> Markdown version of [/jobs/ext/1958682-cybersecurity-specialist](https://www.wearedevelopers.com/jobs/ext/1958682-cybersecurity-specialist). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Cybersecurity Specialist - **Company:** Calvert Systems Engineering - **Location:** Bellevue, NE, United States - **Experience:** Experienced - **Contract:** Permanent contract - **Skills:** Xacta, C (Programming Language), Java (Programming Language), JavaScript (Programming Language), Microsoft Windows, Business Analytics Applications, Software Applications, Software System Penetration Testing, Burp Suite, C Sharp (Programming Language), Unix, Cyber Security, Databases, Linux, White-Box Testing, Identity and Access Management, Python (Programming Language), Kali Linux, Network Security, Open Web Application Security, Windows PowerShell, Fortify (Software), Red Team (Cyber Security), Ruby, Security Software, SQL Databases, Web Applications, Webinspect, Software Security, Mitre Att&ck, GWAPT, Information Technology, Metasploit, Tenable Nessus, Appscan, Software Coding, Blue Team (Cyber Security), Plan of Action and Milestones, Vulnerability Analysis, Programming Languages - **Published:** August 6, 2026 - **Apply:** https://diversityjobs.com/main/sendform/8/8/28176/1/17825896?backUrl=%2Fcareer%2F17825896%2FCybersecurity-Specialist-Nebraska-Bellevue ## About the Role This position requires the ability to obtain and maintain a Top Secret U.S. Government Security Clearance with SCI eligibility. U.S. Citizenship status is required, as this position necessitates an active U.S. Government Security Clearance for employment. Non-U.S. citizens are not eligible to obtain a U.S. security clearance. The Department of Defense Consolidated Adjudications Facility (DoD CAF), a federal government agency, handles the adjudicative aspects of the security clearance process for industry applicants. Adjudicative factors which affect the outcome of the eligibility determination include, but are not limited to, allegiance to the U.S., foreign influence, foreign preference, criminal conduct, security violations, and illegal drug use., * Bachelor's degree in Computer Science or other related field. * Minimum of 3 years of experience conducting penetration testing or Blue team testing required * Possession of one of the following certifications: GPEN, GWAPT, GSE, OSEE, OSCE, OSCP, or GXPN. * Knowledge of application security principles and safe coding techniques. * Experience with programming languages such as SQL, C#, JavaScript, Ruby, PowerShell, and Python. * Proficiency with security assessment tools including Tenable NESSUS, WebInspect, OWASP ZAP, Burp Suite, Metasploit, and Kali Linux. * Familiarity with security frameworks such as NIST, MITRE ATT&CK, OWASP, and APT TTPs. * Experience using operating systems such as Linux, UNIX, and Windows. * Possession of DoD Directive (DoDD) 8570 Information Assurance Management (IAM) Level II certification or DoDD 8140 Information Assurance Security Engineer Level II certification. * Knowledge and experience with NIST 80053 and DoD Risk Management Framework tools, including eMASS and Xacta. ## Description As a Cybersecurity Specialist, you will be responsible for assessing the security of systems, applications, and networks using established cybersecurity tools, frameworks, and testing methodologies. You will identify vulnerabilities, evaluate cybersecurity controls, and support the development of documentation, reports, and recommendations that ensure compliance with required security standards. This role also involves conducting a variety of security tests and audits, analyzing findings, and helping strengthen overall cybersecurity posture across supported environments., * Understand and develop Plan of Action and Milestones (POA&M) required in support of information assurance or security necessities. * Evaluate new applications software technologies; and/or ensuring the rigorous application of information security/ cybersecurity policies, principles, and practices to the delivery of application software services. * Manage the fact finding, analysis, and development of hypothesis, conclusions, production of final reports and presentations, which requires expert knowledge of database practices, and USSTRATCOM database organization, operations and objectives, and requires training in application security and software analytical tools used by the IPT. + These tools include: Application Security AppDetective Pro, Application Security DBProtect, Fortify Source Code Analyzer, Fortify 360 Server, Fortify Real-Time Analyzer, IBM/Rational AppScan. * Support Cybersecurity and Cybersecurity Testing. * Conduct tests of cybersecurity safeguards and integration of systems IAW established test plans, STIGs and Cybersecurity Controls. Cybersecurity support must be able to identify areas of cyber weakness within the programs and assist in providing solutions and document results with POA&Ms. Cybersecurity staff must ensure the design of hardware, operating systems, and software applications adequately address security requirements for the Computing Environment (CE) to include testing cybersecurity mitigations. + This work requires the establishment and sustainment of information security assurance processes that satisfy complex system-wide requirements based upon DoDD 8500.1 Information Assurance, DoDI 8500.2 Information Assurance Implementation, DoDD 8520.1 Protection of SCI, DoDI 8510.01 Risk Management Framework (RMF) for DoD Information Technology, DoD 8570.01M Information Assurance Workforce Improvement Program, and DoDI 8580.1 Information Assurance in the Defense Acquisition Process used for the analysis of user, policy, regulatory, and resource demands. These tasks require the development and production of RMF documentation for Secret, Top Secret and JWICS networks. Cybersecurity recommendations shall be provided based on evaluation and review of engineering proposals to ensure compliance with mandated cybersecurity requirements. * Provide support in the development and implementation of doctrine and policies including CJCSI 6510.01E IA and Computer Network Defense (CND); CNSSP-22 Information Assurance Risk Management Policy for National Security Systems, and CNSSP-6 National Policy on Certification and Accreditation of National Security Systems. * Perform vulnerability assessments and security tests on networks, web-based applications, and computer systems. * Use testing methods to pinpoint ways that attackers could exploit weaknesses in security systems. * Conduct network and system security audits, evaluate how well system conforms to a set of established criteria. * Analyze policies for effectiveness, make suggestions on security policy improvements, and work to enhance methodology material. * Document findings, write security reports, and discuss solutions with IT teams and management. * Provide feedback and verification after security fixes are issued. * Perform "black box" and "white box" testing. * Perform Blue and Red team war gaming exercises. * Perform security and technical assessments on new technologies. * Generate "Best Practices" for implementations of new technologies. * Perform reviews of application designs and source code (mainly Java, JavaScript, and C). * Automate security testing through scripts and macros ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Docker network without Docker](https://www.wearedevelopers.com/videos/1418-docker-network-without-docker) - [WeAreDevelopers LIVE - Node and Package Security](https://www.wearedevelopers.com/videos/2138-wearedevelopers-live-node-and-package-security) - [Coffee with Developers: David Heinemeier Hansson](https://www.wearedevelopers.com/videos/875-coffee-with-developers-david-heinemeier-hansson) - [Coffee with Developers - Robby Russell](https://www.wearedevelopers.com/videos/917-coffee-with-developers-robby-russell) - [Securing Your Web Application Pipeline From Intruders](https://www.wearedevelopers.com/videos/53-securing-your-web-application-pipeline-from-intruders) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Best Coding Boot Camps in Germany](https://www.wearedevelopers.com/magazine/237-best-coding-boot-camps-in-germany) - [The Overflow: Security and Privacy](https://www.wearedevelopers.com/magazine/715-the-overflow-security-and-privacy)