Job Description Job Description Location: Schriever Space Force Base, Colorado Springs, CO Clearance Required: Active DoW Secret Security Clearance Travel Required: Up to 10% of the time LaunchTech is a veteran-owned company that prides itself on delivering service before self and excellence in all we do. We are seeking dynamic professionals who embody our core values of Integrity, Commitment, and Excellence to join our growing Crew in support of our customers across the federal, state, and commercial markets. We are seeking a GNOSC Watch Officer/Network Engineer to support the Missile Defense Agency (MDA) on the Integrated Research and Development for Enterprise Solutions (IRES) contract. What You'll Be Doing Be responsible for all facets of a continuous 24/7 Global Network Operations and Security Center. Execute network, system, and cloud systems monitoring/surveillance, environmental monitoring, incident management and MDA Cybersecurity. Support and service maintenance activities to include Change Management coordination during the assigned quarterly rotating shift day/night shifts. Be responsible for all aspects of IT incident management and escalation, ensuring that incidents are effectively escalated, managed and resolved with full communication of status, plans, and actions provided to executive management and the Government customer. The successful candidate will: Have excellent communication skills, verbal and written, at both technical and senior/Executive management levels. Understand Command level Management. Be able to speak clearly to diverse cultural audiences, VIPs, and dignitaries. Be able to perform as a section trainer and create lesson plans. Be able to operate within a stressful high speed Operational environment and be able to multi-task. What You Bring Basic Requirements: Must have 1, or more, years of IT experience Must have a current DoD 8570.01 IAT Level II Certification such as CompTIA Security+ CE Certification or higher. Must have an active DoW Secret Security Clearance Desired Requirements: Have experience in metrics-based IT Operations and Maintenance (O&M) teams. Have experience with Remedy and SNMP monitoring tools (e.g., SolarWinds and StruxureWare Datacenter Expert). Have education or experience with ITIL framework and ITIL-based processes, to include continual service improvement, change management, and problem investigation. Have previous work experience as a Windows/Linux System Administrator supporting a large Enterprise with knowledge of Microsoft Active Directory, Windows 2008/2012, Linux/UNIX Operating Systems, EMC Storage, Symantec NetBackup and SCCM Patch Management solutions. Have previous work experience as a network engineer, including hands-on experience designing, implementing and managing network components including switches, routers, firewalls, and cryptographic devices. Have experience with Cyber-defense or information assurance, including experience with DISA mandated security tools to include Assured Compliance Assessment Solution (ACAS), Host Based Security System (HBSS), analyze results and create reports Have knowledge of IT Network Operations and connectivity devices that inter-relate with Public Key Infrastructure authentication and Information Security practices. Have Network Operations experience in a network operations center or other 24x7x365 IT Operations environment. Have knowledge of Cybersecurity principles and how to execute system/network security analysis. Have a working knowledge of Tier III Information Assurance practices, IT security governance, security administration, project management, logistics, and Cybersecurity compliance requirements. Have Quality Assurance/Quality Control Inspection process knowledge. Why LaunchTech? LaunchTech is built on a single standard: Excellence, Period. This role places you at the operational heart of a 24/7 enterprise network operations center defending the nation's missile defense infrastructure around the clock. We offer: Medical, Dental, and Vision coverage 401(k) with company match Paid Time Off (PTO) Mission-driven work with opportunities to grow And more Ready to Join the LaunchTech Crew? LaunchTech is an Equal Opportunity Employer. We prohibit discrimination and harassment of any kind. All qualified applicants will receive consideration for employment without regard to race, protected veteran status, color, sex, religion, sexual orientation, national origin, disability, genetic information, age, pregnancy, or any other status protected under federal, state, or local law. Visit to learn more about how we deliver Excellence, Period. Powered by JazzHR NYRvODyGdv
09/28/2026
Full time
Job Description Job Description Location: Schriever Space Force Base, Colorado Springs, CO Clearance Required: Active DoW Secret Security Clearance Travel Required: Up to 10% of the time LaunchTech is a veteran-owned company that prides itself on delivering service before self and excellence in all we do. We are seeking dynamic professionals who embody our core values of Integrity, Commitment, and Excellence to join our growing Crew in support of our customers across the federal, state, and commercial markets. We are seeking a GNOSC Watch Officer/Network Engineer to support the Missile Defense Agency (MDA) on the Integrated Research and Development for Enterprise Solutions (IRES) contract. What You'll Be Doing Be responsible for all facets of a continuous 24/7 Global Network Operations and Security Center. Execute network, system, and cloud systems monitoring/surveillance, environmental monitoring, incident management and MDA Cybersecurity. Support and service maintenance activities to include Change Management coordination during the assigned quarterly rotating shift day/night shifts. Be responsible for all aspects of IT incident management and escalation, ensuring that incidents are effectively escalated, managed and resolved with full communication of status, plans, and actions provided to executive management and the Government customer. The successful candidate will: Have excellent communication skills, verbal and written, at both technical and senior/Executive management levels. Understand Command level Management. Be able to speak clearly to diverse cultural audiences, VIPs, and dignitaries. Be able to perform as a section trainer and create lesson plans. Be able to operate within a stressful high speed Operational environment and be able to multi-task. What You Bring Basic Requirements: Must have 1, or more, years of IT experience Must have a current DoD 8570.01 IAT Level II Certification such as CompTIA Security+ CE Certification or higher. Must have an active DoW Secret Security Clearance Desired Requirements: Have experience in metrics-based IT Operations and Maintenance (O&M) teams. Have experience with Remedy and SNMP monitoring tools (e.g., SolarWinds and StruxureWare Datacenter Expert). Have education or experience with ITIL framework and ITIL-based processes, to include continual service improvement, change management, and problem investigation. Have previous work experience as a Windows/Linux System Administrator supporting a large Enterprise with knowledge of Microsoft Active Directory, Windows 2008/2012, Linux/UNIX Operating Systems, EMC Storage, Symantec NetBackup and SCCM Patch Management solutions. Have previous work experience as a network engineer, including hands-on experience designing, implementing and managing network components including switches, routers, firewalls, and cryptographic devices. Have experience with Cyber-defense or information assurance, including experience with DISA mandated security tools to include Assured Compliance Assessment Solution (ACAS), Host Based Security System (HBSS), analyze results and create reports Have knowledge of IT Network Operations and connectivity devices that inter-relate with Public Key Infrastructure authentication and Information Security practices. Have Network Operations experience in a network operations center or other 24x7x365 IT Operations environment. Have knowledge of Cybersecurity principles and how to execute system/network security analysis. Have a working knowledge of Tier III Information Assurance practices, IT security governance, security administration, project management, logistics, and Cybersecurity compliance requirements. Have Quality Assurance/Quality Control Inspection process knowledge. Why LaunchTech? LaunchTech is built on a single standard: Excellence, Period. This role places you at the operational heart of a 24/7 enterprise network operations center defending the nation's missile defense infrastructure around the clock. We offer: Medical, Dental, and Vision coverage 401(k) with company match Paid Time Off (PTO) Mission-driven work with opportunities to grow And more Ready to Join the LaunchTech Crew? LaunchTech is an Equal Opportunity Employer. We prohibit discrimination and harassment of any kind. All qualified applicants will receive consideration for employment without regard to race, protected veteran status, color, sex, religion, sexual orientation, national origin, disability, genetic information, age, pregnancy, or any other status protected under federal, state, or local law. Visit to learn more about how we deliver Excellence, Period. Powered by JazzHR NYRvODyGdv
Job Description Job Description Dark Wolf Solutions is seeking a Senior Security Control Assessor Representative (SCAR) to conduct independent comprehensive assessments of the management, operation, and technical security controls and control enhancements employed within, or inherited by, an Information technology (IT) system to determine the overall effectiveness of the controls. The SCAR will perform reviews of security artifacts for system authorizations, assessing both the technical and functional adequacy as required for application and software cybersecurity readiness. The SCAR candidate must have prior experience in authorizing tools/applications, systems, and/or enclaves. Additionally, knowledge of network security, technologies, processes, and practices designed for the prevention of damage to, protection of, and restoration of computers, communications systems, services, and various types of communications technologies. The SCAR candidate must be knowledgeable and proficient in assessing DoD GovCloud environments to include testing controls and validating artifacts. A successful candidate will have a strong foundational understanding of NIST, DOD, and DAF cybersecurity focused guidance. This position can be based out of any Dark Wolf Office location and will be a hybrid schedule. Additional responsibilities include: Key Responsibilities: Evaluating IT infrastructure in terms of risk to the organization and defining artifacts required to meet Federal, DoD and DAF requirements Assessing IT systems and architecture to ensure compliance with the Risk Management Framework (RMF), NIST Cybersecurity Framework (CSF), NIST 800-53 revision 5 and applicable guidance Supporting the system/application assessment and authorization (A&A) effort, to include assessing and guiding the quality and completeness of A&A activities, tasks and resulting artifacts mandated by governing DoD and AF policies, and applicable mandates Collecting, reviewing and verifying documented business processes within process narratives or flowcharts, identifying risks and validating proficiency of mitigating controls Reviewing risk and control matrices and testing plans for key controls and determines effectiveness Identifying control gaps, reviewing and testing the design of existing controls. Formulating clear and concise conclusions on internal controls and business process efficiency Recommending policies and procedures to ensure information systems reliability and accessibility and to prevent and defend against unauthorized access to systems, networks, and data Conducting risk and vulnerability assessments of installed information systems to identify vulnerabilities, risks, and protection needs Reviewing Plans of Actions & Milestones (POA&Ms) Providing recommendations and reports to the Security Control Assessor (SCA), Authorizing Official (AO), Chief Information Security Officer (CISO) Reviewing network and systems design to ensure accuracy Ensuring the rigorous application of information security/cybersecurity policies, principles, and practices in the delivery of all IT services Required Qualifications: 15+ years of relevant Cyber experience 15+ years prior experience as a Security Control Assessor/Representative RMF Engineer, ISSO, ISSM and/or information assurance engineer Cloud Platform experience with at least one service offering from AWS, Azure, or Google GCP Hands-on eMASS and/or Xacta experience completing full system lifecycle activities Experience with Air Force risk management policies/procedures, to include, DODI 8510.01, AFI 17-101 Experience with Cloud Computing Security Requirements Guide (CC SRG) Knowledgeable with DoD DevSecOps Fundamentals Playbook Experience evaluating information security compliance against STIGs Ability to clearly articulate ideas Strong technical writing abilities to author reports for AO and CISO dissemination Exudes confidence in providing briefings, presentations, and in conducting/guiding meetings with senior leadership and stakeholders Ability to use prior experience and knowledge to address new situations Certification requirements (at least one of the following): SecurityX / CASP+, CCISO, CGRC/CAP, CISA, CISM, CISSO, CISSP, CISSP-ISSEP, Cloud+, CySA+, FITSP-A, GCSA, GSEC, GSLC, GSNA, PenTest+, Security+ B.A. or B.S. Information Security, Computer Science or related discipline US Citizenship and currently possess a Top Secret security clearance Desired Qualifications: Experience with Fast Track ATO Handbook & AF Continuous ATO Playbook Familiarity with CI/CD Pipelines DevSecOps experience Sharepoint, JIRA, Confluence familiarity The salary range for this position is $140,000.00 - $145,000.00 commensurate on experience and technical skillset. We are open to considering a variety of levels of experience for these projects and potential for 1099 hourly opportunity. We are proud to be an EEO/AA Employer Minorities/Women/Veterans/Disabled and other protected categories. In compliance with federal law, all persons hired will be required to verify identity, confirm US Citizenship, and complete the required employment eligibility verification upon hire.
09/28/2026
Full time
Job Description Job Description Dark Wolf Solutions is seeking a Senior Security Control Assessor Representative (SCAR) to conduct independent comprehensive assessments of the management, operation, and technical security controls and control enhancements employed within, or inherited by, an Information technology (IT) system to determine the overall effectiveness of the controls. The SCAR will perform reviews of security artifacts for system authorizations, assessing both the technical and functional adequacy as required for application and software cybersecurity readiness. The SCAR candidate must have prior experience in authorizing tools/applications, systems, and/or enclaves. Additionally, knowledge of network security, technologies, processes, and practices designed for the prevention of damage to, protection of, and restoration of computers, communications systems, services, and various types of communications technologies. The SCAR candidate must be knowledgeable and proficient in assessing DoD GovCloud environments to include testing controls and validating artifacts. A successful candidate will have a strong foundational understanding of NIST, DOD, and DAF cybersecurity focused guidance. This position can be based out of any Dark Wolf Office location and will be a hybrid schedule. Additional responsibilities include: Key Responsibilities: Evaluating IT infrastructure in terms of risk to the organization and defining artifacts required to meet Federal, DoD and DAF requirements Assessing IT systems and architecture to ensure compliance with the Risk Management Framework (RMF), NIST Cybersecurity Framework (CSF), NIST 800-53 revision 5 and applicable guidance Supporting the system/application assessment and authorization (A&A) effort, to include assessing and guiding the quality and completeness of A&A activities, tasks and resulting artifacts mandated by governing DoD and AF policies, and applicable mandates Collecting, reviewing and verifying documented business processes within process narratives or flowcharts, identifying risks and validating proficiency of mitigating controls Reviewing risk and control matrices and testing plans for key controls and determines effectiveness Identifying control gaps, reviewing and testing the design of existing controls. Formulating clear and concise conclusions on internal controls and business process efficiency Recommending policies and procedures to ensure information systems reliability and accessibility and to prevent and defend against unauthorized access to systems, networks, and data Conducting risk and vulnerability assessments of installed information systems to identify vulnerabilities, risks, and protection needs Reviewing Plans of Actions & Milestones (POA&Ms) Providing recommendations and reports to the Security Control Assessor (SCA), Authorizing Official (AO), Chief Information Security Officer (CISO) Reviewing network and systems design to ensure accuracy Ensuring the rigorous application of information security/cybersecurity policies, principles, and practices in the delivery of all IT services Required Qualifications: 15+ years of relevant Cyber experience 15+ years prior experience as a Security Control Assessor/Representative RMF Engineer, ISSO, ISSM and/or information assurance engineer Cloud Platform experience with at least one service offering from AWS, Azure, or Google GCP Hands-on eMASS and/or Xacta experience completing full system lifecycle activities Experience with Air Force risk management policies/procedures, to include, DODI 8510.01, AFI 17-101 Experience with Cloud Computing Security Requirements Guide (CC SRG) Knowledgeable with DoD DevSecOps Fundamentals Playbook Experience evaluating information security compliance against STIGs Ability to clearly articulate ideas Strong technical writing abilities to author reports for AO and CISO dissemination Exudes confidence in providing briefings, presentations, and in conducting/guiding meetings with senior leadership and stakeholders Ability to use prior experience and knowledge to address new situations Certification requirements (at least one of the following): SecurityX / CASP+, CCISO, CGRC/CAP, CISA, CISM, CISSO, CISSP, CISSP-ISSEP, Cloud+, CySA+, FITSP-A, GCSA, GSEC, GSLC, GSNA, PenTest+, Security+ B.A. or B.S. Information Security, Computer Science or related discipline US Citizenship and currently possess a Top Secret security clearance Desired Qualifications: Experience with Fast Track ATO Handbook & AF Continuous ATO Playbook Familiarity with CI/CD Pipelines DevSecOps experience Sharepoint, JIRA, Confluence familiarity The salary range for this position is $140,000.00 - $145,000.00 commensurate on experience and technical skillset. We are open to considering a variety of levels of experience for these projects and potential for 1099 hourly opportunity. We are proud to be an EEO/AA Employer Minorities/Women/Veterans/Disabled and other protected categories. In compliance with federal law, all persons hired will be required to verify identity, confirm US Citizenship, and complete the required employment eligibility verification upon hire.
Job Description Job Description Dark Wolf Solutions is seeking a Senior Security Control Assessor Representative (SCAR) to conduct independent comprehensive assessments of the management, operation, and technical security controls and control enhancements employed within, or inherited by, an Information technology (IT) system to determine the overall effectiveness of the controls. The SCAR will perform reviews of security artifacts for system authorizations, assessing both the technical and functional adequacy as required for application and software cybersecurity readiness. The SCAR candidate must have prior experience in authorizing tools/applications, systems, and/or enclaves. Additionally, knowledge of network security, technologies, processes, and practices designed for the prevention of damage to, protection of, and restoration of computers, communications systems, services, and various types of communications technologies. The SCAR candidate must be knowledgeable and proficient in assessing DoD GovCloud environments to include testing controls and validating artifacts. A successful candidate will have a strong foundational understanding of NIST, DOD, and DAF cybersecurity focused guidance. This position can be based out of any Dark Wolf Office location and will be a hybrid schedule. Additional responsibilities include: Key Responsibilities: Evaluating IT infrastructure in terms of risk to the organization and defining artifacts required to meet Federal, DoD and DAF requirements Assessing IT systems and architecture to ensure compliance with the Risk Management Framework (RMF), NIST Cybersecurity Framework (CSF), NIST 800-53 revision 5 and applicable guidance Supporting the system/application assessment and authorization (A&A) effort, to include assessing and guiding the quality and completeness of A&A activities, tasks and resulting artifacts mandated by governing DoD and AF policies, and applicable mandates Collecting, reviewing and verifying documented business processes within process narratives or flowcharts, identifying risks and validating proficiency of mitigating controls Reviewing risk and control matrices and testing plans for key controls and determines effectiveness Identifying control gaps, reviewing and testing the design of existing controls. Formulating clear and concise conclusions on internal controls and business process efficiency Recommending policies and procedures to ensure information systems reliability and accessibility and to prevent and defend against unauthorized access to systems, networks, and data Conducting risk and vulnerability assessments of installed information systems to identify vulnerabilities, risks, and protection needs Reviewing Plans of Actions & Milestones (POA&Ms) Providing recommendations and reports to the Security Control Assessor (SCA), Authorizing Official (AO), Chief Information Security Officer (CISO) Reviewing network and systems design to ensure accuracy Ensuring the rigorous application of information security/cybersecurity policies, principles, and practices in the delivery of all IT services Required Qualifications: 15+ years of relevant Cyber experience 15+ years prior experience as a Security Control Assessor/Representative RMF Engineer, ISSO, ISSM and/or information assurance engineer Cloud Platform experience with at least one service offering from AWS, Azure, or Google GCP Hands-on eMASS and/or Xacta experience completing full system lifecycle activities Experience with Air Force risk management policies/procedures, to include, DODI 8510.01, AFI 17-101 Experience with Cloud Computing Security Requirements Guide (CC SRG) Knowledgeable with DoD DevSecOps Fundamentals Playbook Experience evaluating information security compliance against STIGs Ability to clearly articulate ideas Strong technical writing abilities to author reports for AO and CISO dissemination Exudes confidence in providing briefings, presentations, and in conducting/guiding meetings with senior leadership and stakeholders Ability to use prior experience and knowledge to address new situations Certification requirements (at least one of the following): SecurityX / CASP+, CCISO, CGRC/CAP, CISA, CISM, CISSO, CISSP, CISSP-ISSEP, Cloud+, CySA+, FITSP-A, GCSA, GSEC, GSLC, GSNA, PenTest+, Security+ B.A. or B.S. Information Security, Computer Science or related discipline US Citizenship and currently possess a Top Secret security clearance Desired Qualifications: Experience with Fast Track ATO Handbook & AF Continuous ATO Playbook Familiarity with CI/CD Pipelines DevSecOps experience Sharepoint, JIRA, Confluence familiarity The salary range for this position is $140,000.00 - $145,000.00 commensurate on experience and technical skillset. We are open to considering a variety of levels of experience for these projects and potential for 1099 hourly opportunity. We are proud to be an EEO/AA Employer Minorities/Women/Veterans/Disabled and other protected categories. In compliance with federal law, all persons hired will be required to verify identity, confirm US Citizenship, and complete the required employment eligibility verification upon hire.
09/28/2026
Full time
Job Description Job Description Dark Wolf Solutions is seeking a Senior Security Control Assessor Representative (SCAR) to conduct independent comprehensive assessments of the management, operation, and technical security controls and control enhancements employed within, or inherited by, an Information technology (IT) system to determine the overall effectiveness of the controls. The SCAR will perform reviews of security artifacts for system authorizations, assessing both the technical and functional adequacy as required for application and software cybersecurity readiness. The SCAR candidate must have prior experience in authorizing tools/applications, systems, and/or enclaves. Additionally, knowledge of network security, technologies, processes, and practices designed for the prevention of damage to, protection of, and restoration of computers, communications systems, services, and various types of communications technologies. The SCAR candidate must be knowledgeable and proficient in assessing DoD GovCloud environments to include testing controls and validating artifacts. A successful candidate will have a strong foundational understanding of NIST, DOD, and DAF cybersecurity focused guidance. This position can be based out of any Dark Wolf Office location and will be a hybrid schedule. Additional responsibilities include: Key Responsibilities: Evaluating IT infrastructure in terms of risk to the organization and defining artifacts required to meet Federal, DoD and DAF requirements Assessing IT systems and architecture to ensure compliance with the Risk Management Framework (RMF), NIST Cybersecurity Framework (CSF), NIST 800-53 revision 5 and applicable guidance Supporting the system/application assessment and authorization (A&A) effort, to include assessing and guiding the quality and completeness of A&A activities, tasks and resulting artifacts mandated by governing DoD and AF policies, and applicable mandates Collecting, reviewing and verifying documented business processes within process narratives or flowcharts, identifying risks and validating proficiency of mitigating controls Reviewing risk and control matrices and testing plans for key controls and determines effectiveness Identifying control gaps, reviewing and testing the design of existing controls. Formulating clear and concise conclusions on internal controls and business process efficiency Recommending policies and procedures to ensure information systems reliability and accessibility and to prevent and defend against unauthorized access to systems, networks, and data Conducting risk and vulnerability assessments of installed information systems to identify vulnerabilities, risks, and protection needs Reviewing Plans of Actions & Milestones (POA&Ms) Providing recommendations and reports to the Security Control Assessor (SCA), Authorizing Official (AO), Chief Information Security Officer (CISO) Reviewing network and systems design to ensure accuracy Ensuring the rigorous application of information security/cybersecurity policies, principles, and practices in the delivery of all IT services Required Qualifications: 15+ years of relevant Cyber experience 15+ years prior experience as a Security Control Assessor/Representative RMF Engineer, ISSO, ISSM and/or information assurance engineer Cloud Platform experience with at least one service offering from AWS, Azure, or Google GCP Hands-on eMASS and/or Xacta experience completing full system lifecycle activities Experience with Air Force risk management policies/procedures, to include, DODI 8510.01, AFI 17-101 Experience with Cloud Computing Security Requirements Guide (CC SRG) Knowledgeable with DoD DevSecOps Fundamentals Playbook Experience evaluating information security compliance against STIGs Ability to clearly articulate ideas Strong technical writing abilities to author reports for AO and CISO dissemination Exudes confidence in providing briefings, presentations, and in conducting/guiding meetings with senior leadership and stakeholders Ability to use prior experience and knowledge to address new situations Certification requirements (at least one of the following): SecurityX / CASP+, CCISO, CGRC/CAP, CISA, CISM, CISSO, CISSP, CISSP-ISSEP, Cloud+, CySA+, FITSP-A, GCSA, GSEC, GSLC, GSNA, PenTest+, Security+ B.A. or B.S. Information Security, Computer Science or related discipline US Citizenship and currently possess a Top Secret security clearance Desired Qualifications: Experience with Fast Track ATO Handbook & AF Continuous ATO Playbook Familiarity with CI/CD Pipelines DevSecOps experience Sharepoint, JIRA, Confluence familiarity The salary range for this position is $140,000.00 - $145,000.00 commensurate on experience and technical skillset. We are open to considering a variety of levels of experience for these projects and potential for 1099 hourly opportunity. We are proud to be an EEO/AA Employer Minorities/Women/Veterans/Disabled and other protected categories. In compliance with federal law, all persons hired will be required to verify identity, confirm US Citizenship, and complete the required employment eligibility verification upon hire.
Job Description Job Description Benefits: 401(k) Competitive salary Dental insurance Health insurance Paid time off Vision insurance Cimarron is seeking a GNOSC Watch Officer/Network Engineer to support the Missile Defense Agency (MDA) on the Integrated Research and Development for Enterprise Solutions (IRES) contract at Schriever Space Force Base in the Colorado Springs, CO area. Key Duties: Responsible for all facets of a continuous 24/7 Global Network Operations and Security Center. Execute network, system, and cloud systems monitoring/surveillance, environmental monitoring, incident management and MDA Cybersecurity. Be responsible for all aspects of IT incident management and escalation, ensuring that incidents are effectively escalated, managed and resolved with full communication of status, plans, and actions provided to executive management and the Government customer. Support and service maintenance activities to include Change Management coordination during the assigned quarterly rotating shift day/night shifts. Required Skills, Experience, and Education: Due to facility security requirements, only U.S. citizens are eligible for consideration at this time. Ability to complete a pre-employment background check and drug screening, which will include, but is not limited to, testing for marijuana use. This position requires access to federal facilities. Candidates must possess a valid, unexpired Real ID-compliant driver's license or state-issued identification card at the time of hire. If you are unsure whether your ID is Real ID-compliant, please check for the star symbol in the upper portion of your driver's license or state ID. Active Secret Clearance. Current DoD 8570 IAT Level II certification (ex., Security + CE, CySA, etc.). 1 or more years of IT experience. Excellent communication skills, verbal and written, at both technical and senior/Executive management levels. Understanding of Command level Management. Able to speak clearly to diverse cultural audiences, VIPs, and dignitaries. Able to perform as a section trainer and create lesson plans. Able to operate within a stressful high speed Operational environment and be able to multi-task. Desired Skills, Experience, and Education: Experience in metrics-based IT Operations and Maintenance (O&M) teams. Experience with Remedy and SNMP monitoring tools (e.g., SolarWinds and StruxureWare Datacenter Expert). Have education or experience with ITIL framework and ITIL-based processes, to include continual service improvement, change management, and problem investigation. Previous work experience as a Windows/Linux System Administrator supporting a large Enterprise with knowledge of Microsoft Active Directory, Windows 2008/2012, Linux/UNIX Operating Systems, EMC Storage, Symantec NetBackup and SCCM Patch Management solutions. Previous work experience as a network engineer, including hands-on experience designing, implementing and managing network components including switches, routers, firewalls, and cryptographic devices. Experience with Cyber-defense or information assurance, including experience with DISA mandated security tools to include Assured Compliance Assessment Solution (ACAS), Host Based Security System (HBSS), analyze results and create reports Knowledge of IT Network Operations and connectivity devices that inter-relate with Public Key Infrastructure authentication and Information Security practices. Network Operations experience in a network operations center or other 24x7x365 IT Operations environment. Knowledge of Cybersecurity principles and how to execute system/network security analysis. Have a working knowledge of Tier III Information Assurance practices, IT security governance, security administration, project management, logistics, and Cybersecurity compliance requirements. Quality Assurance/Quality Control Inspection process knowledge.
09/28/2026
Full time
Job Description Job Description Benefits: 401(k) Competitive salary Dental insurance Health insurance Paid time off Vision insurance Cimarron is seeking a GNOSC Watch Officer/Network Engineer to support the Missile Defense Agency (MDA) on the Integrated Research and Development for Enterprise Solutions (IRES) contract at Schriever Space Force Base in the Colorado Springs, CO area. Key Duties: Responsible for all facets of a continuous 24/7 Global Network Operations and Security Center. Execute network, system, and cloud systems monitoring/surveillance, environmental monitoring, incident management and MDA Cybersecurity. Be responsible for all aspects of IT incident management and escalation, ensuring that incidents are effectively escalated, managed and resolved with full communication of status, plans, and actions provided to executive management and the Government customer. Support and service maintenance activities to include Change Management coordination during the assigned quarterly rotating shift day/night shifts. Required Skills, Experience, and Education: Due to facility security requirements, only U.S. citizens are eligible for consideration at this time. Ability to complete a pre-employment background check and drug screening, which will include, but is not limited to, testing for marijuana use. This position requires access to federal facilities. Candidates must possess a valid, unexpired Real ID-compliant driver's license or state-issued identification card at the time of hire. If you are unsure whether your ID is Real ID-compliant, please check for the star symbol in the upper portion of your driver's license or state ID. Active Secret Clearance. Current DoD 8570 IAT Level II certification (ex., Security + CE, CySA, etc.). 1 or more years of IT experience. Excellent communication skills, verbal and written, at both technical and senior/Executive management levels. Understanding of Command level Management. Able to speak clearly to diverse cultural audiences, VIPs, and dignitaries. Able to perform as a section trainer and create lesson plans. Able to operate within a stressful high speed Operational environment and be able to multi-task. Desired Skills, Experience, and Education: Experience in metrics-based IT Operations and Maintenance (O&M) teams. Experience with Remedy and SNMP monitoring tools (e.g., SolarWinds and StruxureWare Datacenter Expert). Have education or experience with ITIL framework and ITIL-based processes, to include continual service improvement, change management, and problem investigation. Previous work experience as a Windows/Linux System Administrator supporting a large Enterprise with knowledge of Microsoft Active Directory, Windows 2008/2012, Linux/UNIX Operating Systems, EMC Storage, Symantec NetBackup and SCCM Patch Management solutions. Previous work experience as a network engineer, including hands-on experience designing, implementing and managing network components including switches, routers, firewalls, and cryptographic devices. Experience with Cyber-defense or information assurance, including experience with DISA mandated security tools to include Assured Compliance Assessment Solution (ACAS), Host Based Security System (HBSS), analyze results and create reports Knowledge of IT Network Operations and connectivity devices that inter-relate with Public Key Infrastructure authentication and Information Security practices. Network Operations experience in a network operations center or other 24x7x365 IT Operations environment. Knowledge of Cybersecurity principles and how to execute system/network security analysis. Have a working knowledge of Tier III Information Assurance practices, IT security governance, security administration, project management, logistics, and Cybersecurity compliance requirements. Quality Assurance/Quality Control Inspection process knowledge.
Job Description Job Description Company Overview: Over the past 15 years, eTel has delivered essential solutions for the federal government by securing and managing data, providing scalable identity access, modernizing legacy systems, and building high-performance platforms. By integrating new technologies and ensuring reliable operations we help agencies stay prepared for future challenges As a premier technology solutions and services company to the US federal government, eTel possesses longstanding relationships across the federal civilian marketplace. Other customers include the broader Treasury Department, Commerce Department, and State Department. eTel offers integrated CMMI Level 3 processes, tools, and techniques with innovative, cost-efficient, and secure solutions to address complex challenges. eTel also holds ISO 9001:2015, ISO/IEC 27001:2013, and ISO/IEC 20000-1:2018 certifications, and offers dedicated subject matter experts (SMEs) and thought leaders that possess a deep understanding of customers' environments and challenges. Work Location and On-Site/Telework Requirements: Hybrid - NIH, Bethesda, MD. On site for workshops and pilots (typically 1-2 days/week during the first 120 days, then as scheduled). Citizenship: U.S. Citizenship required Clearance: All staff must obtain NIH suitability and a PIV credential and be fluent in English. Anyone doing risk or vulnerability testing needs a current T2 (BI) or higher investigation. Salary Range: $130,000-$140,000 yearly salary Overview : You will co-author the cloud, network, and identity design patterns behind NIH's Future State ZTA under the NIH Governance, Risk & Compliance (GRC) Zero Trust Architecture (ZTA) Support Services task order for the NIH Office of the Chief Information Officer (OCIO). You will work in the Architecture Pod on Tasks 2, 3, and 4. This is a design and advisory role: you will produce reference architectures, patterns, and control mappings for NIH teams to implement, not operate NIH production systems. Deep hands-on engineering experience is still essential. Responsibilities : Co-author the cloud, on-premises, and hybrid reference architectures (Subtask 2.2) with the Senior ZT Architect, as reusable design patterns with NIST SP 800-53 Rev 5 control mappings. Design microsegmentation and workload-identity patterns (NIST SP 800-207A, CISA and NSA Zero Trust guidance), software-defined perimeter for HPC clusters, and isolated VLANs with brokered remote access for laboratory instruments. Document how centrally provided network, endpoint, and logging services are inherited, as input to the Centrally Provided Services Matrix. Define technical policy anchors for the network and device pillars (segmentation policy in the controller, compliance policy in endpoint management). Map controls to telemetry so continuous-monitoring evidence is collected rather than written by hand. Support Task 3 network use cases: flow baselining to generate and validate microsegmentation policy, and lateral-movement anomaly detection. Support the Task 4 gap assessment for the network, device, and cloud pillars, and the evidence expectations in the ZTA Overlay. Validate patterns with IC engineering teams (CIT, HPC, and clinical platform owners). Tools & Technology Environment : AWS and Azure (including GovCloud), cloud-native IAM and CSPM; SSE/ZTNA (e.g., Zscaler, Palo Alto); microsegmentation platforms (e.g., Illumio); Palo Alto/Fortinet/Cisco firewalls; Microsoft Defender, CrowdStrike, Forescout; Splunk/Microsoft Sentinel; Terraform/IaC; Git. Required Qualifications : Bachelor's degree plus 7+ years of network and/or cloud security engineering. Hands-on experience with identity-aware access, microsegmentation, and cloud security patterns in enterprise environments. Experience with firewalls, SSE/ZTNA, and native AWS or Azure security services. Security+ or a higher security certification. Ability to obtain an NIH suitability determination and PIV credential; fluent in English. Preferred Qualifications : A cloud security certification (AWS Security Specialty, AZ-500, or CCSP); PCNSE or CCNP Security. Experience in FedRAMP-authorized or GovCloud environments. Experience with research networks, HPC (Linux/Slurm), or operational technology/IoT device segmentation. Infrastructure-as-code (Terraform, CloudFormation) and experience writing security patterns as code. Current National Institutes of Health (NIH) or U.S. Department of Health and Human Services (HHS) experience is highly preferred. Commitment to Diversity - eTelligent Group provides equal employment opportunities (EEO) to all applicants without regard to race, color, religion, gender, sexual orientation, gender identity, nations origin, age, disability, genetic information, marital status, amnesty, status as a covered veteran, and any other characteristic provided in accordance with applicable, federal, state and local laws.
09/28/2026
Full time
Job Description Job Description Company Overview: Over the past 15 years, eTel has delivered essential solutions for the federal government by securing and managing data, providing scalable identity access, modernizing legacy systems, and building high-performance platforms. By integrating new technologies and ensuring reliable operations we help agencies stay prepared for future challenges As a premier technology solutions and services company to the US federal government, eTel possesses longstanding relationships across the federal civilian marketplace. Other customers include the broader Treasury Department, Commerce Department, and State Department. eTel offers integrated CMMI Level 3 processes, tools, and techniques with innovative, cost-efficient, and secure solutions to address complex challenges. eTel also holds ISO 9001:2015, ISO/IEC 27001:2013, and ISO/IEC 20000-1:2018 certifications, and offers dedicated subject matter experts (SMEs) and thought leaders that possess a deep understanding of customers' environments and challenges. Work Location and On-Site/Telework Requirements: Hybrid - NIH, Bethesda, MD. On site for workshops and pilots (typically 1-2 days/week during the first 120 days, then as scheduled). Citizenship: U.S. Citizenship required Clearance: All staff must obtain NIH suitability and a PIV credential and be fluent in English. Anyone doing risk or vulnerability testing needs a current T2 (BI) or higher investigation. Salary Range: $130,000-$140,000 yearly salary Overview : You will co-author the cloud, network, and identity design patterns behind NIH's Future State ZTA under the NIH Governance, Risk & Compliance (GRC) Zero Trust Architecture (ZTA) Support Services task order for the NIH Office of the Chief Information Officer (OCIO). You will work in the Architecture Pod on Tasks 2, 3, and 4. This is a design and advisory role: you will produce reference architectures, patterns, and control mappings for NIH teams to implement, not operate NIH production systems. Deep hands-on engineering experience is still essential. Responsibilities : Co-author the cloud, on-premises, and hybrid reference architectures (Subtask 2.2) with the Senior ZT Architect, as reusable design patterns with NIST SP 800-53 Rev 5 control mappings. Design microsegmentation and workload-identity patterns (NIST SP 800-207A, CISA and NSA Zero Trust guidance), software-defined perimeter for HPC clusters, and isolated VLANs with brokered remote access for laboratory instruments. Document how centrally provided network, endpoint, and logging services are inherited, as input to the Centrally Provided Services Matrix. Define technical policy anchors for the network and device pillars (segmentation policy in the controller, compliance policy in endpoint management). Map controls to telemetry so continuous-monitoring evidence is collected rather than written by hand. Support Task 3 network use cases: flow baselining to generate and validate microsegmentation policy, and lateral-movement anomaly detection. Support the Task 4 gap assessment for the network, device, and cloud pillars, and the evidence expectations in the ZTA Overlay. Validate patterns with IC engineering teams (CIT, HPC, and clinical platform owners). Tools & Technology Environment : AWS and Azure (including GovCloud), cloud-native IAM and CSPM; SSE/ZTNA (e.g., Zscaler, Palo Alto); microsegmentation platforms (e.g., Illumio); Palo Alto/Fortinet/Cisco firewalls; Microsoft Defender, CrowdStrike, Forescout; Splunk/Microsoft Sentinel; Terraform/IaC; Git. Required Qualifications : Bachelor's degree plus 7+ years of network and/or cloud security engineering. Hands-on experience with identity-aware access, microsegmentation, and cloud security patterns in enterprise environments. Experience with firewalls, SSE/ZTNA, and native AWS or Azure security services. Security+ or a higher security certification. Ability to obtain an NIH suitability determination and PIV credential; fluent in English. Preferred Qualifications : A cloud security certification (AWS Security Specialty, AZ-500, or CCSP); PCNSE or CCNP Security. Experience in FedRAMP-authorized or GovCloud environments. Experience with research networks, HPC (Linux/Slurm), or operational technology/IoT device segmentation. Infrastructure-as-code (Terraform, CloudFormation) and experience writing security patterns as code. Current National Institutes of Health (NIH) or U.S. Department of Health and Human Services (HHS) experience is highly preferred. Commitment to Diversity - eTelligent Group provides equal employment opportunities (EEO) to all applicants without regard to race, color, religion, gender, sexual orientation, gender identity, nations origin, age, disability, genetic information, marital status, amnesty, status as a covered veteran, and any other characteristic provided in accordance with applicable, federal, state and local laws.
Job Description Job Description Dark Wolf Solutions is seeking a Senior Security Control Assessor Representative (SCAR) to conduct independent comprehensive assessments of the management, operation, and technical security controls and control enhancements employed within, or inherited by, an Information technology (IT) system to determine the overall effectiveness of the controls. The SCAR will perform reviews of security artifacts for system authorizations, assessing both the technical and functional adequacy as required for application and software cybersecurity readiness. The SCAR candidate must have prior experience in authorizing tools/applications, systems, and/or enclaves. Additionally, knowledge of network security, technologies, processes, and practices designed for the prevention of damage to, protection of, and restoration of computers, communications systems, services, and various types of communications technologies. The SCAR candidate must be knowledgeable and proficient in assessing DoD GovCloud environments to include testing controls and validating artifacts. A successful candidate will have a strong foundational understanding of NIST, DOD, and DAF cybersecurity focused guidance. This position can be based out of any Dark Wolf Office location and will be a hybrid schedule. Additional responsibilities include: Key Responsibilities: Evaluating IT infrastructure in terms of risk to the organization and defining artifacts required to meet Federal, DoD and DAF requirements Assessing IT systems and architecture to ensure compliance with the Risk Management Framework (RMF), NIST Cybersecurity Framework (CSF), NIST 800-53 revision 5 and applicable guidance Supporting the system/application assessment and authorization (A&A) effort, to include assessing and guiding the quality and completeness of A&A activities, tasks and resulting artifacts mandated by governing DoD and AF policies, and applicable mandates Collecting, reviewing and verifying documented business processes within process narratives or flowcharts, identifying risks and validating proficiency of mitigating controls Reviewing risk and control matrices and testing plans for key controls and determines effectiveness Identifying control gaps, reviewing and testing the design of existing controls. Formulating clear and concise conclusions on internal controls and business process efficiency Recommending policies and procedures to ensure information systems reliability and accessibility and to prevent and defend against unauthorized access to systems, networks, and data Conducting risk and vulnerability assessments of installed information systems to identify vulnerabilities, risks, and protection needs Reviewing Plans of Actions & Milestones (POA&Ms) Providing recommendations and reports to the Security Control Assessor (SCA), Authorizing Official (AO), Chief Information Security Officer (CISO) Reviewing network and systems design to ensure accuracy Ensuring the rigorous application of information security/cybersecurity policies, principles, and practices in the delivery of all IT services Required Qualifications: 15+ years of relevant Cyber experience 15+ years prior experience as a Security Control Assessor/Representative RMF Engineer, ISSO, ISSM and/or information assurance engineer Cloud Platform experience with at least one service offering from AWS, Azure, or Google GCP Hands-on eMASS and/or Xacta experience completing full system lifecycle activities Experience with Air Force risk management policies/procedures, to include, DODI 8510.01, AFI 17-101 Experience with Cloud Computing Security Requirements Guide (CC SRG) Knowledgeable with DoD DevSecOps Fundamentals Playbook Experience evaluating information security compliance against STIGs Ability to clearly articulate ideas Strong technical writing abilities to author reports for AO and CISO dissemination Exudes confidence in providing briefings, presentations, and in conducting/guiding meetings with senior leadership and stakeholders Ability to use prior experience and knowledge to address new situations Certification requirements (at least one of the following): SecurityX / CASP+, CCISO, CGRC/CAP, CISA, CISM, CISSO, CISSP, CISSP-ISSEP, Cloud+, CySA+, FITSP-A, GCSA, GSEC, GSLC, GSNA, PenTest+, Security+ B.A. or B.S. Information Security, Computer Science or related discipline US Citizenship and currently possess a Top Secret security clearance Desired Qualifications: Experience with Fast Track ATO Handbook & AF Continuous ATO Playbook Familiarity with CI/CD Pipelines DevSecOps experience Sharepoint, JIRA, Confluence familiarity The salary range for this position is $140,000.00 - $145,000.00 commensurate on experience and technical skillset. We are open to considering a variety of levels of experience for these projects and potential for 1099 hourly opportunity. We are proud to be an EEO/AA Employer Minorities/Women/Veterans/Disabled and other protected categories. In compliance with federal law, all persons hired will be required to verify identity, confirm US Citizenship, and complete the required employment eligibility verification upon hire.
09/28/2026
Full time
Job Description Job Description Dark Wolf Solutions is seeking a Senior Security Control Assessor Representative (SCAR) to conduct independent comprehensive assessments of the management, operation, and technical security controls and control enhancements employed within, or inherited by, an Information technology (IT) system to determine the overall effectiveness of the controls. The SCAR will perform reviews of security artifacts for system authorizations, assessing both the technical and functional adequacy as required for application and software cybersecurity readiness. The SCAR candidate must have prior experience in authorizing tools/applications, systems, and/or enclaves. Additionally, knowledge of network security, technologies, processes, and practices designed for the prevention of damage to, protection of, and restoration of computers, communications systems, services, and various types of communications technologies. The SCAR candidate must be knowledgeable and proficient in assessing DoD GovCloud environments to include testing controls and validating artifacts. A successful candidate will have a strong foundational understanding of NIST, DOD, and DAF cybersecurity focused guidance. This position can be based out of any Dark Wolf Office location and will be a hybrid schedule. Additional responsibilities include: Key Responsibilities: Evaluating IT infrastructure in terms of risk to the organization and defining artifacts required to meet Federal, DoD and DAF requirements Assessing IT systems and architecture to ensure compliance with the Risk Management Framework (RMF), NIST Cybersecurity Framework (CSF), NIST 800-53 revision 5 and applicable guidance Supporting the system/application assessment and authorization (A&A) effort, to include assessing and guiding the quality and completeness of A&A activities, tasks and resulting artifacts mandated by governing DoD and AF policies, and applicable mandates Collecting, reviewing and verifying documented business processes within process narratives or flowcharts, identifying risks and validating proficiency of mitigating controls Reviewing risk and control matrices and testing plans for key controls and determines effectiveness Identifying control gaps, reviewing and testing the design of existing controls. Formulating clear and concise conclusions on internal controls and business process efficiency Recommending policies and procedures to ensure information systems reliability and accessibility and to prevent and defend against unauthorized access to systems, networks, and data Conducting risk and vulnerability assessments of installed information systems to identify vulnerabilities, risks, and protection needs Reviewing Plans of Actions & Milestones (POA&Ms) Providing recommendations and reports to the Security Control Assessor (SCA), Authorizing Official (AO), Chief Information Security Officer (CISO) Reviewing network and systems design to ensure accuracy Ensuring the rigorous application of information security/cybersecurity policies, principles, and practices in the delivery of all IT services Required Qualifications: 15+ years of relevant Cyber experience 15+ years prior experience as a Security Control Assessor/Representative RMF Engineer, ISSO, ISSM and/or information assurance engineer Cloud Platform experience with at least one service offering from AWS, Azure, or Google GCP Hands-on eMASS and/or Xacta experience completing full system lifecycle activities Experience with Air Force risk management policies/procedures, to include, DODI 8510.01, AFI 17-101 Experience with Cloud Computing Security Requirements Guide (CC SRG) Knowledgeable with DoD DevSecOps Fundamentals Playbook Experience evaluating information security compliance against STIGs Ability to clearly articulate ideas Strong technical writing abilities to author reports for AO and CISO dissemination Exudes confidence in providing briefings, presentations, and in conducting/guiding meetings with senior leadership and stakeholders Ability to use prior experience and knowledge to address new situations Certification requirements (at least one of the following): SecurityX / CASP+, CCISO, CGRC/CAP, CISA, CISM, CISSO, CISSP, CISSP-ISSEP, Cloud+, CySA+, FITSP-A, GCSA, GSEC, GSLC, GSNA, PenTest+, Security+ B.A. or B.S. Information Security, Computer Science or related discipline US Citizenship and currently possess a Top Secret security clearance Desired Qualifications: Experience with Fast Track ATO Handbook & AF Continuous ATO Playbook Familiarity with CI/CD Pipelines DevSecOps experience Sharepoint, JIRA, Confluence familiarity The salary range for this position is $140,000.00 - $145,000.00 commensurate on experience and technical skillset. We are open to considering a variety of levels of experience for these projects and potential for 1099 hourly opportunity. We are proud to be an EEO/AA Employer Minorities/Women/Veterans/Disabled and other protected categories. In compliance with federal law, all persons hired will be required to verify identity, confirm US Citizenship, and complete the required employment eligibility verification upon hire.
Job Description Job Description This position must meet Export Control compliance requirements, therefore a "US Person" as defined by 22 C.F.R. 120.15 is required. "US Person" includes US Citizen, lawful permanent resident, refugee, or asylee. In compliance with federal law, all persons hired will be required to verify identity and eligibility to work in the United States and to complete the required employment eligibility verification form upon hire. Canyon AeroConnect stands as one of the world's leading suppliers of avionic-standard aircraft communications, navigation and audio/intercom systems. Canyon's products have been widely adopted and proven in-service across a wide range of civilian, paramilitary and military fixed-wing and rotorcraft applications. Over the years, we've become known as the benchmark in aircraft tactical communication and audio equipment for Air Ambulance, Law Enforcement, SAR, EMS, Electronic News Gathering, Military and Marine applications. Products include digital and analog radio/audio management systems, Tac/Com, VHF/UHF radio systems, intercoms, data interface accessories, and aural warning. We are seeking dynamic thinkers who could be integral team members for our high-tech avionics' products. Role purpose (position scope): The Information Security Specialist (Information Systems Security Officer) helps build and operate the internal security program and technology operations. This hands-on role works across security operations, identity and access management, endpoint and network defense, vendor risk, compliance, and end-user enablement. The position works closely with IT, engineering, and business teams to keep the company secure without slowing it down and is intended for an individual who wants to grow into a senior internal security role over time. Key Responsibilities: Support day-to-day security operations, including SIEM and EDR alert triage, log review, and incident-response investigations. Help administer identity and access management systems, including SSO, MFA, directory services, onboarding, transfers, offboarding, periodic access reviews, and cleanup of stale accounts and entitlements. Maintain and improve endpoint security, including EDR health, patch management, configuration baselines, and disk encryption. Assist with firewall rule reviews, VPN administration, network segmentation, and monitoring for misconfigurations. Support vulnerability scanning, prioritization, remediation coordination, and metric tracking. Support compliance activities such as CMMC and NIST by collecting evidence, maintaining policies, completing customer security questionnaires, and preparing for applicable audits. Support vendor risk management by reviewing third-party security documentation and tracking risk acceptances. Develop and deliver security awareness content, including phishing simulations, onboarding training, and internal guidance. Serve as a point of contact for security questions, suspicious emails, lost devices, and access requests. Document security processes, runbooks, and System Security Plan (SSP) so the program can scale as the company grows. Participate in the on-call rotation. Required Qualifications: At least one year of experience in information security, IT operations, or a closely related field Solid fundamentals in networking, operating systems, and authentication protocols. Familiarity with compliance frameworks, especially CMMC and applicable European requirements such as Cyber Essentials. Ability to script in Python, PowerShell, or Bash for automation and ad hoc tasks. Strong written and verbal communication skills, including the ability to explain security concepts to non-technical audiences. Experience supporting and managing highly regulated and secured network systems. Self-directed and comfortable providing Tier 2 helpdesk support as well as working across teams in a fast-moving environment. Willingness to be part of the on-call rotation and respond to cyber incidents during evening or weekends. Ability to obtain industry certifications such as CCNA, CompTIA Security+, or Network+ within the next 12 months. Preferred Qualifications: Three or more years of experience in information security, AI, or a closely related field, with hands-on exposure to multiple security domains. Working knowledge of SIEM, EDR, vulnerability scanners, identity providers such as Okta or Entra ID, and cloud platforms such as AWS, Azure, or GCP. Experience supporting or leading audits. Exposure to cloud security posture management. Familiarity with offensive security concepts and tooling highly regulated and secured network systems. Industry certification such as CISSP, CISM, CCIE, CCNP Security, CISA, CRISC, or similar. Compliance Considerations: The role may support applicable information-security and regulatory requirements identified for the business, including ITAR, CMMC, NIS2, Cyber Essentials and Cyber Essentials Plus, CMS, DCPP, and ISO/IEC 27001. Work Environment: This is an on-site position at the designated company location. Direct Reports No direct reports. The position may provide technical direction, peer review, or mentoring consistent with the assigned level. Physical Demands Tasks involve light physical effort in sedentary to light work and may involve lifting, carrying, pushing, or pulling objects or materials weighing 5-10 lb. Tasks may involve extended periods at a keyboard or workstation. Work Environment Reasonable accommodations may be made to enable individuals with disabilities to perform the essential functions. While performing the job duties described above, the employee mainly works in an office, lab, or factory setting that is relatively quiet and has temperature-control systems. This job description is not intended to be all inclusive of every job function, duty and responsibility. Duties may increase, decrease and/or change as deemed necessary to support the department operations.
09/28/2026
Full time
Job Description Job Description This position must meet Export Control compliance requirements, therefore a "US Person" as defined by 22 C.F.R. 120.15 is required. "US Person" includes US Citizen, lawful permanent resident, refugee, or asylee. In compliance with federal law, all persons hired will be required to verify identity and eligibility to work in the United States and to complete the required employment eligibility verification form upon hire. Canyon AeroConnect stands as one of the world's leading suppliers of avionic-standard aircraft communications, navigation and audio/intercom systems. Canyon's products have been widely adopted and proven in-service across a wide range of civilian, paramilitary and military fixed-wing and rotorcraft applications. Over the years, we've become known as the benchmark in aircraft tactical communication and audio equipment for Air Ambulance, Law Enforcement, SAR, EMS, Electronic News Gathering, Military and Marine applications. Products include digital and analog radio/audio management systems, Tac/Com, VHF/UHF radio systems, intercoms, data interface accessories, and aural warning. We are seeking dynamic thinkers who could be integral team members for our high-tech avionics' products. Role purpose (position scope): The Information Security Specialist (Information Systems Security Officer) helps build and operate the internal security program and technology operations. This hands-on role works across security operations, identity and access management, endpoint and network defense, vendor risk, compliance, and end-user enablement. The position works closely with IT, engineering, and business teams to keep the company secure without slowing it down and is intended for an individual who wants to grow into a senior internal security role over time. Key Responsibilities: Support day-to-day security operations, including SIEM and EDR alert triage, log review, and incident-response investigations. Help administer identity and access management systems, including SSO, MFA, directory services, onboarding, transfers, offboarding, periodic access reviews, and cleanup of stale accounts and entitlements. Maintain and improve endpoint security, including EDR health, patch management, configuration baselines, and disk encryption. Assist with firewall rule reviews, VPN administration, network segmentation, and monitoring for misconfigurations. Support vulnerability scanning, prioritization, remediation coordination, and metric tracking. Support compliance activities such as CMMC and NIST by collecting evidence, maintaining policies, completing customer security questionnaires, and preparing for applicable audits. Support vendor risk management by reviewing third-party security documentation and tracking risk acceptances. Develop and deliver security awareness content, including phishing simulations, onboarding training, and internal guidance. Serve as a point of contact for security questions, suspicious emails, lost devices, and access requests. Document security processes, runbooks, and System Security Plan (SSP) so the program can scale as the company grows. Participate in the on-call rotation. Required Qualifications: At least one year of experience in information security, IT operations, or a closely related field Solid fundamentals in networking, operating systems, and authentication protocols. Familiarity with compliance frameworks, especially CMMC and applicable European requirements such as Cyber Essentials. Ability to script in Python, PowerShell, or Bash for automation and ad hoc tasks. Strong written and verbal communication skills, including the ability to explain security concepts to non-technical audiences. Experience supporting and managing highly regulated and secured network systems. Self-directed and comfortable providing Tier 2 helpdesk support as well as working across teams in a fast-moving environment. Willingness to be part of the on-call rotation and respond to cyber incidents during evening or weekends. Ability to obtain industry certifications such as CCNA, CompTIA Security+, or Network+ within the next 12 months. Preferred Qualifications: Three or more years of experience in information security, AI, or a closely related field, with hands-on exposure to multiple security domains. Working knowledge of SIEM, EDR, vulnerability scanners, identity providers such as Okta or Entra ID, and cloud platforms such as AWS, Azure, or GCP. Experience supporting or leading audits. Exposure to cloud security posture management. Familiarity with offensive security concepts and tooling highly regulated and secured network systems. Industry certification such as CISSP, CISM, CCIE, CCNP Security, CISA, CRISC, or similar. Compliance Considerations: The role may support applicable information-security and regulatory requirements identified for the business, including ITAR, CMMC, NIS2, Cyber Essentials and Cyber Essentials Plus, CMS, DCPP, and ISO/IEC 27001. Work Environment: This is an on-site position at the designated company location. Direct Reports No direct reports. The position may provide technical direction, peer review, or mentoring consistent with the assigned level. Physical Demands Tasks involve light physical effort in sedentary to light work and may involve lifting, carrying, pushing, or pulling objects or materials weighing 5-10 lb. Tasks may involve extended periods at a keyboard or workstation. Work Environment Reasonable accommodations may be made to enable individuals with disabilities to perform the essential functions. While performing the job duties described above, the employee mainly works in an office, lab, or factory setting that is relatively quiet and has temperature-control systems. This job description is not intended to be all inclusive of every job function, duty and responsibility. Duties may increase, decrease and/or change as deemed necessary to support the department operations.
Job Description Job Description Dark Wolf Solutions is seeking a Senior Security Control Assessor Representative (SCAR) to conduct independent comprehensive assessments of the management, operation, and technical security controls and control enhancements employed within, or inherited by, an Information technology (IT) system to determine the overall effectiveness of the controls. The SCAR will perform reviews of security artifacts for system authorizations, assessing both the technical and functional adequacy as required for application and software cybersecurity readiness. The SCAR candidate must have prior experience in authorizing tools/applications, systems, and/or enclaves. Additionally, knowledge of network security, technologies, processes, and practices designed for the prevention of damage to, protection of, and restoration of computers, communications systems, services, and various types of communications technologies. The SCAR candidate must be knowledgeable and proficient in assessing DoD GovCloud environments to include testing controls and validating artifacts. A successful candidate will have a strong foundational understanding of NIST, DOD, and DAF cybersecurity focused guidance. This position can be based out of any Dark Wolf Office location and will be a hybrid schedule. Additional responsibilities include: Key Responsibilities: Evaluating IT infrastructure in terms of risk to the organization and defining artifacts required to meet Federal, DoD and DAF requirements Assessing IT systems and architecture to ensure compliance with the Risk Management Framework (RMF), NIST Cybersecurity Framework (CSF), NIST 800-53 revision 5 and applicable guidance Supporting the system/application assessment and authorization (A&A) effort, to include assessing and guiding the quality and completeness of A&A activities, tasks and resulting artifacts mandated by governing DoD and AF policies, and applicable mandates Collecting, reviewing and verifying documented business processes within process narratives or flowcharts, identifying risks and validating proficiency of mitigating controls Reviewing risk and control matrices and testing plans for key controls and determines effectiveness Identifying control gaps, reviewing and testing the design of existing controls. Formulating clear and concise conclusions on internal controls and business process efficiency Recommending policies and procedures to ensure information systems reliability and accessibility and to prevent and defend against unauthorized access to systems, networks, and data Conducting risk and vulnerability assessments of installed information systems to identify vulnerabilities, risks, and protection needs Reviewing Plans of Actions & Milestones (POA&Ms) Providing recommendations and reports to the Security Control Assessor (SCA), Authorizing Official (AO), Chief Information Security Officer (CISO) Reviewing network and systems design to ensure accuracy Ensuring the rigorous application of information security/cybersecurity policies, principles, and practices in the delivery of all IT services Required Qualifications: 15+ years of relevant Cyber experience 15+ years prior experience as a Security Control Assessor/Representative RMF Engineer, ISSO, ISSM and/or information assurance engineer Cloud Platform experience with at least one service offering from AWS, Azure, or Google GCP Hands-on eMASS and/or Xacta experience completing full system lifecycle activities Experience with Air Force risk management policies/procedures, to include, DODI 8510.01, AFI 17-101 Experience with Cloud Computing Security Requirements Guide (CC SRG) Knowledgeable with DoD DevSecOps Fundamentals Playbook Experience evaluating information security compliance against STIGs Ability to clearly articulate ideas Strong technical writing abilities to author reports for AO and CISO dissemination Exudes confidence in providing briefings, presentations, and in conducting/guiding meetings with senior leadership and stakeholders Ability to use prior experience and knowledge to address new situations Certification requirements (at least one of the following): SecurityX / CASP+, CCISO, CGRC/CAP, CISA, CISM, CISSO, CISSP, CISSP-ISSEP, Cloud+, CySA+, FITSP-A, GCSA, GSEC, GSLC, GSNA, PenTest+, Security+ B.A. or B.S. Information Security, Computer Science or related discipline US Citizenship and currently possess a Top Secret security clearance Desired Qualifications: Experience with Fast Track ATO Handbook & AF Continuous ATO Playbook Familiarity with CI/CD Pipelines DevSecOps experience Sharepoint, JIRA, Confluence familiarity The salary range for this position is $140,000.00 - $145,000.00 commensurate on experience and technical skillset. We are open to considering a variety of levels of experience for these projects and potential for 1099 hourly opportunity. We are proud to be an EEO/AA Employer Minorities/Women/Veterans/Disabled and other protected categories. In compliance with federal law, all persons hired will be required to verify identity, confirm US Citizenship, and complete the required employment eligibility verification upon hire.
09/26/2026
Full time
Job Description Job Description Dark Wolf Solutions is seeking a Senior Security Control Assessor Representative (SCAR) to conduct independent comprehensive assessments of the management, operation, and technical security controls and control enhancements employed within, or inherited by, an Information technology (IT) system to determine the overall effectiveness of the controls. The SCAR will perform reviews of security artifacts for system authorizations, assessing both the technical and functional adequacy as required for application and software cybersecurity readiness. The SCAR candidate must have prior experience in authorizing tools/applications, systems, and/or enclaves. Additionally, knowledge of network security, technologies, processes, and practices designed for the prevention of damage to, protection of, and restoration of computers, communications systems, services, and various types of communications technologies. The SCAR candidate must be knowledgeable and proficient in assessing DoD GovCloud environments to include testing controls and validating artifacts. A successful candidate will have a strong foundational understanding of NIST, DOD, and DAF cybersecurity focused guidance. This position can be based out of any Dark Wolf Office location and will be a hybrid schedule. Additional responsibilities include: Key Responsibilities: Evaluating IT infrastructure in terms of risk to the organization and defining artifacts required to meet Federal, DoD and DAF requirements Assessing IT systems and architecture to ensure compliance with the Risk Management Framework (RMF), NIST Cybersecurity Framework (CSF), NIST 800-53 revision 5 and applicable guidance Supporting the system/application assessment and authorization (A&A) effort, to include assessing and guiding the quality and completeness of A&A activities, tasks and resulting artifacts mandated by governing DoD and AF policies, and applicable mandates Collecting, reviewing and verifying documented business processes within process narratives or flowcharts, identifying risks and validating proficiency of mitigating controls Reviewing risk and control matrices and testing plans for key controls and determines effectiveness Identifying control gaps, reviewing and testing the design of existing controls. Formulating clear and concise conclusions on internal controls and business process efficiency Recommending policies and procedures to ensure information systems reliability and accessibility and to prevent and defend against unauthorized access to systems, networks, and data Conducting risk and vulnerability assessments of installed information systems to identify vulnerabilities, risks, and protection needs Reviewing Plans of Actions & Milestones (POA&Ms) Providing recommendations and reports to the Security Control Assessor (SCA), Authorizing Official (AO), Chief Information Security Officer (CISO) Reviewing network and systems design to ensure accuracy Ensuring the rigorous application of information security/cybersecurity policies, principles, and practices in the delivery of all IT services Required Qualifications: 15+ years of relevant Cyber experience 15+ years prior experience as a Security Control Assessor/Representative RMF Engineer, ISSO, ISSM and/or information assurance engineer Cloud Platform experience with at least one service offering from AWS, Azure, or Google GCP Hands-on eMASS and/or Xacta experience completing full system lifecycle activities Experience with Air Force risk management policies/procedures, to include, DODI 8510.01, AFI 17-101 Experience with Cloud Computing Security Requirements Guide (CC SRG) Knowledgeable with DoD DevSecOps Fundamentals Playbook Experience evaluating information security compliance against STIGs Ability to clearly articulate ideas Strong technical writing abilities to author reports for AO and CISO dissemination Exudes confidence in providing briefings, presentations, and in conducting/guiding meetings with senior leadership and stakeholders Ability to use prior experience and knowledge to address new situations Certification requirements (at least one of the following): SecurityX / CASP+, CCISO, CGRC/CAP, CISA, CISM, CISSO, CISSP, CISSP-ISSEP, Cloud+, CySA+, FITSP-A, GCSA, GSEC, GSLC, GSNA, PenTest+, Security+ B.A. or B.S. Information Security, Computer Science or related discipline US Citizenship and currently possess a Top Secret security clearance Desired Qualifications: Experience with Fast Track ATO Handbook & AF Continuous ATO Playbook Familiarity with CI/CD Pipelines DevSecOps experience Sharepoint, JIRA, Confluence familiarity The salary range for this position is $140,000.00 - $145,000.00 commensurate on experience and technical skillset. We are open to considering a variety of levels of experience for these projects and potential for 1099 hourly opportunity. We are proud to be an EEO/AA Employer Minorities/Women/Veterans/Disabled and other protected categories. In compliance with federal law, all persons hired will be required to verify identity, confirm US Citizenship, and complete the required employment eligibility verification upon hire.
Job Description Job Description Dark Wolf Solutions is seeking a Senior Security Control Assessor Representative (SCAR) to conduct independent comprehensive assessments of the management, operation, and technical security controls and control enhancements employed within, or inherited by, an Information technology (IT) system to determine the overall effectiveness of the controls. The SCAR will perform reviews of security artifacts for system authorizations, assessing both the technical and functional adequacy as required for application and software cybersecurity readiness. The SCAR candidate must have prior experience in authorizing tools/applications, systems, and/or enclaves. Additionally, knowledge of network security, technologies, processes, and practices designed for the prevention of damage to, protection of, and restoration of computers, communications systems, services, and various types of communications technologies. The SCAR candidate must be knowledgeable and proficient in assessing DoD GovCloud environments to include testing controls and validating artifacts. A successful candidate will have a strong foundational understanding of NIST, DOD, and DAF cybersecurity focused guidance. This position can be based out of any Dark Wolf Office location and will be a hybrid schedule. Additional responsibilities include: Key Responsibilities: Evaluating IT infrastructure in terms of risk to the organization and defining artifacts required to meet Federal, DoD and DAF requirements Assessing IT systems and architecture to ensure compliance with the Risk Management Framework (RMF), NIST Cybersecurity Framework (CSF), NIST 800-53 revision 5 and applicable guidance Supporting the system/application assessment and authorization (A&A) effort, to include assessing and guiding the quality and completeness of A&A activities, tasks and resulting artifacts mandated by governing DoD and AF policies, and applicable mandates Collecting, reviewing and verifying documented business processes within process narratives or flowcharts, identifying risks and validating proficiency of mitigating controls Reviewing risk and control matrices and testing plans for key controls and determines effectiveness Identifying control gaps, reviewing and testing the design of existing controls. Formulating clear and concise conclusions on internal controls and business process efficiency Recommending policies and procedures to ensure information systems reliability and accessibility and to prevent and defend against unauthorized access to systems, networks, and data Conducting risk and vulnerability assessments of installed information systems to identify vulnerabilities, risks, and protection needs Reviewing Plans of Actions & Milestones (POA&Ms) Providing recommendations and reports to the Security Control Assessor (SCA), Authorizing Official (AO), Chief Information Security Officer (CISO) Reviewing network and systems design to ensure accuracy Ensuring the rigorous application of information security/cybersecurity policies, principles, and practices in the delivery of all IT services Required Qualifications: 15+ years of relevant Cyber experience 15+ years prior experience as a Security Control Assessor/Representative RMF Engineer, ISSO, ISSM and/or information assurance engineer Cloud Platform experience with at least one service offering from AWS, Azure, or Google GCP Hands-on eMASS and/or Xacta experience completing full system lifecycle activities Experience with Air Force risk management policies/procedures, to include, DODI 8510.01, AFI 17-101 Experience with Cloud Computing Security Requirements Guide (CC SRG) Knowledgeable with DoD DevSecOps Fundamentals Playbook Experience evaluating information security compliance against STIGs Ability to clearly articulate ideas Strong technical writing abilities to author reports for AO and CISO dissemination Exudes confidence in providing briefings, presentations, and in conducting/guiding meetings with senior leadership and stakeholders Ability to use prior experience and knowledge to address new situations Certification requirements (at least one of the following): SecurityX / CASP+, CCISO, CGRC/CAP, CISA, CISM, CISSO, CISSP, CISSP-ISSEP, Cloud+, CySA+, FITSP-A, GCSA, GSEC, GSLC, GSNA, PenTest+, Security+ B.A. or B.S. Information Security, Computer Science or related discipline US Citizenship and currently possess a Top Secret security clearance Desired Qualifications: Experience with Fast Track ATO Handbook & AF Continuous ATO Playbook Familiarity with CI/CD Pipelines DevSecOps experience Sharepoint, JIRA, Confluence familiarity The salary range for this position is $140,000.00 - $145,000.00 commensurate on experience and technical skillset. We are open to considering a variety of levels of experience for these projects and potential for 1099 hourly opportunity. We are proud to be an EEO/AA Employer Minorities/Women/Veterans/Disabled and other protected categories. In compliance with federal law, all persons hired will be required to verify identity, confirm US Citizenship, and complete the required employment eligibility verification upon hire.
09/26/2026
Full time
Job Description Job Description Dark Wolf Solutions is seeking a Senior Security Control Assessor Representative (SCAR) to conduct independent comprehensive assessments of the management, operation, and technical security controls and control enhancements employed within, or inherited by, an Information technology (IT) system to determine the overall effectiveness of the controls. The SCAR will perform reviews of security artifacts for system authorizations, assessing both the technical and functional adequacy as required for application and software cybersecurity readiness. The SCAR candidate must have prior experience in authorizing tools/applications, systems, and/or enclaves. Additionally, knowledge of network security, technologies, processes, and practices designed for the prevention of damage to, protection of, and restoration of computers, communications systems, services, and various types of communications technologies. The SCAR candidate must be knowledgeable and proficient in assessing DoD GovCloud environments to include testing controls and validating artifacts. A successful candidate will have a strong foundational understanding of NIST, DOD, and DAF cybersecurity focused guidance. This position can be based out of any Dark Wolf Office location and will be a hybrid schedule. Additional responsibilities include: Key Responsibilities: Evaluating IT infrastructure in terms of risk to the organization and defining artifacts required to meet Federal, DoD and DAF requirements Assessing IT systems and architecture to ensure compliance with the Risk Management Framework (RMF), NIST Cybersecurity Framework (CSF), NIST 800-53 revision 5 and applicable guidance Supporting the system/application assessment and authorization (A&A) effort, to include assessing and guiding the quality and completeness of A&A activities, tasks and resulting artifacts mandated by governing DoD and AF policies, and applicable mandates Collecting, reviewing and verifying documented business processes within process narratives or flowcharts, identifying risks and validating proficiency of mitigating controls Reviewing risk and control matrices and testing plans for key controls and determines effectiveness Identifying control gaps, reviewing and testing the design of existing controls. Formulating clear and concise conclusions on internal controls and business process efficiency Recommending policies and procedures to ensure information systems reliability and accessibility and to prevent and defend against unauthorized access to systems, networks, and data Conducting risk and vulnerability assessments of installed information systems to identify vulnerabilities, risks, and protection needs Reviewing Plans of Actions & Milestones (POA&Ms) Providing recommendations and reports to the Security Control Assessor (SCA), Authorizing Official (AO), Chief Information Security Officer (CISO) Reviewing network and systems design to ensure accuracy Ensuring the rigorous application of information security/cybersecurity policies, principles, and practices in the delivery of all IT services Required Qualifications: 15+ years of relevant Cyber experience 15+ years prior experience as a Security Control Assessor/Representative RMF Engineer, ISSO, ISSM and/or information assurance engineer Cloud Platform experience with at least one service offering from AWS, Azure, or Google GCP Hands-on eMASS and/or Xacta experience completing full system lifecycle activities Experience with Air Force risk management policies/procedures, to include, DODI 8510.01, AFI 17-101 Experience with Cloud Computing Security Requirements Guide (CC SRG) Knowledgeable with DoD DevSecOps Fundamentals Playbook Experience evaluating information security compliance against STIGs Ability to clearly articulate ideas Strong technical writing abilities to author reports for AO and CISO dissemination Exudes confidence in providing briefings, presentations, and in conducting/guiding meetings with senior leadership and stakeholders Ability to use prior experience and knowledge to address new situations Certification requirements (at least one of the following): SecurityX / CASP+, CCISO, CGRC/CAP, CISA, CISM, CISSO, CISSP, CISSP-ISSEP, Cloud+, CySA+, FITSP-A, GCSA, GSEC, GSLC, GSNA, PenTest+, Security+ B.A. or B.S. Information Security, Computer Science or related discipline US Citizenship and currently possess a Top Secret security clearance Desired Qualifications: Experience with Fast Track ATO Handbook & AF Continuous ATO Playbook Familiarity with CI/CD Pipelines DevSecOps experience Sharepoint, JIRA, Confluence familiarity The salary range for this position is $140,000.00 - $145,000.00 commensurate on experience and technical skillset. We are open to considering a variety of levels of experience for these projects and potential for 1099 hourly opportunity. We are proud to be an EEO/AA Employer Minorities/Women/Veterans/Disabled and other protected categories. In compliance with federal law, all persons hired will be required to verify identity, confirm US Citizenship, and complete the required employment eligibility verification upon hire.
Job Description Job Description Information Security Specialist Officer, Technical Lead, AWS Security • RMF & ATO • NIST 800-53 • Cloud Application Security Clearance: Active CBP, DHS, or Top Secret Clearance required Work Arrangement: Hybrid - onsite 3 days/week during standard business hours in Ashburn, VA About the Role Dev Technology Group is seeking a Senior Information Security Specialist to lead and develop a mid-sized team of ISSOs supporting the security, compliance, and authorization of mission-critical federal applications and information systems hosted in AWS. This is a hands-on technical leadership role combining people leadership, federal cybersecurity expertise, and direct collaboration with government and technical stakeholders. You will mentor junior and mid-level ISSOs while partnering with system owners, developers, architects, cloud/infrastructure engineers, security professionals, and government stakeholders throughout the system development lifecycle. You will provide practical security guidance for AWS-hosted applications, lead Risk Management Framework (RMF) and Authority to Operate (ATO) activities, oversee vulnerability management and continuous monitoring, and translate federal cybersecurity requirements into actionable guidance for technical teams. What You'll Do Lead, mentor, and develop a team of ISSOs by establishing priorities, providing technical direction and coaching, and promoting accountability and consistent security practices. Lead and oversee RMF, ATO, security authorization, compliance, vulnerability management, and continuous monitoring activities across a portfolio of federal systems and applications. Partner with ISSMs, system owners, assessors, developers, architects, engineers, and government stakeholders to maintain authorizations, identify risks, and address security requirements. Lead vulnerability management efforts, prioritizing remediation, developing mitigation strategies, and tracking corrective actions through resolution. Develop, assess, document, and support implementation of security controls aligned with FISMA, NIST 800-53, DHS, and client requirements . Prepare and maintain security and authorization documentation, including SSPs, ISAs, audit artifacts, and RMF documentation . Provide cybersecurity guidance for applications and systems deployed in AWS and integrate security throughout the software development lifecycle. Validate security implementation through technical reviews, discussions, interviews, assessments, and tabletop exercises. Support security audits, assessments, compliance reviews, and reviews of information systems and network connections. Interpret federal and client security policies and translate requirements into practical guidance for technical and development teams. Identify and escalate security risks, communicate priorities and remediation status, and provide clear visibility to Dev Technology leadership and government stakeholders. Develop and present security metrics, status reports, risk assessments, and executive briefings . Establish and improve security processes, procedures, templates, dashboards, and workflows to improve consistency, accountability, and efficiency across the ISSO team. Build trusted relationships with government clients through proactive communication, collaboration, and face-to-face engagement. Required Education, Experience & Skills Bachelor's degree and 7+ years of experience securing federal information systems. Demonstrated experience leading and mentoring information security professionals , including junior and mid-level ISSOs. Experience leading cybersecurity activities in a federal government client environment and working directly with government stakeholders.' Strong working knowledge of NIST Risk Management Framework (RMF) and experience supporting federal systems through security authorization and ATO activities . Experience developing, implementing, assessing, or documenting security controls aligned with FISMA and NIST 800-53 . Experience with vulnerability management, continuous monitoring, security assessments, audits, or compliance reviews for federal systems. Experience providing cybersecurity guidance for AWS-hosted applications and systems . Strong understanding of modern information systems and their technical security considerations. Ability to work effectively with developers, architects, engineers, government stakeholders, and technical and non-technical audiences. Strong written and verbal communication skills, including the ability to communicate security risks and technical findings and develop/present security documentation and executive briefings. Ability to establish priorities, manage competing demands, independently manage security activities, and escalate issues appropriately. Proactive, solutions-oriented approach to identifying risks and improving security practices. Current CBP, DHS, or Top Secret Clearance. Ability to work onsite 3 days per week in Ashburn, VA during standard business hours. Cybersecurity certification such as CISSP, CISM, GIAC, Security+, or another recognized cybersecurity certification. Preferred Education, Experience & Skills Experience developing or supporting RMF and authorization artifacts, including SSPs, ISAs, PTAs, ATTs, POA&Ms , and related documentation. Experience partnering with application development, cloud engineering, and DevSecOps teams to integrate security throughout the SDLC. Experience working in an Agile software development environment using Jira or similar platforms. Experience with GRC tools such as CSAM or similar platforms supporting authorization, compliance, vulnerability management, and security activities. Understanding of AI concepts and practical applications of AI for cybersecurity operations, risk analysis, compliance, or security program management. Our estimated salary range for this position is $88,000 - $ 150,000. This presented salary range is not a guarantee of compensation or salary. Offered salary is based on experience, geographic location, and possibly contractual requirements as appropriate to the role. Salary could fall outside of this range. Who We Are Dev Technology is a growing IT company with an employee-centric culture that works on mission-critical projects for the federal government. We partner with our federal customers to deliver technology services and solutions, and to drive our client's missions forward through innovation. We use Agile and DevSecOps principles to provide services including application development, biometrics and identity management, cloud and infrastructure optimization, IT and legacy modernization, and data management. As a Washington Post Top Workplace award winner for the past THIRTEEN years in a row, the Top Workplaces USA for the past five years, and a recipient of the Companies As Responsive Employers (CARE) Award for the past six years, Dev Technology employees enjoy: Generous and flexible time-off policy Flexible work schedules and telework options, including remote work availability for eligible projects Career development opportunities including a mentorship program, technical and management training through Dev University, hands-on learning through DevLab, tuition reimbursement, and paid training opportunities Industry-leading benefits including a choice of two health plans that include dental and vision, flexible spending account, commuter benefits, life insurance, and more 401K matching with a 5% matching contribution Regular team and company social events including our annual party, happy hours, fitness challenges, and more A focus on community engagement including company wide support activities, employer match for donations, and time off for volunteer efforts To learn more about working at Dev Technology, visit Working At Dev Technology Group Equal Opportunity Employer / Individuals with Disabilities / Protected Veterans Dev Technology Group operates in the following states: AL, AR, AZ, CO, DC, FL, GA, ID, IL, IN, MD, MA, ME, MI, MN, MO, MS, NC, NJ, OH, OR, PA, SC, TN, TX, VA, WV.
09/26/2026
Full time
Job Description Job Description Information Security Specialist Officer, Technical Lead, AWS Security • RMF & ATO • NIST 800-53 • Cloud Application Security Clearance: Active CBP, DHS, or Top Secret Clearance required Work Arrangement: Hybrid - onsite 3 days/week during standard business hours in Ashburn, VA About the Role Dev Technology Group is seeking a Senior Information Security Specialist to lead and develop a mid-sized team of ISSOs supporting the security, compliance, and authorization of mission-critical federal applications and information systems hosted in AWS. This is a hands-on technical leadership role combining people leadership, federal cybersecurity expertise, and direct collaboration with government and technical stakeholders. You will mentor junior and mid-level ISSOs while partnering with system owners, developers, architects, cloud/infrastructure engineers, security professionals, and government stakeholders throughout the system development lifecycle. You will provide practical security guidance for AWS-hosted applications, lead Risk Management Framework (RMF) and Authority to Operate (ATO) activities, oversee vulnerability management and continuous monitoring, and translate federal cybersecurity requirements into actionable guidance for technical teams. What You'll Do Lead, mentor, and develop a team of ISSOs by establishing priorities, providing technical direction and coaching, and promoting accountability and consistent security practices. Lead and oversee RMF, ATO, security authorization, compliance, vulnerability management, and continuous monitoring activities across a portfolio of federal systems and applications. Partner with ISSMs, system owners, assessors, developers, architects, engineers, and government stakeholders to maintain authorizations, identify risks, and address security requirements. Lead vulnerability management efforts, prioritizing remediation, developing mitigation strategies, and tracking corrective actions through resolution. Develop, assess, document, and support implementation of security controls aligned with FISMA, NIST 800-53, DHS, and client requirements . Prepare and maintain security and authorization documentation, including SSPs, ISAs, audit artifacts, and RMF documentation . Provide cybersecurity guidance for applications and systems deployed in AWS and integrate security throughout the software development lifecycle. Validate security implementation through technical reviews, discussions, interviews, assessments, and tabletop exercises. Support security audits, assessments, compliance reviews, and reviews of information systems and network connections. Interpret federal and client security policies and translate requirements into practical guidance for technical and development teams. Identify and escalate security risks, communicate priorities and remediation status, and provide clear visibility to Dev Technology leadership and government stakeholders. Develop and present security metrics, status reports, risk assessments, and executive briefings . Establish and improve security processes, procedures, templates, dashboards, and workflows to improve consistency, accountability, and efficiency across the ISSO team. Build trusted relationships with government clients through proactive communication, collaboration, and face-to-face engagement. Required Education, Experience & Skills Bachelor's degree and 7+ years of experience securing federal information systems. Demonstrated experience leading and mentoring information security professionals , including junior and mid-level ISSOs. Experience leading cybersecurity activities in a federal government client environment and working directly with government stakeholders.' Strong working knowledge of NIST Risk Management Framework (RMF) and experience supporting federal systems through security authorization and ATO activities . Experience developing, implementing, assessing, or documenting security controls aligned with FISMA and NIST 800-53 . Experience with vulnerability management, continuous monitoring, security assessments, audits, or compliance reviews for federal systems. Experience providing cybersecurity guidance for AWS-hosted applications and systems . Strong understanding of modern information systems and their technical security considerations. Ability to work effectively with developers, architects, engineers, government stakeholders, and technical and non-technical audiences. Strong written and verbal communication skills, including the ability to communicate security risks and technical findings and develop/present security documentation and executive briefings. Ability to establish priorities, manage competing demands, independently manage security activities, and escalate issues appropriately. Proactive, solutions-oriented approach to identifying risks and improving security practices. Current CBP, DHS, or Top Secret Clearance. Ability to work onsite 3 days per week in Ashburn, VA during standard business hours. Cybersecurity certification such as CISSP, CISM, GIAC, Security+, or another recognized cybersecurity certification. Preferred Education, Experience & Skills Experience developing or supporting RMF and authorization artifacts, including SSPs, ISAs, PTAs, ATTs, POA&Ms , and related documentation. Experience partnering with application development, cloud engineering, and DevSecOps teams to integrate security throughout the SDLC. Experience working in an Agile software development environment using Jira or similar platforms. Experience with GRC tools such as CSAM or similar platforms supporting authorization, compliance, vulnerability management, and security activities. Understanding of AI concepts and practical applications of AI for cybersecurity operations, risk analysis, compliance, or security program management. Our estimated salary range for this position is $88,000 - $ 150,000. This presented salary range is not a guarantee of compensation or salary. Offered salary is based on experience, geographic location, and possibly contractual requirements as appropriate to the role. Salary could fall outside of this range. Who We Are Dev Technology is a growing IT company with an employee-centric culture that works on mission-critical projects for the federal government. We partner with our federal customers to deliver technology services and solutions, and to drive our client's missions forward through innovation. We use Agile and DevSecOps principles to provide services including application development, biometrics and identity management, cloud and infrastructure optimization, IT and legacy modernization, and data management. As a Washington Post Top Workplace award winner for the past THIRTEEN years in a row, the Top Workplaces USA for the past five years, and a recipient of the Companies As Responsive Employers (CARE) Award for the past six years, Dev Technology employees enjoy: Generous and flexible time-off policy Flexible work schedules and telework options, including remote work availability for eligible projects Career development opportunities including a mentorship program, technical and management training through Dev University, hands-on learning through DevLab, tuition reimbursement, and paid training opportunities Industry-leading benefits including a choice of two health plans that include dental and vision, flexible spending account, commuter benefits, life insurance, and more 401K matching with a 5% matching contribution Regular team and company social events including our annual party, happy hours, fitness challenges, and more A focus on community engagement including company wide support activities, employer match for donations, and time off for volunteer efforts To learn more about working at Dev Technology, visit Working At Dev Technology Group Equal Opportunity Employer / Individuals with Disabilities / Protected Veterans Dev Technology Group operates in the following states: AL, AR, AZ, CO, DC, FL, GA, ID, IL, IN, MD, MA, ME, MI, MN, MO, MS, NC, NJ, OH, OR, PA, SC, TN, TX, VA, WV.
Vaco is hiring a Chief Information Officer (CIO) in Lombard, IL. Location: Lombard, IL (Chicago Area) On-Site About the Opportunity A leading transportation and mobility services organization is seeking a visionary and operationally focused Chief Information Officer (CIO) to lead enterprise-wide technology strategy, digital transformation, cybersecurity, and IT operations. Supporting a large-scale network of transportation services across hundreds of locations nationwide, this organization operates in a highly distributed, mission-critical environment where technology plays a central role in safety, service delivery, workforce productivity, and customer experience. Reporting directly to the Chief Executive Officer and serving as a member of the Executive Leadership Team, the CIO will be responsible for shaping the future technology landscape while ensuring operational excellence across all information technology functions. This executive will serve as a trusted business partner, driving innovation, modernization, and enterprise performance through strategic technology investment and disciplined execution. Position Overview The Chief Information Officer is responsible for developing and executing a comprehensive technology and digital strategy that supports business growth, operational efficiency, safety, and customer satisfaction. This leader will oversee all aspects of information technology, including enterprise applications, infrastructure, cybersecurity, data and analytics, field support services, project management, innovation, and vendor management. Success in this role requires a highly collaborative executive who combines strategic vision with hands-on leadership and a strong operational mindset. The ideal candidate will have experience leading technology organizations in complex, geographically dispersed environments where reliability, scalability, and service excellence are essential. Key Responsibilities Technology Strategy & Digital Transformation Define and execute a long-term technology roadmap aligned with business objectives and customer expectations. Lead enterprise-wide digital transformation initiatives that improve operational efficiency, safety, workforce effectiveness, and customer outcomes. Identify emerging technologies and innovation opportunities that create measurable business value. Serve as a strategic advisor to executive leadership on technology trends, risks, investments, and modernization priorities. Foster a culture that embraces innovation, continuous improvement, and digital adoption. IT Operations & Service Excellence Ensure the reliability, availability, and performance of technology systems supporting a large national operating network. Oversee IT service delivery and support functions, ensuring responsive and effective support for a 24/7 operational environment. Establish strong governance, service management disciplines, and performance metrics across the technology organization. Maintain operational continuity through resilient infrastructure, disaster recovery, and business continuity planning. Drive technology standardization and process optimization across multiple business locations. Enterprise Applications & Data Strategy Lead the strategy, optimization, and governance of enterprise technology platforms supporting operations, finance, human resources, scheduling, maintenance, safety, and customer-facing functions. Modernize legacy applications and streamline the overall technology architecture. Expand data analytics and reporting capabilities to support informed business decisions and operational performance. Promote the use of advanced analytics and business intelligence tools across the organization. Establish a strong data governance framework to ensure quality, consistency, accessibility, and security of enterprise data. Cybersecurity & Risk Management Develop and maintain a comprehensive cybersecurity strategy that protects critical systems, data, and operational assets. Strengthen security governance, risk management, and compliance capabilities. Oversee incident response, disaster recovery, and business continuity programs. Ensure technology practices meet applicable regulatory, legal, and industry requirements. Create a culture of security awareness and accountability throughout the organization. Leadership & Talent Development Build and lead a high-performing technology organization focused on collaboration, innovation, and results. Recruit, develop, and retain top technology talent. Partner closely with operational and corporate leaders to align technology solutions with business needs. Lead organizational change efforts that support successful technology adoption and business transformation. Encourage a customer-focused mindset and culture of accountability across the IT function. Financial, Vendor & Portfolio Management Manage technology budgets, capital investments, and resource allocation to maximize business value. Identify opportunities for cost optimization while maintaining high service levels. Oversee strategic technology vendors, contract negotiations, and supplier performance. Manage the enterprise technology project portfolio, ensuring prioritization, governance, and successful delivery. Establish clear ROI measures for technology investments and transformation initiatives. Qualifications Required Experience Executive-level technology leadership experience in a large, distributed, operationally intensive organization. Demonstrated success leading enterprise technology modernization and digital transformation programs. Significant experience managing mission-critical systems within complex, customer-facing operating environments. Proven track record of building high-performing teams and developing strong leadership benches. Strong business acumen with experience managing large budgets, strategic technology investments, and vendor ecosystems. Ability to influence senior stakeholders and lead effectively within a matrixed organizational structure. Preferred Experience Background in transportation, logistics, infrastructure, industrial services, utilities, field services, or similarly complex industries. Experience operating within multinational or globally integrated organizations. Familiarity with public-sector environments, regulatory compliance requirements, or transportation technologies. Experience overseeing cloud transformation, enterprise application modernization, and advanced analytics initiatives. Leadership Profile The successful candidate will demonstrate: Strategic thinking combined with disciplined execution. Strong business partnership and stakeholder management skills. Excellent communication and influencing capabilities. A pragmatic, hands-on leadership style. Strong operational awareness and customer focus. The ability to lead through change and transformation. High integrity, humility, accountability, and commitment to organizational success. By submitting to this position, you are agreeing to be included in our talent pool for future hiring for similarly qualified positions. EEO Notice Vaco by Highspring is an Equal Opportunity Employer and does not discriminate against any employee or applicant for employment because of race (including but not limited to traits historically associated with race such as hair texture and hair style), color, sex (includes pregnancy or related conditions), religion or creed, national origin, citizenship, age, disability, status as a veteran, union membership, ethnicity, gender, gender identity, gender expression, sexual orientation, marital status, political affiliation, or any other protected characteristics as required by federal, state or local law. Vaco by Highspring and its parents, affiliates, and subsidiaries are committed to the full inclusion of all qualified individuals. As part of this commitment, Vaco by Highspring and its parents, affiliates, and subsidiaries will ensure that persons with disabilities are provided reasonable accommodations. If reasonable accommodation is needed to participate in the job application or interview process, to perform essential job functions, and/or to receive other benefits and privileges of employment, please contact . Vaco by Highspring also wants all applicants to know their rights that workplace discrimination is illegal. Representation Notice By submitting to this position, you agree that you will be giving Vaco by Highspring the exclusive right to present your as a candidate for the foregoing employment opportunity. You further agree that you have represented information about yourself accurately and have not affirmatively misrepresented your qualifications. You also agree to maintain as confidential, to the fullest extent permitted by law, any information you learn from Vaco by Highspring about the position and you will limit disclosure of information about the position only to the extent necessary to perform any obligations in furtherance of your application. In exchange, Vaco by Highspring agrees to exercise reasonable efforts to represent you through all solicitation, job screening and resume dispersal. For residents of Ontario, Canada: Based on Highspring's discussions with its Client, Highspring's understanding is that this position for employment is a current vacancy (either through Highspring as a contractor or with the client directly). Privacy Notice Vaco by Highspring and its parents, affiliates, and subsidiaries ("we," "our," or "Vaco by Highspring") respects your privacy and are committed to providing transparent notice of our policies. California residents may access Vaco by Highspring HR Notice at Collection for California Applicants and Employees here. Virginia residents may access our state specific policies here. Residents of all other states may access our policies here . click apply for full job details
09/26/2026
Full time
Vaco is hiring a Chief Information Officer (CIO) in Lombard, IL. Location: Lombard, IL (Chicago Area) On-Site About the Opportunity A leading transportation and mobility services organization is seeking a visionary and operationally focused Chief Information Officer (CIO) to lead enterprise-wide technology strategy, digital transformation, cybersecurity, and IT operations. Supporting a large-scale network of transportation services across hundreds of locations nationwide, this organization operates in a highly distributed, mission-critical environment where technology plays a central role in safety, service delivery, workforce productivity, and customer experience. Reporting directly to the Chief Executive Officer and serving as a member of the Executive Leadership Team, the CIO will be responsible for shaping the future technology landscape while ensuring operational excellence across all information technology functions. This executive will serve as a trusted business partner, driving innovation, modernization, and enterprise performance through strategic technology investment and disciplined execution. Position Overview The Chief Information Officer is responsible for developing and executing a comprehensive technology and digital strategy that supports business growth, operational efficiency, safety, and customer satisfaction. This leader will oversee all aspects of information technology, including enterprise applications, infrastructure, cybersecurity, data and analytics, field support services, project management, innovation, and vendor management. Success in this role requires a highly collaborative executive who combines strategic vision with hands-on leadership and a strong operational mindset. The ideal candidate will have experience leading technology organizations in complex, geographically dispersed environments where reliability, scalability, and service excellence are essential. Key Responsibilities Technology Strategy & Digital Transformation Define and execute a long-term technology roadmap aligned with business objectives and customer expectations. Lead enterprise-wide digital transformation initiatives that improve operational efficiency, safety, workforce effectiveness, and customer outcomes. Identify emerging technologies and innovation opportunities that create measurable business value. Serve as a strategic advisor to executive leadership on technology trends, risks, investments, and modernization priorities. Foster a culture that embraces innovation, continuous improvement, and digital adoption. IT Operations & Service Excellence Ensure the reliability, availability, and performance of technology systems supporting a large national operating network. Oversee IT service delivery and support functions, ensuring responsive and effective support for a 24/7 operational environment. Establish strong governance, service management disciplines, and performance metrics across the technology organization. Maintain operational continuity through resilient infrastructure, disaster recovery, and business continuity planning. Drive technology standardization and process optimization across multiple business locations. Enterprise Applications & Data Strategy Lead the strategy, optimization, and governance of enterprise technology platforms supporting operations, finance, human resources, scheduling, maintenance, safety, and customer-facing functions. Modernize legacy applications and streamline the overall technology architecture. Expand data analytics and reporting capabilities to support informed business decisions and operational performance. Promote the use of advanced analytics and business intelligence tools across the organization. Establish a strong data governance framework to ensure quality, consistency, accessibility, and security of enterprise data. Cybersecurity & Risk Management Develop and maintain a comprehensive cybersecurity strategy that protects critical systems, data, and operational assets. Strengthen security governance, risk management, and compliance capabilities. Oversee incident response, disaster recovery, and business continuity programs. Ensure technology practices meet applicable regulatory, legal, and industry requirements. Create a culture of security awareness and accountability throughout the organization. Leadership & Talent Development Build and lead a high-performing technology organization focused on collaboration, innovation, and results. Recruit, develop, and retain top technology talent. Partner closely with operational and corporate leaders to align technology solutions with business needs. Lead organizational change efforts that support successful technology adoption and business transformation. Encourage a customer-focused mindset and culture of accountability across the IT function. Financial, Vendor & Portfolio Management Manage technology budgets, capital investments, and resource allocation to maximize business value. Identify opportunities for cost optimization while maintaining high service levels. Oversee strategic technology vendors, contract negotiations, and supplier performance. Manage the enterprise technology project portfolio, ensuring prioritization, governance, and successful delivery. Establish clear ROI measures for technology investments and transformation initiatives. Qualifications Required Experience Executive-level technology leadership experience in a large, distributed, operationally intensive organization. Demonstrated success leading enterprise technology modernization and digital transformation programs. Significant experience managing mission-critical systems within complex, customer-facing operating environments. Proven track record of building high-performing teams and developing strong leadership benches. Strong business acumen with experience managing large budgets, strategic technology investments, and vendor ecosystems. Ability to influence senior stakeholders and lead effectively within a matrixed organizational structure. Preferred Experience Background in transportation, logistics, infrastructure, industrial services, utilities, field services, or similarly complex industries. Experience operating within multinational or globally integrated organizations. Familiarity with public-sector environments, regulatory compliance requirements, or transportation technologies. Experience overseeing cloud transformation, enterprise application modernization, and advanced analytics initiatives. Leadership Profile The successful candidate will demonstrate: Strategic thinking combined with disciplined execution. Strong business partnership and stakeholder management skills. Excellent communication and influencing capabilities. A pragmatic, hands-on leadership style. Strong operational awareness and customer focus. The ability to lead through change and transformation. High integrity, humility, accountability, and commitment to organizational success. By submitting to this position, you are agreeing to be included in our talent pool for future hiring for similarly qualified positions. EEO Notice Vaco by Highspring is an Equal Opportunity Employer and does not discriminate against any employee or applicant for employment because of race (including but not limited to traits historically associated with race such as hair texture and hair style), color, sex (includes pregnancy or related conditions), religion or creed, national origin, citizenship, age, disability, status as a veteran, union membership, ethnicity, gender, gender identity, gender expression, sexual orientation, marital status, political affiliation, or any other protected characteristics as required by federal, state or local law. Vaco by Highspring and its parents, affiliates, and subsidiaries are committed to the full inclusion of all qualified individuals. As part of this commitment, Vaco by Highspring and its parents, affiliates, and subsidiaries will ensure that persons with disabilities are provided reasonable accommodations. If reasonable accommodation is needed to participate in the job application or interview process, to perform essential job functions, and/or to receive other benefits and privileges of employment, please contact . Vaco by Highspring also wants all applicants to know their rights that workplace discrimination is illegal. Representation Notice By submitting to this position, you agree that you will be giving Vaco by Highspring the exclusive right to present your as a candidate for the foregoing employment opportunity. You further agree that you have represented information about yourself accurately and have not affirmatively misrepresented your qualifications. You also agree to maintain as confidential, to the fullest extent permitted by law, any information you learn from Vaco by Highspring about the position and you will limit disclosure of information about the position only to the extent necessary to perform any obligations in furtherance of your application. In exchange, Vaco by Highspring agrees to exercise reasonable efforts to represent you through all solicitation, job screening and resume dispersal. For residents of Ontario, Canada: Based on Highspring's discussions with its Client, Highspring's understanding is that this position for employment is a current vacancy (either through Highspring as a contractor or with the client directly). Privacy Notice Vaco by Highspring and its parents, affiliates, and subsidiaries ("we," "our," or "Vaco by Highspring") respects your privacy and are committed to providing transparent notice of our policies. California residents may access Vaco by Highspring HR Notice at Collection for California Applicants and Employees here. Virginia residents may access our state specific policies here. Residents of all other states may access our policies here . click apply for full job details
Job Summary The SVP, Global Chief Information Security Officer (CISO) & IT Governance is responsible for leading the organization's global cybersecurity strategy, governance model, risk management program, and cyber resilience capabilities. This executive provides strategic oversight of security operations, architecture, governance, compliance, regulatory readiness, audit coordination, incident response, and recovery. The role ensures cybersecurity is embedded into enterprise strategy, technology transformation, digital innovation, third-party relationships, and day-to-day operations, while serving as a trusted advisor to senior leadership, Board-level stakeholders, Legal, Compliance, Privacy, Internal Audit, regulators, auditors, customers, and external partners. Job Description Key Responsibilities Set and execute the enterprise cybersecurity strategy and multi-year roadmap aligned with business priorities, risk appetite, regulatory expectations, technology transformation, and enterprise growth. Analyze emerging cybersecurity and governance threats (including AI) and create remediation recommendations. Establish and mature the cyber governance model, including policies, standards, decision rights, executive reporting, escalation protocols, and accountability mechanisms. Lead global security operations, including threat monitoring, intelligence, incident detection, vulnerability management, identity and access management, endpoint security, cloud security, encryption, data protection, analytics, response, and recovery. Oversee security architecture and control design to embed security into technology platforms, cloud environments, data ecosystems, business applications, digital products, privileged access management, and Zero Trust initiatives. Lead Governance, Risk & Compliance (GRC) programs, including risk identification, assessment, prioritization, mitigation, acceptance, monitoring, reporting, policy governance, and compliance oversight. Integrate cybersecurity risk management into enterprise risk management, business planning, technology governance, third-party oversight, customer assurance, and major transformation initiatives. Oversee readiness for applicable laws, regulations, contractual obligations, supervisory expectations, industry standards, and frameworks such as NIST, ISO 27001, CIS Controls, GDPR, HIPAA, PCI DSS, HITRUST, SOX / ITGC, or other relevant requirements. Serve as the primary technology liaison to Legal, Compliance, Privacy, and Internal Audit on cybersecurity, regulatory, privacy, audit, contractual, and customer assurance matters. Lead cyber resilience planning, including incident response strategy, crisis escalation, executive communications, tabletop exercises, ransomware preparedness, recovery coordination, recovery validation, and lessons-learned governance. Advise executive leadership and Board-level stakeholders on cyber risk exposure, emerging threats, program maturity, investment priorities, strategic trade-offs, incident readiness, and regulatory disclosure considerations. Build, lead, and develop a high-performing global cybersecurity and IT governance organization with clear accountability, succession planning, talent development, operating rhythms, and measurable maturity improvements. Champion an enterprise culture in which cybersecurity is understood as a shared leadership responsibility and embedded into business decision-making. Scope of Accountability Global Cybersecurity Program Security Operations, Threat Intelligence & Incident Response Security Architecture & Engineering Identity & Access Management Governance Privileged Access Management Governance Governance, Risk & Compliance (GRC) HITRUST Certification Program PCI Compliance Program SOX / IT General Controls (ITGC) Technology Change Management Governance Cyber Resilience & Recovery Readiness Third-Party Security Assurance Legal, Compliance & Privacy Technology Coordination Executive, Audit Committee, and Board Cybersecurity Reporting Cybersecurity Strategy, Governance, Maturity Roadmap, Investment Prioritization & Enterprise Risk Reporting AI Security Risk Analysis / Threat Mitigation AI Risk Governance Leadership Expectations Operate as a strategic business executive balancing cybersecurity risk, compliance, privacy, technology governance, resilience, and operational priorities. Translate complex cyber, technology, and operational risks into business impact, financial exposure, regulatory implications, and strategic choices. Lead through ambiguity, manage high-pressure incidents, and communicate clearly with senior stakeholders during crisis situations. Influence without direct authority, drive cross-functional alignment, and enable pragmatic, risk-informed decisions. Promote a culture of accountability, resilience, cybersecurity awareness, and continuous improvement. Enable business growth through security leadership that supports innovation, operational resilience, and regulatory readiness. Maintain a mature global security and governance program that supports evolving business, technology, regulatory, customer, and audit requirements. Our benefit package includes health insurance, life and disability, 401(k) contributions, paid time off, etc., for employees working 30 or more hours per week on average. For a more comprehensive list of our benefits please click here. For roles where employees work less than 30 hours per week, benefits include 401(k) contributions as well as access to the Employee Assistance Program, Employee Resource Groups and the Employee Service Corp. We're dedicated to creating a Medline where everyone feels they belong and can grow their career. We strive to do this by seeking diversity in all forms, acting inclusively, and ensuring that people have tools and resources to perform at their best. Explore our Belonging page here. Medline Industries, LP is an equal opportunity employer. Medline evaluates qualified individuals without regard to race, color, religion, gender, gender identity or expression, sexual orientation, national origin, age, disability, neurodivergence, protected veteran status, marital or family status, caregiver responsibilities, genetic information, or any other characteristic protected by applicable federal, state, or local laws.
09/25/2026
Full time
Job Summary The SVP, Global Chief Information Security Officer (CISO) & IT Governance is responsible for leading the organization's global cybersecurity strategy, governance model, risk management program, and cyber resilience capabilities. This executive provides strategic oversight of security operations, architecture, governance, compliance, regulatory readiness, audit coordination, incident response, and recovery. The role ensures cybersecurity is embedded into enterprise strategy, technology transformation, digital innovation, third-party relationships, and day-to-day operations, while serving as a trusted advisor to senior leadership, Board-level stakeholders, Legal, Compliance, Privacy, Internal Audit, regulators, auditors, customers, and external partners. Job Description Key Responsibilities Set and execute the enterprise cybersecurity strategy and multi-year roadmap aligned with business priorities, risk appetite, regulatory expectations, technology transformation, and enterprise growth. Analyze emerging cybersecurity and governance threats (including AI) and create remediation recommendations. Establish and mature the cyber governance model, including policies, standards, decision rights, executive reporting, escalation protocols, and accountability mechanisms. Lead global security operations, including threat monitoring, intelligence, incident detection, vulnerability management, identity and access management, endpoint security, cloud security, encryption, data protection, analytics, response, and recovery. Oversee security architecture and control design to embed security into technology platforms, cloud environments, data ecosystems, business applications, digital products, privileged access management, and Zero Trust initiatives. Lead Governance, Risk & Compliance (GRC) programs, including risk identification, assessment, prioritization, mitigation, acceptance, monitoring, reporting, policy governance, and compliance oversight. Integrate cybersecurity risk management into enterprise risk management, business planning, technology governance, third-party oversight, customer assurance, and major transformation initiatives. Oversee readiness for applicable laws, regulations, contractual obligations, supervisory expectations, industry standards, and frameworks such as NIST, ISO 27001, CIS Controls, GDPR, HIPAA, PCI DSS, HITRUST, SOX / ITGC, or other relevant requirements. Serve as the primary technology liaison to Legal, Compliance, Privacy, and Internal Audit on cybersecurity, regulatory, privacy, audit, contractual, and customer assurance matters. Lead cyber resilience planning, including incident response strategy, crisis escalation, executive communications, tabletop exercises, ransomware preparedness, recovery coordination, recovery validation, and lessons-learned governance. Advise executive leadership and Board-level stakeholders on cyber risk exposure, emerging threats, program maturity, investment priorities, strategic trade-offs, incident readiness, and regulatory disclosure considerations. Build, lead, and develop a high-performing global cybersecurity and IT governance organization with clear accountability, succession planning, talent development, operating rhythms, and measurable maturity improvements. Champion an enterprise culture in which cybersecurity is understood as a shared leadership responsibility and embedded into business decision-making. Scope of Accountability Global Cybersecurity Program Security Operations, Threat Intelligence & Incident Response Security Architecture & Engineering Identity & Access Management Governance Privileged Access Management Governance Governance, Risk & Compliance (GRC) HITRUST Certification Program PCI Compliance Program SOX / IT General Controls (ITGC) Technology Change Management Governance Cyber Resilience & Recovery Readiness Third-Party Security Assurance Legal, Compliance & Privacy Technology Coordination Executive, Audit Committee, and Board Cybersecurity Reporting Cybersecurity Strategy, Governance, Maturity Roadmap, Investment Prioritization & Enterprise Risk Reporting AI Security Risk Analysis / Threat Mitigation AI Risk Governance Leadership Expectations Operate as a strategic business executive balancing cybersecurity risk, compliance, privacy, technology governance, resilience, and operational priorities. Translate complex cyber, technology, and operational risks into business impact, financial exposure, regulatory implications, and strategic choices. Lead through ambiguity, manage high-pressure incidents, and communicate clearly with senior stakeholders during crisis situations. Influence without direct authority, drive cross-functional alignment, and enable pragmatic, risk-informed decisions. Promote a culture of accountability, resilience, cybersecurity awareness, and continuous improvement. Enable business growth through security leadership that supports innovation, operational resilience, and regulatory readiness. Maintain a mature global security and governance program that supports evolving business, technology, regulatory, customer, and audit requirements. Our benefit package includes health insurance, life and disability, 401(k) contributions, paid time off, etc., for employees working 30 or more hours per week on average. For a more comprehensive list of our benefits please click here. For roles where employees work less than 30 hours per week, benefits include 401(k) contributions as well as access to the Employee Assistance Program, Employee Resource Groups and the Employee Service Corp. We're dedicated to creating a Medline where everyone feels they belong and can grow their career. We strive to do this by seeking diversity in all forms, acting inclusively, and ensuring that people have tools and resources to perform at their best. Explore our Belonging page here. Medline Industries, LP is an equal opportunity employer. Medline evaluates qualified individuals without regard to race, color, religion, gender, gender identity or expression, sexual orientation, national origin, age, disability, neurodivergence, protected veteran status, marital or family status, caregiver responsibilities, genetic information, or any other characteristic protected by applicable federal, state, or local laws.
Overview Journeyman Security Specialist (SAP) (STO) (JWAC) Bowhead seeks a Journeyman Security Specialist with Special Access Program (SAP) and Special Technical Operations (STO) experience to support the Joint Warfare Analysis Center (JWAC) Security Support Services (SSS) contract on-site at Naval Support Activity (NSP)-South Potomac (SP) in Dahlgren, VA. This position supports special access program, special technical operations, personnel security, information security and other security-related tasks in support of the JWAC mission. Responsibilities Prepare, process, and/or review Program Access Requests (PARs) in Joint Access Database Environment (JADE) for accuracy and access eligibility. Resolve classification/declassification issues. Process annual SAP self-reporting forms and report unfavorable/derogatory information; monitor required changes in DISS for status, incidents, and information affecting SAP; receive and forward reports of violations, infractions, and derogatory information. Advise, guide and/or train personnel on SAP/STO information security requirements and procedures relating to classification, marking, safeguarding, storage, reproduction, destruction and transmission of info. Coordinate and process; visit requests, badge requests and authorizations, area accesses, special briefings clearance requirements, security job performance problems and reportable security incidents. Perform briefings, and/or training activities to ensure all personnel are informed of new/change policies procedures or to alert them to threats of espionage and sabotage. Assist in managing security and special access programs according to JWAC, DoD/DoW, Air Force and USSTRATCOM (or applicable higher headquarters) policies, directives and instructions in the following disciplines: personnel security, physical security, industrial security, and information security. Assist in determining SAP/STO access requirements for assigned civilian, military, and contractor personnel. Ensure the required initial and annual updates to paperwork are submitted. When notified, report potential derogatory information to appropriate Cognizant Security Officer. Prepare, process, and/or review Program Access Requests (PARs) in Joint Access Database Environment (JADE) for accuracy and access eligibility. Apply applicable regulations regarding type of clearance and access requirements, utilizing Defense Information System for Security (DISS), as required. Apply applicable regulations regarding type of clearance and access requirements, utilizing Defense Information System for Security (DISS), as required. Assist in maintaining personnel security files for all personnel of the supported element. Perform data entry into required databases and maintain all customer sponsored billets and quota information. Review, track, and monitor security clearance processing activities with appropriate government personnel to achieve appropriate clearance actions. Maintain Facility SOP/instructions/policy recommendations and updates and develop addendums, as required, for specific JWAC SAP facilities that require additional procedures. Conduct an annual assessment of JWAC's SAP security program IAW DoD/DoW, Joint Staff, USSTRATCOM regulations. Inspect facilities and develop courses of action to remediate all issues. Coordinate request(s) for modifications to existing facility accreditations to include inspecting proposed spaces for compliance with applicable regulations, evaluation of proposed uses of spaces and developing and coordinate approval of risk mitigation strategies. Assist in developing and maintaining System Security Management Plans, Program Protection Plans, Security Risk Analyses, OPSEC Plans, Computer Certification and accreditation, Security Vulnerability and Countermeasure analyses, Security Concepts of Operations and other system security related documents. Support the entry/exit inspection of equipment from/to secure areas and schedule and participate in security spot checks. Attend security meetings and coordinate responses to action items. Perform miscellaneous administrative support functions as directed by the contractor site lead and/or the government Senior Security Representative. Perform additional duties related to Special Access Program requirements; INFOSEC, PERSEC, and automation security programs. Process and troubleshoot account requests for Secure Integration Cloud (SIC) and Compartmented Enterprise Services (CED). Assist with Security Classification Guidance. Review, update or create Security Classification Guides as directed. Train personnel on classification guidance. Process Billet Access requests/access and perform account management in/on the Planning and Decision Aid System (PDAS). Perform SAP, Integrated Joint Special Technical Operations (IJSTO) and Alternate Compensatory Control Measures (ACCM) briefings and debriefings, as required. Conduct and document the security compliance inspection using the checklist template. Identify areas of inadequacy and bring to resolution and/or provide recommendations for remedy. Review, update or create local security instructions and policies in accordance with DoD/DoW, Joint Staff and USSTRATCOM regulations. Qualifications Minimum of a Associates Degree or additional years of relevant experience can be used in lieu of a degree. Minimum of five years or more (5+) of experience with SAP/STO Security. Must be proficient in using Microsoft Office Suite products to include Outlook, MS Teams, Word, PowerPoint, and Excel, as well as Adobe Acrobat for PDFs. Targeted salary range is $100,000 to $110,000 annually based on qualifications and experience. Physical Demands: Must be able to lift up to 10-25 pounds Must be able to stand and walk for prolonged amounts of time Must be able to twist, bend and squat periodically SECURITY CLEARANCE REQUIREMENTS: Must hold and be able to maintain security clearance at the Top Secret level. Must be SCI eligible or able to obtain SCI. Must be eligible for SAP access. US Citizenship is a requirement for a Top Secret clearance at this location. Please note that the salary information is a general guideline only. Bowhead considers factors such as (but not limited to) scope and responsibilities of the position, candidate's work experience, education/training, key skills, internal peer equity, as well as, market and business considerations when extending an offer.
09/24/2026
Full time
Overview Journeyman Security Specialist (SAP) (STO) (JWAC) Bowhead seeks a Journeyman Security Specialist with Special Access Program (SAP) and Special Technical Operations (STO) experience to support the Joint Warfare Analysis Center (JWAC) Security Support Services (SSS) contract on-site at Naval Support Activity (NSP)-South Potomac (SP) in Dahlgren, VA. This position supports special access program, special technical operations, personnel security, information security and other security-related tasks in support of the JWAC mission. Responsibilities Prepare, process, and/or review Program Access Requests (PARs) in Joint Access Database Environment (JADE) for accuracy and access eligibility. Resolve classification/declassification issues. Process annual SAP self-reporting forms and report unfavorable/derogatory information; monitor required changes in DISS for status, incidents, and information affecting SAP; receive and forward reports of violations, infractions, and derogatory information. Advise, guide and/or train personnel on SAP/STO information security requirements and procedures relating to classification, marking, safeguarding, storage, reproduction, destruction and transmission of info. Coordinate and process; visit requests, badge requests and authorizations, area accesses, special briefings clearance requirements, security job performance problems and reportable security incidents. Perform briefings, and/or training activities to ensure all personnel are informed of new/change policies procedures or to alert them to threats of espionage and sabotage. Assist in managing security and special access programs according to JWAC, DoD/DoW, Air Force and USSTRATCOM (or applicable higher headquarters) policies, directives and instructions in the following disciplines: personnel security, physical security, industrial security, and information security. Assist in determining SAP/STO access requirements for assigned civilian, military, and contractor personnel. Ensure the required initial and annual updates to paperwork are submitted. When notified, report potential derogatory information to appropriate Cognizant Security Officer. Prepare, process, and/or review Program Access Requests (PARs) in Joint Access Database Environment (JADE) for accuracy and access eligibility. Apply applicable regulations regarding type of clearance and access requirements, utilizing Defense Information System for Security (DISS), as required. Apply applicable regulations regarding type of clearance and access requirements, utilizing Defense Information System for Security (DISS), as required. Assist in maintaining personnel security files for all personnel of the supported element. Perform data entry into required databases and maintain all customer sponsored billets and quota information. Review, track, and monitor security clearance processing activities with appropriate government personnel to achieve appropriate clearance actions. Maintain Facility SOP/instructions/policy recommendations and updates and develop addendums, as required, for specific JWAC SAP facilities that require additional procedures. Conduct an annual assessment of JWAC's SAP security program IAW DoD/DoW, Joint Staff, USSTRATCOM regulations. Inspect facilities and develop courses of action to remediate all issues. Coordinate request(s) for modifications to existing facility accreditations to include inspecting proposed spaces for compliance with applicable regulations, evaluation of proposed uses of spaces and developing and coordinate approval of risk mitigation strategies. Assist in developing and maintaining System Security Management Plans, Program Protection Plans, Security Risk Analyses, OPSEC Plans, Computer Certification and accreditation, Security Vulnerability and Countermeasure analyses, Security Concepts of Operations and other system security related documents. Support the entry/exit inspection of equipment from/to secure areas and schedule and participate in security spot checks. Attend security meetings and coordinate responses to action items. Perform miscellaneous administrative support functions as directed by the contractor site lead and/or the government Senior Security Representative. Perform additional duties related to Special Access Program requirements; INFOSEC, PERSEC, and automation security programs. Process and troubleshoot account requests for Secure Integration Cloud (SIC) and Compartmented Enterprise Services (CED). Assist with Security Classification Guidance. Review, update or create Security Classification Guides as directed. Train personnel on classification guidance. Process Billet Access requests/access and perform account management in/on the Planning and Decision Aid System (PDAS). Perform SAP, Integrated Joint Special Technical Operations (IJSTO) and Alternate Compensatory Control Measures (ACCM) briefings and debriefings, as required. Conduct and document the security compliance inspection using the checklist template. Identify areas of inadequacy and bring to resolution and/or provide recommendations for remedy. Review, update or create local security instructions and policies in accordance with DoD/DoW, Joint Staff and USSTRATCOM regulations. Qualifications Minimum of a Associates Degree or additional years of relevant experience can be used in lieu of a degree. Minimum of five years or more (5+) of experience with SAP/STO Security. Must be proficient in using Microsoft Office Suite products to include Outlook, MS Teams, Word, PowerPoint, and Excel, as well as Adobe Acrobat for PDFs. Targeted salary range is $100,000 to $110,000 annually based on qualifications and experience. Physical Demands: Must be able to lift up to 10-25 pounds Must be able to stand and walk for prolonged amounts of time Must be able to twist, bend and squat periodically SECURITY CLEARANCE REQUIREMENTS: Must hold and be able to maintain security clearance at the Top Secret level. Must be SCI eligible or able to obtain SCI. Must be eligible for SAP access. US Citizenship is a requirement for a Top Secret clearance at this location. Please note that the salary information is a general guideline only. Bowhead considers factors such as (but not limited to) scope and responsibilities of the position, candidate's work experience, education/training, key skills, internal peer equity, as well as, market and business considerations when extending an offer.
Overview Journeyman Security Specialist/ Physical Security Specialist (SAP) (JWAC) Bowhead seeks a Journeyman Security Specialist - Physical Security with Special Access Program (SAP) experience to support the Joint Warfare Analysis Center (JWAC) Security Support Services (SSS) contract on-site at Naval Support Activity (NSP)-South Potomac (SP) in Dahlgren, VA. This position supports physical security, special access programs and other security-related tasks in support of the JWAC mission. Responsibilities Maintain Facility SOP/instructions/policy recommendations and updates and develop addendums, as required, for specific JWAC SAP facilities that require additional procedures. Maintain facility accreditation visual representation and door memorandums. Conduct an annual assessment of JWAC's SAP security program IAW DoD/DoW, Joint Staff, USSTRATCOM regulations. Inspect facilities and develop/recommend courses of action to remediate all issues. Coordinate request(s) for modifications to existing facility accreditations. Participate in monthly zone inspections. Coordinate with Special Security Officer (SSO) Physical Security personnel to ensure SCIF/SAPF spaces are inspection ready, issues are documented, and mitigation strategy is communicated to SSO/GSSO. Assist in managing security and special access programs according to JWAC, DoD/DoW, Air Force and USSTRATCOM (or applicable higher headquarters) policies, directives, and instructions in the following disciplines: physical security, industrial security, information security. Advise, guide and/or train personnel on SAP information security requirements and procedures relating to classification, marking, safeguarding, storage, reproduction, destruction, and transmission of info. Perform Physical Security indoctrination briefing and instruct new personnel on zone opening and closing procedures. Perform physical security functions, as requested or required, by customer or regulation that includes, but not limited to, zone/safe combination changes, safe lifecycle for retirement, replace zone locks, replace/troubleshoot zone keypads and repair or retire shredders. Perform escorting duties for security alarm testing, inspections, and other times, as required. Access and verify program information in JADE to support zone move requests, Secure Integration Cloud (SIC) and Compartmented Enterprise Services (CED) account requests. These include inspecting proposed spaces for compliance with applicable regulations, evaluation of proposed uses of spaces and developing/coordinating approval of risk mitigation strategies. Assist in developing and maintaining System Security Management Plans, Program Protection Plans, Security Risk Analyses, OPSEC Plans, Computer Certification and accreditation, Security Vulnerability and Countermeasure analyses, Security Concepts of Operations and other system security related documents. Support the entry/exit inspection of equipment from/to secure areas, schedule and participate in security spot checks. Attend security meetings and coordinate responses to action items. Perform miscellaneous administrative support functions as directed by the contractor site lead and/or the government Senior Security Representative. Perform additional duties related to SAP requirements; PHYSEC, INFOSEC, and automation security programs. Process and troubleshoot account requests for SIC and CED. Maintain document/item inventory/required records, to be reconciled annually. Perform destruction of classified materials, generate required documentation, and maintain required records. Review, update or create local security instructions and policies in accordance with DoD/DoW, Joint Staff and USSTRATCOM regulations. Assist in the development and review of annual security refresher training. Qualifications Minimum of a Associates Degree or additional years of relevant experience can be used in lieu of a degree. Minimum of five years or more (5+) with SAP/SCI programs. Must be proficient in using Microsoft Office Suite products to include Outlook, MS Teams, Word, PowerPoint, and Excel, as well as Adobe Acrobat for PDFs. Targeted salary range is $100,000 to $110,000 annually based on qualifications and experience. Physical Demands: Must be able to lift 40 pounds and climb a ladder up to 12 feet. Must be able to stand and walk for prolonged amounts of time Must be able to twist, bend and squat periodically SECURITY CLEARANCE REQUIREMENTS: Must hold and be able to maintain security clearance at the Top Secret level. Must be SCI eligible or able to obtain SCI. Must be eligible for SAP access. US Citizenship is a requirement for a Top Secret clearance at this location. Please note that the salary information is a general guideline only. Bowhead considers factors such as (but not limited to) scope and responsibilities of the position, candidate's work experience, education/training, key skills, internal peer equity, as well as, market and business considerations when extending an offer.
09/24/2026
Full time
Overview Journeyman Security Specialist/ Physical Security Specialist (SAP) (JWAC) Bowhead seeks a Journeyman Security Specialist - Physical Security with Special Access Program (SAP) experience to support the Joint Warfare Analysis Center (JWAC) Security Support Services (SSS) contract on-site at Naval Support Activity (NSP)-South Potomac (SP) in Dahlgren, VA. This position supports physical security, special access programs and other security-related tasks in support of the JWAC mission. Responsibilities Maintain Facility SOP/instructions/policy recommendations and updates and develop addendums, as required, for specific JWAC SAP facilities that require additional procedures. Maintain facility accreditation visual representation and door memorandums. Conduct an annual assessment of JWAC's SAP security program IAW DoD/DoW, Joint Staff, USSTRATCOM regulations. Inspect facilities and develop/recommend courses of action to remediate all issues. Coordinate request(s) for modifications to existing facility accreditations. Participate in monthly zone inspections. Coordinate with Special Security Officer (SSO) Physical Security personnel to ensure SCIF/SAPF spaces are inspection ready, issues are documented, and mitigation strategy is communicated to SSO/GSSO. Assist in managing security and special access programs according to JWAC, DoD/DoW, Air Force and USSTRATCOM (or applicable higher headquarters) policies, directives, and instructions in the following disciplines: physical security, industrial security, information security. Advise, guide and/or train personnel on SAP information security requirements and procedures relating to classification, marking, safeguarding, storage, reproduction, destruction, and transmission of info. Perform Physical Security indoctrination briefing and instruct new personnel on zone opening and closing procedures. Perform physical security functions, as requested or required, by customer or regulation that includes, but not limited to, zone/safe combination changes, safe lifecycle for retirement, replace zone locks, replace/troubleshoot zone keypads and repair or retire shredders. Perform escorting duties for security alarm testing, inspections, and other times, as required. Access and verify program information in JADE to support zone move requests, Secure Integration Cloud (SIC) and Compartmented Enterprise Services (CED) account requests. These include inspecting proposed spaces for compliance with applicable regulations, evaluation of proposed uses of spaces and developing/coordinating approval of risk mitigation strategies. Assist in developing and maintaining System Security Management Plans, Program Protection Plans, Security Risk Analyses, OPSEC Plans, Computer Certification and accreditation, Security Vulnerability and Countermeasure analyses, Security Concepts of Operations and other system security related documents. Support the entry/exit inspection of equipment from/to secure areas, schedule and participate in security spot checks. Attend security meetings and coordinate responses to action items. Perform miscellaneous administrative support functions as directed by the contractor site lead and/or the government Senior Security Representative. Perform additional duties related to SAP requirements; PHYSEC, INFOSEC, and automation security programs. Process and troubleshoot account requests for SIC and CED. Maintain document/item inventory/required records, to be reconciled annually. Perform destruction of classified materials, generate required documentation, and maintain required records. Review, update or create local security instructions and policies in accordance with DoD/DoW, Joint Staff and USSTRATCOM regulations. Assist in the development and review of annual security refresher training. Qualifications Minimum of a Associates Degree or additional years of relevant experience can be used in lieu of a degree. Minimum of five years or more (5+) with SAP/SCI programs. Must be proficient in using Microsoft Office Suite products to include Outlook, MS Teams, Word, PowerPoint, and Excel, as well as Adobe Acrobat for PDFs. Targeted salary range is $100,000 to $110,000 annually based on qualifications and experience. Physical Demands: Must be able to lift 40 pounds and climb a ladder up to 12 feet. Must be able to stand and walk for prolonged amounts of time Must be able to twist, bend and squat periodically SECURITY CLEARANCE REQUIREMENTS: Must hold and be able to maintain security clearance at the Top Secret level. Must be SCI eligible or able to obtain SCI. Must be eligible for SAP access. US Citizenship is a requirement for a Top Secret clearance at this location. Please note that the salary information is a general guideline only. Bowhead considers factors such as (but not limited to) scope and responsibilities of the position, candidate's work experience, education/training, key skills, internal peer equity, as well as, market and business considerations when extending an offer.