> Markdown version of [/jobs/ext/1828274-cyber-security-specialist-4](https://www.wearedevelopers.com/jobs/ext/1828274-cyber-security-specialist-4). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # CYBER SECURITY SPECIALIST 4 - **Company:** VSolvit - **Location:** Ventura, CA, United States - **Experience:** Experienced - **Contract:** Permanent contract - **Skills:** Microsoft Azure, Cloud Computing Security, Cloud Engineering, Cyber Security, Continuous Integration, Zero Trust Network Access, Security Content Automation Protocol, Security Support Provider Interface, Software Vulnerability Management, Information Technology, Tenable Nessus, Devsecops, Plan of Action and Milestones - **Published:** July 15, 2026 - **Apply:** https://www.clearancejobs.com/jobs/9030180/cyber-security-specialist-4 ## About the Role Basic : * Must be a U.S. Citizen * Bachelor's degree in Computer Science or a related field. * 2-4 years of cloud engineering experience with specific expertise in RMF activities and ATO deadlines. * Expertise in Azure administration and cloud architecture. * Proficiency with Security Content Automation Protocol (SCAP) scanning tools and Navy eVALUATE. * Experience managing contractual deliverables and project schedules. * Experience with CI/CD and DevSecOps toolchains. * Current Security+ certification. * Active DoD Top Secret clearance or the ability to obtain one. Preferred: * Active DoD Top Secret clearance. * Active Security+ certification. * Professional cloud certification, such as Microsoft Certified: Azure Associate. * Proven experience implementing DISA STIG configurations and supporting compliance for DoD SRG and NIST SP 800-53 security controls. ## Description The Cybersecurity Specialist 4 provides security and compliance oversight for the Risk Management Framework (RMF) Steps 1-6. This role ensures the integrity of current legacy and future security stacks through continuous monitoring, vulnerability management, and enforcement of DISA STIG compliance. You will act as a key technical resource for ensuring that Department of Navy CSM packages meet Authorization to Operate (ATO) deadlines while transitioning toward Zero Trust Architecture (ZTA). As with any position, additional expectations exist. Some of these include, but are not limited to, adhering to normal working hours, meeting deadlines, following company policies as outlined by the Employee Handbook, communicating regularly with assigned supervisor(s), staying focused on the assigned tasks, and completing other tasks as assigned., * RMF Lifecycle & Compliance Management + Provide ongoing security support for the legacy SCCA stack and future ZTA Mission Landing Zone (MLZ) stacks in Azure Government across all RMF steps (1-6). + Perform RMF activities to support CSM Packages, ensuring all requirements are met to achieve and maintain ATO status. + Schedule package checkpoints, deliver status reports, and perform quality assurance reviews. + Maintain and report the system's Authorization and Assessment (A&A) status and related security events. + Assist in identifying the security control baseline set and any applicable overlays. + Manage Plan of Action and Milestone (POA&M) entries to ensure vulnerabilities are properly tracked, mitigated, and resolved. * Technical Security Operations + Support the implementation and maintenance of the SCCA, including routine patching and ensuring Secure Technical Implementation Guide (STIG) compliance. + Continuously monitor applications by assessing security control quality against requirements defined in the System Level Continuous Monitoring (SLCM) strategy. + Utilize Assured Compliance Assessment Solution (ACAS) results to update system POA&Ms. + Maintain Hardware and Software assessment sheets annually or upon environment changes. + Ensure strict adherence to the DoD SCCA Functional Requirements (v2.9) and the latest DoD Cloud Computing Security Requirements Guide (CC SRG). * Package & Tool Sustainment + Provide compliance support for RMF packages. + Manage, configure, and sustain future CN/ZTA MLZ security tools in Azure Government and Commercial. ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [DevSecOps: Injecting Security into Mobile CI/CD Pipelines](https://www.wearedevelopers.com/videos/273-devsecops-injecting-security-into-mobile-ci-cd-pipelines) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [DevSecOps culture](https://www.wearedevelopers.com/videos/783-devsecops-culture) - [DevSecOps: Security in DevOps](https://www.wearedevelopers.com/videos/36-devsecops-security-in-devops) - [You can’t hack what you can’t see](https://www.wearedevelopers.com/videos/41-you-can-t-hack-what-you-can-t-see) ## Related Articles - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks)