> Markdown version of [/jobs/ext/1508197-cybersecurity-specialist-4](https://www.wearedevelopers.com/jobs/ext/1508197-cybersecurity-specialist-4). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Cybersecurity Specialist 4 - **Company:** Caribou Thunder - **Location:** Albuquerque, NM, United States - **Experience:** Expert - **Salary:** $100,000.0 - $130,000.0 - **Contract:** Permanent contract - **Skills:** Microsoft Windows, Access Control List, Static Program Analysis, Software Documentation, Cyber Security, Linux, Identity and Access Management, Information Security Management, Open Web Application Security, Public Key Infrastructure, Systems Development Life Cycle, Fortify (Software), Secure Coding, Security Content Automation Protocol, Systems Integration, Virtualization Technology, Software Vulnerability Management, Network Routers, Enterprise Software Applications, Firewalls (Computer Science), Information Technology, Plan of Action and Milestones - **Published:** July 30, 2026 - **Apply:** https://www.clearancejobs.com/jobs/9067305/cybersecurity-specialist-4 ## About the Role * Bachelor's degree in Computer Science, Cybersecurity, Information Technology, or a related STEM (Science, Technology, Engineering, or Mathematics) discipline and 9 years of related experience. * Four additional years of relevant cybersecurity experience may be substituted in lieu of a degree. * Minimum 5 years of hands-on cybersecurity experience supporting classified or enterprise information systems. * Active Top Secret security clearance with SCI eligibility and the ability to obtain and maintain TS/SCI access. * Experience supporting the DoD Risk Management Framework (RMF) lifecycle and Authority to Operate (ATO) activities. * Experience developing and maintaining RMF Body of Evidence documentation. * Experience administering accreditation packages using eMASS. * Experience developing and maintaining Plan of Action & Milestones (POA&M) documentation. * Strong technical writing and documentation skills supporting cybersecurity compliance. * Experience collaborating with internal engineering teams and external government oversight organizations. * Strong analytical, organizational, and project management skills. * Current DoD 8570 IAT Level II certification or Cybersecurity Service Provider (CSSP) certification. * Experience integrating and administering Linux and Windows systems within virtualized environments. * Experience installing and managing Enterprise Security Systems (ESS) and Assured Compliance Assessment Solution (ACAS). * Experience performing SCAP compliance scanning and Security Technical Implementation Guide (STIG) validation using STIG Viewer. * Experience implementing STIGs and security controls across classified military environments. * Experience securing enterprise technologies including: + Firewalls + Router Access Control Lists (ACLs) + Public Key Infrastructure (PKI) + Identity and Access Management (IAM) + Virtualization platforms + Secure scripting and automation + OWASP secure development practices * Experience performing Static Code Analysis using tools such as Fortify. * Experience supporting cybersecurity modernization initiatives within Department of Defense or other federal programs. ## Description Senior Level | $100,000 - $130,000 | Travel: Minimal | Location: Kirtland AFB, NM | Active Top Secret Clearance (SCI Eligible) Required Support the modernization and expansion of mission-critical cybersecurity capabilities by leading Risk Management Framework (RMF) activities, Assessment & Authorization (A&A) efforts, and enterprise cybersecurity compliance initiatives. Join a collaborative engineering team responsible for securing classified systems through continuous monitoring, vulnerability management, security control implementation, and accreditation support while ensuring compliance with DoD cybersecurity standards. * Lead Risk Management Framework (RMF) activities supporting the authorization and continuous monitoring of classified information systems. * Develop, maintain, and manage RMF Body of Evidence (BoE) documentation including System Security Plans (SSPs), Security Controls Traceability Matrices (SCTMs), Plan of Action & Milestones (POA&Ms), Security Assessment documentation, and supporting authorization artifacts. * Maintain accreditation packages within Enterprise Mission Assurance Support Service (eMASS), ensuring system documentation remains accurate, complete, and audit-ready. * Coordinate with government Authorizing Officials (AOs), Information System Security Managers (ISSMs), cybersecurity engineers, and program leadership to achieve and maintain Authority to Operate (ATO). * Install, configure, integrate, and troubleshoot enterprise cybersecurity tools supporting secure system operations and continuous monitoring. * Develop cybersecurity policies, standard operating procedures, and process improvements that strengthen program security posture and operational efficiency. * Perform security control assessments and verification activities to ensure compliance with NIST, DoD, and organizational cybersecurity requirements. * Identify, document, and track cybersecurity vulnerabilities and deficiencies through Plan of Action & Milestones (POA&M) management while coordinating remediation efforts across engineering teams. * Support identity and access management solutions, Public Key Infrastructure (PKI), cryptographic implementations, and secure authentication technologies. * Maintain secure repositories of RMF documentation and ensure controlled access to sensitive cybersecurity artifacts. * Provide cybersecurity subject matter expertise to engineering teams, project managers, and government stakeholders throughout the system development lifecycle. * Support continuous improvement initiatives by evaluating emerging cybersecurity technologies, security tools, and compliance processes. ## Related Videos - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [How to Cause (or Prevent) a Massive Data Breach- Secure Coding and IDOR](https://www.wearedevelopers.com/videos/39-how-to-cause-or-prevent-a-massive-data-breach-secure-coding-and-idor) - [Docker network without Docker](https://www.wearedevelopers.com/videos/1418-docker-network-without-docker) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [What makes Cybersecurity different for critical infrastructure?](https://www.wearedevelopers.com/videos/571-what-makes-cybersecurity-different-for-critical-infrastructure) - [Cyber Security: Small, and Large!](https://www.wearedevelopers.com/videos/259-cyber-security-small-and-large) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Dev Digest 138 - Are you secure about this?](https://www.wearedevelopers.com/magazine/486-dev-digest-138-are-you-secure-about-this) - [Dev Digest 129 - Now that's what I call private data!](https://www.wearedevelopers.com/magazine/468-dev-digest-129-now-that-s-what-i-call-private-data) - [7 Important Tips That Every Software Developer Should Know](https://www.wearedevelopers.com/magazine/101-7-important-tips-that-every-software-developer-should-know)