Career Growth: Up to $10,000 provided for approved career-related learning, training, education, and/or tuition.Life and AD&D Insurance/Short-Term & Long-Term Disability: More peace of mind, at zero cost to you.Profit Sharing Bonus: End of year cash gets added to your bottom-line.Referral Bonus Program: Our tiered program provides an incentive with each stage of the hiring process your referral passes. Our bonuses range from $7,000-$20,000, if your referral joins the team.Columbia Technology Partners is an Equal Opportunity Employer. We consider applicants without regard to race, color, religion, age, national origin, ancestry, ethnicity, gender, gender identity, gender expression, sexual orientation, marital status, veteran status, disability, genetic information, citizenship status, or membership in any other group protected by federal, state, or local law. Our EEO policy reflects our commitment to ensure equality and promote diversity and inclusion in the workplace. Our policy applies to all employees, job candidates, contractors, stakeholders, partners, and visitors.CTP was voted one of the top 25 best places to work in Baltimore by Baltimore Magazine!
09/26/2026
Full time
Job Description Job Description Description:Columbia Technology Partners is seeking a Configuration Manager to implement and maintain configuration management (CM) and version control processes for hardware and software systems throughout the full system lifecycle. This role ensures configuration integrity, traceability, and control by managing baselines, enforcing standardized CM processes, utilizing configuration tools, and supporting audits and change control activities.Key Responsibilities: Develop, implement, and enforce hardware and software configuration management and version control policies, processes, and proceduresEstablish, maintain, and control configuration baselines, ensuring accurate versioning and traceability of all configuration items (CIs)Manage end-to-end configuration control, including change tracking, impact analysis, approvals, and audit readinessUtilize CM tools (e.g., DOORS, Eclipse) to store, track, and manage configuration artifactsSupport build, integration, test, and release environments while maintaining configuration integrity across all phasesDevelop and document CM processes, including automated build and release procedures aligned with applicable standardsConduct configuration audits, support Change Control Board (CCB) activities, and ensure end-to-end configuration traceabilityQualifications: Six (6) years of experience in configuration management and version control on programs of similar scope, complexity, and technical requirementsBachelor 's degree in a technical or business-related discipline from an accredited institution, or four (4) additional years of relevant CM experience in lieu of a degreeDemonstrated experience implementing and managing hardware and software configuration baselines and version control systemsFor developmental programs, a minimum of one (1) year of experience using source code control systems such as Git, SVN, or equivalent toolsRequirements: U.S. Citizenship is required for all applicants. CTP is an equal opportunity employer and abides by applicable employment laws and regulations. All applicants and employees are subject to random drug testing in accordance with Executive Order 12564. Employment is contingent upon successful completion of a security background investigation and polygraph.Certification Requirements:DOD 8570 CertificationThis position requires an active Security Clearance with appropriate Polygraph.About us:Founded in 2007, Columbia Technology Partners is a Service-Disabled Veteran Owned Small Business with a specialization in technology and management consulting committed to solving intricate and sensitive technology issues facing corporations and federal agencies. Since its inception, CTP has been instrumental in the technical design, engineering development, operational deployment, and support of key systems. With a proven track record in information security, project management, systems/network engineering, security risk management, vulnerability assessments, and mobile security implementation; our employees have the experience, expertise, and innovative thinking our customers need for results that exceed expectations. CTP staff have worked closely with both government engineers and management to gather mission requirements, develop the architecture to deliver the needed functionality and assess tools available to meet or exceed the needs of the mission.At Columbia Technology Partners (CTP), we are united in being the best that we can be as individuals, but our core belief is that we can be better together. Together we will take on each mission with an execution process that authentically represents who we are. Our success relies on our team values, the foundation we built around them, and the Partners we become along the way.That's why our pay is competitive, our missions are critical, and our benefits represent what matters most to CTP: Our People.Salary Range TransparencyAt Columbia Technology Partners we are committed to transparency and fairness in our compensation practices. We believe in creating a work environment where employees feel valued, empowered, and rewarded for their contributions.How We Determine Salary RangesOur salary ranges are based on the following key factors:Job Role and Responsibilities: The specific duties and responsibilities associated with each role form the foundation of our compensation structure.Market Research and Industry Benchmarks: We conduct regular analysis of market trends and salaries across our industry, using reliable compensation data to ensure we stay competitive.Experience and Qualifications: An individual's experience, education, certifications, and specialized skills all contribute to determining their position within a salary range.Location: Salary ranges may be adjusted based on geographic cost of living, in accordance with local and national standards.Company Performance: Our compensation practices also take into account overall company performance and financial health, ensuring that we maintain sustainability while rewarding our team.Really good benefits, for really GREAT people:From our CTP Family to yours, we know how important these decisions are. Your benefits are about you, not us. Tell us what you need in order to see a future at CTP; let's get where you're going, together. Medical: CTP offers 3 superior plans, bringing our employees both in-network and out-of-network options.Vision + Dental: Both free to you + paid in full by CTP.Retirement: 401k - 6% company contributionPTO + Leave: A work life balance is extremely important to our team here at CTP, which is why our paid time off plans are so lucrative. Offering customizable leave plans to meet your needs is just one of our many perks! Jury Duty, Bereavement + Military Leave provided.Career Growth: Up to $10,000 provided for approved career-related learning, training, education, and/or tuition.Life and AD&D Insurance/Short-Term & Long-Term Disability: More peace of mind, at zero cost to you.Profit Sharing Bonus: End of year cash gets added to your bottom-line.Referral Bonus Program: Our tiered program provides an incentive with each stage of the hiring process your referral passes. Our bonuses range from $7,000-$20,000, if your referral joins the team.Columbia Technology Partners is an Equal Opportunity Employer. We consider applicants without regard to race, color, religion, age, national origin, ancestry, ethnicity, gender, gender identity, gender expression, sexual orientation, marital status, veteran status, disability, genetic information, citizenship status, or membership in any other group protected by federal, state, or local law. Our EEO policy reflects our commitment to ensure equality and promote diversity and inclusion in the workplace. Our policy applies to all employees, job candidates, contractors, stakeholders, partners, and visitors.CTP was voted one of the top 25 best places to work in Baltimore by Baltimore Magazine!
Senior Configuration Manager
S4, LLC Fort George G Meade, Maryland
Job Description Job Description Systems & System Software Solutions (S4), LLC is a privately held small business working with federal customers since 1998. We offer competitive compensation packages to include full employee benefits and schedule flexibility. The location of this position is in the Fort Meade, MD vicinity. If you enjoy a company with a family-oriented culture where the owners appreciate and recognize your achievements, come explore our opportunities! We offer engineering positions with frontline experience in operations and mission support to the Department of Defense. Applicants MUST be a US citizen AND currently possess a TS/SCI security clearance with polygraph. Seeking a Senior Configuration Manager (CM) to work closely with a DoD customer to provide CM and Systems Engineering (SE) support towards the development of software baselines for a large operational team from cradle-to-grave. The candidate will: Use or recommend automated CM tools to implement CM policies and procedures. Develop or modify CM plans, policies, and procedures tailored to the complexity and scope of the developmental or operational system. Implement CM discipline for the entire life cycle of systems from initial requirements/capabilities baselines to system end-of-life. Perform change control and configuration audits. Create and maintain configuration baselines (development, test, production, etc.). Coordinate across multiple organizations to schedule and facilitate meetings such as CCB's, ERB's, MRB's and RRG's and ensure the correct Stakeholders are available. Facilitate meetings ensuring audio video equipment is properly configured and briefing material is available. Brief internal and external organizations on processes to include Configuration Management, Data Management, Requirements Management and System Engineering. Support the organization's corporate tools to include multiple Atlassian JIRA instances and Confluence spaces and administration of SharePoint libraries. Record meeting minutes and capture artifacts. Requirements: Must be a U.S. citizen and currently possess a TS/SCI security clearance with full scope polygraph . A Bachelors degree in a technical discipline is required or 5 additional years of work experience can be substituted for a degree A master's degree may be substituted for 2 years of experience. Eight (8) years of experience as a Configuration Manager, System Engineer or Test Engineer Ability to multi-task and possess strong organizational skills This position is available immediately and is fully funded.
09/26/2026
Full time
Job Description Job Description Systems & System Software Solutions (S4), LLC is a privately held small business working with federal customers since 1998. We offer competitive compensation packages to include full employee benefits and schedule flexibility. The location of this position is in the Fort Meade, MD vicinity. If you enjoy a company with a family-oriented culture where the owners appreciate and recognize your achievements, come explore our opportunities! We offer engineering positions with frontline experience in operations and mission support to the Department of Defense. Applicants MUST be a US citizen AND currently possess a TS/SCI security clearance with polygraph. Seeking a Senior Configuration Manager (CM) to work closely with a DoD customer to provide CM and Systems Engineering (SE) support towards the development of software baselines for a large operational team from cradle-to-grave. The candidate will: Use or recommend automated CM tools to implement CM policies and procedures. Develop or modify CM plans, policies, and procedures tailored to the complexity and scope of the developmental or operational system. Implement CM discipline for the entire life cycle of systems from initial requirements/capabilities baselines to system end-of-life. Perform change control and configuration audits. Create and maintain configuration baselines (development, test, production, etc.). Coordinate across multiple organizations to schedule and facilitate meetings such as CCB's, ERB's, MRB's and RRG's and ensure the correct Stakeholders are available. Facilitate meetings ensuring audio video equipment is properly configured and briefing material is available. Brief internal and external organizations on processes to include Configuration Management, Data Management, Requirements Management and System Engineering. Support the organization's corporate tools to include multiple Atlassian JIRA instances and Confluence spaces and administration of SharePoint libraries. Record meeting minutes and capture artifacts. Requirements: Must be a U.S. citizen and currently possess a TS/SCI security clearance with full scope polygraph . A Bachelors degree in a technical discipline is required or 5 additional years of work experience can be substituted for a degree A master's degree may be substituted for 2 years of experience. Eight (8) years of experience as a Configuration Manager, System Engineer or Test Engineer Ability to multi-task and possess strong organizational skills This position is available immediately and is fully funded.
Engineering Configuration Manager, Hydrogen
Heven AeroTech Winchester, Virginia
Job Description Job Description Title: Engineering Configuration Manager, Hydrogen Company: Heven AeroTech Location: Winchester, VA FLSA: Exempt Role Summary: The Engineering Configuration Manager for Hydrogen owns the configuration management and documentation backbone of Heven AeroTech's hydrogen generation and fueling technologies, guiding them from engineering development into scalable, repeatable manufacturing. Based at our Winchester, VA facility, this role governs product baselines, change control, and design documentation-ensuring hardware, software, baseline designs, and change histories remain consistent across engineering, production, and field operations. Working cross-functionally with fuel cell engineering, program management, quality, supply chain, and production teams, the Configuration Manager ensures Heven's hydrogen systems transition from concept to the production floor safely, on schedule, and at the cost and quality targets required by our defense and commercial customers. Essential Responsibilities: Bill of Materials (BOMs): Structuring and maintaining multi-level engineering BOMs and manufacturing BOMs, ensuring full traceability down to individual components, raw materials, or sub-assemblies. Change Control Management: Owning the formal end-to-end change management workflow for Engineering Change Requests/Orders (ECR / ECO / ECN), from evaluating a proposed change to routing it through approval and verifying implementation. PLM/PDM System Ownership: Administering product data management and product lifecycle management software (e.g., Windchill, Teamcenter, Arena, Aras) to enforce revision control, access permissions, and workflow rules. Cross-Discipline Alignment: Serving as the central nexus connecting design engineering, supply chain, manufacturing, and quality assurance to prevent "version drift" between design releases and vendor orders. Qualifications & Experience: Required: Bachelor's degree in Mechanical Engineering, Chemical Engineering, Manufacturing Engineering, or a related technical discipline. 5+ years of experience in product lifecycle management, manufacturing engineering, new product introduction (NPI), or a related technology transfer role. Demonstrated experience taking hardware products from engineering prototype through production, including DFM/DFA reviews and stage-gate processes. Working knowledge of BOM structures, engineering change management, and PLM/PDM tooling. Experience reading and working with engineering drawings, P&IDs, and system schematics. Strong project management skills, with the ability to coordinate cross-functional teams across engineering, supply chain, quality, and production. Excellent written and verbal communication skills, with the ability to translate technical detail into clear documentation and decisions for varied audiences. Preferred: Background in energy, aerospace, or defense hardware programs. Familiarity with high-pressure gas systems and relevant codes and standards (NFPA 2, ASME B31.3, CGA). Experience supporting hazard analyses (HAZOP, FMEA). Experience scaling manufacturing at an early-stage or low-rate-initial-production. Familiarity with defense procurement and export control considerations (ITAR/EAR, MTCR) as they relate to production planning. Direct experience with hydrogen generation/electrolyzer technology. Physical Requirements: Prolonged periods of sitting at a desk and working on a computer performing documentation, data entry, and configuration management tasks. Regular use of hands and fingers to operate a computer keyboard, mouse, and other office equipment. Frequent movement between office areas, engineering spaces, and the production/manufacturing floor. Ability to occasionally stand and walk for extended periods while conducting reviews, inspections, or floor coordination. Ability to occasionally lift, carry, and move objects weighing up to 25 pounds (e.g., hardware components, documentation, or equipment). Occasional bending, stooping, kneeling, crouching, or reaching to inspect components, sub-assemblies, or equipment. Sufficient visual acuity to read engineering drawings, P&IDs, system schematics, and detailed technical documentation, both on screen and in print. Ability to communicate clearly and effectively, both verbally and in writing, with cross-functional teams in person and remotely. Ability to work in a manufacturing environment that may include exposure to noise, moving machinery, and high-pressure gas systems, requiring adherence to all safety protocols and use of personal protective equipment (PPE) as required. Ability to wear required PPE (e.g., safety glasses, hearing protection, closed-toe/safety footwear) when on the production floor or in testing areas. May occasionally be required to work extended hours to meet project deadlines or support production schedules. Benefits Overview: Heven AeroTech offers a competitive benefits package designed to support the health, financial security, and overall well-being of our employees and their families. Benefits include medical, dental, and vision coverage, retirement plans, paid time off/sick, and additional protections such as critical illness, hospital indemnity, accident coverage, and short- and long-term disability. Equal Employment Opportunity Statement: Heven AeroTech is an Equal Opportunity Employer and considers all qualified applicants without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability, veteran status, or any other protected characteristic under applicable law. Budgeted Salary Range: $105,000-$135,000 USD
09/26/2026
Full time
Job Description Job Description Title: Engineering Configuration Manager, Hydrogen Company: Heven AeroTech Location: Winchester, VA FLSA: Exempt Role Summary: The Engineering Configuration Manager for Hydrogen owns the configuration management and documentation backbone of Heven AeroTech's hydrogen generation and fueling technologies, guiding them from engineering development into scalable, repeatable manufacturing. Based at our Winchester, VA facility, this role governs product baselines, change control, and design documentation-ensuring hardware, software, baseline designs, and change histories remain consistent across engineering, production, and field operations. Working cross-functionally with fuel cell engineering, program management, quality, supply chain, and production teams, the Configuration Manager ensures Heven's hydrogen systems transition from concept to the production floor safely, on schedule, and at the cost and quality targets required by our defense and commercial customers. Essential Responsibilities: Bill of Materials (BOMs): Structuring and maintaining multi-level engineering BOMs and manufacturing BOMs, ensuring full traceability down to individual components, raw materials, or sub-assemblies. Change Control Management: Owning the formal end-to-end change management workflow for Engineering Change Requests/Orders (ECR / ECO / ECN), from evaluating a proposed change to routing it through approval and verifying implementation. PLM/PDM System Ownership: Administering product data management and product lifecycle management software (e.g., Windchill, Teamcenter, Arena, Aras) to enforce revision control, access permissions, and workflow rules. Cross-Discipline Alignment: Serving as the central nexus connecting design engineering, supply chain, manufacturing, and quality assurance to prevent "version drift" between design releases and vendor orders. Qualifications & Experience: Required: Bachelor's degree in Mechanical Engineering, Chemical Engineering, Manufacturing Engineering, or a related technical discipline. 5+ years of experience in product lifecycle management, manufacturing engineering, new product introduction (NPI), or a related technology transfer role. Demonstrated experience taking hardware products from engineering prototype through production, including DFM/DFA reviews and stage-gate processes. Working knowledge of BOM structures, engineering change management, and PLM/PDM tooling. Experience reading and working with engineering drawings, P&IDs, and system schematics. Strong project management skills, with the ability to coordinate cross-functional teams across engineering, supply chain, quality, and production. Excellent written and verbal communication skills, with the ability to translate technical detail into clear documentation and decisions for varied audiences. Preferred: Background in energy, aerospace, or defense hardware programs. Familiarity with high-pressure gas systems and relevant codes and standards (NFPA 2, ASME B31.3, CGA). Experience supporting hazard analyses (HAZOP, FMEA). Experience scaling manufacturing at an early-stage or low-rate-initial-production. Familiarity with defense procurement and export control considerations (ITAR/EAR, MTCR) as they relate to production planning. Direct experience with hydrogen generation/electrolyzer technology. Physical Requirements: Prolonged periods of sitting at a desk and working on a computer performing documentation, data entry, and configuration management tasks. Regular use of hands and fingers to operate a computer keyboard, mouse, and other office equipment. Frequent movement between office areas, engineering spaces, and the production/manufacturing floor. Ability to occasionally stand and walk for extended periods while conducting reviews, inspections, or floor coordination. Ability to occasionally lift, carry, and move objects weighing up to 25 pounds (e.g., hardware components, documentation, or equipment). Occasional bending, stooping, kneeling, crouching, or reaching to inspect components, sub-assemblies, or equipment. Sufficient visual acuity to read engineering drawings, P&IDs, system schematics, and detailed technical documentation, both on screen and in print. Ability to communicate clearly and effectively, both verbally and in writing, with cross-functional teams in person and remotely. Ability to work in a manufacturing environment that may include exposure to noise, moving machinery, and high-pressure gas systems, requiring adherence to all safety protocols and use of personal protective equipment (PPE) as required. Ability to wear required PPE (e.g., safety glasses, hearing protection, closed-toe/safety footwear) when on the production floor or in testing areas. May occasionally be required to work extended hours to meet project deadlines or support production schedules. Benefits Overview: Heven AeroTech offers a competitive benefits package designed to support the health, financial security, and overall well-being of our employees and their families. Benefits include medical, dental, and vision coverage, retirement plans, paid time off/sick, and additional protections such as critical illness, hospital indemnity, accident coverage, and short- and long-term disability. Equal Employment Opportunity Statement: Heven AeroTech is an Equal Opportunity Employer and considers all qualified applicants without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability, veteran status, or any other protected characteristic under applicable law. Budgeted Salary Range: $105,000-$135,000 USD
Sr. Operations Engineer - Space Control
Solutions Through Innovative Technologies, Inc Colorado Springs, Colorado
Job Description Job Description Solutions Through Innovative Technologies, Inc. (STI-TEC) specializes in the delivery of professional business and information management services. STI-TEC offers government and commercial clients a comprehensive portfolio of services that identify, manage, distribute and improve business processes related to entities' most valued resource, information. As a fast-growing solutions provider, established in 2000, total customer satisfaction has remained the cornerstone of our business. Our business model focuses on integrity, loyalty, and trust. Position Overview Space Systems Command (SSC), is the United States Space Force field command responsible for acquiring, developing, and delivering resilient capabilities to outpace emerging threats and protect our Nation's strategic advantage in, from, and to space. SSC plays a critical role in advancing the United States space capabilities, delivering cutting-edge solutions to protect and enhance national security. Join us and be part of the mission to shape the future of space and protect the assets that keep our nation secure. Essential Job Function Provide space acquisitions, engineering, operations, and technical advice and assistance for various project and program stages to support the acquisition life cycle. Support program acquisition efforts in advanced technology, future concept development, and integration activities. Advise and assist on cost, schedule, and performance issues. Revise or draft Joint Capabilities Integrated Development System (JCIDS) and acquisition documentation for government program managers. Support presentations of products to internal and external customers. Documentation includes Initial Capability Documents, Interface Control Documents, Capability Development/Production/Requirements Documents, Milestone documentation, Acquisition Strategies, Analysis of Alternatives, Concept of Operations, Memorandums of Agreement/Understanding, Technical/Systems Requirement Documents, Defense Acquisition Board documentation, Technical Evaluations, System Specifications, enabling concepts, training material, briefings, white papers, reports, and analysis results. Provide draft SME-level technical and/or programmatic status reports as requested. Identify improvement areas in acquisition processes and recommend actionable changes. Assist in building and maintaining a government risk program. Maintain current awareness of program schedules, monitor acquisition implementation, report requirement shortfalls, and provide program assessments based on identified risks. Provide advice on technical engagements such as technical interchange meetings, design reviews, and program conferences. Provide technical and operational insights for mission protection and operations. Recommend solutions for technical anomalies and evaluate impact analysis, audits, studies, compliance inspections, and readiness reviews. Provide cybersecurity support in accordance with DoDI 8500.01. Recommend actions on cyber activities and provide cybersecurity issue briefings as requested. Facilitate and support cybersecurity working groups and meetings. Maintain awareness and manage program Authority to Operate, Authority to Test, Authority to Connect, and associated Interim Authorities. Support cyber testing and assessment activities and document findings and corrective actions in accordance with the Federal Information Security Management Act. Minimum Qualifications Highly knowledgeable in space control space, ground, and C2 systems (concepts, development, build, and test) Highly knowledgeable in managing operations strategy Highly knowledgeable in coordinating and managing exercise and operations training Highly knowledgeable in space control mission planning and coops development BA/BS Over 10 years of relative experience Experience with the MS Office Suite of Tools Active TS/SCI eligibility COMPENSATION / SALARY RANGE: STI-TEC adheres to federal, state, and local regulations. This is a Full-Time, Salary, Exempt position. The following salary range is what we reasonably expect to pay but is contingent and subject to a variety of factors, including but not limited to years of experience, education, certification(s), training, specialized skills, responsibilities, etc. Salary Range $140,000.00 - $160,000.00 Annual Salary STI-TEC offers a competitive benefits package including: Medical, dental, and vision coverage Life insurance Short term/long term disability coverage Retirement savings - 401(k) Paid time off (PTO) Holiday leave Alternate work schedules (depending on work site) Flexible spending account options Whether you're an experienced professional, a veteran, a former military or civilian federal employee, or a recent graduate, STI-TEC has a career opportunity for you. Applicants selected may be subject to a U.S. Government security investigation and must meet eligibility requirements for access to classified information. STI-TEC is an equal opportunity employer and values diversity. Employment is decided on the basis of qualifications, merit, and business need. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, national origin, disability, protected Veteran status, gender identity and sexual orientation. This policy applies to all terms and conditions of employment, including recruiting, hiring, placement, promotion, termination, layoff, transfer, leaves of absence, compensation and training. If you need assistance or an accommodation due to a disability, you may contact us at or you may call us at .583.9900. This job posting is to identify potential candidates for positions in order to respond to a request for proposal. This job posting, including but not limited to, qualifications, duties, compensation and benefits, is subject to change based on the terms and conditions of the awarded contract and is contingent on STI-TEC being awarded the contract.
09/26/2026
Full time
Job Description Job Description Solutions Through Innovative Technologies, Inc. (STI-TEC) specializes in the delivery of professional business and information management services. STI-TEC offers government and commercial clients a comprehensive portfolio of services that identify, manage, distribute and improve business processes related to entities' most valued resource, information. As a fast-growing solutions provider, established in 2000, total customer satisfaction has remained the cornerstone of our business. Our business model focuses on integrity, loyalty, and trust. Position Overview Space Systems Command (SSC), is the United States Space Force field command responsible for acquiring, developing, and delivering resilient capabilities to outpace emerging threats and protect our Nation's strategic advantage in, from, and to space. SSC plays a critical role in advancing the United States space capabilities, delivering cutting-edge solutions to protect and enhance national security. Join us and be part of the mission to shape the future of space and protect the assets that keep our nation secure. Essential Job Function Provide space acquisitions, engineering, operations, and technical advice and assistance for various project and program stages to support the acquisition life cycle. Support program acquisition efforts in advanced technology, future concept development, and integration activities. Advise and assist on cost, schedule, and performance issues. Revise or draft Joint Capabilities Integrated Development System (JCIDS) and acquisition documentation for government program managers. Support presentations of products to internal and external customers. Documentation includes Initial Capability Documents, Interface Control Documents, Capability Development/Production/Requirements Documents, Milestone documentation, Acquisition Strategies, Analysis of Alternatives, Concept of Operations, Memorandums of Agreement/Understanding, Technical/Systems Requirement Documents, Defense Acquisition Board documentation, Technical Evaluations, System Specifications, enabling concepts, training material, briefings, white papers, reports, and analysis results. Provide draft SME-level technical and/or programmatic status reports as requested. Identify improvement areas in acquisition processes and recommend actionable changes. Assist in building and maintaining a government risk program. Maintain current awareness of program schedules, monitor acquisition implementation, report requirement shortfalls, and provide program assessments based on identified risks. Provide advice on technical engagements such as technical interchange meetings, design reviews, and program conferences. Provide technical and operational insights for mission protection and operations. Recommend solutions for technical anomalies and evaluate impact analysis, audits, studies, compliance inspections, and readiness reviews. Provide cybersecurity support in accordance with DoDI 8500.01. Recommend actions on cyber activities and provide cybersecurity issue briefings as requested. Facilitate and support cybersecurity working groups and meetings. Maintain awareness and manage program Authority to Operate, Authority to Test, Authority to Connect, and associated Interim Authorities. Support cyber testing and assessment activities and document findings and corrective actions in accordance with the Federal Information Security Management Act. Minimum Qualifications Highly knowledgeable in space control space, ground, and C2 systems (concepts, development, build, and test) Highly knowledgeable in managing operations strategy Highly knowledgeable in coordinating and managing exercise and operations training Highly knowledgeable in space control mission planning and coops development BA/BS Over 10 years of relative experience Experience with the MS Office Suite of Tools Active TS/SCI eligibility COMPENSATION / SALARY RANGE: STI-TEC adheres to federal, state, and local regulations. This is a Full-Time, Salary, Exempt position. The following salary range is what we reasonably expect to pay but is contingent and subject to a variety of factors, including but not limited to years of experience, education, certification(s), training, specialized skills, responsibilities, etc. Salary Range $140,000.00 - $160,000.00 Annual Salary STI-TEC offers a competitive benefits package including: Medical, dental, and vision coverage Life insurance Short term/long term disability coverage Retirement savings - 401(k) Paid time off (PTO) Holiday leave Alternate work schedules (depending on work site) Flexible spending account options Whether you're an experienced professional, a veteran, a former military or civilian federal employee, or a recent graduate, STI-TEC has a career opportunity for you. Applicants selected may be subject to a U.S. Government security investigation and must meet eligibility requirements for access to classified information. STI-TEC is an equal opportunity employer and values diversity. Employment is decided on the basis of qualifications, merit, and business need. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, national origin, disability, protected Veteran status, gender identity and sexual orientation. This policy applies to all terms and conditions of employment, including recruiting, hiring, placement, promotion, termination, layoff, transfer, leaves of absence, compensation and training. If you need assistance or an accommodation due to a disability, you may contact us at or you may call us at .583.9900. This job posting is to identify potential candidates for positions in order to respond to a request for proposal. This job posting, including but not limited to, qualifications, duties, compensation and benefits, is subject to change based on the terms and conditions of the awarded contract and is contingent on STI-TEC being awarded the contract.
Operations System Engineer
XMSTART Chantilly, Virginia
Job Description Job Description XMSTART is looking for an Operations System Engineer to support a very dynamic and innovative space program in Chantilly, VA. The candidate will gain experience acquiring and deploying the next-generation of space assets including first of a kind satellite constellations with ground-breaking technology. This rewarding and mission focused position will enable you to have a positive impact on our nation's capabilities, while working with an incredibly strong team that is focused on mission success. This position requires a strong understanding of operations, with prior experience in satellite operations. The candidate must demonstrate excellent problem-solving skills, creativity, and a proactive attitude, with a willingness to go the extra mile to resolve issues in a dynamic, fast-paced NRO System Program Office environment. If you are passionate about the mission and are excited about next-generation space, you'll love this team! This position is 100% Onsite. Requirements Security Clearance Requirements: Top Secret/SCI with CI Polygraph required Education: Bachelor's and 14 years or more experience, or; Master's and 12 years or more experience, or; PhD and 9 years of experience Qualifications: Experience with NRO satellite systems Available to travel domestically Responsibilities: Provide operations planning and execution support Develop and coordinate operations transition plans for large constellations Provides support to anomaly resolution Develops innovative ways to utilize systems Develop productive relationships with Contractor counterparts, functional counterparts, and other subject matter experts. Maintains solid understanding of system capabilities Maintains a solid understanding of system CONOPS to include numerous tools needed for system tasking, data file transfers, collection statistics Serves as mentor to team members Ability to provide on-call support Provide proactive support to the Government customer and tasks in an integrated office environment Participate in full lifecycle acquisition and SE activities from pre-acquisition through launch and on-orbit checkout Author, review, and coordinate documents, briefings and data to aid the Government in communications and decision-making
09/26/2026
Full time
Job Description Job Description XMSTART is looking for an Operations System Engineer to support a very dynamic and innovative space program in Chantilly, VA. The candidate will gain experience acquiring and deploying the next-generation of space assets including first of a kind satellite constellations with ground-breaking technology. This rewarding and mission focused position will enable you to have a positive impact on our nation's capabilities, while working with an incredibly strong team that is focused on mission success. This position requires a strong understanding of operations, with prior experience in satellite operations. The candidate must demonstrate excellent problem-solving skills, creativity, and a proactive attitude, with a willingness to go the extra mile to resolve issues in a dynamic, fast-paced NRO System Program Office environment. If you are passionate about the mission and are excited about next-generation space, you'll love this team! This position is 100% Onsite. Requirements Security Clearance Requirements: Top Secret/SCI with CI Polygraph required Education: Bachelor's and 14 years or more experience, or; Master's and 12 years or more experience, or; PhD and 9 years of experience Qualifications: Experience with NRO satellite systems Available to travel domestically Responsibilities: Provide operations planning and execution support Develop and coordinate operations transition plans for large constellations Provides support to anomaly resolution Develops innovative ways to utilize systems Develop productive relationships with Contractor counterparts, functional counterparts, and other subject matter experts. Maintains solid understanding of system capabilities Maintains a solid understanding of system CONOPS to include numerous tools needed for system tasking, data file transfers, collection statistics Serves as mentor to team members Ability to provide on-call support Provide proactive support to the Government customer and tasks in an integrated office environment Participate in full lifecycle acquisition and SE activities from pre-acquisition through launch and on-orbit checkout Author, review, and coordinate documents, briefings and data to aid the Government in communications and decision-making
Senior Security Control Assessor Representative (SCAR)
Dark Wolf Solutions Herndon, Virginia
Job Description Job Description Dark Wolf Solutions is seeking a Senior Security Control Assessor Representative (SCAR) to conduct independent comprehensive assessments of the management, operation, and technical security controls and control enhancements employed within, or inherited by, an Information technology (IT) system to determine the overall effectiveness of the controls. The SCAR will perform reviews of security artifacts for system authorizations, assessing both the technical and functional adequacy as required for application and software cybersecurity readiness. The SCAR candidate must have prior experience in authorizing tools/applications, systems, and/or enclaves. Additionally, knowledge of network security, technologies, processes, and practices designed for the prevention of damage to, protection of, and restoration of computers, communications systems, services, and various types of communications technologies. The SCAR candidate must be knowledgeable and proficient in assessing DoD GovCloud environments to include testing controls and validating artifacts. A successful candidate will have a strong foundational understanding of NIST, DOD, and DAF cybersecurity focused guidance. This position can be based out of any Dark Wolf Office location and will be a hybrid schedule. Additional responsibilities include: Key Responsibilities: Evaluating IT infrastructure in terms of risk to the organization and defining artifacts required to meet Federal, DoD and DAF requirements Assessing IT systems and architecture to ensure compliance with the Risk Management Framework (RMF), NIST Cybersecurity Framework (CSF), NIST 800-53 revision 5 and applicable guidance Supporting the system/application assessment and authorization (A&A) effort, to include assessing and guiding the quality and completeness of A&A activities, tasks and resulting artifacts mandated by governing DoD and AF policies, and applicable mandates Collecting, reviewing and verifying documented business processes within process narratives or flowcharts, identifying risks and validating proficiency of mitigating controls Reviewing risk and control matrices and testing plans for key controls and determines effectiveness Identifying control gaps, reviewing and testing the design of existing controls. Formulating clear and concise conclusions on internal controls and business process efficiency Recommending policies and procedures to ensure information systems reliability and accessibility and to prevent and defend against unauthorized access to systems, networks, and data Conducting risk and vulnerability assessments of installed information systems to identify vulnerabilities, risks, and protection needs Reviewing Plans of Actions & Milestones (POA&Ms) Providing recommendations and reports to the Security Control Assessor (SCA), Authorizing Official (AO), Chief Information Security Officer (CISO) Reviewing network and systems design to ensure accuracy Ensuring the rigorous application of information security/cybersecurity policies, principles, and practices in the delivery of all IT services Required Qualifications: 15+ years of relevant Cyber experience 15+ years prior experience as a Security Control Assessor/Representative RMF Engineer, ISSO, ISSM and/or information assurance engineer Cloud Platform experience with at least one service offering from AWS, Azure, or Google GCP Hands-on eMASS and/or Xacta experience completing full system lifecycle activities Experience with Air Force risk management policies/procedures, to include, DODI 8510.01, AFI 17-101 Experience with Cloud Computing Security Requirements Guide (CC SRG) Knowledgeable with DoD DevSecOps Fundamentals Playbook Experience evaluating information security compliance against STIGs Ability to clearly articulate ideas Strong technical writing abilities to author reports for AO and CISO dissemination Exudes confidence in providing briefings, presentations, and in conducting/guiding meetings with senior leadership and stakeholders Ability to use prior experience and knowledge to address new situations Certification requirements (at least one of the following): SecurityX / CASP+, CCISO, CGRC/CAP, CISA, CISM, CISSO, CISSP, CISSP-ISSEP, Cloud+, CySA+, FITSP-A, GCSA, GSEC, GSLC, GSNA, PenTest+, Security+ B.A. or B.S. Information Security, Computer Science or related discipline US Citizenship and currently possess a Top Secret security clearance Desired Qualifications: Experience with Fast Track ATO Handbook & AF Continuous ATO Playbook Familiarity with CI/CD Pipelines DevSecOps experience Sharepoint, JIRA, Confluence familiarity The salary range for this position is $140,000.00 - $145,000.00 commensurate on experience and technical skillset. We are open to considering a variety of levels of experience for these projects and potential for 1099 hourly opportunity. We are proud to be an EEO/AA Employer Minorities/Women/Veterans/Disabled and other protected categories. In compliance with federal law, all persons hired will be required to verify identity, confirm US Citizenship, and complete the required employment eligibility verification upon hire.
09/26/2026
Full time
Job Description Job Description Dark Wolf Solutions is seeking a Senior Security Control Assessor Representative (SCAR) to conduct independent comprehensive assessments of the management, operation, and technical security controls and control enhancements employed within, or inherited by, an Information technology (IT) system to determine the overall effectiveness of the controls. The SCAR will perform reviews of security artifacts for system authorizations, assessing both the technical and functional adequacy as required for application and software cybersecurity readiness. The SCAR candidate must have prior experience in authorizing tools/applications, systems, and/or enclaves. Additionally, knowledge of network security, technologies, processes, and practices designed for the prevention of damage to, protection of, and restoration of computers, communications systems, services, and various types of communications technologies. The SCAR candidate must be knowledgeable and proficient in assessing DoD GovCloud environments to include testing controls and validating artifacts. A successful candidate will have a strong foundational understanding of NIST, DOD, and DAF cybersecurity focused guidance. This position can be based out of any Dark Wolf Office location and will be a hybrid schedule. Additional responsibilities include: Key Responsibilities: Evaluating IT infrastructure in terms of risk to the organization and defining artifacts required to meet Federal, DoD and DAF requirements Assessing IT systems and architecture to ensure compliance with the Risk Management Framework (RMF), NIST Cybersecurity Framework (CSF), NIST 800-53 revision 5 and applicable guidance Supporting the system/application assessment and authorization (A&A) effort, to include assessing and guiding the quality and completeness of A&A activities, tasks and resulting artifacts mandated by governing DoD and AF policies, and applicable mandates Collecting, reviewing and verifying documented business processes within process narratives or flowcharts, identifying risks and validating proficiency of mitigating controls Reviewing risk and control matrices and testing plans for key controls and determines effectiveness Identifying control gaps, reviewing and testing the design of existing controls. Formulating clear and concise conclusions on internal controls and business process efficiency Recommending policies and procedures to ensure information systems reliability and accessibility and to prevent and defend against unauthorized access to systems, networks, and data Conducting risk and vulnerability assessments of installed information systems to identify vulnerabilities, risks, and protection needs Reviewing Plans of Actions & Milestones (POA&Ms) Providing recommendations and reports to the Security Control Assessor (SCA), Authorizing Official (AO), Chief Information Security Officer (CISO) Reviewing network and systems design to ensure accuracy Ensuring the rigorous application of information security/cybersecurity policies, principles, and practices in the delivery of all IT services Required Qualifications: 15+ years of relevant Cyber experience 15+ years prior experience as a Security Control Assessor/Representative RMF Engineer, ISSO, ISSM and/or information assurance engineer Cloud Platform experience with at least one service offering from AWS, Azure, or Google GCP Hands-on eMASS and/or Xacta experience completing full system lifecycle activities Experience with Air Force risk management policies/procedures, to include, DODI 8510.01, AFI 17-101 Experience with Cloud Computing Security Requirements Guide (CC SRG) Knowledgeable with DoD DevSecOps Fundamentals Playbook Experience evaluating information security compliance against STIGs Ability to clearly articulate ideas Strong technical writing abilities to author reports for AO and CISO dissemination Exudes confidence in providing briefings, presentations, and in conducting/guiding meetings with senior leadership and stakeholders Ability to use prior experience and knowledge to address new situations Certification requirements (at least one of the following): SecurityX / CASP+, CCISO, CGRC/CAP, CISA, CISM, CISSO, CISSP, CISSP-ISSEP, Cloud+, CySA+, FITSP-A, GCSA, GSEC, GSLC, GSNA, PenTest+, Security+ B.A. or B.S. Information Security, Computer Science or related discipline US Citizenship and currently possess a Top Secret security clearance Desired Qualifications: Experience with Fast Track ATO Handbook & AF Continuous ATO Playbook Familiarity with CI/CD Pipelines DevSecOps experience Sharepoint, JIRA, Confluence familiarity The salary range for this position is $140,000.00 - $145,000.00 commensurate on experience and technical skillset. We are open to considering a variety of levels of experience for these projects and potential for 1099 hourly opportunity. We are proud to be an EEO/AA Employer Minorities/Women/Veterans/Disabled and other protected categories. In compliance with federal law, all persons hired will be required to verify identity, confirm US Citizenship, and complete the required employment eligibility verification upon hire.
Offensive Security Control Assessor Security Control Assessor Representative
Dark Wolf Solutions Herndon, Virginia
Job Description Job Description Dark Wolf Solutions is seeking Security Control Assessor/Representatives (SCA/Rs) to lead security control assessments across high-priority projects. Working at the intersection of cybersecurity engineering, cloud architecture, and DevSecOps prototyping, you will evaluate security controls for cutting-edge AI/LLM technologies across multiple classification levels. This position is ideal for a pragmatic cloud assessor or SCAR who excels in fast-paced DevSecOps environments, understands AWS cloud security, and is eager to shape the cybersecurity posture of next-generation DoD AI capabilities.This position will be based out of Arlington, VA with hybrid/remote opportunities. Additional responsibilities include: Key Responsibilities Execute formal SCA/R duties. Lead security assessment efforts, establishing reusable security playbooks and assessment frameworks for rapid AI deployment into enterprise workflows. Evaluate technical control effectiveness across AWS cloud infrastructure, DevSecOps pipelines, microservices, containerized workloads, and GenAI/LLM application stacks. Bridge the gap between OffSec and development by applying software design best practices. Lead technical exchange meetings (TEMs), participate in Discovery & Framing workshops, and maintain effective communication with cross-functional teams and stakeholders. Act as the primary subject matter expert and lead developer for custom offensive tooling, integrating disparate capabilities into a cohesive, mission-ready platform. Review, author, and maintain assessment packages-including System Security Plans (SSPs), Security Assessment Plans (SAPs), Security Assessment Reports (SARs), and POA&Ms-tailored to rapid prototyping and AI systems. Assess technical security risks specific to AI/LLM implementations, such as API exposure, vector database access controls, model integration surface area, and software supply chain dependencies. Support continuous monitoring (ConMon), technical risk evaluations, and cloud architecture reviews across multi-tenant, multi-classification environments. Coordinate with Authorizing Officials (AOs), program managers, and engineering leads to deliver decision-ready risk briefings and ATO recommendations. Provide technical input and oversight for cybersecurity engineering and penetration testing activities across prototype projects. Required Qualifications Active Top Secret security clearance Current DoD 8570/8140 IAM Level II or Level III certification (e.g., Security+, CySA+, CISM, CISSP, CCISO, CAP/CISC) 5-7+ years of experience conducting security control assessments, compliance testing, or A&A/RMF activities for DoD or federal information systems Solid operational understanding of core AWS cloud services (EC2, S3, IAM, VPCs, Security Groups, Security Hub) and how security controls function within cloud-native and CI/CD pipeline environments. Experience with GitLab CI/CD (pipeline design, runners, artifact management) and AWS Cloud services (EC2, VPC, IAM, S3). Strong working knowledge of NIST SP 800-53 (Rev. 4/5), NIST SP 800-37 (RMF), DoD Cloud Computing SRG, and FedRAMP baselines. Demonstrated experience writing and evaluating core RMF artifacts (SSPs, SAPs, SARs, POA&Ms) Exceptional written and verbal communication skills, with the ability to articulate technical risk clearly to executive stakeholders, Authorizing Officials, and engineering teams. Hands-on experience navigating government GRC repositories, such as eMASS or XACTA. Desired Qualifications Hands-on experience mapping security controls to the NIST AI Risk Management Framework (AI RMF), the OWASP Top 10 for LLM Applications, or the DoD Responsible AI (RAI) Guidelines. Familiarity evaluating secure design patterns for autonomous AI Agents (e.g., tool-calling permissions, sandboxing agent execution environments, prompt boundaries, and ReAct/LangGraph architectures). Experience assessing cloud-managed AI ecosystems and foundation model platforms (e.g., AWS Bedrock, AWS SageMaker, Hugging Face Enterprise, or self-hosted open-source models). Understanding of data protection, access controls, and boundary security for RAG pipelines and vector databases (e.g., OpenSearch Vector Engine, Pinecone, Milvus, or PostgreSQL pgvector). Familiarity evaluating risks unique to LLMs-including prompt injection, data poisoning, model inversion, insecure output handling, and open-source supply chain vulnerabilities in AI libraries (PyTorch, LangChain, LlamaIndex). Exposure to LLM guardrail platforms, evaluation frameworks, or AI security tools (e.g., Promptfoo, Garak, Giskard, NeMo Guardrails) used to test model robustness and output safety. Experience with cATO methodologies, Infrastructure as Code (IaC) templates (Terraform, CloudFormation), and container security (AWS EKS/ECS, Docker). Active AWS Certifications (e.g., AWS Certified Security - Specialty or AWS Certified Solutions Architect). Background or familiarity with offensive security, penetration testing The salary range for this position is estimated to be between $135,000.00 - $160,000.00, commensurate on experience and technical skillset. We are proud to be an EEO/AA employer Minorities/Women/Veterans/Disabled and other protected categories. In compliance with federal law, all persons hired will be required to verify identity, confirm US Citizenship, and complete the required employment eligibility verification upon hire. We are strictly looking for direct, full-time W2 employees. We do not engage with third-party staffing agencies, C2C, or 1099 independent contractors for this role.
09/26/2026
Full time
Job Description Job Description Dark Wolf Solutions is seeking Security Control Assessor/Representatives (SCA/Rs) to lead security control assessments across high-priority projects. Working at the intersection of cybersecurity engineering, cloud architecture, and DevSecOps prototyping, you will evaluate security controls for cutting-edge AI/LLM technologies across multiple classification levels. This position is ideal for a pragmatic cloud assessor or SCAR who excels in fast-paced DevSecOps environments, understands AWS cloud security, and is eager to shape the cybersecurity posture of next-generation DoD AI capabilities.This position will be based out of Arlington, VA with hybrid/remote opportunities. Additional responsibilities include: Key Responsibilities Execute formal SCA/R duties. Lead security assessment efforts, establishing reusable security playbooks and assessment frameworks for rapid AI deployment into enterprise workflows. Evaluate technical control effectiveness across AWS cloud infrastructure, DevSecOps pipelines, microservices, containerized workloads, and GenAI/LLM application stacks. Bridge the gap between OffSec and development by applying software design best practices. Lead technical exchange meetings (TEMs), participate in Discovery & Framing workshops, and maintain effective communication with cross-functional teams and stakeholders. Act as the primary subject matter expert and lead developer for custom offensive tooling, integrating disparate capabilities into a cohesive, mission-ready platform. Review, author, and maintain assessment packages-including System Security Plans (SSPs), Security Assessment Plans (SAPs), Security Assessment Reports (SARs), and POA&Ms-tailored to rapid prototyping and AI systems. Assess technical security risks specific to AI/LLM implementations, such as API exposure, vector database access controls, model integration surface area, and software supply chain dependencies. Support continuous monitoring (ConMon), technical risk evaluations, and cloud architecture reviews across multi-tenant, multi-classification environments. Coordinate with Authorizing Officials (AOs), program managers, and engineering leads to deliver decision-ready risk briefings and ATO recommendations. Provide technical input and oversight for cybersecurity engineering and penetration testing activities across prototype projects. Required Qualifications Active Top Secret security clearance Current DoD 8570/8140 IAM Level II or Level III certification (e.g., Security+, CySA+, CISM, CISSP, CCISO, CAP/CISC) 5-7+ years of experience conducting security control assessments, compliance testing, or A&A/RMF activities for DoD or federal information systems Solid operational understanding of core AWS cloud services (EC2, S3, IAM, VPCs, Security Groups, Security Hub) and how security controls function within cloud-native and CI/CD pipeline environments. Experience with GitLab CI/CD (pipeline design, runners, artifact management) and AWS Cloud services (EC2, VPC, IAM, S3). Strong working knowledge of NIST SP 800-53 (Rev. 4/5), NIST SP 800-37 (RMF), DoD Cloud Computing SRG, and FedRAMP baselines. Demonstrated experience writing and evaluating core RMF artifacts (SSPs, SAPs, SARs, POA&Ms) Exceptional written and verbal communication skills, with the ability to articulate technical risk clearly to executive stakeholders, Authorizing Officials, and engineering teams. Hands-on experience navigating government GRC repositories, such as eMASS or XACTA. Desired Qualifications Hands-on experience mapping security controls to the NIST AI Risk Management Framework (AI RMF), the OWASP Top 10 for LLM Applications, or the DoD Responsible AI (RAI) Guidelines. Familiarity evaluating secure design patterns for autonomous AI Agents (e.g., tool-calling permissions, sandboxing agent execution environments, prompt boundaries, and ReAct/LangGraph architectures). Experience assessing cloud-managed AI ecosystems and foundation model platforms (e.g., AWS Bedrock, AWS SageMaker, Hugging Face Enterprise, or self-hosted open-source models). Understanding of data protection, access controls, and boundary security for RAG pipelines and vector databases (e.g., OpenSearch Vector Engine, Pinecone, Milvus, or PostgreSQL pgvector). Familiarity evaluating risks unique to LLMs-including prompt injection, data poisoning, model inversion, insecure output handling, and open-source supply chain vulnerabilities in AI libraries (PyTorch, LangChain, LlamaIndex). Exposure to LLM guardrail platforms, evaluation frameworks, or AI security tools (e.g., Promptfoo, Garak, Giskard, NeMo Guardrails) used to test model robustness and output safety. Experience with cATO methodologies, Infrastructure as Code (IaC) templates (Terraform, CloudFormation), and container security (AWS EKS/ECS, Docker). Active AWS Certifications (e.g., AWS Certified Security - Specialty or AWS Certified Solutions Architect). Background or familiarity with offensive security, penetration testing The salary range for this position is estimated to be between $135,000.00 - $160,000.00, commensurate on experience and technical skillset. We are proud to be an EEO/AA employer Minorities/Women/Veterans/Disabled and other protected categories. In compliance with federal law, all persons hired will be required to verify identity, confirm US Citizenship, and complete the required employment eligibility verification upon hire. We are strictly looking for direct, full-time W2 employees. We do not engage with third-party staffing agencies, C2C, or 1099 independent contractors for this role.
Senior Security Control Assessor Representative (SCAR)
Dark Wolf Solutions San Antonio, Texas
Job Description Job Description Dark Wolf Solutions is seeking a Senior Security Control Assessor Representative (SCAR) to conduct independent comprehensive assessments of the management, operation, and technical security controls and control enhancements employed within, or inherited by, an Information technology (IT) system to determine the overall effectiveness of the controls. The SCAR will perform reviews of security artifacts for system authorizations, assessing both the technical and functional adequacy as required for application and software cybersecurity readiness. The SCAR candidate must have prior experience in authorizing tools/applications, systems, and/or enclaves. Additionally, knowledge of network security, technologies, processes, and practices designed for the prevention of damage to, protection of, and restoration of computers, communications systems, services, and various types of communications technologies. The SCAR candidate must be knowledgeable and proficient in assessing DoD GovCloud environments to include testing controls and validating artifacts. A successful candidate will have a strong foundational understanding of NIST, DOD, and DAF cybersecurity focused guidance. This position can be based out of any Dark Wolf Office location and will be a hybrid schedule. Additional responsibilities include: Key Responsibilities: Evaluating IT infrastructure in terms of risk to the organization and defining artifacts required to meet Federal, DoD and DAF requirements Assessing IT systems and architecture to ensure compliance with the Risk Management Framework (RMF), NIST Cybersecurity Framework (CSF), NIST 800-53 revision 5 and applicable guidance Supporting the system/application assessment and authorization (A&A) effort, to include assessing and guiding the quality and completeness of A&A activities, tasks and resulting artifacts mandated by governing DoD and AF policies, and applicable mandates Collecting, reviewing and verifying documented business processes within process narratives or flowcharts, identifying risks and validating proficiency of mitigating controls Reviewing risk and control matrices and testing plans for key controls and determines effectiveness Identifying control gaps, reviewing and testing the design of existing controls. Formulating clear and concise conclusions on internal controls and business process efficiency Recommending policies and procedures to ensure information systems reliability and accessibility and to prevent and defend against unauthorized access to systems, networks, and data Conducting risk and vulnerability assessments of installed information systems to identify vulnerabilities, risks, and protection needs Reviewing Plans of Actions & Milestones (POA&Ms) Providing recommendations and reports to the Security Control Assessor (SCA), Authorizing Official (AO), Chief Information Security Officer (CISO) Reviewing network and systems design to ensure accuracy Ensuring the rigorous application of information security/cybersecurity policies, principles, and practices in the delivery of all IT services Required Qualifications: 15+ years of relevant Cyber experience 15+ years prior experience as a Security Control Assessor/Representative RMF Engineer, ISSO, ISSM and/or information assurance engineer Cloud Platform experience with at least one service offering from AWS, Azure, or Google GCP Hands-on eMASS and/or Xacta experience completing full system lifecycle activities Experience with Air Force risk management policies/procedures, to include, DODI 8510.01, AFI 17-101 Experience with Cloud Computing Security Requirements Guide (CC SRG) Knowledgeable with DoD DevSecOps Fundamentals Playbook Experience evaluating information security compliance against STIGs Ability to clearly articulate ideas Strong technical writing abilities to author reports for AO and CISO dissemination Exudes confidence in providing briefings, presentations, and in conducting/guiding meetings with senior leadership and stakeholders Ability to use prior experience and knowledge to address new situations Certification requirements (at least one of the following): SecurityX / CASP+, CCISO, CGRC/CAP, CISA, CISM, CISSO, CISSP, CISSP-ISSEP, Cloud+, CySA+, FITSP-A, GCSA, GSEC, GSLC, GSNA, PenTest+, Security+ B.A. or B.S. Information Security, Computer Science or related discipline US Citizenship and currently possess a Top Secret security clearance Desired Qualifications: Experience with Fast Track ATO Handbook & AF Continuous ATO Playbook Familiarity with CI/CD Pipelines DevSecOps experience Sharepoint, JIRA, Confluence familiarity The salary range for this position is $140,000.00 - $145,000.00 commensurate on experience and technical skillset. We are open to considering a variety of levels of experience for these projects and potential for 1099 hourly opportunity. We are proud to be an EEO/AA Employer Minorities/Women/Veterans/Disabled and other protected categories. In compliance with federal law, all persons hired will be required to verify identity, confirm US Citizenship, and complete the required employment eligibility verification upon hire.
09/26/2026
Full time
Job Description Job Description Dark Wolf Solutions is seeking a Senior Security Control Assessor Representative (SCAR) to conduct independent comprehensive assessments of the management, operation, and technical security controls and control enhancements employed within, or inherited by, an Information technology (IT) system to determine the overall effectiveness of the controls. The SCAR will perform reviews of security artifacts for system authorizations, assessing both the technical and functional adequacy as required for application and software cybersecurity readiness. The SCAR candidate must have prior experience in authorizing tools/applications, systems, and/or enclaves. Additionally, knowledge of network security, technologies, processes, and practices designed for the prevention of damage to, protection of, and restoration of computers, communications systems, services, and various types of communications technologies. The SCAR candidate must be knowledgeable and proficient in assessing DoD GovCloud environments to include testing controls and validating artifacts. A successful candidate will have a strong foundational understanding of NIST, DOD, and DAF cybersecurity focused guidance. This position can be based out of any Dark Wolf Office location and will be a hybrid schedule. Additional responsibilities include: Key Responsibilities: Evaluating IT infrastructure in terms of risk to the organization and defining artifacts required to meet Federal, DoD and DAF requirements Assessing IT systems and architecture to ensure compliance with the Risk Management Framework (RMF), NIST Cybersecurity Framework (CSF), NIST 800-53 revision 5 and applicable guidance Supporting the system/application assessment and authorization (A&A) effort, to include assessing and guiding the quality and completeness of A&A activities, tasks and resulting artifacts mandated by governing DoD and AF policies, and applicable mandates Collecting, reviewing and verifying documented business processes within process narratives or flowcharts, identifying risks and validating proficiency of mitigating controls Reviewing risk and control matrices and testing plans for key controls and determines effectiveness Identifying control gaps, reviewing and testing the design of existing controls. Formulating clear and concise conclusions on internal controls and business process efficiency Recommending policies and procedures to ensure information systems reliability and accessibility and to prevent and defend against unauthorized access to systems, networks, and data Conducting risk and vulnerability assessments of installed information systems to identify vulnerabilities, risks, and protection needs Reviewing Plans of Actions & Milestones (POA&Ms) Providing recommendations and reports to the Security Control Assessor (SCA), Authorizing Official (AO), Chief Information Security Officer (CISO) Reviewing network and systems design to ensure accuracy Ensuring the rigorous application of information security/cybersecurity policies, principles, and practices in the delivery of all IT services Required Qualifications: 15+ years of relevant Cyber experience 15+ years prior experience as a Security Control Assessor/Representative RMF Engineer, ISSO, ISSM and/or information assurance engineer Cloud Platform experience with at least one service offering from AWS, Azure, or Google GCP Hands-on eMASS and/or Xacta experience completing full system lifecycle activities Experience with Air Force risk management policies/procedures, to include, DODI 8510.01, AFI 17-101 Experience with Cloud Computing Security Requirements Guide (CC SRG) Knowledgeable with DoD DevSecOps Fundamentals Playbook Experience evaluating information security compliance against STIGs Ability to clearly articulate ideas Strong technical writing abilities to author reports for AO and CISO dissemination Exudes confidence in providing briefings, presentations, and in conducting/guiding meetings with senior leadership and stakeholders Ability to use prior experience and knowledge to address new situations Certification requirements (at least one of the following): SecurityX / CASP+, CCISO, CGRC/CAP, CISA, CISM, CISSO, CISSP, CISSP-ISSEP, Cloud+, CySA+, FITSP-A, GCSA, GSEC, GSLC, GSNA, PenTest+, Security+ B.A. or B.S. Information Security, Computer Science or related discipline US Citizenship and currently possess a Top Secret security clearance Desired Qualifications: Experience with Fast Track ATO Handbook & AF Continuous ATO Playbook Familiarity with CI/CD Pipelines DevSecOps experience Sharepoint, JIRA, Confluence familiarity The salary range for this position is $140,000.00 - $145,000.00 commensurate on experience and technical skillset. We are open to considering a variety of levels of experience for these projects and potential for 1099 hourly opportunity. We are proud to be an EEO/AA Employer Minorities/Women/Veterans/Disabled and other protected categories. In compliance with federal law, all persons hired will be required to verify identity, confirm US Citizenship, and complete the required employment eligibility verification upon hire.
Senior Security Control Assessor Representative (SCAR)
Dark Wolf Solutions Colorado Springs, Colorado
Job Description Job Description Dark Wolf Solutions is seeking a Senior Security Control Assessor Representative (SCAR) to conduct independent comprehensive assessments of the management, operation, and technical security controls and control enhancements employed within, or inherited by, an Information technology (IT) system to determine the overall effectiveness of the controls. The SCAR will perform reviews of security artifacts for system authorizations, assessing both the technical and functional adequacy as required for application and software cybersecurity readiness. The SCAR candidate must have prior experience in authorizing tools/applications, systems, and/or enclaves. Additionally, knowledge of network security, technologies, processes, and practices designed for the prevention of damage to, protection of, and restoration of computers, communications systems, services, and various types of communications technologies. The SCAR candidate must be knowledgeable and proficient in assessing DoD GovCloud environments to include testing controls and validating artifacts. A successful candidate will have a strong foundational understanding of NIST, DOD, and DAF cybersecurity focused guidance. This position can be based out of any Dark Wolf Office location and will be a hybrid schedule. Additional responsibilities include: Key Responsibilities: Evaluating IT infrastructure in terms of risk to the organization and defining artifacts required to meet Federal, DoD and DAF requirements Assessing IT systems and architecture to ensure compliance with the Risk Management Framework (RMF), NIST Cybersecurity Framework (CSF), NIST 800-53 revision 5 and applicable guidance Supporting the system/application assessment and authorization (A&A) effort, to include assessing and guiding the quality and completeness of A&A activities, tasks and resulting artifacts mandated by governing DoD and AF policies, and applicable mandates Collecting, reviewing and verifying documented business processes within process narratives or flowcharts, identifying risks and validating proficiency of mitigating controls Reviewing risk and control matrices and testing plans for key controls and determines effectiveness Identifying control gaps, reviewing and testing the design of existing controls. Formulating clear and concise conclusions on internal controls and business process efficiency Recommending policies and procedures to ensure information systems reliability and accessibility and to prevent and defend against unauthorized access to systems, networks, and data Conducting risk and vulnerability assessments of installed information systems to identify vulnerabilities, risks, and protection needs Reviewing Plans of Actions & Milestones (POA&Ms) Providing recommendations and reports to the Security Control Assessor (SCA), Authorizing Official (AO), Chief Information Security Officer (CISO) Reviewing network and systems design to ensure accuracy Ensuring the rigorous application of information security/cybersecurity policies, principles, and practices in the delivery of all IT services Required Qualifications: 15+ years of relevant Cyber experience 15+ years prior experience as a Security Control Assessor/Representative RMF Engineer, ISSO, ISSM and/or information assurance engineer Cloud Platform experience with at least one service offering from AWS, Azure, or Google GCP Hands-on eMASS and/or Xacta experience completing full system lifecycle activities Experience with Air Force risk management policies/procedures, to include, DODI 8510.01, AFI 17-101 Experience with Cloud Computing Security Requirements Guide (CC SRG) Knowledgeable with DoD DevSecOps Fundamentals Playbook Experience evaluating information security compliance against STIGs Ability to clearly articulate ideas Strong technical writing abilities to author reports for AO and CISO dissemination Exudes confidence in providing briefings, presentations, and in conducting/guiding meetings with senior leadership and stakeholders Ability to use prior experience and knowledge to address new situations Certification requirements (at least one of the following): SecurityX / CASP+, CCISO, CGRC/CAP, CISA, CISM, CISSO, CISSP, CISSP-ISSEP, Cloud+, CySA+, FITSP-A, GCSA, GSEC, GSLC, GSNA, PenTest+, Security+ B.A. or B.S. Information Security, Computer Science or related discipline US Citizenship and currently possess a Top Secret security clearance Desired Qualifications: Experience with Fast Track ATO Handbook & AF Continuous ATO Playbook Familiarity with CI/CD Pipelines DevSecOps experience Sharepoint, JIRA, Confluence familiarity The salary range for this position is $140,000.00 - $145,000.00 commensurate on experience and technical skillset. We are open to considering a variety of levels of experience for these projects and potential for 1099 hourly opportunity. We are proud to be an EEO/AA Employer Minorities/Women/Veterans/Disabled and other protected categories. In compliance with federal law, all persons hired will be required to verify identity, confirm US Citizenship, and complete the required employment eligibility verification upon hire.
09/26/2026
Full time
Job Description Job Description Dark Wolf Solutions is seeking a Senior Security Control Assessor Representative (SCAR) to conduct independent comprehensive assessments of the management, operation, and technical security controls and control enhancements employed within, or inherited by, an Information technology (IT) system to determine the overall effectiveness of the controls. The SCAR will perform reviews of security artifacts for system authorizations, assessing both the technical and functional adequacy as required for application and software cybersecurity readiness. The SCAR candidate must have prior experience in authorizing tools/applications, systems, and/or enclaves. Additionally, knowledge of network security, technologies, processes, and practices designed for the prevention of damage to, protection of, and restoration of computers, communications systems, services, and various types of communications technologies. The SCAR candidate must be knowledgeable and proficient in assessing DoD GovCloud environments to include testing controls and validating artifacts. A successful candidate will have a strong foundational understanding of NIST, DOD, and DAF cybersecurity focused guidance. This position can be based out of any Dark Wolf Office location and will be a hybrid schedule. Additional responsibilities include: Key Responsibilities: Evaluating IT infrastructure in terms of risk to the organization and defining artifacts required to meet Federal, DoD and DAF requirements Assessing IT systems and architecture to ensure compliance with the Risk Management Framework (RMF), NIST Cybersecurity Framework (CSF), NIST 800-53 revision 5 and applicable guidance Supporting the system/application assessment and authorization (A&A) effort, to include assessing and guiding the quality and completeness of A&A activities, tasks and resulting artifacts mandated by governing DoD and AF policies, and applicable mandates Collecting, reviewing and verifying documented business processes within process narratives or flowcharts, identifying risks and validating proficiency of mitigating controls Reviewing risk and control matrices and testing plans for key controls and determines effectiveness Identifying control gaps, reviewing and testing the design of existing controls. Formulating clear and concise conclusions on internal controls and business process efficiency Recommending policies and procedures to ensure information systems reliability and accessibility and to prevent and defend against unauthorized access to systems, networks, and data Conducting risk and vulnerability assessments of installed information systems to identify vulnerabilities, risks, and protection needs Reviewing Plans of Actions & Milestones (POA&Ms) Providing recommendations and reports to the Security Control Assessor (SCA), Authorizing Official (AO), Chief Information Security Officer (CISO) Reviewing network and systems design to ensure accuracy Ensuring the rigorous application of information security/cybersecurity policies, principles, and practices in the delivery of all IT services Required Qualifications: 15+ years of relevant Cyber experience 15+ years prior experience as a Security Control Assessor/Representative RMF Engineer, ISSO, ISSM and/or information assurance engineer Cloud Platform experience with at least one service offering from AWS, Azure, or Google GCP Hands-on eMASS and/or Xacta experience completing full system lifecycle activities Experience with Air Force risk management policies/procedures, to include, DODI 8510.01, AFI 17-101 Experience with Cloud Computing Security Requirements Guide (CC SRG) Knowledgeable with DoD DevSecOps Fundamentals Playbook Experience evaluating information security compliance against STIGs Ability to clearly articulate ideas Strong technical writing abilities to author reports for AO and CISO dissemination Exudes confidence in providing briefings, presentations, and in conducting/guiding meetings with senior leadership and stakeholders Ability to use prior experience and knowledge to address new situations Certification requirements (at least one of the following): SecurityX / CASP+, CCISO, CGRC/CAP, CISA, CISM, CISSO, CISSP, CISSP-ISSEP, Cloud+, CySA+, FITSP-A, GCSA, GSEC, GSLC, GSNA, PenTest+, Security+ B.A. or B.S. Information Security, Computer Science or related discipline US Citizenship and currently possess a Top Secret security clearance Desired Qualifications: Experience with Fast Track ATO Handbook & AF Continuous ATO Playbook Familiarity with CI/CD Pipelines DevSecOps experience Sharepoint, JIRA, Confluence familiarity The salary range for this position is $140,000.00 - $145,000.00 commensurate on experience and technical skillset. We are open to considering a variety of levels of experience for these projects and potential for 1099 hourly opportunity. We are proud to be an EEO/AA Employer Minorities/Women/Veterans/Disabled and other protected categories. In compliance with federal law, all persons hired will be required to verify identity, confirm US Citizenship, and complete the required employment eligibility verification upon hire.
Technical Lead
Eliassen Group Reston, Virginia
Job Description Job Description Description: Hybrid 2-3 days in Reston, VA As a Technical Lead, you will partner closely with executive leadership to evaluate technology investments, modernize enterprise applications, and recommend solutions that align business objectives with technical capabilities. You will serve as a trusted advisor across application development, integrations, vendor management, and architecture discussions, helping teams make informed decisions that balance cost, risk, scalability, and long-term business value. This role is ideal for a technically experienced professional who enjoys solving complex business problems, guiding technical teams, influencing strategy, and translating technical concepts into actionable recommendations for both executive and operational stakeholders. Due to federal security clearance requirements, applicant must be a United States Citizen with an active Secret clearance. This is a full-time, permanent opportunity, offering a competitive salary and comprehensive benefits package. Qualified applicants must be willing and able to work on a w2 basis. Salary: $145,000 - $160,000/ yr. w2 JN -20 Responsibilities: Partner with executive leadership to evaluate technology investments, modernization opportunities, and business priorities. Assess technical and business impacts of proposed solutions and recommend the most effective path forward. Develop architecture recommendations, technical strategies, white papers, and executive briefings. Guide cross-functional teams through solution design, integration planning, and technology decision-making. Collaborate with developers, business analysts, infrastructure teams, and vendors to ensure solutions meet business objectives. Evaluate vendor offerings, implementation approaches, and platform capabilities to reduce risk and maximize value. Identify opportunities to modernize applications, improve processes, and streamline operations through technology. Provide technical leadership across application, integration, infrastructure, security, and data initiatives. Translate complex technical concepts into actionable recommendations for business stakeholders and executive leadership. Serve as a trusted advisor to leadership on technology strategy, solution selection, and enterprise modernization efforts. Experience Requirements: Active Public Trust clearance. 8+ years of experience designing, implementing, supporting, or modernizing enterprise technology solutions. 3+ years in a Technical Lead, SME, Solutions Lead, or similar role with hands-on development and influence on business outcomes. Experience evaluating business requirements, identifying risks, and recommending technology solutions aligned to goals and operational needs. Strong understanding of enterprise application architecture, systems integration, networking fundamentals, security concepts, and data flow across interconnected platforms. Experience partnering with executives, business stakeholders, vendors, and technical teams to assess solution options and drive informed technology decisions. Ability to evaluate technology investments and make recommendations based on cost, scalability, maintainability, risk, vendor lock-in, and long-term business impact. Experience facilitating technical discussions across software development, infrastructure, cybersecurity, networking, and third-party solution providers. Strong understanding of Microsoft ecosystems including .NET, SQL Server, APIs, cloud services, and enterprise integration patterns. Ability to translate complex business challenges into practical technical solutions and communicate recommendations to technical and non-technical audiences. Proven ability to ask discovery questions, challenge assumptions, identify root causes, and develop strategic recommendations. Experience working within Agile environments and collaborating with business analysts, Scrum Masters, developers, QA teams, and infrastructure teams. Strong written and verbal communication skills with experience developing executive briefings, technical recommendations, white papers, architecture guidance, or strategy documents. Education Requirements: Bachelor's degree in Computer Science, Information Systems, Engineering, or a related discipline. Additional years of relevant experience may be considered in lieu of a degree. Recruitment Transparency Notice Eliassen Group values transparency in our recruitment practices. Please be advised that Eliassen Group utilizes artificial intelligence (AI) tools as part of its initial application screening and hiring process. You may receive email and SMS notifications from the Eliassen Virtual Recruiting Team ( , ) inviting you to complete a brief voice screening as part of your application process. These tools assist our hiring teams in different ways, including but not limited to, assistance in reviewing application materials to help identify candidates whose qualifications most closely match the requirements of the position. All AI-assisted evaluations and responses are reviewed by human recruiters before any hiring decisions are made. The use of AI in our process is intended to support fairness, efficiency, and consistency, and Eliassen Group takes measures to prevent bias or discrimination in connection with its hiring practices. By proceeding, you acknowledge, agree, and consent to Eliassen Group's use of these tools, including AI tools, as part of the application and hiring process. Skills, experience, and other compensable factors will be considered when determining pay rate. The pay range provided in this posting reflects a W2 hourly rate; other employment options may be available that may result in pay outside of the provided range.W2 employees of Eliassen Group who are regularly scheduled to work 30 or more hours per week are eligible for the following benefits: medical (choice of 3 plans), dental, vision, pre-tax accounts, other voluntary benefits including life and disability insurance, 401(k) with match, and sick time if required by law in the worked-in state/locality.If anyone reaches out to you about an open position connected with Eliassen Group, please ensure that you are working directly with us by confirming the following: When you work with Eliassen Group, all email communication will come from an address, never Gmail, Yahoo, etc. Eliassen Group will never ask you for personal information (home address, bank account, or check routing number) until you have worked with someone clearly associated with Eliassen Group. If you have any indication of fraudulent activity, please contact . About Eliassen Group: Eliassen Group is a strategic consulting firm that helps organizations reach further and achieve more through our technology, business advisory, and life sciences solutions. For nearly 40 years, we have combined exceptional people, deep domain expertise, and intelligent capabilities to expand our clients' capacity and accelerate meaningful outcomes. We are driven by a purpose to positively impact the lives of our employees, clients, consultants, and the communities we serve. Eliassen is committed to building a diverse and inclusive team from a variety of backgrounds, perspectives, and skills. We are an Equal Opportunity and Affirmative Action Employer and all employment decisions are based on merit, performance, and business needs. Eliassen does not discriminate on the basis of race, color, gender identity or expression, sexual preference or orientation, sex (including pregnancy, childbirth, and related medical conditions), marital status, creed, religion, physical or mental disability, genetic information, military or veteran status, age, ancestry, national origin, citizenship status, prohibited criminal record inquiries of applicants and employees, or any other category protected by federal, state, or local laws. Don't miss out on our referral program! If we hire a candidate that you refer us to then you can be eligible for a $1,000 referral check!
09/26/2026
Full time
Job Description Job Description Description: Hybrid 2-3 days in Reston, VA As a Technical Lead, you will partner closely with executive leadership to evaluate technology investments, modernize enterprise applications, and recommend solutions that align business objectives with technical capabilities. You will serve as a trusted advisor across application development, integrations, vendor management, and architecture discussions, helping teams make informed decisions that balance cost, risk, scalability, and long-term business value. This role is ideal for a technically experienced professional who enjoys solving complex business problems, guiding technical teams, influencing strategy, and translating technical concepts into actionable recommendations for both executive and operational stakeholders. Due to federal security clearance requirements, applicant must be a United States Citizen with an active Secret clearance. This is a full-time, permanent opportunity, offering a competitive salary and comprehensive benefits package. Qualified applicants must be willing and able to work on a w2 basis. Salary: $145,000 - $160,000/ yr. w2 JN -20 Responsibilities: Partner with executive leadership to evaluate technology investments, modernization opportunities, and business priorities. Assess technical and business impacts of proposed solutions and recommend the most effective path forward. Develop architecture recommendations, technical strategies, white papers, and executive briefings. Guide cross-functional teams through solution design, integration planning, and technology decision-making. Collaborate with developers, business analysts, infrastructure teams, and vendors to ensure solutions meet business objectives. Evaluate vendor offerings, implementation approaches, and platform capabilities to reduce risk and maximize value. Identify opportunities to modernize applications, improve processes, and streamline operations through technology. Provide technical leadership across application, integration, infrastructure, security, and data initiatives. Translate complex technical concepts into actionable recommendations for business stakeholders and executive leadership. Serve as a trusted advisor to leadership on technology strategy, solution selection, and enterprise modernization efforts. Experience Requirements: Active Public Trust clearance. 8+ years of experience designing, implementing, supporting, or modernizing enterprise technology solutions. 3+ years in a Technical Lead, SME, Solutions Lead, or similar role with hands-on development and influence on business outcomes. Experience evaluating business requirements, identifying risks, and recommending technology solutions aligned to goals and operational needs. Strong understanding of enterprise application architecture, systems integration, networking fundamentals, security concepts, and data flow across interconnected platforms. Experience partnering with executives, business stakeholders, vendors, and technical teams to assess solution options and drive informed technology decisions. Ability to evaluate technology investments and make recommendations based on cost, scalability, maintainability, risk, vendor lock-in, and long-term business impact. Experience facilitating technical discussions across software development, infrastructure, cybersecurity, networking, and third-party solution providers. Strong understanding of Microsoft ecosystems including .NET, SQL Server, APIs, cloud services, and enterprise integration patterns. Ability to translate complex business challenges into practical technical solutions and communicate recommendations to technical and non-technical audiences. Proven ability to ask discovery questions, challenge assumptions, identify root causes, and develop strategic recommendations. Experience working within Agile environments and collaborating with business analysts, Scrum Masters, developers, QA teams, and infrastructure teams. Strong written and verbal communication skills with experience developing executive briefings, technical recommendations, white papers, architecture guidance, or strategy documents. Education Requirements: Bachelor's degree in Computer Science, Information Systems, Engineering, or a related discipline. Additional years of relevant experience may be considered in lieu of a degree. Recruitment Transparency Notice Eliassen Group values transparency in our recruitment practices. Please be advised that Eliassen Group utilizes artificial intelligence (AI) tools as part of its initial application screening and hiring process. You may receive email and SMS notifications from the Eliassen Virtual Recruiting Team ( , ) inviting you to complete a brief voice screening as part of your application process. These tools assist our hiring teams in different ways, including but not limited to, assistance in reviewing application materials to help identify candidates whose qualifications most closely match the requirements of the position. All AI-assisted evaluations and responses are reviewed by human recruiters before any hiring decisions are made. The use of AI in our process is intended to support fairness, efficiency, and consistency, and Eliassen Group takes measures to prevent bias or discrimination in connection with its hiring practices. By proceeding, you acknowledge, agree, and consent to Eliassen Group's use of these tools, including AI tools, as part of the application and hiring process. Skills, experience, and other compensable factors will be considered when determining pay rate. The pay range provided in this posting reflects a W2 hourly rate; other employment options may be available that may result in pay outside of the provided range.W2 employees of Eliassen Group who are regularly scheduled to work 30 or more hours per week are eligible for the following benefits: medical (choice of 3 plans), dental, vision, pre-tax accounts, other voluntary benefits including life and disability insurance, 401(k) with match, and sick time if required by law in the worked-in state/locality.If anyone reaches out to you about an open position connected with Eliassen Group, please ensure that you are working directly with us by confirming the following: When you work with Eliassen Group, all email communication will come from an address, never Gmail, Yahoo, etc. Eliassen Group will never ask you for personal information (home address, bank account, or check routing number) until you have worked with someone clearly associated with Eliassen Group. If you have any indication of fraudulent activity, please contact . About Eliassen Group: Eliassen Group is a strategic consulting firm that helps organizations reach further and achieve more through our technology, business advisory, and life sciences solutions. For nearly 40 years, we have combined exceptional people, deep domain expertise, and intelligent capabilities to expand our clients' capacity and accelerate meaningful outcomes. We are driven by a purpose to positively impact the lives of our employees, clients, consultants, and the communities we serve. Eliassen is committed to building a diverse and inclusive team from a variety of backgrounds, perspectives, and skills. We are an Equal Opportunity and Affirmative Action Employer and all employment decisions are based on merit, performance, and business needs. Eliassen does not discriminate on the basis of race, color, gender identity or expression, sexual preference or orientation, sex (including pregnancy, childbirth, and related medical conditions), marital status, creed, religion, physical or mental disability, genetic information, military or veteran status, age, ancestry, national origin, citizenship status, prohibited criminal record inquiries of applicants and employees, or any other category protected by federal, state, or local laws. Don't miss out on our referral program! If we hire a candidate that you refer us to then you can be eligible for a $1,000 referral check!
Security Control Assessor (SCA)
LV8D Solutions Chantilly, Virginia
Job Description Job Description Mission Context LV8D Solutions supports national security space and intelligence customers delivering next-generation sensing and exploitation capabilities. The role of a Security Control Assessor (SCA) is focused on providing information security Assessment and Authorization (A&A) support throughout the mission program's lifecycle. Position Overview LV8D Solutions is seeking a SCA to conduct independent assessments of the management, operational, and technical security controls employed within or inherited by an information technology (IT) system to determine the overall effectiveness of the security controls. A Security Control Assessor (SCA) performs comprehensive INFOSEC assessment of management, operational, and technical security controls to determine overall effectiveness of the controls for A&A determination throughout a program's system lifecycle. SCAs provide an assessment of the severity of weakness or deficiencies discovered in the Information System (IS) and its environment of operation and recommend corrective actions to address identified vulnerabilities. Prior to initiating the security control assessment, the SCA reviews the System Security Plan (SSP) to ensure the plan provides a set of security controls for the ISs that meet the stated security requirements. Additionally, the SCA must verify that all allocated controls have an acceptable status (i.e., implemented, excepted, or inherited) with appropriate documented details and provides responses in the Government's Risk Management Framework (RMF) tools. Interested candidates need to thrive in an innovative, fast-paced environment; are highly motivated and not afraid to take on uncharted territory; possess strong communication, leadership, and organizational skills; and be able to prioritize their time to be effective in a dynamic environment. Requirements Key Responsibilities Reviews IS for compliance with applicable Intelligence Community (IC), Department of War (DoW), and National Directorate (ND) guidance, and make recommendations to the Government. Provides ISs security advice and guidance Joint Analytical Workstation (JAW) applicable IC, DoW, and NDs and guidance to Government and industry partners for the protection of data at all classification levels including Sensitive Compartmented Information (SCI). Evaluates threats and vulnerabilities to ISs to ascertain the need for additional safeguards and recommend approval, disapproval, or waiver(s) for IS processing national security data at industry and/or Government facilities. Supports development and implementation of directives and guidance for policies. Provides input for consideration in the promulgation of future ISs security policy. Supports and/or conduct site visits and assessments to inspect and verify IS reports. Ensures security control assessments are completed for each IS. Supports the preparation and delivery of presentations, briefings, reports, and memoranda associated with the RMF process. Uses the RMF system of record to complete RMF workflow duties and maintain the asset documentation repository. Establishes and maintains means and methods to track RMF process workflow activities to inform task volume, velocity, and duration of activities. Prepares the final Security Assessment Report (SAR) containing the results and findings from the assessment at the conclusion of each security control assessment activity and the Authorization Recommendation. Ensures appropriate IS security requirements including applicable Interface Control Documents (ICDs), DoW Instructions, NDs and other guidance are addressed and applied and appropriate documentation is prepared by the system owners or programs. The documentation will be contained in the Security Assessment Package, including, but not limited to, the Concept of Operations (CONOP), SSP, Systems Requirements Traceability Matrix, Risk Management Matrix, Test Results, interface control documents, requests for changes, test plans, and other related program security documentation. Collaborates with Information Security Officers (ISOs) and Common Control Providers to initiate Plan of Action and Milestones (POAMs) for ISs based on findings and recommendations from the SAR. Reviews and approves the IS Security Assessment Plan which is comprised of the Security Controls Traceability Matrix and the Security Control Assessment Procedures. Tracks the completion of the SAR. Reviews, coordinates, and responds to security issues as requested by the Government. Provides A&A support to the Government for the protection of special programs and tactical operations related activities. Supplies the effort needed to conduct the reviews and write reports to support Integrated Security Assessment Program (ISAP) or Technical Information Systems Security Reviews (TISSRs). Required Qualifications Practical experience performing information systems A&A as defined in applicable ICDs and guidance Practical experience utilizing risk management strategies for information technology solutions Technical understanding of emerging technologies and their implementation within Government system and network environments Knowledge of information technology concepts used in the evaluation of security performance and integrity of state-of-the-art applications, communications systems, hardware, software, satellite control systems, and information processing systems Technical understanding of information technology systems, software, and networks Ability to effectively coordinate A&A activities of industry and Government information systems to meet acquisition milestone requirements Effective technical report and general correspondence writing ability Ability to manage and track systems or programs involved in the A&A process Experience developing and implementing security related directives and guidance for Information Assurance, Information Technology, and Information Management Experience working with a mixed level skill team to ensure that appropriate knowledge and skill transfer occurs High school's degree and 7+ years of relevant experience, or Associate's degree and 7+ years of relevant experience, or Bachelor's degree and 5+ years of relevant experience, or Master's degree and 3+ years of relevant experience Certifications Must have one of the following IAM Level 2 Certification: CGRC (Previously CAP) CASP CISM CISSP GSLC CCISO Security Requirements U.S. Citizenship Active Top Secret/Sensitive Compartmented Information (TS/SCI) clearance Active Counterintelligence (CI) or Full Scope (FS) Polygraph Work Environment On-site work in a government or contractor facility Occasional travel (up to 10%) This position is dependent on a contract seat being awarded. About LV8D Solutions LV8D Solutions is an elite Systems Engineering and Technical Advisory (SETA) company that delivers advanced systems engineering, integration, acquisition, mission operations, network communications, and cybersecurity support to our defense and intelligence customers. Founded in 2019, we apply our deep technical expertise, understanding, and mission-first mindset to design, acquire, and implement complex, high-impact solutions for our Intelligence Community (IC) and Department of War (DoW) customers. We specialize in every aspect of our customers' space and ground mission systems while offering exceptional work-life balance and an exemplary compensation and total rewards package designed to recruit, train, and retain top talent and committed to national defense and career growth. Equal Employment Opportunity Statement LV8D Solutions LLC is an Equal Opportunity Employer committed to diversity and inclusion. All qualified applicants will receive consideration without regard to race, religion, gender, national origin, disability, veteran status, or other protected categories. Benefits Performance & Recognition Period of Performance (PoP) Bonus Opportunities Performance-based bonus opportunities tied to contract or organizational performance. Retention Incentive Benefit Bounty Receive a payout for unused annual company contributions designated for health insurance premiums and professional training. Referral Bonus Earn up to $5,000 for each successful employee referral. Customer Recognition Letter of Appreciation (LoA) Bonus Opportunities Bonus opportunities based on customer recognition received through Letters of Appreciation. Milestone Rewards Celebrate your career achievements with anniversary awards on your 1st, 5th, 10th, and 20th years of service. Financial & Retirement Benefits Profit Sharing Receive an annual contribution equal to 4% of your W-2 gross earnings into your 401 (k), with immediate vesting. 401(k) Company Match The company matches your 401 (k) contributions dollar-for-dollar up to 6% of your monthly contribution, with immediate vesting. Career Development The company invests in your professional growth through: Annual financial support for professional training and industry certifications. Enhanced financial support for employees actively pursuing a degree at an accredited institution. Work-Life Balance . click apply for full job details
09/26/2026
Full time
Job Description Job Description Mission Context LV8D Solutions supports national security space and intelligence customers delivering next-generation sensing and exploitation capabilities. The role of a Security Control Assessor (SCA) is focused on providing information security Assessment and Authorization (A&A) support throughout the mission program's lifecycle. Position Overview LV8D Solutions is seeking a SCA to conduct independent assessments of the management, operational, and technical security controls employed within or inherited by an information technology (IT) system to determine the overall effectiveness of the security controls. A Security Control Assessor (SCA) performs comprehensive INFOSEC assessment of management, operational, and technical security controls to determine overall effectiveness of the controls for A&A determination throughout a program's system lifecycle. SCAs provide an assessment of the severity of weakness or deficiencies discovered in the Information System (IS) and its environment of operation and recommend corrective actions to address identified vulnerabilities. Prior to initiating the security control assessment, the SCA reviews the System Security Plan (SSP) to ensure the plan provides a set of security controls for the ISs that meet the stated security requirements. Additionally, the SCA must verify that all allocated controls have an acceptable status (i.e., implemented, excepted, or inherited) with appropriate documented details and provides responses in the Government's Risk Management Framework (RMF) tools. Interested candidates need to thrive in an innovative, fast-paced environment; are highly motivated and not afraid to take on uncharted territory; possess strong communication, leadership, and organizational skills; and be able to prioritize their time to be effective in a dynamic environment. Requirements Key Responsibilities Reviews IS for compliance with applicable Intelligence Community (IC), Department of War (DoW), and National Directorate (ND) guidance, and make recommendations to the Government. Provides ISs security advice and guidance Joint Analytical Workstation (JAW) applicable IC, DoW, and NDs and guidance to Government and industry partners for the protection of data at all classification levels including Sensitive Compartmented Information (SCI). Evaluates threats and vulnerabilities to ISs to ascertain the need for additional safeguards and recommend approval, disapproval, or waiver(s) for IS processing national security data at industry and/or Government facilities. Supports development and implementation of directives and guidance for policies. Provides input for consideration in the promulgation of future ISs security policy. Supports and/or conduct site visits and assessments to inspect and verify IS reports. Ensures security control assessments are completed for each IS. Supports the preparation and delivery of presentations, briefings, reports, and memoranda associated with the RMF process. Uses the RMF system of record to complete RMF workflow duties and maintain the asset documentation repository. Establishes and maintains means and methods to track RMF process workflow activities to inform task volume, velocity, and duration of activities. Prepares the final Security Assessment Report (SAR) containing the results and findings from the assessment at the conclusion of each security control assessment activity and the Authorization Recommendation. Ensures appropriate IS security requirements including applicable Interface Control Documents (ICDs), DoW Instructions, NDs and other guidance are addressed and applied and appropriate documentation is prepared by the system owners or programs. The documentation will be contained in the Security Assessment Package, including, but not limited to, the Concept of Operations (CONOP), SSP, Systems Requirements Traceability Matrix, Risk Management Matrix, Test Results, interface control documents, requests for changes, test plans, and other related program security documentation. Collaborates with Information Security Officers (ISOs) and Common Control Providers to initiate Plan of Action and Milestones (POAMs) for ISs based on findings and recommendations from the SAR. Reviews and approves the IS Security Assessment Plan which is comprised of the Security Controls Traceability Matrix and the Security Control Assessment Procedures. Tracks the completion of the SAR. Reviews, coordinates, and responds to security issues as requested by the Government. Provides A&A support to the Government for the protection of special programs and tactical operations related activities. Supplies the effort needed to conduct the reviews and write reports to support Integrated Security Assessment Program (ISAP) or Technical Information Systems Security Reviews (TISSRs). Required Qualifications Practical experience performing information systems A&A as defined in applicable ICDs and guidance Practical experience utilizing risk management strategies for information technology solutions Technical understanding of emerging technologies and their implementation within Government system and network environments Knowledge of information technology concepts used in the evaluation of security performance and integrity of state-of-the-art applications, communications systems, hardware, software, satellite control systems, and information processing systems Technical understanding of information technology systems, software, and networks Ability to effectively coordinate A&A activities of industry and Government information systems to meet acquisition milestone requirements Effective technical report and general correspondence writing ability Ability to manage and track systems or programs involved in the A&A process Experience developing and implementing security related directives and guidance for Information Assurance, Information Technology, and Information Management Experience working with a mixed level skill team to ensure that appropriate knowledge and skill transfer occurs High school's degree and 7+ years of relevant experience, or Associate's degree and 7+ years of relevant experience, or Bachelor's degree and 5+ years of relevant experience, or Master's degree and 3+ years of relevant experience Certifications Must have one of the following IAM Level 2 Certification: CGRC (Previously CAP) CASP CISM CISSP GSLC CCISO Security Requirements U.S. Citizenship Active Top Secret/Sensitive Compartmented Information (TS/SCI) clearance Active Counterintelligence (CI) or Full Scope (FS) Polygraph Work Environment On-site work in a government or contractor facility Occasional travel (up to 10%) This position is dependent on a contract seat being awarded. About LV8D Solutions LV8D Solutions is an elite Systems Engineering and Technical Advisory (SETA) company that delivers advanced systems engineering, integration, acquisition, mission operations, network communications, and cybersecurity support to our defense and intelligence customers. Founded in 2019, we apply our deep technical expertise, understanding, and mission-first mindset to design, acquire, and implement complex, high-impact solutions for our Intelligence Community (IC) and Department of War (DoW) customers. We specialize in every aspect of our customers' space and ground mission systems while offering exceptional work-life balance and an exemplary compensation and total rewards package designed to recruit, train, and retain top talent and committed to national defense and career growth. Equal Employment Opportunity Statement LV8D Solutions LLC is an Equal Opportunity Employer committed to diversity and inclusion. All qualified applicants will receive consideration without regard to race, religion, gender, national origin, disability, veteran status, or other protected categories. Benefits Performance & Recognition Period of Performance (PoP) Bonus Opportunities Performance-based bonus opportunities tied to contract or organizational performance. Retention Incentive Benefit Bounty Receive a payout for unused annual company contributions designated for health insurance premiums and professional training. Referral Bonus Earn up to $5,000 for each successful employee referral. Customer Recognition Letter of Appreciation (LoA) Bonus Opportunities Bonus opportunities based on customer recognition received through Letters of Appreciation. Milestone Rewards Celebrate your career achievements with anniversary awards on your 1st, 5th, 10th, and 20th years of service. Financial & Retirement Benefits Profit Sharing Receive an annual contribution equal to 4% of your W-2 gross earnings into your 401 (k), with immediate vesting. 401(k) Company Match The company matches your 401 (k) contributions dollar-for-dollar up to 6% of your monthly contribution, with immediate vesting. Career Development The company invests in your professional growth through: Annual financial support for professional training and industry certifications. Enhanced financial support for employees actively pursuing a degree at an accredited institution. Work-Life Balance . click apply for full job details
Senior Information Security Specialist
Dev Technology Ashburn, Virginia
Job Description Job Description Information Security Specialist Officer, Technical Lead, AWS Security • RMF & ATO • NIST 800-53 • Cloud Application Security Clearance: Active CBP, DHS, or Top Secret Clearance required Work Arrangement: Hybrid - onsite 3 days/week during standard business hours in Ashburn, VA About the Role Dev Technology Group is seeking a Senior Information Security Specialist to lead and develop a mid-sized team of ISSOs supporting the security, compliance, and authorization of mission-critical federal applications and information systems hosted in AWS. This is a hands-on technical leadership role combining people leadership, federal cybersecurity expertise, and direct collaboration with government and technical stakeholders. You will mentor junior and mid-level ISSOs while partnering with system owners, developers, architects, cloud/infrastructure engineers, security professionals, and government stakeholders throughout the system development lifecycle. You will provide practical security guidance for AWS-hosted applications, lead Risk Management Framework (RMF) and Authority to Operate (ATO) activities, oversee vulnerability management and continuous monitoring, and translate federal cybersecurity requirements into actionable guidance for technical teams. What You'll Do Lead, mentor, and develop a team of ISSOs by establishing priorities, providing technical direction and coaching, and promoting accountability and consistent security practices. Lead and oversee RMF, ATO, security authorization, compliance, vulnerability management, and continuous monitoring activities across a portfolio of federal systems and applications. Partner with ISSMs, system owners, assessors, developers, architects, engineers, and government stakeholders to maintain authorizations, identify risks, and address security requirements. Lead vulnerability management efforts, prioritizing remediation, developing mitigation strategies, and tracking corrective actions through resolution. Develop, assess, document, and support implementation of security controls aligned with FISMA, NIST 800-53, DHS, and client requirements . Prepare and maintain security and authorization documentation, including SSPs, ISAs, audit artifacts, and RMF documentation . Provide cybersecurity guidance for applications and systems deployed in AWS and integrate security throughout the software development lifecycle. Validate security implementation through technical reviews, discussions, interviews, assessments, and tabletop exercises. Support security audits, assessments, compliance reviews, and reviews of information systems and network connections. Interpret federal and client security policies and translate requirements into practical guidance for technical and development teams. Identify and escalate security risks, communicate priorities and remediation status, and provide clear visibility to Dev Technology leadership and government stakeholders. Develop and present security metrics, status reports, risk assessments, and executive briefings . Establish and improve security processes, procedures, templates, dashboards, and workflows to improve consistency, accountability, and efficiency across the ISSO team. Build trusted relationships with government clients through proactive communication, collaboration, and face-to-face engagement. Required Education, Experience & Skills Bachelor's degree and 7+ years of experience securing federal information systems. Demonstrated experience leading and mentoring information security professionals , including junior and mid-level ISSOs. Experience leading cybersecurity activities in a federal government client environment and working directly with government stakeholders.' Strong working knowledge of NIST Risk Management Framework (RMF) and experience supporting federal systems through security authorization and ATO activities . Experience developing, implementing, assessing, or documenting security controls aligned with FISMA and NIST 800-53 . Experience with vulnerability management, continuous monitoring, security assessments, audits, or compliance reviews for federal systems. Experience providing cybersecurity guidance for AWS-hosted applications and systems . Strong understanding of modern information systems and their technical security considerations. Ability to work effectively with developers, architects, engineers, government stakeholders, and technical and non-technical audiences. Strong written and verbal communication skills, including the ability to communicate security risks and technical findings and develop/present security documentation and executive briefings. Ability to establish priorities, manage competing demands, independently manage security activities, and escalate issues appropriately. Proactive, solutions-oriented approach to identifying risks and improving security practices. Current CBP, DHS, or Top Secret Clearance. Ability to work onsite 3 days per week in Ashburn, VA during standard business hours. Cybersecurity certification such as CISSP, CISM, GIAC, Security+, or another recognized cybersecurity certification. Preferred Education, Experience & Skills Experience developing or supporting RMF and authorization artifacts, including SSPs, ISAs, PTAs, ATTs, POA&Ms , and related documentation. Experience partnering with application development, cloud engineering, and DevSecOps teams to integrate security throughout the SDLC. Experience working in an Agile software development environment using Jira or similar platforms. Experience with GRC tools such as CSAM or similar platforms supporting authorization, compliance, vulnerability management, and security activities. Understanding of AI concepts and practical applications of AI for cybersecurity operations, risk analysis, compliance, or security program management. Our estimated salary range for this position is $88,000 - $ 150,000. This presented salary range is not a guarantee of compensation or salary. Offered salary is based on experience, geographic location, and possibly contractual requirements as appropriate to the role. Salary could fall outside of this range. Who We Are Dev Technology is a growing IT company with an employee-centric culture that works on mission-critical projects for the federal government. We partner with our federal customers to deliver technology services and solutions, and to drive our client's missions forward through innovation. We use Agile and DevSecOps principles to provide services including application development, biometrics and identity management, cloud and infrastructure optimization, IT and legacy modernization, and data management. As a Washington Post Top Workplace award winner for the past THIRTEEN years in a row, the Top Workplaces USA for the past five years, and a recipient of the Companies As Responsive Employers (CARE) Award for the past six years, Dev Technology employees enjoy: Generous and flexible time-off policy Flexible work schedules and telework options, including remote work availability for eligible projects Career development opportunities including a mentorship program, technical and management training through Dev University, hands-on learning through DevLab, tuition reimbursement, and paid training opportunities Industry-leading benefits including a choice of two health plans that include dental and vision, flexible spending account, commuter benefits, life insurance, and more 401K matching with a 5% matching contribution Regular team and company social events including our annual party, happy hours, fitness challenges, and more A focus on community engagement including company wide support activities, employer match for donations, and time off for volunteer efforts To learn more about working at Dev Technology, visit Working At Dev Technology Group Equal Opportunity Employer / Individuals with Disabilities / Protected Veterans Dev Technology Group operates in the following states: AL, AR, AZ, CO, DC, FL, GA, ID, IL, IN, MD, MA, ME, MI, MN, MO, MS, NC, NJ, OH, OR, PA, SC, TN, TX, VA, WV.
09/26/2026
Full time
Job Description Job Description Information Security Specialist Officer, Technical Lead, AWS Security • RMF & ATO • NIST 800-53 • Cloud Application Security Clearance: Active CBP, DHS, or Top Secret Clearance required Work Arrangement: Hybrid - onsite 3 days/week during standard business hours in Ashburn, VA About the Role Dev Technology Group is seeking a Senior Information Security Specialist to lead and develop a mid-sized team of ISSOs supporting the security, compliance, and authorization of mission-critical federal applications and information systems hosted in AWS. This is a hands-on technical leadership role combining people leadership, federal cybersecurity expertise, and direct collaboration with government and technical stakeholders. You will mentor junior and mid-level ISSOs while partnering with system owners, developers, architects, cloud/infrastructure engineers, security professionals, and government stakeholders throughout the system development lifecycle. You will provide practical security guidance for AWS-hosted applications, lead Risk Management Framework (RMF) and Authority to Operate (ATO) activities, oversee vulnerability management and continuous monitoring, and translate federal cybersecurity requirements into actionable guidance for technical teams. What You'll Do Lead, mentor, and develop a team of ISSOs by establishing priorities, providing technical direction and coaching, and promoting accountability and consistent security practices. Lead and oversee RMF, ATO, security authorization, compliance, vulnerability management, and continuous monitoring activities across a portfolio of federal systems and applications. Partner with ISSMs, system owners, assessors, developers, architects, engineers, and government stakeholders to maintain authorizations, identify risks, and address security requirements. Lead vulnerability management efforts, prioritizing remediation, developing mitigation strategies, and tracking corrective actions through resolution. Develop, assess, document, and support implementation of security controls aligned with FISMA, NIST 800-53, DHS, and client requirements . Prepare and maintain security and authorization documentation, including SSPs, ISAs, audit artifacts, and RMF documentation . Provide cybersecurity guidance for applications and systems deployed in AWS and integrate security throughout the software development lifecycle. Validate security implementation through technical reviews, discussions, interviews, assessments, and tabletop exercises. Support security audits, assessments, compliance reviews, and reviews of information systems and network connections. Interpret federal and client security policies and translate requirements into practical guidance for technical and development teams. Identify and escalate security risks, communicate priorities and remediation status, and provide clear visibility to Dev Technology leadership and government stakeholders. Develop and present security metrics, status reports, risk assessments, and executive briefings . Establish and improve security processes, procedures, templates, dashboards, and workflows to improve consistency, accountability, and efficiency across the ISSO team. Build trusted relationships with government clients through proactive communication, collaboration, and face-to-face engagement. Required Education, Experience & Skills Bachelor's degree and 7+ years of experience securing federal information systems. Demonstrated experience leading and mentoring information security professionals , including junior and mid-level ISSOs. Experience leading cybersecurity activities in a federal government client environment and working directly with government stakeholders.' Strong working knowledge of NIST Risk Management Framework (RMF) and experience supporting federal systems through security authorization and ATO activities . Experience developing, implementing, assessing, or documenting security controls aligned with FISMA and NIST 800-53 . Experience with vulnerability management, continuous monitoring, security assessments, audits, or compliance reviews for federal systems. Experience providing cybersecurity guidance for AWS-hosted applications and systems . Strong understanding of modern information systems and their technical security considerations. Ability to work effectively with developers, architects, engineers, government stakeholders, and technical and non-technical audiences. Strong written and verbal communication skills, including the ability to communicate security risks and technical findings and develop/present security documentation and executive briefings. Ability to establish priorities, manage competing demands, independently manage security activities, and escalate issues appropriately. Proactive, solutions-oriented approach to identifying risks and improving security practices. Current CBP, DHS, or Top Secret Clearance. Ability to work onsite 3 days per week in Ashburn, VA during standard business hours. Cybersecurity certification such as CISSP, CISM, GIAC, Security+, or another recognized cybersecurity certification. Preferred Education, Experience & Skills Experience developing or supporting RMF and authorization artifacts, including SSPs, ISAs, PTAs, ATTs, POA&Ms , and related documentation. Experience partnering with application development, cloud engineering, and DevSecOps teams to integrate security throughout the SDLC. Experience working in an Agile software development environment using Jira or similar platforms. Experience with GRC tools such as CSAM or similar platforms supporting authorization, compliance, vulnerability management, and security activities. Understanding of AI concepts and practical applications of AI for cybersecurity operations, risk analysis, compliance, or security program management. Our estimated salary range for this position is $88,000 - $ 150,000. This presented salary range is not a guarantee of compensation or salary. Offered salary is based on experience, geographic location, and possibly contractual requirements as appropriate to the role. Salary could fall outside of this range. Who We Are Dev Technology is a growing IT company with an employee-centric culture that works on mission-critical projects for the federal government. We partner with our federal customers to deliver technology services and solutions, and to drive our client's missions forward through innovation. We use Agile and DevSecOps principles to provide services including application development, biometrics and identity management, cloud and infrastructure optimization, IT and legacy modernization, and data management. As a Washington Post Top Workplace award winner for the past THIRTEEN years in a row, the Top Workplaces USA for the past five years, and a recipient of the Companies As Responsive Employers (CARE) Award for the past six years, Dev Technology employees enjoy: Generous and flexible time-off policy Flexible work schedules and telework options, including remote work availability for eligible projects Career development opportunities including a mentorship program, technical and management training through Dev University, hands-on learning through DevLab, tuition reimbursement, and paid training opportunities Industry-leading benefits including a choice of two health plans that include dental and vision, flexible spending account, commuter benefits, life insurance, and more 401K matching with a 5% matching contribution Regular team and company social events including our annual party, happy hours, fitness challenges, and more A focus on community engagement including company wide support activities, employer match for donations, and time off for volunteer efforts To learn more about working at Dev Technology, visit Working At Dev Technology Group Equal Opportunity Employer / Individuals with Disabilities / Protected Veterans Dev Technology Group operates in the following states: AL, AR, AZ, CO, DC, FL, GA, ID, IL, IN, MD, MA, ME, MI, MN, MO, MS, NC, NJ, OH, OR, PA, SC, TN, TX, VA, WV.

Modal Window

  • Home
  • Contact
  • About Us
  • FAQs
  • Terms & Conditions
  • Privacy
  • Employer
  • Post a Job
  • Search Resumes
  • Sign in
  • Job Seeker
  • Find Jobs
  • Create Resume
  • Sign in
  • IT blog
  • Facebook
  • Twitter
  • LinkedIn
  • Youtube
© 2008-2026 IT Job Board