BMO Financial seeks a Senior Cloud Security Engineer to secure critical banking, insurance, and investment platforms in a multi cloud environment. You will design and implement cloud security architectures, harden workloads, embed controls into CI/CD pipelines, and ensure compliance with financial regulations. Partnering with IT and Cybersecurity, you will lead threat modeling, incident response, and security automation while mentoring engineers. BMO offers an inclusive, equitable culture where diverse perspectives are valued and you can shape the future of secure digital banking. Responsibilities Design and implement secure architectures for multi cloud banking and insurance platforms. Define and enforce cloud security standards, patterns, and guardrails across AWS, Azure, and GCP. Integrate security into CI/CD pipelines and automate controls using Ia C and scripting. Lead threat modeling, risk assessments, and remediation for cloud initiatives. Configure and optimize IAM, network segmentation, encryption, and monitoring for critical workloads. Partner with IT, Cybersecurity, and lines of business to embed security in digital products. Drive incident response for cloud security events, including investigation and root cause analysis. Ensure compliance with financial services regulations and industry frameworks. Mentor engineers and champion cloud security best practices across BMO Financial. Contribute to an inclusive culture where diverse perspectives improve security outcomes. Required Skills Cloud security architecture AWS security Azure security GCP security Identity and access management (IAM) Zero Trust design Network security in cloud (VPC, security groups) Container and Kubernetes security Security automation & scripting (Python, Terraform) SIEM, logging, and monitoring Threat modeling and risk assessment Compliance (PCI-DSS, SOX, OSFI, GDPR) Incident response and forensics in cloud Dev Sec Ops and CI/CD security Encryption & key management (KMS, HSM)
09/27/2026
Full time
BMO Financial seeks a Senior Cloud Security Engineer to secure critical banking, insurance, and investment platforms in a multi cloud environment. You will design and implement cloud security architectures, harden workloads, embed controls into CI/CD pipelines, and ensure compliance with financial regulations. Partnering with IT and Cybersecurity, you will lead threat modeling, incident response, and security automation while mentoring engineers. BMO offers an inclusive, equitable culture where diverse perspectives are valued and you can shape the future of secure digital banking. Responsibilities Design and implement secure architectures for multi cloud banking and insurance platforms. Define and enforce cloud security standards, patterns, and guardrails across AWS, Azure, and GCP. Integrate security into CI/CD pipelines and automate controls using Ia C and scripting. Lead threat modeling, risk assessments, and remediation for cloud initiatives. Configure and optimize IAM, network segmentation, encryption, and monitoring for critical workloads. Partner with IT, Cybersecurity, and lines of business to embed security in digital products. Drive incident response for cloud security events, including investigation and root cause analysis. Ensure compliance with financial services regulations and industry frameworks. Mentor engineers and champion cloud security best practices across BMO Financial. Contribute to an inclusive culture where diverse perspectives improve security outcomes. Required Skills Cloud security architecture AWS security Azure security GCP security Identity and access management (IAM) Zero Trust design Network security in cloud (VPC, security groups) Container and Kubernetes security Security automation & scripting (Python, Terraform) SIEM, logging, and monitoring Threat modeling and risk assessment Compliance (PCI-DSS, SOX, OSFI, GDPR) Incident response and forensics in cloud Dev Sec Ops and CI/CD security Encryption & key management (KMS, HSM)
GovCIO LLC seeks a Cybersecurity Engineer SME to secure mission-critical federal systems. You will design secure architectures across cloud and on-prem, lead vulnerability assessments and incident response, and guide compliance with NIST and FedRAMP. Partnering with agile development and infrastructure teams, you'll embed security into DevSecOps pipelines and engineer security tools for monitoring and threat detection. As a mission-driven SME, you'll mentor teammates, advise government stakeholders on risk, and help modernize federal IT to improve services for citizens nationwide in a collaborative, fast-paced environment. Responsibilities Design, implement, and maintain secure network and cloud architectures for federal systems Lead security assessments, penetration testing, and vulnerability remediation activities Develop, document, and enforce cybersecurity policies, standards, and procedures Implement monitoring, logging, and incident detection/response capabilities Advise stakeholders on risk, compliance (e.g., Fed RAMP, NIST), and security best practices Collaborate with agile development teams to embed security into SDLC and Dev Sec Ops pipelines Perform security tool engineering, integration, and tuning across enterprise environments Support ATO/authorization activities, security documentation, and audit responses Mentor junior engineers and serve as SME on large, mission-critical federal projects Continuously evaluate emerging threats and technologies to enhance security posture Required Skills Network security architecture Cloud security (AWS/Azure/GCP) SIEM implementation and tuning Incident detection and response Vulnerability management and penetration testing NIST/Fed RAMP/RMF compliance Zero Trust and identity/access management Secure SDLC and Dev Sec Ops Scripting/automation (Python, Power Shell, or similar) Security tool engineering and integration
09/27/2026
Full time
GovCIO LLC seeks a Cybersecurity Engineer SME to secure mission-critical federal systems. You will design secure architectures across cloud and on-prem, lead vulnerability assessments and incident response, and guide compliance with NIST and FedRAMP. Partnering with agile development and infrastructure teams, you'll embed security into DevSecOps pipelines and engineer security tools for monitoring and threat detection. As a mission-driven SME, you'll mentor teammates, advise government stakeholders on risk, and help modernize federal IT to improve services for citizens nationwide in a collaborative, fast-paced environment. Responsibilities Design, implement, and maintain secure network and cloud architectures for federal systems Lead security assessments, penetration testing, and vulnerability remediation activities Develop, document, and enforce cybersecurity policies, standards, and procedures Implement monitoring, logging, and incident detection/response capabilities Advise stakeholders on risk, compliance (e.g., Fed RAMP, NIST), and security best practices Collaborate with agile development teams to embed security into SDLC and Dev Sec Ops pipelines Perform security tool engineering, integration, and tuning across enterprise environments Support ATO/authorization activities, security documentation, and audit responses Mentor junior engineers and serve as SME on large, mission-critical federal projects Continuously evaluate emerging threats and technologies to enhance security posture Required Skills Network security architecture Cloud security (AWS/Azure/GCP) SIEM implementation and tuning Incident detection and response Vulnerability management and penetration testing NIST/Fed RAMP/RMF compliance Zero Trust and identity/access management Secure SDLC and Dev Sec Ops Scripting/automation (Python, Power Shell, or similar) Security tool engineering and integration
GovCIO LLC seeks a Senior Cyber Security Administrator to secure mission-critical federal IT systems. In this role, you will administer and harden security tools, monitor and investigate security events, and lead incident response to protect complex, multi-cloud and on-prem environments. You'll implement security baselines, support NIST/FISMA compliance, manage identity and access controls, and drive remediation of vulnerabilities. Working in a mission-driven, collaborative culture, you'll mentor others, influence security architecture, and help modernize government technology at scale. Responsibilities Administer and harden security tools, firewalls, IDS/IPS, and endpoint protection across federal environments. Monitor security events, investigate incidents, and coordinate response and remediation. Implement and maintain security baselines, configurations, and patch management processes. Support compliance with federal security standards (e.g., NIST, FISMA) and internal policies. Conduct vulnerability scans, analyze findings, and drive remediation with engineering teams. Manage identity and access controls, including privileged account management and MFA. Develop and update security documentation, runbooks, and standard operating procedures. Collaborate with Dev, Cloud, and Network teams to embed security into system designs. Support security audits, assessments, and ATO-related activities for federal systems. Mentor junior staff and contribute to continuous improvement of cybersecurity operations. Required Skills Network security administration (firewalls, IDS/IPS) Security Information and Event Management (SIEM) tools Endpoint protection and EDR platforms Vulnerability assessment and remediation Identity and Access Management (IAM) and MFANIST and FISMA compliance frameworks Incident detection, triage, and response Security hardening and configuration management Cloud security (AWS/Azure/GCP) fundamentals Scripting/automation (Power Shell, Python, or similar)
09/27/2026
Full time
GovCIO LLC seeks a Senior Cyber Security Administrator to secure mission-critical federal IT systems. In this role, you will administer and harden security tools, monitor and investigate security events, and lead incident response to protect complex, multi-cloud and on-prem environments. You'll implement security baselines, support NIST/FISMA compliance, manage identity and access controls, and drive remediation of vulnerabilities. Working in a mission-driven, collaborative culture, you'll mentor others, influence security architecture, and help modernize government technology at scale. Responsibilities Administer and harden security tools, firewalls, IDS/IPS, and endpoint protection across federal environments. Monitor security events, investigate incidents, and coordinate response and remediation. Implement and maintain security baselines, configurations, and patch management processes. Support compliance with federal security standards (e.g., NIST, FISMA) and internal policies. Conduct vulnerability scans, analyze findings, and drive remediation with engineering teams. Manage identity and access controls, including privileged account management and MFA. Develop and update security documentation, runbooks, and standard operating procedures. Collaborate with Dev, Cloud, and Network teams to embed security into system designs. Support security audits, assessments, and ATO-related activities for federal systems. Mentor junior staff and contribute to continuous improvement of cybersecurity operations. Required Skills Network security administration (firewalls, IDS/IPS) Security Information and Event Management (SIEM) tools Endpoint protection and EDR platforms Vulnerability assessment and remediation Identity and Access Management (IAM) and MFANIST and FISMA compliance frameworks Incident detection, triage, and response Security hardening and configuration management Cloud security (AWS/Azure/GCP) fundamentals Scripting/automation (Power Shell, Python, or similar)
RELOCATION ASSISTANCE: Relocation assistance may be available CLEARANCE REQUIRED FOR START: Yes CLEARANCE TYPE: Secret TRAVEL: Yes, 10% of the Time Description At Northrop Grumman, our employees have incredible opportunities to work on revolutionary systems that impact people's lives around the world today, and for generations to come. Our pioneering and inventive spirit has enabled us to be at the forefront of many technological advancements in our nation's history - from the first flight across the Atlantic Ocean, to stealth bombers, to landing on the moon. We look for people who have bold new ideas, courage and a pioneering spirit to join forces to invent the future, and have fun along the way. Our culture thrives on intellectual curiosity, cognitive diversity and bringing your whole self to work - and we have an insatiable drive to do what others think is impossible. Our employees are not only part of history, they're making history. Join Northrop Grumman on our continued mission to push the boundaries of possible across land, sea, air, space, and cyberspace. Enjoy a culture where your voice is valued and start contributing to our team of passionate professionals providing real-life solutions to our world's biggest challenges. We take pride in creating purposeful work and allowing our employees to grow and achieve their goals every day by Defining Possible. With our competitive pay and comprehensive benefits, we have the right opportunities to fit your life and launch your career today. Northrop Grumman Defense Systems is seeking a System States and Controls Capability Lead (Staff Systems Engineer - Level 5) to join the team located in Roy UT, Bellevue NE, Huntsville, AL or Manhattan Beach, CA in support of the Sentinel program. Northrop Grumman supports the Air Force's sustainment, development, production and deployment of hardware and system modifications for Intercontinental Ballistic Missile (ICBM,) Ground and Airborne Launch Control Systems, Launch Facilities, and associated infrastructure. What you will get to do: The Sentinel program has an exciting opportunity for a System States & Controls Capability Lead Staff Systems Engineer (Level 5) to join the Command Systems team leading activities including requirements definition / allocation, functional decomposition, interface definition, verification & validation, and requirements traceability across the ground segment of the Sentinel Weapon System. Specific duties to include, but are not limited to the following: Lead a small team of systems engineers to develop systems engineering artifacts across wing-wide maintenance, operations, initialize, fault detection, and shutdown capabilities Work with both technical teams and stakeholders to develop and mature off-nominal system use cases and states deriving full-scope functionality for the wing and preliminary product selection and development Help develop and incorporate the appropriate requirements for the system and ensure that they are properly represented in the model. Develop systems architecture using Cameo Enterprise Architecture (behavioral, structural, analytical). Contribute to system requirements development, management, and analysis. Develop unifying model techniques, procedures, and processes (for model development, tool integration, and team integration). Basic Qualifications: Bachelor's degree in STEM (Science, Technology, Engineering, and Mathematics) with 12 years of experience; or master's degree with 10 years of experience; or PhD with 8 years of experience Must be a US Citizen with an active DoD Secret Clearance, at time of application, current and within scope, with an investigation date within the last 6 years. Must have the ability to obtain Special Access Program (SAP) approval within a reasonable period, as determined by the company to meet its business needs. 4 years of experience with requirements management/analysis/allocations 3 years of experience with Model-Based Engineering / Model-Based Systems Engineering (MBE/MBSE) practices, languages and/or tools such as Cameo, Rhapsody or MagicDraw 5 years of experience with one or more of the following: Command & Control (C2), physical security, cybersecurity, Nuclear Command, Control, and Communications (NC3) systems/processes, communications systems, facility design, military aerospace development (e.g. Sentinel, Minute Man III, B-2, B-21 delivery systems) Preferred Qualifications: Active DoD Top Secret Clearance Demonstrated understanding of the Systems Engineering Vee Model 3+ years of experience in model-based systems engineering; thread-based system decomposition, requirements engineering, system modeling in SysML Experience in documenting Interface Control Documents, Interface Requirement Specifications, and Interface Description Documents Understanding of Object-Oriented Systems Engineering Methodology and systems thinking Excellent collaboration skills and experience working across product, design, and systems engineering teams with various stakeholder communities Proven technical leadership in designing, modeling, and verifying complex, hierarchical State Machines for distributed, real-time command and control architectures. This includes defining clear, deterministic state transitions for critical mission sequences (e.g., Power-On, Daily Monitoring, Targeting/Planning, Countdown, Launch, Abort, and Shutdown) Extensive experience developing automated FDIR frameworks and Built-In Test (BIT) strategies (Periodic, Initiated, and Continuous) for high-consequence systems. This includes leveraging fault-tree analysis to design algorithms that isolate anomalous behavior down to the specific LRU or software. Demonstrated understanding of the systematic challenges of distributed system synchronization - specifically how a network of geographically separated ground nodes initially coordinates clocks, shares state telemetry, loads cryptographic keys, and handles simultaneous, secure shutdowns Experience with ICBM weapon system engineering and integration Experience with complex system development on large programs As a full-time employee of Northrop Grumman, you are eligible for our robust benefits package including: - Medical, Dental & Vision coverage - 401k - Educational Assistance - Life Insurance - Employee Assistance Programs & Work/Life Solutions - Paid Time Off - Health & Wellness Resources - Employee Discounts This position's standard work schedule is 9/80. The 9/80 schedule allows employees who work a nine-hour day Monday through Thursday to take every other Friday off. Primary Level Salary Range: $152,900.00 - $229,300.00 The above salary range represents a general guideline; however, Northrop Grumman considers a number of factors when determining base salary offers such as the scope and responsibilities of the position and the candidate's experience, education, skills and current market conditions. Depending on the position, employees may be eligible for overtime, shift differential, and a discretionary bonus in addition to base pay. Annual bonuses are designed to reward individual contributions as well as allow employees to share in company results. Employees in Vice President or Director positions may be eligible for Long Term Incentives. In addition, Northrop Grumman provides a variety of benefits including health insurance coverage, life and disability insurance, savings plan, Company paid holidays and paid time off (PTO) for vacation and/or personal business. The application period for the job is estimated to be 20 days from the job posting date. However, this timeline may be shortened or extended depending on business needs and the availability of qualified candidates. Northrop Grumman is an Equal Opportunity Employer, making decisions without regard to race, color, religion, creed, sex, sexual orientation, gender identity, marital status, national origin, age, veteran status, disability, or any other protected class. For our complete EEO and pay transparency statement, please visit U.S. Citizenship is required for all positions with a government clearance and certain other restricted positions.
09/27/2026
Full time
RELOCATION ASSISTANCE: Relocation assistance may be available CLEARANCE REQUIRED FOR START: Yes CLEARANCE TYPE: Secret TRAVEL: Yes, 10% of the Time Description At Northrop Grumman, our employees have incredible opportunities to work on revolutionary systems that impact people's lives around the world today, and for generations to come. Our pioneering and inventive spirit has enabled us to be at the forefront of many technological advancements in our nation's history - from the first flight across the Atlantic Ocean, to stealth bombers, to landing on the moon. We look for people who have bold new ideas, courage and a pioneering spirit to join forces to invent the future, and have fun along the way. Our culture thrives on intellectual curiosity, cognitive diversity and bringing your whole self to work - and we have an insatiable drive to do what others think is impossible. Our employees are not only part of history, they're making history. Join Northrop Grumman on our continued mission to push the boundaries of possible across land, sea, air, space, and cyberspace. Enjoy a culture where your voice is valued and start contributing to our team of passionate professionals providing real-life solutions to our world's biggest challenges. We take pride in creating purposeful work and allowing our employees to grow and achieve their goals every day by Defining Possible. With our competitive pay and comprehensive benefits, we have the right opportunities to fit your life and launch your career today. Northrop Grumman Defense Systems is seeking a System States and Controls Capability Lead (Staff Systems Engineer - Level 5) to join the team located in Roy UT, Bellevue NE, Huntsville, AL or Manhattan Beach, CA in support of the Sentinel program. Northrop Grumman supports the Air Force's sustainment, development, production and deployment of hardware and system modifications for Intercontinental Ballistic Missile (ICBM,) Ground and Airborne Launch Control Systems, Launch Facilities, and associated infrastructure. What you will get to do: The Sentinel program has an exciting opportunity for a System States & Controls Capability Lead Staff Systems Engineer (Level 5) to join the Command Systems team leading activities including requirements definition / allocation, functional decomposition, interface definition, verification & validation, and requirements traceability across the ground segment of the Sentinel Weapon System. Specific duties to include, but are not limited to the following: Lead a small team of systems engineers to develop systems engineering artifacts across wing-wide maintenance, operations, initialize, fault detection, and shutdown capabilities Work with both technical teams and stakeholders to develop and mature off-nominal system use cases and states deriving full-scope functionality for the wing and preliminary product selection and development Help develop and incorporate the appropriate requirements for the system and ensure that they are properly represented in the model. Develop systems architecture using Cameo Enterprise Architecture (behavioral, structural, analytical). Contribute to system requirements development, management, and analysis. Develop unifying model techniques, procedures, and processes (for model development, tool integration, and team integration). Basic Qualifications: Bachelor's degree in STEM (Science, Technology, Engineering, and Mathematics) with 12 years of experience; or master's degree with 10 years of experience; or PhD with 8 years of experience Must be a US Citizen with an active DoD Secret Clearance, at time of application, current and within scope, with an investigation date within the last 6 years. Must have the ability to obtain Special Access Program (SAP) approval within a reasonable period, as determined by the company to meet its business needs. 4 years of experience with requirements management/analysis/allocations 3 years of experience with Model-Based Engineering / Model-Based Systems Engineering (MBE/MBSE) practices, languages and/or tools such as Cameo, Rhapsody or MagicDraw 5 years of experience with one or more of the following: Command & Control (C2), physical security, cybersecurity, Nuclear Command, Control, and Communications (NC3) systems/processes, communications systems, facility design, military aerospace development (e.g. Sentinel, Minute Man III, B-2, B-21 delivery systems) Preferred Qualifications: Active DoD Top Secret Clearance Demonstrated understanding of the Systems Engineering Vee Model 3+ years of experience in model-based systems engineering; thread-based system decomposition, requirements engineering, system modeling in SysML Experience in documenting Interface Control Documents, Interface Requirement Specifications, and Interface Description Documents Understanding of Object-Oriented Systems Engineering Methodology and systems thinking Excellent collaboration skills and experience working across product, design, and systems engineering teams with various stakeholder communities Proven technical leadership in designing, modeling, and verifying complex, hierarchical State Machines for distributed, real-time command and control architectures. This includes defining clear, deterministic state transitions for critical mission sequences (e.g., Power-On, Daily Monitoring, Targeting/Planning, Countdown, Launch, Abort, and Shutdown) Extensive experience developing automated FDIR frameworks and Built-In Test (BIT) strategies (Periodic, Initiated, and Continuous) for high-consequence systems. This includes leveraging fault-tree analysis to design algorithms that isolate anomalous behavior down to the specific LRU or software. Demonstrated understanding of the systematic challenges of distributed system synchronization - specifically how a network of geographically separated ground nodes initially coordinates clocks, shares state telemetry, loads cryptographic keys, and handles simultaneous, secure shutdowns Experience with ICBM weapon system engineering and integration Experience with complex system development on large programs As a full-time employee of Northrop Grumman, you are eligible for our robust benefits package including: - Medical, Dental & Vision coverage - 401k - Educational Assistance - Life Insurance - Employee Assistance Programs & Work/Life Solutions - Paid Time Off - Health & Wellness Resources - Employee Discounts This position's standard work schedule is 9/80. The 9/80 schedule allows employees who work a nine-hour day Monday through Thursday to take every other Friday off. Primary Level Salary Range: $152,900.00 - $229,300.00 The above salary range represents a general guideline; however, Northrop Grumman considers a number of factors when determining base salary offers such as the scope and responsibilities of the position and the candidate's experience, education, skills and current market conditions. Depending on the position, employees may be eligible for overtime, shift differential, and a discretionary bonus in addition to base pay. Annual bonuses are designed to reward individual contributions as well as allow employees to share in company results. Employees in Vice President or Director positions may be eligible for Long Term Incentives. In addition, Northrop Grumman provides a variety of benefits including health insurance coverage, life and disability insurance, savings plan, Company paid holidays and paid time off (PTO) for vacation and/or personal business. The application period for the job is estimated to be 20 days from the job posting date. However, this timeline may be shortened or extended depending on business needs and the availability of qualified candidates. Northrop Grumman is an Equal Opportunity Employer, making decisions without regard to race, color, religion, creed, sex, sexual orientation, gender identity, marital status, national origin, age, veteran status, disability, or any other protected class. For our complete EEO and pay transparency statement, please visit U.S. Citizenship is required for all positions with a government clearance and certain other restricted positions.
Job Description Job Description About NDi: Network Designs, Inc. (NDi) is a leading Federal contractor that specializes in designing, developing, and delivering information technology and network solutions for government customers. Founded in 1985, NDi's firmly defined core values have driven all aspects of the business, which have been paramount to our company's success and the establishment of an enjoyable workplace atmosphere. At NDi, we believe that our people are the cornerstone of our success, and we value collaboration, career growth, and winning ideas. Military Veterans Encouraged to Apply. Job Description: NDi is seeking a Scrum Master / Agile Coach to support a major federal enterprise information and data integration program. This role enables consistent, transparent Agile delivery across multidisciplinary technical teams by facilitating ceremonies, strengthening backlog and sprint practices, coaching teams and stakeholders, removing impediments, and using delivery metrics to promote continuous improvement. Requirements : U.S. Citizenship is required Must be able to obtain and maintain a Public Trust clearance This position is remote, candidate must reside in one of the following states: AL, AZ, DC, FL, GA, ID, MD, MS, NJ, NC, OK, OH, PA, SC, TN, TX, UT, VA, WV Occasional travel may be required. Candidates should be able to attend meetings at FAA facilities and other locations throughout the Continental United States (CONUS) as required. Must be available during Eastern Time (ET) business hours to support program needs and FAA coordination. Qualifications and Experience: Bachelors degree in a relevant field; masters degree preferred Minimum of 4 years of demonstrable experience serving as a Scrum Master and/or Agile Coach in an enterprise environment Experience supporting technical teams that deliver software, data, cloud, platform, analytics, integration, cybersecurity, or comparable enterprise capabilities. Proficiency with Agile frameworks, Scrum practices, backlog management, sprint execution, facilitation, and continuous-improvement methods. Hands-on experience with Jira or a comparable enterprise Agile and task-tracking platform. Ability to facilitate productive discussions, resolve delivery friction, and communicate effectively with technical and nontechnical stakeholders. Ability to obtain and maintain FAA Contractor Personnel Suitability. Strong written, verbal, analytical, organizational, coaching, facilitation, and cross-functional collaboration skills. Preferred Qualifications: Agile or Scrum certification, such as Certified ScrumMaster, Professional Scrum Master, SAFe Scrum Master, or comparable credential. FAA or other federal experience and experience supporting regulated or mission-critical enterprise programs. Experience coaching multiple teams or supporting cross-team planning, dependencies, release coordination, and delivery reporting. Experience with hybrid delivery environments that combine Agile methods with federal governance, compliance, documentation, and lifecycle requirements. Familiarity with data platforms, cloud modernization, software development, data governance, AI/ML, business intelligence, or DevSecOps delivery environments. Technologies and Methods: Scrum, Agile coaching, Kanban, backlog refinement, estimation, and continuous improvement Jira and Government-approved task-tracking and reporting systems Sprint, flow, backlog-health, risk, dependency, and delivery metrics Cross-team planning, demonstrations, release coordination, retrospectives, and impediment management Enterprise software, data, cloud, analytics, governance, security, and platform delivery contexts Responsibilities: Facilitate sprint planning, daily coordination, backlog refinement, estimation, sprint reviews, retrospectives, and other Agile working sessions for technical delivery teams. Coach delivery teams, product owners, program stakeholders, and technical leads on Scrum and Agile principles, roles, ceremonies, flow, prioritization, and continuous improvement. Promote healthy backlog management by supporting clear user stories, acceptance criteria, prioritization, readiness, dependencies, and definition-of-done practices. Track sprint execution, commitments, risks, impediments, dependencies, and cross-team coordination needs and help drive timely resolution. Use burn-down, velocity, cycle-time, throughput, backlog-health, and related delivery indicators to improve predictability, transparency, quality, and stakeholder outcomes. Maintain accurate Agile artifacts, boards, dashboards, action items, and status information in Government-approved Jira or task-tracking systems. Coordinate demonstrations, release planning, milestone reviews, and cross-team planning with product, program, engineering, data, cloud, security, testing, governance, and documentation stakeholders. Identify recurring delivery constraints and facilitate root-cause discussions, experiments, and practical process improvements. Encourage self-organization, accountability, collaboration, and constructive problem solving while protecting teams from avoidable disruption. Support program reporting and centralized work tracking by providing clear, timely information on progress, blockers, risks, dependencies, and planned outcomes. Compensation and Benefits: At NDi, we value our team and are committed to retaining top talent by offering competitive benefits and compensation packages. Our employee benefits package includes comprehensive health, dental, vision, pet, and legal insurance. Our corporate benefits include 401(k) retirement matching, paid leave, paid holidays, and health and wellness programs. In addition, we provide employer-paid life and disability insurance, professional development, education benefits, and much more to ensure our team has the resources they need to thrive on and off the job. Veterans First Commitment: As a Service-Disabled Veteran-Owned Small Business (SDVOSB), NDi is dedicated to hiring veterans and providing a supportive work environment that honors their service while recognizing the unique skills and experiences they bring to our organization. Our Commitment: Qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability, protected veteran status or other characteristics protected by law. Apply Now: Take advantage of this unique opportunity to join one of the fastest-growing companies in Federal contracting!
09/27/2026
Full time
Job Description Job Description About NDi: Network Designs, Inc. (NDi) is a leading Federal contractor that specializes in designing, developing, and delivering information technology and network solutions for government customers. Founded in 1985, NDi's firmly defined core values have driven all aspects of the business, which have been paramount to our company's success and the establishment of an enjoyable workplace atmosphere. At NDi, we believe that our people are the cornerstone of our success, and we value collaboration, career growth, and winning ideas. Military Veterans Encouraged to Apply. Job Description: NDi is seeking a Scrum Master / Agile Coach to support a major federal enterprise information and data integration program. This role enables consistent, transparent Agile delivery across multidisciplinary technical teams by facilitating ceremonies, strengthening backlog and sprint practices, coaching teams and stakeholders, removing impediments, and using delivery metrics to promote continuous improvement. Requirements : U.S. Citizenship is required Must be able to obtain and maintain a Public Trust clearance This position is remote, candidate must reside in one of the following states: AL, AZ, DC, FL, GA, ID, MD, MS, NJ, NC, OK, OH, PA, SC, TN, TX, UT, VA, WV Occasional travel may be required. Candidates should be able to attend meetings at FAA facilities and other locations throughout the Continental United States (CONUS) as required. Must be available during Eastern Time (ET) business hours to support program needs and FAA coordination. Qualifications and Experience: Bachelors degree in a relevant field; masters degree preferred Minimum of 4 years of demonstrable experience serving as a Scrum Master and/or Agile Coach in an enterprise environment Experience supporting technical teams that deliver software, data, cloud, platform, analytics, integration, cybersecurity, or comparable enterprise capabilities. Proficiency with Agile frameworks, Scrum practices, backlog management, sprint execution, facilitation, and continuous-improvement methods. Hands-on experience with Jira or a comparable enterprise Agile and task-tracking platform. Ability to facilitate productive discussions, resolve delivery friction, and communicate effectively with technical and nontechnical stakeholders. Ability to obtain and maintain FAA Contractor Personnel Suitability. Strong written, verbal, analytical, organizational, coaching, facilitation, and cross-functional collaboration skills. Preferred Qualifications: Agile or Scrum certification, such as Certified ScrumMaster, Professional Scrum Master, SAFe Scrum Master, or comparable credential. FAA or other federal experience and experience supporting regulated or mission-critical enterprise programs. Experience coaching multiple teams or supporting cross-team planning, dependencies, release coordination, and delivery reporting. Experience with hybrid delivery environments that combine Agile methods with federal governance, compliance, documentation, and lifecycle requirements. Familiarity with data platforms, cloud modernization, software development, data governance, AI/ML, business intelligence, or DevSecOps delivery environments. Technologies and Methods: Scrum, Agile coaching, Kanban, backlog refinement, estimation, and continuous improvement Jira and Government-approved task-tracking and reporting systems Sprint, flow, backlog-health, risk, dependency, and delivery metrics Cross-team planning, demonstrations, release coordination, retrospectives, and impediment management Enterprise software, data, cloud, analytics, governance, security, and platform delivery contexts Responsibilities: Facilitate sprint planning, daily coordination, backlog refinement, estimation, sprint reviews, retrospectives, and other Agile working sessions for technical delivery teams. Coach delivery teams, product owners, program stakeholders, and technical leads on Scrum and Agile principles, roles, ceremonies, flow, prioritization, and continuous improvement. Promote healthy backlog management by supporting clear user stories, acceptance criteria, prioritization, readiness, dependencies, and definition-of-done practices. Track sprint execution, commitments, risks, impediments, dependencies, and cross-team coordination needs and help drive timely resolution. Use burn-down, velocity, cycle-time, throughput, backlog-health, and related delivery indicators to improve predictability, transparency, quality, and stakeholder outcomes. Maintain accurate Agile artifacts, boards, dashboards, action items, and status information in Government-approved Jira or task-tracking systems. Coordinate demonstrations, release planning, milestone reviews, and cross-team planning with product, program, engineering, data, cloud, security, testing, governance, and documentation stakeholders. Identify recurring delivery constraints and facilitate root-cause discussions, experiments, and practical process improvements. Encourage self-organization, accountability, collaboration, and constructive problem solving while protecting teams from avoidable disruption. Support program reporting and centralized work tracking by providing clear, timely information on progress, blockers, risks, dependencies, and planned outcomes. Compensation and Benefits: At NDi, we value our team and are committed to retaining top talent by offering competitive benefits and compensation packages. Our employee benefits package includes comprehensive health, dental, vision, pet, and legal insurance. Our corporate benefits include 401(k) retirement matching, paid leave, paid holidays, and health and wellness programs. In addition, we provide employer-paid life and disability insurance, professional development, education benefits, and much more to ensure our team has the resources they need to thrive on and off the job. Veterans First Commitment: As a Service-Disabled Veteran-Owned Small Business (SDVOSB), NDi is dedicated to hiring veterans and providing a supportive work environment that honors their service while recognizing the unique skills and experiences they bring to our organization. Our Commitment: Qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability, protected veteran status or other characteristics protected by law. Apply Now: Take advantage of this unique opportunity to join one of the fastest-growing companies in Federal contracting!
Cobalt Benefits Group LLC
Manchester, New Hampshire
Description: Cobalt Benefits Group is seeking an Information Security Analyst to help safeguard information assets and technology services across cloud and on-premises environments. The analyst will monitor security controls, investigate alerts, coordinate remediation, and improve the organization's ability to prevent, detect, and respond to cybersecurity risk. The successful candidate will bring practical experience across multiple security domains rather than expertise in a single vendor platform. The role works closely with IT Operations, infrastructure, and application teams in a regulated environment. Security Operations & Incident Response Monitor managed detection and response, endpoint, identity, email, network, cloud, and security analytics platforms for suspicious activity. Triage and investigate alerts; document findings; coordinate containment, remediation, recovery, and post-incident follow-up. Analyze event, identity, endpoint, cloud, application, and network logs to distinguish security incidents from expected activity and false positives. Maintain incident response plans, investigation procedures, escalation paths and case documentation. Cloud, Identity & Secure Access Assess and improve security across public cloud subscriptions, storage, workloads, applications, and hybrid connectivity. Administer identity and access controls including multifactor authentication, conditional access, role-based access, privileged access, service identities, access reviews, and joiner-mover-leaver processes. Support Zero Trust and secure access services for private applications. Partner with administrators and engineers to design secure access for cloud data platforms, application hosting, and future AI-enabled services. Data Protection, Human Risk & Insider Risk Operate data security posture management capabilities to discover sensitive data, excessive access, shadow data, orphaned files, and insecure sharing. Administer data loss prevention controls across email, endpoints, collaboration platforms, cloud services, applications, and file repositories. Support data discovery, classification, information protection, retention, encryption, and remediation workflows for regulated and confidential information. Administer security awareness training, phishing simulations, targeted education, completion tracking, and human-risk reporting. Endpoint, Network & Application Security Support endpoint detection and response, device security, mobile device management, application control, browser protection, and workstation security baselines. Coordinate vulnerability and exposure management across endpoints, servers, network devices, databases, applications, and cloud workloads and prioritize remediation through patching. Assess application and infrastructure changes for secure configuration, logging, access, data protection, and resilience requirements. Monitor security systems, including firewalls, intrusion detection systems, to detect and respond to security incidents in a timely manner. Collaborate on operating system, application, firmware, and security patching; validate remediation and document accepted exceptions. Resilience, Governance & Continuous Improvement Support backup, recovery, immutable storage, business continuity, and disaster recovery security requirements. Maintain policies, standards, procedures, diagrams, and inventories. Contribute to automation and repeatable analysis using scripting, query languages, and workflow integrations. Evaluate emerging security requirements for cloud, software-as-a-service, and AI Agents. Partner with business and technology stakeholders to establish AI governance, security controls, and risk management practices that enable the responsible use of generative AI, AI agents, automation, and machine-to-machine services. Contribute to the organization's AI Risk Management Framework (AI RMF) program by supporting AI inventory management, risk assessments, control validations, policy development, monitoring activities, and ongoing governance reviews. Requirements: Job Requirements Bachelor's degree in Cybersecurity, Computer Science, Information Technology, or a related field, or equivalent relevant experience. Three to five years of experience in security operations, cloud security, infrastructure security, or a comparable role. Hands-on experience investigating alerts and working across endpoint, identity, email, network, cloud, and data security controls. Experience with vulnerability assessment, remediation tracking, patch management, incident response, and security control validation. Understanding of data discovery, classification, data loss prevention, sensitive-information handling, and insider-risk concepts. Ability to explain technical findings, business impact, and recommended actions to both technical and non-technical audiences. Strong judgment, discretion, documentation, analytical thinking, and the ability to manage multiple priorities. Preferred Qualifications Experience in a regulated environment and familiarity with security or compliance frameworks such as NIST, MITRE ATT&CK, SOC 2, or HITRUST. Experience securing hybrid environments with cloud infrastructure, productivity platforms, on-premises systems, virtualized infrastructure, and software-as-a-service applications. Working knowledge of cloud security, identity governance, and hybrid infrastructure. Familiarity with security information and event management, extended detection and response, cloud security posture management, web application protection, and security orchestration. Experience with scripting or security analytics using PowerShell, query languages, or comparable automation methods. Relevant industry or cloud security certifications Equal Opportunity Employer, including disability/protected veterans Compensation details: 00 Yearly Salary PIef2d3b3d6-
09/27/2026
Full time
Description: Cobalt Benefits Group is seeking an Information Security Analyst to help safeguard information assets and technology services across cloud and on-premises environments. The analyst will monitor security controls, investigate alerts, coordinate remediation, and improve the organization's ability to prevent, detect, and respond to cybersecurity risk. The successful candidate will bring practical experience across multiple security domains rather than expertise in a single vendor platform. The role works closely with IT Operations, infrastructure, and application teams in a regulated environment. Security Operations & Incident Response Monitor managed detection and response, endpoint, identity, email, network, cloud, and security analytics platforms for suspicious activity. Triage and investigate alerts; document findings; coordinate containment, remediation, recovery, and post-incident follow-up. Analyze event, identity, endpoint, cloud, application, and network logs to distinguish security incidents from expected activity and false positives. Maintain incident response plans, investigation procedures, escalation paths and case documentation. Cloud, Identity & Secure Access Assess and improve security across public cloud subscriptions, storage, workloads, applications, and hybrid connectivity. Administer identity and access controls including multifactor authentication, conditional access, role-based access, privileged access, service identities, access reviews, and joiner-mover-leaver processes. Support Zero Trust and secure access services for private applications. Partner with administrators and engineers to design secure access for cloud data platforms, application hosting, and future AI-enabled services. Data Protection, Human Risk & Insider Risk Operate data security posture management capabilities to discover sensitive data, excessive access, shadow data, orphaned files, and insecure sharing. Administer data loss prevention controls across email, endpoints, collaboration platforms, cloud services, applications, and file repositories. Support data discovery, classification, information protection, retention, encryption, and remediation workflows for regulated and confidential information. Administer security awareness training, phishing simulations, targeted education, completion tracking, and human-risk reporting. Endpoint, Network & Application Security Support endpoint detection and response, device security, mobile device management, application control, browser protection, and workstation security baselines. Coordinate vulnerability and exposure management across endpoints, servers, network devices, databases, applications, and cloud workloads and prioritize remediation through patching. Assess application and infrastructure changes for secure configuration, logging, access, data protection, and resilience requirements. Monitor security systems, including firewalls, intrusion detection systems, to detect and respond to security incidents in a timely manner. Collaborate on operating system, application, firmware, and security patching; validate remediation and document accepted exceptions. Resilience, Governance & Continuous Improvement Support backup, recovery, immutable storage, business continuity, and disaster recovery security requirements. Maintain policies, standards, procedures, diagrams, and inventories. Contribute to automation and repeatable analysis using scripting, query languages, and workflow integrations. Evaluate emerging security requirements for cloud, software-as-a-service, and AI Agents. Partner with business and technology stakeholders to establish AI governance, security controls, and risk management practices that enable the responsible use of generative AI, AI agents, automation, and machine-to-machine services. Contribute to the organization's AI Risk Management Framework (AI RMF) program by supporting AI inventory management, risk assessments, control validations, policy development, monitoring activities, and ongoing governance reviews. Requirements: Job Requirements Bachelor's degree in Cybersecurity, Computer Science, Information Technology, or a related field, or equivalent relevant experience. Three to five years of experience in security operations, cloud security, infrastructure security, or a comparable role. Hands-on experience investigating alerts and working across endpoint, identity, email, network, cloud, and data security controls. Experience with vulnerability assessment, remediation tracking, patch management, incident response, and security control validation. Understanding of data discovery, classification, data loss prevention, sensitive-information handling, and insider-risk concepts. Ability to explain technical findings, business impact, and recommended actions to both technical and non-technical audiences. Strong judgment, discretion, documentation, analytical thinking, and the ability to manage multiple priorities. Preferred Qualifications Experience in a regulated environment and familiarity with security or compliance frameworks such as NIST, MITRE ATT&CK, SOC 2, or HITRUST. Experience securing hybrid environments with cloud infrastructure, productivity platforms, on-premises systems, virtualized infrastructure, and software-as-a-service applications. Working knowledge of cloud security, identity governance, and hybrid infrastructure. Familiarity with security information and event management, extended detection and response, cloud security posture management, web application protection, and security orchestration. Experience with scripting or security analytics using PowerShell, query languages, or comparable automation methods. Relevant industry or cloud security certifications Equal Opportunity Employer, including disability/protected veterans Compensation details: 00 Yearly Salary PIef2d3b3d6-
MANTECH seeks a motivated, career and customer-oriented Senior Information System Security Engineer (ISSE) to join our team in Huntsville, AL. Responsibilities include, but are not limited to: Define and implement cybersecurity requirements, architectures, and secure system designs across information systems and network environments Design, develop, and integrate security solutions, including Cross Domain Solutions (CDS), to support secure data flow and system interoperability Implement network security controls and countermeasures to ensure confidentiality, integrity, availability, authentication, and non-repudiation Identify, assess, and mitigate system and network vulnerabilities, recommending enhancements to strengthen overall security posture Maintain and track vulnerability data, POA&Ms, and remediation activities using GRC and enterprise tracking tools Lead stakeholder engagement through office hours, guidance, and updated procedures to support vulnerability management and compliance efforts Provide rapid response to data calls, RFIs, and leadership inquiries, including escalation and reporting of high-risk or non-compliant remediation actions Minimum Qualifications: Must meet one of the following levels of experience: A high school diploma/GED and 14 years' experience, an Associate's degree and 10 years' experience, a Bachelors degree and 8 years' experience, or a Master's and 6 years' experience. Hold at least one of the following certifications: Certified Information Systems Security Professional (CISSP) (or Associate), CompTIA Advanced Security Practitioner (CASP) CE, Certified Secure Software Lifecycle Professional (CSSLP), CISSP- Information System Security Engineering Professional (ISSEP), Certified Information Security Manager (CISM), or CISSP- Information System Security Architecture Professional (ISSAP). Familiarity with the use and operation of security tools including: Tenable Nessus and/or Security Center, IBM Guardium, HP WeblInspect, Network Mapper (NMAP), and/or similar applications. Working knowledge of the National Institute of Standards and Technology (NIST) Risk Management Framework (RMF) and ATO processes. Experience with vulnerability management programs, including identification, tracking, and remediation of CVEs and Known Exploited Vulnerabilities (KEVs). Knowledge of federal cybersecurity directives and frameworks, including CISA Emergency Directives (EDs), Binding Operational Directives (BODs), and DOJ Vulnerability Patch Requirements (VPRs). Experience with Risk Management Framework (RMF), POA&M tracking, and governance, risk, and compliance (GRC) tools. Preferred Qualifications: Degree in Computer Science, Cybersecurity, or other cyber discipline. Ability to operate in high-tempo environments with rapid response requirements and strict deadlines. Strong organizational and process improvement skills to support reporting, tracking, and compliance initiatives. Security Clearance Requirements: Must have an active TOP SECRET security clearance and be willing and able to obtain SCI eligibility prior to start. Selected candidate must be willing to undergo a Polygraph. Physical Requirements: Must be able to remain in a stationary position 50% Needs to occasionally move about inside the office to access file cabinets, office machinery, etc. Constantly operates a computer and other office productivity machinery, such as a calculator, copy machine and computer printer Often positions self to maintain computers in the lab, including under the desks and in the server closet Frequently communicates with co-workers, management and customers, which may involve delivering presentations. Must be able to exchange accurate information in these situations
09/27/2026
Full time
MANTECH seeks a motivated, career and customer-oriented Senior Information System Security Engineer (ISSE) to join our team in Huntsville, AL. Responsibilities include, but are not limited to: Define and implement cybersecurity requirements, architectures, and secure system designs across information systems and network environments Design, develop, and integrate security solutions, including Cross Domain Solutions (CDS), to support secure data flow and system interoperability Implement network security controls and countermeasures to ensure confidentiality, integrity, availability, authentication, and non-repudiation Identify, assess, and mitigate system and network vulnerabilities, recommending enhancements to strengthen overall security posture Maintain and track vulnerability data, POA&Ms, and remediation activities using GRC and enterprise tracking tools Lead stakeholder engagement through office hours, guidance, and updated procedures to support vulnerability management and compliance efforts Provide rapid response to data calls, RFIs, and leadership inquiries, including escalation and reporting of high-risk or non-compliant remediation actions Minimum Qualifications: Must meet one of the following levels of experience: A high school diploma/GED and 14 years' experience, an Associate's degree and 10 years' experience, a Bachelors degree and 8 years' experience, or a Master's and 6 years' experience. Hold at least one of the following certifications: Certified Information Systems Security Professional (CISSP) (or Associate), CompTIA Advanced Security Practitioner (CASP) CE, Certified Secure Software Lifecycle Professional (CSSLP), CISSP- Information System Security Engineering Professional (ISSEP), Certified Information Security Manager (CISM), or CISSP- Information System Security Architecture Professional (ISSAP). Familiarity with the use and operation of security tools including: Tenable Nessus and/or Security Center, IBM Guardium, HP WeblInspect, Network Mapper (NMAP), and/or similar applications. Working knowledge of the National Institute of Standards and Technology (NIST) Risk Management Framework (RMF) and ATO processes. Experience with vulnerability management programs, including identification, tracking, and remediation of CVEs and Known Exploited Vulnerabilities (KEVs). Knowledge of federal cybersecurity directives and frameworks, including CISA Emergency Directives (EDs), Binding Operational Directives (BODs), and DOJ Vulnerability Patch Requirements (VPRs). Experience with Risk Management Framework (RMF), POA&M tracking, and governance, risk, and compliance (GRC) tools. Preferred Qualifications: Degree in Computer Science, Cybersecurity, or other cyber discipline. Ability to operate in high-tempo environments with rapid response requirements and strict deadlines. Strong organizational and process improvement skills to support reporting, tracking, and compliance initiatives. Security Clearance Requirements: Must have an active TOP SECRET security clearance and be willing and able to obtain SCI eligibility prior to start. Selected candidate must be willing to undergo a Polygraph. Physical Requirements: Must be able to remain in a stationary position 50% Needs to occasionally move about inside the office to access file cabinets, office machinery, etc. Constantly operates a computer and other office productivity machinery, such as a calculator, copy machine and computer printer Often positions self to maintain computers in the lab, including under the desks and in the server closet Frequently communicates with co-workers, management and customers, which may involve delivering presentations. Must be able to exchange accurate information in these situations
MANTECH seeks a motivated, career and customer-oriented Technical Project Manager to join our team at Quantico, VA. Responsibilities include but are not limited to: Coordinates the procurement, shipping, installation, configuration, and integration of multi-network systems for a global USMC program, driving a seamless "DISA-to-Desktop" architecture. Plans, designs, and maintains the connectivity of enterprise system and network assets, ensuring compliance and secure operations across classified networks and domains Ensures all systems, servers, network switches, and routers are operational, properly configured, and strictly compliant with DISA STIG requirements; performs regular maintenance and troubleshooting. Configures, maintains, and monitors firewalls, IDS/IPS, and Cisco Identity Services Engine (ISE) for access control, implementing security measures tailored for specialized USMC systems. Supports the planning and implementation of enterprise service connections across domains, facilitating secure cloud computing architecture (SCCA), cross-domain solutions, and guards. Collaborates with ISSOs and Cybersecurity Services Leads in the Risk Management Framework (RMF) process, providing inputs and documentation, and mentors/trains other NOC staff and Junior Engineers. Minimum Qualifications: BA/BS in a relevant technical field (Four (4) years of additional relevant experience can be substituted in lieu of degree); 9+ years of overall IT experience with at least 5 years of that time spent working in a relevant Systems/Network Engineering role. Deep understanding of systems integration, networking protocols (TCP/IP, DNS, DHCP), routing, and comprehensive network security principles. Expertise in configuring and managing enterprise devices (routers, switches, firewalls) with hands-on experience in Cisco technologies (e.g., IOS, NX-OS) and security appliances (e.g., ASA firewalls, ISE). Proven experience securing classified networks (SIPR, NIPR, JWICS) and implementing DISA STIGs; strong familiarity with NIST frameworks and RMF. Must hold an active DoD 8570.01-M IAT Level II certification at minimum. Desired Qualifications: Master's degree in Computer Science, IT, Systems Engineering, or a relevant discipline. Experience implementing multi-vendor VoIP and VTC products in RMF environments. Experience with scripting/automation tools for system management; familiarity with the ITIL framework (ITIL Foundation certificate desired). Relevant high-level networking or systems certifications (e.g., Cisco CCNP, CCIE, CompTIA Security+, Microsoft, or Red Hat). Prior experience supporting a USMC enterprise program, or experience at a DoD Combatant Command (e.g., INDOPACOM, CENTCOM, CYBERCOM). Clearance Requirements: Must have a current/active TS/SCI clearance Must be eligible to obtain Special Access Program (SAP) Travel Requirements: 25% CONUS and OCONUS Physical Requirements: The person in this position must be able to remain in a stationary position 50% of the time. Occasionally move about inside the office to access file cabinets, office machinery, or to communicate with co-workers, management, and customers, via email, phone, and or virtual communication, which may involve delivering presentations.
09/27/2026
Full time
MANTECH seeks a motivated, career and customer-oriented Technical Project Manager to join our team at Quantico, VA. Responsibilities include but are not limited to: Coordinates the procurement, shipping, installation, configuration, and integration of multi-network systems for a global USMC program, driving a seamless "DISA-to-Desktop" architecture. Plans, designs, and maintains the connectivity of enterprise system and network assets, ensuring compliance and secure operations across classified networks and domains Ensures all systems, servers, network switches, and routers are operational, properly configured, and strictly compliant with DISA STIG requirements; performs regular maintenance and troubleshooting. Configures, maintains, and monitors firewalls, IDS/IPS, and Cisco Identity Services Engine (ISE) for access control, implementing security measures tailored for specialized USMC systems. Supports the planning and implementation of enterprise service connections across domains, facilitating secure cloud computing architecture (SCCA), cross-domain solutions, and guards. Collaborates with ISSOs and Cybersecurity Services Leads in the Risk Management Framework (RMF) process, providing inputs and documentation, and mentors/trains other NOC staff and Junior Engineers. Minimum Qualifications: BA/BS in a relevant technical field (Four (4) years of additional relevant experience can be substituted in lieu of degree); 9+ years of overall IT experience with at least 5 years of that time spent working in a relevant Systems/Network Engineering role. Deep understanding of systems integration, networking protocols (TCP/IP, DNS, DHCP), routing, and comprehensive network security principles. Expertise in configuring and managing enterprise devices (routers, switches, firewalls) with hands-on experience in Cisco technologies (e.g., IOS, NX-OS) and security appliances (e.g., ASA firewalls, ISE). Proven experience securing classified networks (SIPR, NIPR, JWICS) and implementing DISA STIGs; strong familiarity with NIST frameworks and RMF. Must hold an active DoD 8570.01-M IAT Level II certification at minimum. Desired Qualifications: Master's degree in Computer Science, IT, Systems Engineering, or a relevant discipline. Experience implementing multi-vendor VoIP and VTC products in RMF environments. Experience with scripting/automation tools for system management; familiarity with the ITIL framework (ITIL Foundation certificate desired). Relevant high-level networking or systems certifications (e.g., Cisco CCNP, CCIE, CompTIA Security+, Microsoft, or Red Hat). Prior experience supporting a USMC enterprise program, or experience at a DoD Combatant Command (e.g., INDOPACOM, CENTCOM, CYBERCOM). Clearance Requirements: Must have a current/active TS/SCI clearance Must be eligible to obtain Special Access Program (SAP) Travel Requirements: 25% CONUS and OCONUS Physical Requirements: The person in this position must be able to remain in a stationary position 50% of the time. Occasionally move about inside the office to access file cabinets, office machinery, or to communicate with co-workers, management, and customers, via email, phone, and or virtual communication, which may involve delivering presentations.
MANTECH seeks a motivated, career and customer-oriented Cybersecurity System Security Engineer (CSSE) - III to join our team in El Segundo, CA. In this role, you will provide critical support within Special Access Programs (SAPs) supporting SSC and AFSPC acquisition programs. You will deliver daily technical support across Collateral, Sensitive Compartmented Information (SCI), and SAP activities to ensure systems meet essential NIST Cybersecurity requirements for system assessment and authorization in a full-time, on-site environment. Responsibilities Lead a team of System Security Engineers and Certification Analysts ensuring customer national and international security interests are protected during acquisition system design and testing. Chair and co-chair customer and SAP community Cybersecurity working groups while actively participating in Systems Security Engineering IPT reviews. Perform oversight for the development, implementation, and evaluation of information system security program policies with emphasis on SAP network infrastructures. Provide expert-level consultation and technical services on all aspects of Information Security and system designs. Develop and provide Cybersecurity risk management recommendations, Program Protection Plans, and Cybersecurity Strategies to the customer. Assist with site activation activities, design reviews, and test and evaluation of systems. Work directly with approval and accreditation authorities to successfully obtain systems' Authorization to Operate (ATO). Minimum Qualifications Bachelor's degree in a related discipline an additional 4 years of related experience may be accepted in lieu of degree. 12+ years of total experience, including a minimum of 8 years of experience within an SCI or SAR environment. 4 years of direct Special Access Program (SAP) relevant experience. Must meet DoD Directive 8570.01-M/8140 requirements for Information Assurance Technician (IAT) Level 3 and Information Assurance Manager (IAM) Level 3 within 6 months of hire. Full understanding of Risk Management Framework (RMF) and Joint SAP Implementation Guide (JSIG) processes for system accreditation. Preferred Qualifications Familiarity with DoD security policies, manuals, and appropriate ICDs, JAFANs, and related guiding policy documents. Proven ability to work in a dynamic environment and effectively interact with DoD, military, civilian, and industry partners. Strong working knowledge of Microsoft Office applications including Word, PowerPoint, and Excel. Possess a high degree of originality, creativity, and initiative while requiring minimal supervision. Clearance Requirements Current Top-Secret Clearance with SCI Eligibility. Must be eligible for access to Special Access Programs (SAP). Willingness to submit to a Counterintelligence polygraph. Physical Requirements Must be willing to travel within the organizational Area of Responsibility (AOR), including both air and ground transportation. Person in this position may remain in a stationary position 50% of the time in closed-area offices. Must be able to occasionally move about inside and outside of the office to access files, cabinets, and safes, or install and remove computer-related equipment.
09/27/2026
Full time
MANTECH seeks a motivated, career and customer-oriented Cybersecurity System Security Engineer (CSSE) - III to join our team in El Segundo, CA. In this role, you will provide critical support within Special Access Programs (SAPs) supporting SSC and AFSPC acquisition programs. You will deliver daily technical support across Collateral, Sensitive Compartmented Information (SCI), and SAP activities to ensure systems meet essential NIST Cybersecurity requirements for system assessment and authorization in a full-time, on-site environment. Responsibilities Lead a team of System Security Engineers and Certification Analysts ensuring customer national and international security interests are protected during acquisition system design and testing. Chair and co-chair customer and SAP community Cybersecurity working groups while actively participating in Systems Security Engineering IPT reviews. Perform oversight for the development, implementation, and evaluation of information system security program policies with emphasis on SAP network infrastructures. Provide expert-level consultation and technical services on all aspects of Information Security and system designs. Develop and provide Cybersecurity risk management recommendations, Program Protection Plans, and Cybersecurity Strategies to the customer. Assist with site activation activities, design reviews, and test and evaluation of systems. Work directly with approval and accreditation authorities to successfully obtain systems' Authorization to Operate (ATO). Minimum Qualifications Bachelor's degree in a related discipline an additional 4 years of related experience may be accepted in lieu of degree. 12+ years of total experience, including a minimum of 8 years of experience within an SCI or SAR environment. 4 years of direct Special Access Program (SAP) relevant experience. Must meet DoD Directive 8570.01-M/8140 requirements for Information Assurance Technician (IAT) Level 3 and Information Assurance Manager (IAM) Level 3 within 6 months of hire. Full understanding of Risk Management Framework (RMF) and Joint SAP Implementation Guide (JSIG) processes for system accreditation. Preferred Qualifications Familiarity with DoD security policies, manuals, and appropriate ICDs, JAFANs, and related guiding policy documents. Proven ability to work in a dynamic environment and effectively interact with DoD, military, civilian, and industry partners. Strong working knowledge of Microsoft Office applications including Word, PowerPoint, and Excel. Possess a high degree of originality, creativity, and initiative while requiring minimal supervision. Clearance Requirements Current Top-Secret Clearance with SCI Eligibility. Must be eligible for access to Special Access Programs (SAP). Willingness to submit to a Counterintelligence polygraph. Physical Requirements Must be willing to travel within the organizational Area of Responsibility (AOR), including both air and ground transportation. Person in this position may remain in a stationary position 50% of the time in closed-area offices. Must be able to occasionally move about inside and outside of the office to access files, cabinets, and safes, or install and remove computer-related equipment.
MANTECH seeks a motivated, career and customer-oriented Senior Cloud Information System Security Engineer (ISSE) to join our team in Washington, D.C Responsibilities include, but are not limited to: Identify information protection needs for an IS and Network Environment. Define IS and Network Environment security requirements in accordance with applicable cybersecurity requirements Design security architectures for use within the IS and Network Environment. Design and develop cybersecurity-enabled products for use within an IS and Network Environment Integrate and/or implement security with Cross Domain Solutions (CDS) for use within an IS and Network Environment Develop and implement security designs for new or existing network system(s). Ensure that the design of hardware, operating systems, and software applications adequately address cybersecurity requirements for the IS and Network Environment Design, develop, and implement network security measures that provide confidentiality, integrity, availability, authentication, and non-repudiation. Design, develop, and implement specific cybersecurity countermeasures for the IS and Network Environment Develop interface specifications for the IS and Network Environment. Develop approaches to mitigate IS and Network Environment vulnerabilities and recommend changes to network or network system components as needed Ensure that network system(s) designs support the incorporation of FBI directed cybersecurity vulnerability solutions Minimum Qualifications: Must meet one of the following levels of experience: A high school diploma/GED and 14 years' experience, an Associate's degree and 10 years' experience, a Bachelors degree and 8 years' experience, or a Master's and 6 years' experience. Must possess a current DoD 8140 level III certification Familiarity with the use and operation of security tools including: Tenable Nessus and/or Security Center, IBM Guardium, HP WeblInspect, Network Mapper (NMAP), and/or similar applications. Working knowledge of the National Institute of Standards and Technology (NIST) Risk Management Framework (RMF) and ATO processes. Preferred Qualifications: Degree in Computer Science, Cybersecurity, or other cyber discipline. Clearance Requirements: Must have a current/active Top Secret security clearance and be willing and able to obtain SCI eligibility prior to start. Selected candidate must be willing to undergo a Polygraph. Physical Requirements: Must be able to remain in a stationary position 50% Needs to occasionally move about inside the office to access file cabinets, office machinery, etc. Constantly operates a computer and other office productivity machinery, such as a calculator, copy machine and computer printer Often positions self to maintain computers in the lab, including under the desks and in the server closet Frequently communicates with co-workers, management and customers, which may involve delivering presentations. Must be able to exchange accurate information in these situations
09/27/2026
Full time
MANTECH seeks a motivated, career and customer-oriented Senior Cloud Information System Security Engineer (ISSE) to join our team in Washington, D.C Responsibilities include, but are not limited to: Identify information protection needs for an IS and Network Environment. Define IS and Network Environment security requirements in accordance with applicable cybersecurity requirements Design security architectures for use within the IS and Network Environment. Design and develop cybersecurity-enabled products for use within an IS and Network Environment Integrate and/or implement security with Cross Domain Solutions (CDS) for use within an IS and Network Environment Develop and implement security designs for new or existing network system(s). Ensure that the design of hardware, operating systems, and software applications adequately address cybersecurity requirements for the IS and Network Environment Design, develop, and implement network security measures that provide confidentiality, integrity, availability, authentication, and non-repudiation. Design, develop, and implement specific cybersecurity countermeasures for the IS and Network Environment Develop interface specifications for the IS and Network Environment. Develop approaches to mitigate IS and Network Environment vulnerabilities and recommend changes to network or network system components as needed Ensure that network system(s) designs support the incorporation of FBI directed cybersecurity vulnerability solutions Minimum Qualifications: Must meet one of the following levels of experience: A high school diploma/GED and 14 years' experience, an Associate's degree and 10 years' experience, a Bachelors degree and 8 years' experience, or a Master's and 6 years' experience. Must possess a current DoD 8140 level III certification Familiarity with the use and operation of security tools including: Tenable Nessus and/or Security Center, IBM Guardium, HP WeblInspect, Network Mapper (NMAP), and/or similar applications. Working knowledge of the National Institute of Standards and Technology (NIST) Risk Management Framework (RMF) and ATO processes. Preferred Qualifications: Degree in Computer Science, Cybersecurity, or other cyber discipline. Clearance Requirements: Must have a current/active Top Secret security clearance and be willing and able to obtain SCI eligibility prior to start. Selected candidate must be willing to undergo a Polygraph. Physical Requirements: Must be able to remain in a stationary position 50% Needs to occasionally move about inside the office to access file cabinets, office machinery, etc. Constantly operates a computer and other office productivity machinery, such as a calculator, copy machine and computer printer Often positions self to maintain computers in the lab, including under the desks and in the server closet Frequently communicates with co-workers, management and customers, which may involve delivering presentations. Must be able to exchange accurate information in these situations
Job Description Job Description Palo Alto Firewall Engineer / SME (PCNSE) Location: Springfield, VA - on site Time Type: Full time, Exempt Clearance Required to Start: Active TS/SCI (U.S. citizenship required) Additional Requirement: Must be able to obtain and maintain a U.S. Government polygraph Travel: Up to 15%, local and CONUS Salary Range: $117,000 - $128,000 Own the Palo Alto estate - legacy iron through Prisma and Panorama. RISA is hiring a Palo Alto SME to be the focal point for every Palo Alto task, operation, and project on the Network Security Services team supporting an Intelligence Community customer. The work spans both ends of the estate: PA-3000 and PA-5000 hardware refreshes and legacy CLI on one side, Prisma Access, VM-Series, and Cortex on the other. You will talk to the owner here, not a recruiting queue. What You Will Do Serve as the lead technical authority for administering, configuring, and troubleshooting Palo Alto NGFWs across a hybrid enterprise. Lead the design, analysis, testing, and implementation of secure network architectures on the Palo Alto stack. Manage the full hardware and software lifecycle, including complex refreshes and PAN-OS upgrades on legacy platforms. Run Panorama for centralized policy management across a fleet of physical and virtual firewalls. Configure master-level security profiles - App-ID, User-ID, Content-ID, SSL Decryption, and WildFire. Own configuration management processes and SOPs for all Palo Alto platforms. Mentor junior engineers and act as the escalation point for complex troubleshooting. Liaise with contract, customer, and government DAA on network security status, policies, and procedures. What You'll Bring U.S. citizenship and an active TS/SCI. Ability to successfully obtain and maintain a U.S. Government polygraph. Education and experience, per the contract labor category criteria: Bachelor's degree in a field applicable to the position plus 6 years of relevant experience. Equivalents accepted - Master's plus 4, Associate's plus 8, or High School diploma/GED plus 10. 7+ years hands-on administering, configuring, and troubleshooting Palo Alto NGFWs in large-scale enterprise or global environments. Active PCNSE certification. DoD 8140.01 and 8570.01-M IAT Level II (e.g. Security+ CE), and CSSP Infrastructure Support within 120 days of start. Deep practical knowledge of legacy Gen 2/Gen 3 hardware - PA-3000 and PA-5000 series, legacy CLI, physical troubleshooting, line-card replacement. Prisma Access (SASE), Prisma SD-WAN, and VM-Series in AWS, Azure, or GCP. Panorama template and device-group inheritance across a hybrid fleet. Advanced BGP, OSPF, IPSec VPN, and NAT. Nice to Have PCNSC or Prisma Certified SASE Professional (PCSAE). Python, plus firewall automation with Ansible, Terraform, or the Palo Alto XML/REST APIs. Cortex XDR or XSOAR; Expedition for legacy rule migration to App-ID policy. Zero Trust Network Access architecture; F5 (APM, AFM), Juniper SRX, or Cisco FTD/ASA. About RISA Rolston Information Systems Assurance (RISA) is a Service-Disabled Veteran-Owned Small Business that has supported federal defense and intelligence cybersecurity missions for more than seventeen years. We are small on purpose: direct access to leadership, a real say in how the work gets done, and none of the layers that slow large primes down. Benefits Medical, dental, and vision insurance; 401(k) and Roth; Paid Time Off; and 11 paid Federal Holidays. RISA is an Equal Opportunity Employer.
09/27/2026
Full time
Job Description Job Description Palo Alto Firewall Engineer / SME (PCNSE) Location: Springfield, VA - on site Time Type: Full time, Exempt Clearance Required to Start: Active TS/SCI (U.S. citizenship required) Additional Requirement: Must be able to obtain and maintain a U.S. Government polygraph Travel: Up to 15%, local and CONUS Salary Range: $117,000 - $128,000 Own the Palo Alto estate - legacy iron through Prisma and Panorama. RISA is hiring a Palo Alto SME to be the focal point for every Palo Alto task, operation, and project on the Network Security Services team supporting an Intelligence Community customer. The work spans both ends of the estate: PA-3000 and PA-5000 hardware refreshes and legacy CLI on one side, Prisma Access, VM-Series, and Cortex on the other. You will talk to the owner here, not a recruiting queue. What You Will Do Serve as the lead technical authority for administering, configuring, and troubleshooting Palo Alto NGFWs across a hybrid enterprise. Lead the design, analysis, testing, and implementation of secure network architectures on the Palo Alto stack. Manage the full hardware and software lifecycle, including complex refreshes and PAN-OS upgrades on legacy platforms. Run Panorama for centralized policy management across a fleet of physical and virtual firewalls. Configure master-level security profiles - App-ID, User-ID, Content-ID, SSL Decryption, and WildFire. Own configuration management processes and SOPs for all Palo Alto platforms. Mentor junior engineers and act as the escalation point for complex troubleshooting. Liaise with contract, customer, and government DAA on network security status, policies, and procedures. What You'll Bring U.S. citizenship and an active TS/SCI. Ability to successfully obtain and maintain a U.S. Government polygraph. Education and experience, per the contract labor category criteria: Bachelor's degree in a field applicable to the position plus 6 years of relevant experience. Equivalents accepted - Master's plus 4, Associate's plus 8, or High School diploma/GED plus 10. 7+ years hands-on administering, configuring, and troubleshooting Palo Alto NGFWs in large-scale enterprise or global environments. Active PCNSE certification. DoD 8140.01 and 8570.01-M IAT Level II (e.g. Security+ CE), and CSSP Infrastructure Support within 120 days of start. Deep practical knowledge of legacy Gen 2/Gen 3 hardware - PA-3000 and PA-5000 series, legacy CLI, physical troubleshooting, line-card replacement. Prisma Access (SASE), Prisma SD-WAN, and VM-Series in AWS, Azure, or GCP. Panorama template and device-group inheritance across a hybrid fleet. Advanced BGP, OSPF, IPSec VPN, and NAT. Nice to Have PCNSC or Prisma Certified SASE Professional (PCSAE). Python, plus firewall automation with Ansible, Terraform, or the Palo Alto XML/REST APIs. Cortex XDR or XSOAR; Expedition for legacy rule migration to App-ID policy. Zero Trust Network Access architecture; F5 (APM, AFM), Juniper SRX, or Cisco FTD/ASA. About RISA Rolston Information Systems Assurance (RISA) is a Service-Disabled Veteran-Owned Small Business that has supported federal defense and intelligence cybersecurity missions for more than seventeen years. We are small on purpose: direct access to leadership, a real say in how the work gets done, and none of the layers that slow large primes down. Benefits Medical, dental, and vision insurance; 401(k) and Roth; Paid Time Off; and 11 paid Federal Holidays. RISA is an Equal Opportunity Employer.
MANTECH seeks a motivated, career and customer-oriented Senior Software Engineer in the Fort Meade, MD area. This is an onsite position. Responsibilities include, but are not limited to: Cyber Security and development expertise to design, test, implement, and manage safeguards against cyberattacks of the system to include Identify, mitigate, and resolve vulnerabilities within existing security systems. Responsible for designing, engineering, analyzing, and developing software systems; work directly with penetration testers to perform penetration tests and assess potential security problems. Develop organization wide security measures. Prepare performance reports and communicate system status to keep users and leadership informed. Maintain quality service by following organization standards, attending educational workshops for increased technical knowledge, and reviewing publications. Designs, analyzes, and develops the software delivery processes (including DevOps pipelines). models and analyzes the software development and deployment processes. Engage with Government leaders in defining the context, problem space, and vision to determine capabilities, priorities, roadmaps, Transformation Plans, and next steps. Develops Agile processes, plans, and architectures to support software development, analysis, and operations. Minimum Qualifications: Bachelor's degree, DoD 8570.01-m IAT Level II Certification and 9 years of position-relevant work experience Experience with C, C#, C++, SQL, or Java; experience with Jira, Confluence, Ghidra and GIT. Experience and knowledge of operating software programs, configuring hardware devices and developing critical procedural steps, Strong knowledge in a Linux environment developing and managing code requiring hands on experience with Linux internals along with Python (interpreted language) and C (compiled language). Knowledge with applications to complete tasks with underlying systems that run devices and control networks. Familiarity of vulnerability research and reverse engineering with CNO development. Knowledge in cybersecurity to safeguard against threats will be the key in identifying, mitigating, and resolving vulnerabilities on this mission. Preferred Qualifications: Experience with embedded system vulnerability development. Experience working within a Scrum team or agile environment. Security Clearance Requirements: Must have an active TS/SCI security clearance Physical Requirements: Must be able to remain in a stationary position 50%. Needs to occasionally move about inside the office to access file cabinets, office machinery, etc. Constantly operates a computer and other office productivity machinery, such as a calculator, copy machine and computer printer. Frequently communicates with co-workers, management, and customers, which may involve delivering presentations. Must be able to exchange accurate information in these situations.
09/27/2026
Full time
MANTECH seeks a motivated, career and customer-oriented Senior Software Engineer in the Fort Meade, MD area. This is an onsite position. Responsibilities include, but are not limited to: Cyber Security and development expertise to design, test, implement, and manage safeguards against cyberattacks of the system to include Identify, mitigate, and resolve vulnerabilities within existing security systems. Responsible for designing, engineering, analyzing, and developing software systems; work directly with penetration testers to perform penetration tests and assess potential security problems. Develop organization wide security measures. Prepare performance reports and communicate system status to keep users and leadership informed. Maintain quality service by following organization standards, attending educational workshops for increased technical knowledge, and reviewing publications. Designs, analyzes, and develops the software delivery processes (including DevOps pipelines). models and analyzes the software development and deployment processes. Engage with Government leaders in defining the context, problem space, and vision to determine capabilities, priorities, roadmaps, Transformation Plans, and next steps. Develops Agile processes, plans, and architectures to support software development, analysis, and operations. Minimum Qualifications: Bachelor's degree, DoD 8570.01-m IAT Level II Certification and 9 years of position-relevant work experience Experience with C, C#, C++, SQL, or Java; experience with Jira, Confluence, Ghidra and GIT. Experience and knowledge of operating software programs, configuring hardware devices and developing critical procedural steps, Strong knowledge in a Linux environment developing and managing code requiring hands on experience with Linux internals along with Python (interpreted language) and C (compiled language). Knowledge with applications to complete tasks with underlying systems that run devices and control networks. Familiarity of vulnerability research and reverse engineering with CNO development. Knowledge in cybersecurity to safeguard against threats will be the key in identifying, mitigating, and resolving vulnerabilities on this mission. Preferred Qualifications: Experience with embedded system vulnerability development. Experience working within a Scrum team or agile environment. Security Clearance Requirements: Must have an active TS/SCI security clearance Physical Requirements: Must be able to remain in a stationary position 50%. Needs to occasionally move about inside the office to access file cabinets, office machinery, etc. Constantly operates a computer and other office productivity machinery, such as a calculator, copy machine and computer printer. Frequently communicates with co-workers, management, and customers, which may involve delivering presentations. Must be able to exchange accurate information in these situations.
Job Description Job Description Network Security Systems Manager - Q Clearance Required Summary: We are seeking an experienced Network Security Systems Manager to lead the administration, security, and operations of network security systems supporting LAN/WAN environments. The ideal candidate will have extensive experience managing enterprise network security infrastructure, leading technical security teams, and implementing security policies, controls, and best practices. This role requires strong technical judgment, leadership skills, and the ability to plan, prioritize, and execute network security initiatives in a complex government environment. Location: Washington, DC or Gaithersburg, MD Salary: Up to $178,000 Clearance: Active Q Clearance Required Education: Bachelor's degree from an accredited university or college in Information Technology with an emphasis in Cybersecurity or Information Assurance, Computer Science, or a related field. Required Certifications: One or more of the following certifications or equivalent: GIAC Information Security Professional (GISP) ISC2 Certified Information Systems Security Professional (CISSP) GIAC Security Essentials (GSEC) Experience: Minimum of five (5) years of experience managing network security systems in LAN/WAN environments. Experience leading network security administration staff and technical teams. Experience managing enterprise network security infrastructure, systems, and technologies. Broad knowledge of network security concepts, practices, principles, and procedures. Experience planning, implementing, and maintaining network security solutions. Experience identifying and addressing network security risks, vulnerabilities, and operational issues. Ability to apply extensive technical experience and sound judgment to plan and accomplish organizational goals. Experience developing and implementing security policies, procedures, standards, and controls. Strong understanding of network security architecture, access controls, firewalls, intrusion detection/prevention, VPNs, and secure network communications. Experience supporting security monitoring, incident response, vulnerability management, and network security assessments. Ability to lead technical teams, prioritize workload, manage competing requirements, and communicate effectively with technical and management stakeholders. Preferred Certifications: Certified Information Security Manager (CISM) ISC2 Certified Cloud Security Professional (CCSP) GIAC Network Forensic Analyst (GNFA) GIAC Certified Intrusion Analyst (GCIA) GIAC Certified Incident Handler (GCIH) GIAC Certified Firewall Analyst (GCFW) Cisco Certified Network Professional - Security (CCNP Security) Fortinet Certified Professional or equivalent Fortinet certification Palo Alto Networks Certified Network Security Engineer (PCNSE) or equivalent CompTIA Security+ CompTIA CySA+ ISACA Certified in Risk and Information Systems Control (CRISC) Certified Ethical Hacker (CEH) Juniper Networks security certification or equivalent ActioNet is a CMMI-DEV Level 4, CMMI-SVC Level 4, ISO 20000, ISO 27001, ISO 9001, HDI-certified, woman-owned IT Solutions Provider with strong qualifications and expertise in Agile Software Engineering, Cloud Solutions, Cyber Security and IT Managed Services. With 24+ years of stellar past performance, ActioNet is the premier Trusted Innogrator! Why ActioNet? At ActioNet, our Passion for Quality is at the heart of everything we do: We are committed to make ActioNet a great place to work and continue to invest in our ActioNeters We are committed to our customers by driving and sustaining Service Delivery Excellence We are committed to give back to our Community, help others and make the world a better place for our next generation ActioNet is proud to be named as a Top Workplace for the ninth year in a row (2014 - 2022). We have 98% of Customer retention rate. We are passionate about the inspirational missions of our customers and we entrust our employees and teams to deliver exceptional performance to enable the safety, security, health and well-being of our nation. What's in It For You? As an ActioNeter, you get to be part of exceptional team and a corporate culture that nurtures mutual success for our customers, employees and our communities. We give you the tools to be successful; all you need to do is bring your best ideas, your energy and a desire to develop your skills, experience and career. Are you ready to make a difference? ActioNet is an equal opportunity employer and value diversity at our company. We do not discriminate on the basis of race, religion, color, national origin, gender, sexual orientation, age, marital status, veteran status, or disability status. Direct Applicants, only. No Agencies, No third-party recruiters, please
09/27/2026
Full time
Job Description Job Description Network Security Systems Manager - Q Clearance Required Summary: We are seeking an experienced Network Security Systems Manager to lead the administration, security, and operations of network security systems supporting LAN/WAN environments. The ideal candidate will have extensive experience managing enterprise network security infrastructure, leading technical security teams, and implementing security policies, controls, and best practices. This role requires strong technical judgment, leadership skills, and the ability to plan, prioritize, and execute network security initiatives in a complex government environment. Location: Washington, DC or Gaithersburg, MD Salary: Up to $178,000 Clearance: Active Q Clearance Required Education: Bachelor's degree from an accredited university or college in Information Technology with an emphasis in Cybersecurity or Information Assurance, Computer Science, or a related field. Required Certifications: One or more of the following certifications or equivalent: GIAC Information Security Professional (GISP) ISC2 Certified Information Systems Security Professional (CISSP) GIAC Security Essentials (GSEC) Experience: Minimum of five (5) years of experience managing network security systems in LAN/WAN environments. Experience leading network security administration staff and technical teams. Experience managing enterprise network security infrastructure, systems, and technologies. Broad knowledge of network security concepts, practices, principles, and procedures. Experience planning, implementing, and maintaining network security solutions. Experience identifying and addressing network security risks, vulnerabilities, and operational issues. Ability to apply extensive technical experience and sound judgment to plan and accomplish organizational goals. Experience developing and implementing security policies, procedures, standards, and controls. Strong understanding of network security architecture, access controls, firewalls, intrusion detection/prevention, VPNs, and secure network communications. Experience supporting security monitoring, incident response, vulnerability management, and network security assessments. Ability to lead technical teams, prioritize workload, manage competing requirements, and communicate effectively with technical and management stakeholders. Preferred Certifications: Certified Information Security Manager (CISM) ISC2 Certified Cloud Security Professional (CCSP) GIAC Network Forensic Analyst (GNFA) GIAC Certified Intrusion Analyst (GCIA) GIAC Certified Incident Handler (GCIH) GIAC Certified Firewall Analyst (GCFW) Cisco Certified Network Professional - Security (CCNP Security) Fortinet Certified Professional or equivalent Fortinet certification Palo Alto Networks Certified Network Security Engineer (PCNSE) or equivalent CompTIA Security+ CompTIA CySA+ ISACA Certified in Risk and Information Systems Control (CRISC) Certified Ethical Hacker (CEH) Juniper Networks security certification or equivalent ActioNet is a CMMI-DEV Level 4, CMMI-SVC Level 4, ISO 20000, ISO 27001, ISO 9001, HDI-certified, woman-owned IT Solutions Provider with strong qualifications and expertise in Agile Software Engineering, Cloud Solutions, Cyber Security and IT Managed Services. With 24+ years of stellar past performance, ActioNet is the premier Trusted Innogrator! Why ActioNet? At ActioNet, our Passion for Quality is at the heart of everything we do: We are committed to make ActioNet a great place to work and continue to invest in our ActioNeters We are committed to our customers by driving and sustaining Service Delivery Excellence We are committed to give back to our Community, help others and make the world a better place for our next generation ActioNet is proud to be named as a Top Workplace for the ninth year in a row (2014 - 2022). We have 98% of Customer retention rate. We are passionate about the inspirational missions of our customers and we entrust our employees and teams to deliver exceptional performance to enable the safety, security, health and well-being of our nation. What's in It For You? As an ActioNeter, you get to be part of exceptional team and a corporate culture that nurtures mutual success for our customers, employees and our communities. We give you the tools to be successful; all you need to do is bring your best ideas, your energy and a desire to develop your skills, experience and career. Are you ready to make a difference? ActioNet is an equal opportunity employer and value diversity at our company. We do not discriminate on the basis of race, religion, color, national origin, gender, sexual orientation, age, marital status, veteran status, or disability status. Direct Applicants, only. No Agencies, No third-party recruiters, please
Job Description Job Description Role: Cybersecurity / Network Engineer Location: Houston, TX (Hybrid) Pay Range: $120,000 - $125,000 / year Benefits: This position is eligible for medical, dental, vision and 401(k) About the Role We are seeking a Cybersecurity / Network Engineer to take ownership of a growing enterprise network and help shape the organization's long-term infrastructure and security strategy. This role combines hands-on network engineering with cybersecurity oversight, making it an excellent opportunity for someone who enjoys building secure, scalable environments while proactively identifying opportunities for improvement. The ideal candidate has experience managing enterprise network infrastructure, strengthening security posture, and partnering with third-party security providers to protect business operations. This position is best suited for someone who takes initiative, thinks strategically, and is comfortable serving as the technical owner of a complex network environment. Primary Responsibilities Manage, maintain, and optimize enterprise network infrastructure across multiple locations. Design, implement, and support secure networking solutions including firewalls, VPNs, wireless networks, and SD-WAN connectivity. Administer and support Cisco Meraki and Fortinet network environments. Partner with third-party security vendors to monitor, investigate, and respond to cybersecurity events. Lead vulnerability remediation efforts and support ongoing risk reduction initiatives. Develop and enhance security policies, standards, and best practices to strengthen the organization's cybersecurity posture. Support compliance initiatives including NIST and CMMC frameworks. Perform regular security assessments, identify infrastructure risks, and recommend improvements. Administer core Microsoft infrastructure including Active Directory, DNS, DHCP, and Group Policy. Troubleshoot network, server, and infrastructure issues across both on-premises and cloud environments. Maintain accurate network diagrams, technical documentation, and system inventories. Provide Tier II/III infrastructure support and collaborate with internal teams on technology initiatives. Participate in infrastructure planning, capacity management, and continuous improvement efforts. Required Background 5+ years of experience in Network Engineering, Cybersecurity, or Infrastructure Engineering. Experience administering Cisco Meraki networking environments. Hands-on experience managing Fortinet/FortiGate firewalls. Strong understanding of enterprise networking including routing, switching, VPNs, wireless networking, and SD-WAN. Experience supporting Microsoft Active Directory, DNS, DHCP, and Group Policy. Knowledge of cybersecurity frameworks such as NIST and/or CMMC. Experience working through a cybersecurity incident, including investigation, remediation, and recovery efforts. Experience coordinating with third-party security vendors or managed security providers. Strong troubleshooting skills across network and infrastructure technologies. Skills & Qualifications Strong understanding of network architecture, cybersecurity principles, and infrastructure best practices. Ability to proactively identify risks and implement long-term technical improvements. Excellent problem-solving and analytical skills. Strong verbal and written communication skills. Ability to work independently while collaborating with cross-functional teams. Experience with VMware, SAN/NAS storage, or cloud infrastructure is a plus. Familiarity with endpoint security platforms, vulnerability management, SIEM solutions, or email security tools is preferred. Comfortable supporting multiple locations and occasional travel to local data center facilities as needed. Self-motivated with a strong sense of ownership and accountability. Addison Group is an Equal Opportunity Employer. Addison Group provides equal employment opportunities (EEO) to all employees and applicants for employment without regard to race, color, religion, gender, sexual orientation, national origin, age, disability, genetic information, marital status, amnesty, or status as a covered veteran in accordance with applicable federal, state and local laws. Addison Group complies with applicable state and local laws governing non-discrimination in employment in every location in which the company has facilities. Reasonable accommodation is available for qualified individuals with disabilities, upon request. IND 005-009
09/27/2026
Full time
Job Description Job Description Role: Cybersecurity / Network Engineer Location: Houston, TX (Hybrid) Pay Range: $120,000 - $125,000 / year Benefits: This position is eligible for medical, dental, vision and 401(k) About the Role We are seeking a Cybersecurity / Network Engineer to take ownership of a growing enterprise network and help shape the organization's long-term infrastructure and security strategy. This role combines hands-on network engineering with cybersecurity oversight, making it an excellent opportunity for someone who enjoys building secure, scalable environments while proactively identifying opportunities for improvement. The ideal candidate has experience managing enterprise network infrastructure, strengthening security posture, and partnering with third-party security providers to protect business operations. This position is best suited for someone who takes initiative, thinks strategically, and is comfortable serving as the technical owner of a complex network environment. Primary Responsibilities Manage, maintain, and optimize enterprise network infrastructure across multiple locations. Design, implement, and support secure networking solutions including firewalls, VPNs, wireless networks, and SD-WAN connectivity. Administer and support Cisco Meraki and Fortinet network environments. Partner with third-party security vendors to monitor, investigate, and respond to cybersecurity events. Lead vulnerability remediation efforts and support ongoing risk reduction initiatives. Develop and enhance security policies, standards, and best practices to strengthen the organization's cybersecurity posture. Support compliance initiatives including NIST and CMMC frameworks. Perform regular security assessments, identify infrastructure risks, and recommend improvements. Administer core Microsoft infrastructure including Active Directory, DNS, DHCP, and Group Policy. Troubleshoot network, server, and infrastructure issues across both on-premises and cloud environments. Maintain accurate network diagrams, technical documentation, and system inventories. Provide Tier II/III infrastructure support and collaborate with internal teams on technology initiatives. Participate in infrastructure planning, capacity management, and continuous improvement efforts. Required Background 5+ years of experience in Network Engineering, Cybersecurity, or Infrastructure Engineering. Experience administering Cisco Meraki networking environments. Hands-on experience managing Fortinet/FortiGate firewalls. Strong understanding of enterprise networking including routing, switching, VPNs, wireless networking, and SD-WAN. Experience supporting Microsoft Active Directory, DNS, DHCP, and Group Policy. Knowledge of cybersecurity frameworks such as NIST and/or CMMC. Experience working through a cybersecurity incident, including investigation, remediation, and recovery efforts. Experience coordinating with third-party security vendors or managed security providers. Strong troubleshooting skills across network and infrastructure technologies. Skills & Qualifications Strong understanding of network architecture, cybersecurity principles, and infrastructure best practices. Ability to proactively identify risks and implement long-term technical improvements. Excellent problem-solving and analytical skills. Strong verbal and written communication skills. Ability to work independently while collaborating with cross-functional teams. Experience with VMware, SAN/NAS storage, or cloud infrastructure is a plus. Familiarity with endpoint security platforms, vulnerability management, SIEM solutions, or email security tools is preferred. Comfortable supporting multiple locations and occasional travel to local data center facilities as needed. Self-motivated with a strong sense of ownership and accountability. Addison Group is an Equal Opportunity Employer. Addison Group provides equal employment opportunities (EEO) to all employees and applicants for employment without regard to race, color, religion, gender, sexual orientation, national origin, age, disability, genetic information, marital status, amnesty, or status as a covered veteran in accordance with applicable federal, state and local laws. Addison Group complies with applicable state and local laws governing non-discrimination in employment in every location in which the company has facilities. Reasonable accommodation is available for qualified individuals with disabilities, upon request. IND 005-009
Johnson Controls is seeking a Technical Support Engineer 4 to provide advanced support for building automation and manufacturing control systems. In this role, you will diagnose and resolve complex hardware, software, and network issues, both remotely and on-site, ensuring safe, reliable system performance. You will collaborate with engineering and field teams, support upgrades and commissioning, and create clear documentation of incidents and solutions. Operating in an innovative, safety-focused, and customer-centric culture, you will mentor junior staff, contribute to continuous improvement, and help drive smart, sustainable building solutions worldwide. Responsibilities Provide advanced technical support for building automation and manufacturing control systems Diagnose and resolve complex hardware, software, and network issues remotely and on-site Collaborate with engineering and field teams to troubleshoot system integrations Document incidents, root causes, and solutions in ticketing and knowledge base tools Support system upgrades, patching, and configuration changes following safety standards Assist in commissioning and testing of control systems for new and existing facilities Guide junior engineers and technicians on best practices and troubleshooting methods Engage with customers to clarify requirements and ensure timely resolution of escalations Monitor system performance and recommend improvements to reliability and security Participate in on-call rotation and adhere to Johnson Controls' safety and quality processes Required Skills Building automation systems support Industrial control systems (PLCs, SCADA) Network troubleshooting (TCP/IP, VLANs, VPN) Windows and server administration Scripting or basic programming for automation (e.g., Python, Power Shell) Reading electrical and control schematics Ticketing and IT service management tools (e.g., Service Now, Jira) Cybersecurity best practices for operational technology Root cause analysis and problem solving Technical documentation and customer communication
09/27/2026
Full time
Johnson Controls is seeking a Technical Support Engineer 4 to provide advanced support for building automation and manufacturing control systems. In this role, you will diagnose and resolve complex hardware, software, and network issues, both remotely and on-site, ensuring safe, reliable system performance. You will collaborate with engineering and field teams, support upgrades and commissioning, and create clear documentation of incidents and solutions. Operating in an innovative, safety-focused, and customer-centric culture, you will mentor junior staff, contribute to continuous improvement, and help drive smart, sustainable building solutions worldwide. Responsibilities Provide advanced technical support for building automation and manufacturing control systems Diagnose and resolve complex hardware, software, and network issues remotely and on-site Collaborate with engineering and field teams to troubleshoot system integrations Document incidents, root causes, and solutions in ticketing and knowledge base tools Support system upgrades, patching, and configuration changes following safety standards Assist in commissioning and testing of control systems for new and existing facilities Guide junior engineers and technicians on best practices and troubleshooting methods Engage with customers to clarify requirements and ensure timely resolution of escalations Monitor system performance and recommend improvements to reliability and security Participate in on-call rotation and adhere to Johnson Controls' safety and quality processes Required Skills Building automation systems support Industrial control systems (PLCs, SCADA) Network troubleshooting (TCP/IP, VLANs, VPN) Windows and server administration Scripting or basic programming for automation (e.g., Python, Power Shell) Reading electrical and control schematics Ticketing and IT service management tools (e.g., Service Now, Jira) Cybersecurity best practices for operational technology Root cause analysis and problem solving Technical documentation and customer communication
Job Description Job Description Omitron is seeking a Configuration Manager to support the CROWN effort in Colorado Springs, CO. This role owns configuration management across the CROWN lifecycle, from establishing CM planning and configuration identification through baseline management, change control, configuration status accounting, verification, and audit. The Configuration Manager is responsible for ensuring CROWN's hardware, software, network configurations, technical documentation, and associated configuration items remain controlled, traceable, reproducible, and auditable throughout the system lifecycle. This role requires someone capable of building and owning CM structure where it does not yet exist and maintaining that discipline within an evolving, Agile-driven technical environment. The ideal candidate can establish configuration baselines, operate a Change Control Board (CCB), maintain configuration status accounting, control changes across hardware and software components, and coordinate with Omitron and Government stakeholders to ensure configuration integrity throughout development, deployment, operations, and sustainment. The Configuration Manager will work closely with systems engineering, network engineering, software, cybersecurity, installation, operations, logistics, and program management personnel to ensure that the approved configuration accurately reflects what is designed, tested, deployed, and operating in the field. Key Responsibilities Develop and document the life cycle of CM planning, including program milestones and schedules to monitor CM status. Implement an internal CM system to manage all configuration documentation, physical media, and system components (hardware and software). Ensure CM practices cover engineering, implementation, and testing environments in accordance with evolving requirements. Implement change control guidelines for managing updates to project baselines and associated documentation. Establish and facilitate a Change Control Board (CCB) to review and approve changes. Track and maintain configuration baselines for each Prime Mission Product, including Commercial Off-The-Shelf (COTS) and Free and Open-Source Software (FOSS) components. Coordinate CM activities with Omitron and government stakeholders to ensure compliance with Agile product development processes and government requirements. Work closely with engineering, cybersecurity, and operations personnel to ensure configuration traceability, auditability, and consistent documentation across CROWN's lifecycle. Coordinate with installation and operations teams to ensure fielded system configurations accurately reflect approved baselines and as-built documentation. Conduct or support Functional Configuration Audits (FCA), Physical Configuration Audits (PCA), baseline reviews, and internal CM audits as applicable. Continuously improve CM processes as CROWN capabilities, deployments, and operational requirements evolve. Required Qualifications US citizenship required Security Clearance: Active TS/SCI clearance. Education: Bachelor's degree. Experience: 6+ years of relevant experience in configuration management, or an equivalent combination of education and experience. Demonstrated experience developing and implementing CM plans, baselines, and change control processes for a complex technical program. Experience establishing or facilitating a Change Control Board (CCB) or equivalent change management process. Strong coordination and documentation skills, with the ability to work across engineering, cybersecurity, and operations teams and with government stakeholders. Experience with version control, release management, or software configuration management concepts. Experience identifying and managing Configuration Items across hardware, software, firmware, and technical documentation. Preferred Qualifications Experience supporting DoD, Space Force, NRO, or other federal/IC programs. Familiarity with Agile product development processes and how CM practices adapt within an Agile environment. Industry certifications in configuration management (e.g., CMPIC, ITIL) or related disciplines. Familiarity with the CROWN program or similar network/systems delivery initiatives. Industry certification in configuration management or related disciplines, such as CMPIC, CM2, ITIL, or equivalent. Experience managing configuration for enterprise networks, distributed systems, mission systems, or other complex IT infrastructure. Compensation and Benefits: The salary range for this role is $120,000 to $160,000. Actual compensation will be determined based on factors including, but not limited to, relevant experience, education, technical expertise, certifications, security clearance, geographic location, internal equity, market conditions, contract requirements, and other factors. Benefits include: Health, Dental and Vision Insurance HSA or FSA accounts Company paid ST/LT Disability and AD&D insurance Paid Federal Holidays Paid Vacation Leave and Sick Leave Parental Leave 401k with company match Supplemental Insurance options like AFLAC Professional Development Reimbursement Voluntary Life Insurance Company Overview: Omitron is an Aerospace Engineering and Information Technology small business firm headquartered in Beltsville, Maryland with a field office located in Colorado Springs, Colorado. Since 1984, Omitron has provided excellence in engineering services and product development to government and industry customers for both civilian and military aerospace programs. Omitron recognizes that outstanding people are the key to our success. Our goal is to select highly qualified and motivated individuals and provide them with an environment necessary to stimulate and nurture engineering and business objectives. Omitron offers its employees competitive salaries, a full benefits package, and excellent career growth opportunities. We welcome talented professionals who wish to take advantage of the opportunities we offer. At Omitron, we believe that a workplace that fosters innovation and collaboration will be a successful one. We are committed to attracting, developing, and retaining top talent from a broad range of backgrounds, perspectives, and experiences. Per Title VII, our hiring decisions are made based on qualifications, skills, and experience, in accordance with our commitment to equal opportunity employment and nondiscrimination policies. We welcome all individuals who share our passion for excellence and encourage applicants from diverse backgrounds to apply. We also support a workplace where every employee feels valued, respected, and empowered to contribute their best work. Our workplace initiatives are open to all and designed to create a culture of belonging for everyone. E-Verify Participation. Powered by JazzHR KBcXtmP5bX
09/26/2026
Full time
Job Description Job Description Omitron is seeking a Configuration Manager to support the CROWN effort in Colorado Springs, CO. This role owns configuration management across the CROWN lifecycle, from establishing CM planning and configuration identification through baseline management, change control, configuration status accounting, verification, and audit. The Configuration Manager is responsible for ensuring CROWN's hardware, software, network configurations, technical documentation, and associated configuration items remain controlled, traceable, reproducible, and auditable throughout the system lifecycle. This role requires someone capable of building and owning CM structure where it does not yet exist and maintaining that discipline within an evolving, Agile-driven technical environment. The ideal candidate can establish configuration baselines, operate a Change Control Board (CCB), maintain configuration status accounting, control changes across hardware and software components, and coordinate with Omitron and Government stakeholders to ensure configuration integrity throughout development, deployment, operations, and sustainment. The Configuration Manager will work closely with systems engineering, network engineering, software, cybersecurity, installation, operations, logistics, and program management personnel to ensure that the approved configuration accurately reflects what is designed, tested, deployed, and operating in the field. Key Responsibilities Develop and document the life cycle of CM planning, including program milestones and schedules to monitor CM status. Implement an internal CM system to manage all configuration documentation, physical media, and system components (hardware and software). Ensure CM practices cover engineering, implementation, and testing environments in accordance with evolving requirements. Implement change control guidelines for managing updates to project baselines and associated documentation. Establish and facilitate a Change Control Board (CCB) to review and approve changes. Track and maintain configuration baselines for each Prime Mission Product, including Commercial Off-The-Shelf (COTS) and Free and Open-Source Software (FOSS) components. Coordinate CM activities with Omitron and government stakeholders to ensure compliance with Agile product development processes and government requirements. Work closely with engineering, cybersecurity, and operations personnel to ensure configuration traceability, auditability, and consistent documentation across CROWN's lifecycle. Coordinate with installation and operations teams to ensure fielded system configurations accurately reflect approved baselines and as-built documentation. Conduct or support Functional Configuration Audits (FCA), Physical Configuration Audits (PCA), baseline reviews, and internal CM audits as applicable. Continuously improve CM processes as CROWN capabilities, deployments, and operational requirements evolve. Required Qualifications US citizenship required Security Clearance: Active TS/SCI clearance. Education: Bachelor's degree. Experience: 6+ years of relevant experience in configuration management, or an equivalent combination of education and experience. Demonstrated experience developing and implementing CM plans, baselines, and change control processes for a complex technical program. Experience establishing or facilitating a Change Control Board (CCB) or equivalent change management process. Strong coordination and documentation skills, with the ability to work across engineering, cybersecurity, and operations teams and with government stakeholders. Experience with version control, release management, or software configuration management concepts. Experience identifying and managing Configuration Items across hardware, software, firmware, and technical documentation. Preferred Qualifications Experience supporting DoD, Space Force, NRO, or other federal/IC programs. Familiarity with Agile product development processes and how CM practices adapt within an Agile environment. Industry certifications in configuration management (e.g., CMPIC, ITIL) or related disciplines. Familiarity with the CROWN program or similar network/systems delivery initiatives. Industry certification in configuration management or related disciplines, such as CMPIC, CM2, ITIL, or equivalent. Experience managing configuration for enterprise networks, distributed systems, mission systems, or other complex IT infrastructure. Compensation and Benefits: The salary range for this role is $120,000 to $160,000. Actual compensation will be determined based on factors including, but not limited to, relevant experience, education, technical expertise, certifications, security clearance, geographic location, internal equity, market conditions, contract requirements, and other factors. Benefits include: Health, Dental and Vision Insurance HSA or FSA accounts Company paid ST/LT Disability and AD&D insurance Paid Federal Holidays Paid Vacation Leave and Sick Leave Parental Leave 401k with company match Supplemental Insurance options like AFLAC Professional Development Reimbursement Voluntary Life Insurance Company Overview: Omitron is an Aerospace Engineering and Information Technology small business firm headquartered in Beltsville, Maryland with a field office located in Colorado Springs, Colorado. Since 1984, Omitron has provided excellence in engineering services and product development to government and industry customers for both civilian and military aerospace programs. Omitron recognizes that outstanding people are the key to our success. Our goal is to select highly qualified and motivated individuals and provide them with an environment necessary to stimulate and nurture engineering and business objectives. Omitron offers its employees competitive salaries, a full benefits package, and excellent career growth opportunities. We welcome talented professionals who wish to take advantage of the opportunities we offer. At Omitron, we believe that a workplace that fosters innovation and collaboration will be a successful one. We are committed to attracting, developing, and retaining top talent from a broad range of backgrounds, perspectives, and experiences. Per Title VII, our hiring decisions are made based on qualifications, skills, and experience, in accordance with our commitment to equal opportunity employment and nondiscrimination policies. We welcome all individuals who share our passion for excellence and encourage applicants from diverse backgrounds to apply. We also support a workplace where every employee feels valued, respected, and empowered to contribute their best work. Our workplace initiatives are open to all and designed to create a culture of belonging for everyone. E-Verify Participation. Powered by JazzHR KBcXtmP5bX
Job Description Job Description: VIATEQ Corporation is looking for a Security Control Assessor (SCA) to support a comprehensive enterprise cybersecurity services program for a federal government client. This position requires the ability to obtain and maintain a Minimum Background Investigation (MBI) or higher, PIV credentials, and all requisite IT access authorizations prior to performing work. Primary work will be performed at the client site in Washington, DC and approved remote/telework locations. This role serves as a key technical contributor responsible for the independent assessment and evaluation of security and privacy controls across the client's enterprise IT portfolio, spanning on-premises, cloud-hosted, and hybrid systems, in support of the agency's Federal Information Security Modernization Act (FISMA) compliance program, Risk Management Framework (RMF) activities, and Ongoing Authorization (OA) initiatives. The ideal candidate is a detail-oriented and technically proficient security assessment professional with demonstrated experience conducting NIST SP 800-53 security and privacy controls assessments, developing Security Assessment Reports (SARs), supporting Authority to Operate (ATO) activities, and executing continuous monitoring assessments across a diverse federal enterprise IT environment. This individual must possess the ability to work independently across complex, multi-technology system boundaries and deliver thorough, accurate, and well-written assessment artifacts that meet rigorous federal documentation standards. The Security Control Assessor will serve as an independent technical evaluator responsible for planning, executing, and reporting on security and privacy controls assessments for assigned systems and services across the client's enterprise IT portfolio. This individual is responsible for assessing the implementation and effectiveness of NIST SP 800-53 security and privacy controls, documenting assessment findings in accordance with NIST SP 800-53A methodologies, producing high-quality assessment artifacts, and supporting the full RMF assessment lifecycle from initial planning through final report delivery and POA&M development. The SCA works closely with ISSOs, system owners, security engineers, and Government stakeholders to ensure assessments are thorough, accurate, and completed within required timelines. Responsibilities: Security & Privacy Controls Assessment Plan, execute, and report on comprehensive security and privacy controls assessments for assigned federal information systems and services, including on-premises, IaaS, PaaS, and SaaS implementations, in accordance with NIST SP 800-53 Rev 5, NIST SP 800-53A Rev 5, and applicable agency implementation procedures. Conduct point-in-time full controls assessments, annual controls assessments, multi-year one-third assessments, and Ongoing Authorization (OA) evaluation assessments in accordance with the agency's assessment schedule and applicable implementation procedures. Develop and deliver draft Security Assessment Plans (SAPs) no less than ten (10) business days prior to beginning each assessment, clearly documenting the assessment scope, boundaries, sampling strategies, test methods, and schedule. Execute NIST SP 800-53A Determine If Statements (DISs) for all in-scope controls, documenting assessment findings to a level of detail sufficient to demonstrate that the implementation of each control objective is validated or not validated, avoiding high-level summary statements and ensuring technical depth across all technology types within the system boundary. Conduct technical controls assessments across all technology types within each system boundary, including Windows and UNIX servers, network devices (routers, switches, Cisco, F5 load balancers), web applications, databases, cloud platforms, and endpoint systems, applying appropriate sampling strategies approved by the Government prior to implementation. Develop Government-approved sampling strategies encompassing all asset types within each system boundary, typically between ten (10) and twenty (20) percent of applicable assets where appropriate, ensuring sampling covers all relevant device types, users, and services. Map identified vulnerabilities and assessment findings to applicable NIST SP 800-53 Rev 5 controls and control families, ensuring accurate and complete linkage between technical findings and corresponding control deficiencies. Produce comprehensive draft and final Security Assessment Reports (SARs) within required timelines, ensuring reports are comprehensive to the scope identified in the SAP, fully aligned to the agency's Governance, Risk, and Compliance (GRC) tool, include visual representation against the NIST Cybersecurity Framework (CSF), and are peer-reviewed for accuracy and grammar prior to submission. Develop draft Plans of Action and Milestones (POA&M) entries for identified control deficiencies, typically using the agency's GRC tool, delivering draft POA&Ms within thirty (30) calendar days from point-in-time assessment kickoff. Develop draft Annual Assessment Reports (AARs) per in-scope system within one-hundred-twenty (120) business days from point-in-time annual assessment kickoff, and deliver draft summary reports for multi-year assessment efforts no later than sixty (60) business days prior to the end of each Fiscal Year. Incorporate all Government feedback into assessment artifacts within five (5) business days of receipt of comments, delivering finalized deliverables that accurately reflect all Government-provided corrections, questions, and recommendations. Ongoing Authorization (OA) Evaluation Support Conduct Ongoing Authorization (OA) controls assessments for systems approved for OA, applying agency-specific OA test procedures that replace traditional NIST SP 800-53A test procedures for OA-approved systems. Execute OA Positive Testing monthly for OA-approved systems, using automated or semi-automated techniques to determine whether controls are operating effectively under normal circumstances, documenting results in the agency GRC tool in accordance with OA implementation procedures. Execute OA Negative Testing annually for OA-approved systems, using automated or semi-automated techniques to determine whether controls respond as expected under abnormal circumstances where misuse is injected to attempt to circumvent the control, coordinating as necessary with penetration testing purple team resources. Assist in the development and submission of OA Playbooks for Government approval, documenting the testing methodology for each OA core control including Test Strategy, Test Design, Test Execution, Results Evaluation, and Visualization components. Conduct OA testing comprehensively across all technology types within each target system's boundary, including sampling across in-scope devices, users, and services, documenting all test results in detail within the agency GRC tool in accordance with applicable OA implementation procedures. Ensure all OA Positive and Negative Testing documentation is peer-reviewed for accuracy and grammar prior to submission to the Government. ISSO Support & Collaboration Collaborate closely with assigned ISSOs to support their development of in-depth technical and operational knowledge about assigned systems, providing assessment expertise, technical guidance, and documentation support as needed. Provide technical support and expertise to ISSOs in the development and maintenance of all security documentation in the ATO package, including System Security Plans (SSPs), Configuration Management Plans (CMPs), Information System Contingency Plans (ISCPs), and other RMF artifacts, ensuring documentation aligns with applicable agency implementation procedures and template requirements. Support ISSOs in reviewing and validating system security documentation for technical accuracy, completeness, and alignment with the system boundary and technology stack, providing specific and actionable feedback to improve documentation quality. Assist ISSOs in ensuring control implementation descriptions within SSPs are written to the required level of technical detail, clearly explaining how each control is implemented across all technologies within the system boundary using specific naming conventions, configurations, and operational procedures rather than high-level general statements. Participate in Enterprise Change Control Board (ECCB) activities as needed, providing security assessment expertise to support the evaluation of proposed system changes and their potential impact on the system's security posture and ATO status. Audit & Compliance Support Support internal and external audit activities for assigned FISMA systems, facilitating meetings and walkthroughs of key cybersecurity capabilities, coordinating with system support personnel, and supplying auditors with requested artifacts and evidence within required timeframes. Ensure audit artifacts are complete, accurate, and delivered on time to avoid repeated requests from auditors, communicating any issues or problems to the Government immediately upon discovery. Support FISMA continuous monitoring activities, including the collection, validation, and submission of system-level FISMA metrics for assigned systems in alignment with federal CIO metrics requirements and agency reporting schedules. Assist in the development and maintenance of automated visualizations and dashboards that reflect the status and effectiveness of security controls for assigned systems, providing continuous visibility into the security posture and compliance status of assigned systems. Support High Value Asset (HVA) assessment activities for designated HVA systems, including vulnerability scanning and remediation validation, monitoring and analysis of relevant audit logs . click apply for full job details
09/26/2026
Full time
Job Description Job Description: VIATEQ Corporation is looking for a Security Control Assessor (SCA) to support a comprehensive enterprise cybersecurity services program for a federal government client. This position requires the ability to obtain and maintain a Minimum Background Investigation (MBI) or higher, PIV credentials, and all requisite IT access authorizations prior to performing work. Primary work will be performed at the client site in Washington, DC and approved remote/telework locations. This role serves as a key technical contributor responsible for the independent assessment and evaluation of security and privacy controls across the client's enterprise IT portfolio, spanning on-premises, cloud-hosted, and hybrid systems, in support of the agency's Federal Information Security Modernization Act (FISMA) compliance program, Risk Management Framework (RMF) activities, and Ongoing Authorization (OA) initiatives. The ideal candidate is a detail-oriented and technically proficient security assessment professional with demonstrated experience conducting NIST SP 800-53 security and privacy controls assessments, developing Security Assessment Reports (SARs), supporting Authority to Operate (ATO) activities, and executing continuous monitoring assessments across a diverse federal enterprise IT environment. This individual must possess the ability to work independently across complex, multi-technology system boundaries and deliver thorough, accurate, and well-written assessment artifacts that meet rigorous federal documentation standards. The Security Control Assessor will serve as an independent technical evaluator responsible for planning, executing, and reporting on security and privacy controls assessments for assigned systems and services across the client's enterprise IT portfolio. This individual is responsible for assessing the implementation and effectiveness of NIST SP 800-53 security and privacy controls, documenting assessment findings in accordance with NIST SP 800-53A methodologies, producing high-quality assessment artifacts, and supporting the full RMF assessment lifecycle from initial planning through final report delivery and POA&M development. The SCA works closely with ISSOs, system owners, security engineers, and Government stakeholders to ensure assessments are thorough, accurate, and completed within required timelines. Responsibilities: Security & Privacy Controls Assessment Plan, execute, and report on comprehensive security and privacy controls assessments for assigned federal information systems and services, including on-premises, IaaS, PaaS, and SaaS implementations, in accordance with NIST SP 800-53 Rev 5, NIST SP 800-53A Rev 5, and applicable agency implementation procedures. Conduct point-in-time full controls assessments, annual controls assessments, multi-year one-third assessments, and Ongoing Authorization (OA) evaluation assessments in accordance with the agency's assessment schedule and applicable implementation procedures. Develop and deliver draft Security Assessment Plans (SAPs) no less than ten (10) business days prior to beginning each assessment, clearly documenting the assessment scope, boundaries, sampling strategies, test methods, and schedule. Execute NIST SP 800-53A Determine If Statements (DISs) for all in-scope controls, documenting assessment findings to a level of detail sufficient to demonstrate that the implementation of each control objective is validated or not validated, avoiding high-level summary statements and ensuring technical depth across all technology types within the system boundary. Conduct technical controls assessments across all technology types within each system boundary, including Windows and UNIX servers, network devices (routers, switches, Cisco, F5 load balancers), web applications, databases, cloud platforms, and endpoint systems, applying appropriate sampling strategies approved by the Government prior to implementation. Develop Government-approved sampling strategies encompassing all asset types within each system boundary, typically between ten (10) and twenty (20) percent of applicable assets where appropriate, ensuring sampling covers all relevant device types, users, and services. Map identified vulnerabilities and assessment findings to applicable NIST SP 800-53 Rev 5 controls and control families, ensuring accurate and complete linkage between technical findings and corresponding control deficiencies. Produce comprehensive draft and final Security Assessment Reports (SARs) within required timelines, ensuring reports are comprehensive to the scope identified in the SAP, fully aligned to the agency's Governance, Risk, and Compliance (GRC) tool, include visual representation against the NIST Cybersecurity Framework (CSF), and are peer-reviewed for accuracy and grammar prior to submission. Develop draft Plans of Action and Milestones (POA&M) entries for identified control deficiencies, typically using the agency's GRC tool, delivering draft POA&Ms within thirty (30) calendar days from point-in-time assessment kickoff. Develop draft Annual Assessment Reports (AARs) per in-scope system within one-hundred-twenty (120) business days from point-in-time annual assessment kickoff, and deliver draft summary reports for multi-year assessment efforts no later than sixty (60) business days prior to the end of each Fiscal Year. Incorporate all Government feedback into assessment artifacts within five (5) business days of receipt of comments, delivering finalized deliverables that accurately reflect all Government-provided corrections, questions, and recommendations. Ongoing Authorization (OA) Evaluation Support Conduct Ongoing Authorization (OA) controls assessments for systems approved for OA, applying agency-specific OA test procedures that replace traditional NIST SP 800-53A test procedures for OA-approved systems. Execute OA Positive Testing monthly for OA-approved systems, using automated or semi-automated techniques to determine whether controls are operating effectively under normal circumstances, documenting results in the agency GRC tool in accordance with OA implementation procedures. Execute OA Negative Testing annually for OA-approved systems, using automated or semi-automated techniques to determine whether controls respond as expected under abnormal circumstances where misuse is injected to attempt to circumvent the control, coordinating as necessary with penetration testing purple team resources. Assist in the development and submission of OA Playbooks for Government approval, documenting the testing methodology for each OA core control including Test Strategy, Test Design, Test Execution, Results Evaluation, and Visualization components. Conduct OA testing comprehensively across all technology types within each target system's boundary, including sampling across in-scope devices, users, and services, documenting all test results in detail within the agency GRC tool in accordance with applicable OA implementation procedures. Ensure all OA Positive and Negative Testing documentation is peer-reviewed for accuracy and grammar prior to submission to the Government. ISSO Support & Collaboration Collaborate closely with assigned ISSOs to support their development of in-depth technical and operational knowledge about assigned systems, providing assessment expertise, technical guidance, and documentation support as needed. Provide technical support and expertise to ISSOs in the development and maintenance of all security documentation in the ATO package, including System Security Plans (SSPs), Configuration Management Plans (CMPs), Information System Contingency Plans (ISCPs), and other RMF artifacts, ensuring documentation aligns with applicable agency implementation procedures and template requirements. Support ISSOs in reviewing and validating system security documentation for technical accuracy, completeness, and alignment with the system boundary and technology stack, providing specific and actionable feedback to improve documentation quality. Assist ISSOs in ensuring control implementation descriptions within SSPs are written to the required level of technical detail, clearly explaining how each control is implemented across all technologies within the system boundary using specific naming conventions, configurations, and operational procedures rather than high-level general statements. Participate in Enterprise Change Control Board (ECCB) activities as needed, providing security assessment expertise to support the evaluation of proposed system changes and their potential impact on the system's security posture and ATO status. Audit & Compliance Support Support internal and external audit activities for assigned FISMA systems, facilitating meetings and walkthroughs of key cybersecurity capabilities, coordinating with system support personnel, and supplying auditors with requested artifacts and evidence within required timeframes. Ensure audit artifacts are complete, accurate, and delivered on time to avoid repeated requests from auditors, communicating any issues or problems to the Government immediately upon discovery. Support FISMA continuous monitoring activities, including the collection, validation, and submission of system-level FISMA metrics for assigned systems in alignment with federal CIO metrics requirements and agency reporting schedules. Assist in the development and maintenance of automated visualizations and dashboards that reflect the status and effectiveness of security controls for assigned systems, providing continuous visibility into the security posture and compliance status of assigned systems. Support High Value Asset (HVA) assessment activities for designated HVA systems, including vulnerability scanning and remediation validation, monitoring and analysis of relevant audit logs . click apply for full job details
Job Description Job Description Dark Wolf Solutions is seeking a Senior Security Control Assessor Representative (SCAR) to conduct independent comprehensive assessments of the management, operation, and technical security controls and control enhancements employed within, or inherited by, an Information technology (IT) system to determine the overall effectiveness of the controls. The SCAR will perform reviews of security artifacts for system authorizations, assessing both the technical and functional adequacy as required for application and software cybersecurity readiness. The SCAR candidate must have prior experience in authorizing tools/applications, systems, and/or enclaves. Additionally, knowledge of network security, technologies, processes, and practices designed for the prevention of damage to, protection of, and restoration of computers, communications systems, services, and various types of communications technologies. The SCAR candidate must be knowledgeable and proficient in assessing DoD GovCloud environments to include testing controls and validating artifacts. A successful candidate will have a strong foundational understanding of NIST, DOD, and DAF cybersecurity focused guidance. This position can be based out of any Dark Wolf Office location and will be a hybrid schedule. Additional responsibilities include: Key Responsibilities: Evaluating IT infrastructure in terms of risk to the organization and defining artifacts required to meet Federal, DoD and DAF requirements Assessing IT systems and architecture to ensure compliance with the Risk Management Framework (RMF), NIST Cybersecurity Framework (CSF), NIST 800-53 revision 5 and applicable guidance Supporting the system/application assessment and authorization (A&A) effort, to include assessing and guiding the quality and completeness of A&A activities, tasks and resulting artifacts mandated by governing DoD and AF policies, and applicable mandates Collecting, reviewing and verifying documented business processes within process narratives or flowcharts, identifying risks and validating proficiency of mitigating controls Reviewing risk and control matrices and testing plans for key controls and determines effectiveness Identifying control gaps, reviewing and testing the design of existing controls. Formulating clear and concise conclusions on internal controls and business process efficiency Recommending policies and procedures to ensure information systems reliability and accessibility and to prevent and defend against unauthorized access to systems, networks, and data Conducting risk and vulnerability assessments of installed information systems to identify vulnerabilities, risks, and protection needs Reviewing Plans of Actions & Milestones (POA&Ms) Providing recommendations and reports to the Security Control Assessor (SCA), Authorizing Official (AO), Chief Information Security Officer (CISO) Reviewing network and systems design to ensure accuracy Ensuring the rigorous application of information security/cybersecurity policies, principles, and practices in the delivery of all IT services Required Qualifications: 15+ years of relevant Cyber experience 15+ years prior experience as a Security Control Assessor/Representative RMF Engineer, ISSO, ISSM and/or information assurance engineer Cloud Platform experience with at least one service offering from AWS, Azure, or Google GCP Hands-on eMASS and/or Xacta experience completing full system lifecycle activities Experience with Air Force risk management policies/procedures, to include, DODI 8510.01, AFI 17-101 Experience with Cloud Computing Security Requirements Guide (CC SRG) Knowledgeable with DoD DevSecOps Fundamentals Playbook Experience evaluating information security compliance against STIGs Ability to clearly articulate ideas Strong technical writing abilities to author reports for AO and CISO dissemination Exudes confidence in providing briefings, presentations, and in conducting/guiding meetings with senior leadership and stakeholders Ability to use prior experience and knowledge to address new situations Certification requirements (at least one of the following): SecurityX / CASP+, CCISO, CGRC/CAP, CISA, CISM, CISSO, CISSP, CISSP-ISSEP, Cloud+, CySA+, FITSP-A, GCSA, GSEC, GSLC, GSNA, PenTest+, Security+ B.A. or B.S. Information Security, Computer Science or related discipline US Citizenship and currently possess a Top Secret security clearance Desired Qualifications: Experience with Fast Track ATO Handbook & AF Continuous ATO Playbook Familiarity with CI/CD Pipelines DevSecOps experience Sharepoint, JIRA, Confluence familiarity The salary range for this position is $140,000.00 - $145,000.00 commensurate on experience and technical skillset. We are open to considering a variety of levels of experience for these projects and potential for 1099 hourly opportunity. We are proud to be an EEO/AA Employer Minorities/Women/Veterans/Disabled and other protected categories. In compliance with federal law, all persons hired will be required to verify identity, confirm US Citizenship, and complete the required employment eligibility verification upon hire.
09/26/2026
Full time
Job Description Job Description Dark Wolf Solutions is seeking a Senior Security Control Assessor Representative (SCAR) to conduct independent comprehensive assessments of the management, operation, and technical security controls and control enhancements employed within, or inherited by, an Information technology (IT) system to determine the overall effectiveness of the controls. The SCAR will perform reviews of security artifacts for system authorizations, assessing both the technical and functional adequacy as required for application and software cybersecurity readiness. The SCAR candidate must have prior experience in authorizing tools/applications, systems, and/or enclaves. Additionally, knowledge of network security, technologies, processes, and practices designed for the prevention of damage to, protection of, and restoration of computers, communications systems, services, and various types of communications technologies. The SCAR candidate must be knowledgeable and proficient in assessing DoD GovCloud environments to include testing controls and validating artifacts. A successful candidate will have a strong foundational understanding of NIST, DOD, and DAF cybersecurity focused guidance. This position can be based out of any Dark Wolf Office location and will be a hybrid schedule. Additional responsibilities include: Key Responsibilities: Evaluating IT infrastructure in terms of risk to the organization and defining artifacts required to meet Federal, DoD and DAF requirements Assessing IT systems and architecture to ensure compliance with the Risk Management Framework (RMF), NIST Cybersecurity Framework (CSF), NIST 800-53 revision 5 and applicable guidance Supporting the system/application assessment and authorization (A&A) effort, to include assessing and guiding the quality and completeness of A&A activities, tasks and resulting artifacts mandated by governing DoD and AF policies, and applicable mandates Collecting, reviewing and verifying documented business processes within process narratives or flowcharts, identifying risks and validating proficiency of mitigating controls Reviewing risk and control matrices and testing plans for key controls and determines effectiveness Identifying control gaps, reviewing and testing the design of existing controls. Formulating clear and concise conclusions on internal controls and business process efficiency Recommending policies and procedures to ensure information systems reliability and accessibility and to prevent and defend against unauthorized access to systems, networks, and data Conducting risk and vulnerability assessments of installed information systems to identify vulnerabilities, risks, and protection needs Reviewing Plans of Actions & Milestones (POA&Ms) Providing recommendations and reports to the Security Control Assessor (SCA), Authorizing Official (AO), Chief Information Security Officer (CISO) Reviewing network and systems design to ensure accuracy Ensuring the rigorous application of information security/cybersecurity policies, principles, and practices in the delivery of all IT services Required Qualifications: 15+ years of relevant Cyber experience 15+ years prior experience as a Security Control Assessor/Representative RMF Engineer, ISSO, ISSM and/or information assurance engineer Cloud Platform experience with at least one service offering from AWS, Azure, or Google GCP Hands-on eMASS and/or Xacta experience completing full system lifecycle activities Experience with Air Force risk management policies/procedures, to include, DODI 8510.01, AFI 17-101 Experience with Cloud Computing Security Requirements Guide (CC SRG) Knowledgeable with DoD DevSecOps Fundamentals Playbook Experience evaluating information security compliance against STIGs Ability to clearly articulate ideas Strong technical writing abilities to author reports for AO and CISO dissemination Exudes confidence in providing briefings, presentations, and in conducting/guiding meetings with senior leadership and stakeholders Ability to use prior experience and knowledge to address new situations Certification requirements (at least one of the following): SecurityX / CASP+, CCISO, CGRC/CAP, CISA, CISM, CISSO, CISSP, CISSP-ISSEP, Cloud+, CySA+, FITSP-A, GCSA, GSEC, GSLC, GSNA, PenTest+, Security+ B.A. or B.S. Information Security, Computer Science or related discipline US Citizenship and currently possess a Top Secret security clearance Desired Qualifications: Experience with Fast Track ATO Handbook & AF Continuous ATO Playbook Familiarity with CI/CD Pipelines DevSecOps experience Sharepoint, JIRA, Confluence familiarity The salary range for this position is $140,000.00 - $145,000.00 commensurate on experience and technical skillset. We are open to considering a variety of levels of experience for these projects and potential for 1099 hourly opportunity. We are proud to be an EEO/AA Employer Minorities/Women/Veterans/Disabled and other protected categories. In compliance with federal law, all persons hired will be required to verify identity, confirm US Citizenship, and complete the required employment eligibility verification upon hire.
Job Description Job Description Dark Wolf Solutions is seeking a Senior Security Control Assessor Representative (SCAR) to conduct independent comprehensive assessments of the management, operation, and technical security controls and control enhancements employed within, or inherited by, an Information technology (IT) system to determine the overall effectiveness of the controls. The SCAR will perform reviews of security artifacts for system authorizations, assessing both the technical and functional adequacy as required for application and software cybersecurity readiness. The SCAR candidate must have prior experience in authorizing tools/applications, systems, and/or enclaves. Additionally, knowledge of network security, technologies, processes, and practices designed for the prevention of damage to, protection of, and restoration of computers, communications systems, services, and various types of communications technologies. The SCAR candidate must be knowledgeable and proficient in assessing DoD GovCloud environments to include testing controls and validating artifacts. A successful candidate will have a strong foundational understanding of NIST, DOD, and DAF cybersecurity focused guidance. This position can be based out of any Dark Wolf Office location and will be a hybrid schedule. Additional responsibilities include: Key Responsibilities: Evaluating IT infrastructure in terms of risk to the organization and defining artifacts required to meet Federal, DoD and DAF requirements Assessing IT systems and architecture to ensure compliance with the Risk Management Framework (RMF), NIST Cybersecurity Framework (CSF), NIST 800-53 revision 5 and applicable guidance Supporting the system/application assessment and authorization (A&A) effort, to include assessing and guiding the quality and completeness of A&A activities, tasks and resulting artifacts mandated by governing DoD and AF policies, and applicable mandates Collecting, reviewing and verifying documented business processes within process narratives or flowcharts, identifying risks and validating proficiency of mitigating controls Reviewing risk and control matrices and testing plans for key controls and determines effectiveness Identifying control gaps, reviewing and testing the design of existing controls. Formulating clear and concise conclusions on internal controls and business process efficiency Recommending policies and procedures to ensure information systems reliability and accessibility and to prevent and defend against unauthorized access to systems, networks, and data Conducting risk and vulnerability assessments of installed information systems to identify vulnerabilities, risks, and protection needs Reviewing Plans of Actions & Milestones (POA&Ms) Providing recommendations and reports to the Security Control Assessor (SCA), Authorizing Official (AO), Chief Information Security Officer (CISO) Reviewing network and systems design to ensure accuracy Ensuring the rigorous application of information security/cybersecurity policies, principles, and practices in the delivery of all IT services Required Qualifications: 15+ years of relevant Cyber experience 15+ years prior experience as a Security Control Assessor/Representative RMF Engineer, ISSO, ISSM and/or information assurance engineer Cloud Platform experience with at least one service offering from AWS, Azure, or Google GCP Hands-on eMASS and/or Xacta experience completing full system lifecycle activities Experience with Air Force risk management policies/procedures, to include, DODI 8510.01, AFI 17-101 Experience with Cloud Computing Security Requirements Guide (CC SRG) Knowledgeable with DoD DevSecOps Fundamentals Playbook Experience evaluating information security compliance against STIGs Ability to clearly articulate ideas Strong technical writing abilities to author reports for AO and CISO dissemination Exudes confidence in providing briefings, presentations, and in conducting/guiding meetings with senior leadership and stakeholders Ability to use prior experience and knowledge to address new situations Certification requirements (at least one of the following): SecurityX / CASP+, CCISO, CGRC/CAP, CISA, CISM, CISSO, CISSP, CISSP-ISSEP, Cloud+, CySA+, FITSP-A, GCSA, GSEC, GSLC, GSNA, PenTest+, Security+ B.A. or B.S. Information Security, Computer Science or related discipline US Citizenship and currently possess a Top Secret security clearance Desired Qualifications: Experience with Fast Track ATO Handbook & AF Continuous ATO Playbook Familiarity with CI/CD Pipelines DevSecOps experience Sharepoint, JIRA, Confluence familiarity The salary range for this position is $140,000.00 - $145,000.00 commensurate on experience and technical skillset. We are open to considering a variety of levels of experience for these projects and potential for 1099 hourly opportunity. We are proud to be an EEO/AA Employer Minorities/Women/Veterans/Disabled and other protected categories. In compliance with federal law, all persons hired will be required to verify identity, confirm US Citizenship, and complete the required employment eligibility verification upon hire.
09/26/2026
Full time
Job Description Job Description Dark Wolf Solutions is seeking a Senior Security Control Assessor Representative (SCAR) to conduct independent comprehensive assessments of the management, operation, and technical security controls and control enhancements employed within, or inherited by, an Information technology (IT) system to determine the overall effectiveness of the controls. The SCAR will perform reviews of security artifacts for system authorizations, assessing both the technical and functional adequacy as required for application and software cybersecurity readiness. The SCAR candidate must have prior experience in authorizing tools/applications, systems, and/or enclaves. Additionally, knowledge of network security, technologies, processes, and practices designed for the prevention of damage to, protection of, and restoration of computers, communications systems, services, and various types of communications technologies. The SCAR candidate must be knowledgeable and proficient in assessing DoD GovCloud environments to include testing controls and validating artifacts. A successful candidate will have a strong foundational understanding of NIST, DOD, and DAF cybersecurity focused guidance. This position can be based out of any Dark Wolf Office location and will be a hybrid schedule. Additional responsibilities include: Key Responsibilities: Evaluating IT infrastructure in terms of risk to the organization and defining artifacts required to meet Federal, DoD and DAF requirements Assessing IT systems and architecture to ensure compliance with the Risk Management Framework (RMF), NIST Cybersecurity Framework (CSF), NIST 800-53 revision 5 and applicable guidance Supporting the system/application assessment and authorization (A&A) effort, to include assessing and guiding the quality and completeness of A&A activities, tasks and resulting artifacts mandated by governing DoD and AF policies, and applicable mandates Collecting, reviewing and verifying documented business processes within process narratives or flowcharts, identifying risks and validating proficiency of mitigating controls Reviewing risk and control matrices and testing plans for key controls and determines effectiveness Identifying control gaps, reviewing and testing the design of existing controls. Formulating clear and concise conclusions on internal controls and business process efficiency Recommending policies and procedures to ensure information systems reliability and accessibility and to prevent and defend against unauthorized access to systems, networks, and data Conducting risk and vulnerability assessments of installed information systems to identify vulnerabilities, risks, and protection needs Reviewing Plans of Actions & Milestones (POA&Ms) Providing recommendations and reports to the Security Control Assessor (SCA), Authorizing Official (AO), Chief Information Security Officer (CISO) Reviewing network and systems design to ensure accuracy Ensuring the rigorous application of information security/cybersecurity policies, principles, and practices in the delivery of all IT services Required Qualifications: 15+ years of relevant Cyber experience 15+ years prior experience as a Security Control Assessor/Representative RMF Engineer, ISSO, ISSM and/or information assurance engineer Cloud Platform experience with at least one service offering from AWS, Azure, or Google GCP Hands-on eMASS and/or Xacta experience completing full system lifecycle activities Experience with Air Force risk management policies/procedures, to include, DODI 8510.01, AFI 17-101 Experience with Cloud Computing Security Requirements Guide (CC SRG) Knowledgeable with DoD DevSecOps Fundamentals Playbook Experience evaluating information security compliance against STIGs Ability to clearly articulate ideas Strong technical writing abilities to author reports for AO and CISO dissemination Exudes confidence in providing briefings, presentations, and in conducting/guiding meetings with senior leadership and stakeholders Ability to use prior experience and knowledge to address new situations Certification requirements (at least one of the following): SecurityX / CASP+, CCISO, CGRC/CAP, CISA, CISM, CISSO, CISSP, CISSP-ISSEP, Cloud+, CySA+, FITSP-A, GCSA, GSEC, GSLC, GSNA, PenTest+, Security+ B.A. or B.S. Information Security, Computer Science or related discipline US Citizenship and currently possess a Top Secret security clearance Desired Qualifications: Experience with Fast Track ATO Handbook & AF Continuous ATO Playbook Familiarity with CI/CD Pipelines DevSecOps experience Sharepoint, JIRA, Confluence familiarity The salary range for this position is $140,000.00 - $145,000.00 commensurate on experience and technical skillset. We are open to considering a variety of levels of experience for these projects and potential for 1099 hourly opportunity. We are proud to be an EEO/AA Employer Minorities/Women/Veterans/Disabled and other protected categories. In compliance with federal law, all persons hired will be required to verify identity, confirm US Citizenship, and complete the required employment eligibility verification upon hire.