Cyber Analyst RMF Specialist

Science Applications International Corporation
Colorado Springs, CO, United States
3 days ago
Apply on www.dice.com
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Experienced
Experience required
2 years minimum
Compensation
$120,001.0 - $160,000.0
Working hours
Regular working hours
Job source

Tech stack

Microsoft Windows Active Directory Cyber Security Information Systems Linux Linux Servers Network Monitoring Security Content Automation Protocol Information Technology Plan of Action and Milestones Vulnerability Analysis

Job description

Join our team and play a pivotal role in defending North America. We are seeking a highly skilled Cyber Analyst RMF Specialist in Colorado Springs, CO to support the critical North American Aerospace Defense Command and United States Northern Command (N&NC) Information Technology Enterprise Services (NITES) contract in Colorado Springs, CO.

In this role, you will act as a key technical compliance specialist. You will hold administrator-level access to information systems to perform advanced vulnerability and compliance scanning and manage Security Technical Implementation Guide (STIG) compliance. Crucially, you will bridge the gap between technical operations and cyber governance by directly supporting the Risk Management Framework (RMF) team, maintaining up-to-date system records in Enterprise Mission Assurance Support Service (eMASS), and executing rapid response protocols to downward-directed Cyber Tasking Orders (CTASKORDs).

Responsibilities

The selected candidate will be responsible for the following technical and compliance activities:

  • Directly support the Risk Management Framework (RMF) team by registering, updating, and maintaining continuous monitoring records within the eMASS.
  • Maintain administrator-level access to enterprise information systems to configure, manage, and perform regular Assured Compliance Assessment Solution (ACAS) and Security Content Automation Protocol (SCAP) compliance scans.
  • Analyze scan results to ensure continuous patching and STIG compliance.
  • Implement, track, and validate system hardening measures across Windows, Linux, and network enclaves.
  • Lead the execution, tracking, and operational response to Cyber Tasking Orders (CTASKORDs) and other downward-directed orders when STIG compliance gaps must be urgently addressed.
  • Translate technical scan findings and non-compliant STIG items into actionable Plan of Action and Milestones (POA&Ms), maintaining accurate tracking of remediation milestones.
  • Maintain continuous cyber security posture and system hygiene to ensure systems remain in a Cyber Operational Readiness Assessment (CORA) ready state.
  • Provide clear vulnerability status updates, technical mitigations, and compliance roadmaps to System Owners, technical administration teams, and leadership.

Requirements

  • Active TS/SCI security clearance
  • Certification required per DoDD 8140.03, Intermediate Level (e.g., CompTIA CySA+, Security+ CE, GSEC, or equivalent)
  • BS or equivalent work experience in the Information Assurance, Cybersecurity, or Systems Administration field
  • 5+ years of overall IT and cybersecurity experience
  • Demonstrated experience with defending identity services, domain environments, Active Directory, and Windows/Linux server systems
  • 2+ years of experience as an ISSO for DoD systems
  • Experience using STIG Viewer and SCAP tools, such as EvaluateSTIG, * Familiarity with enterprise vulnerability scanners and continuous network monitoring tools
  • Previous experience operating in a highly complex, metrics-driven DoD cybersecurity environment
  • Familiarity with the use of eMASS as a central repository for RMF artifacts

Benefits & conditions

Target salary range: $120,001 - $160,000. The estimate displayed represents the typical salary range for this position based on experience and other factors.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.dice.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

4:01 min

Finding personal fulfillment in the cybersecurity industry

LIVE

4:11 min

Introduction to cloud-native application developer security

Micah Silverman · World Congress 2022

1:43 min

The physical pain of early web app deployment

52 sec

Running persistent Linux environments directly on Windows

Ben Breard Ben Breard · World Congress 2025

1:45 min

Transitioning from software development to security roles

Stefania Chaplin · World Congress 2022

3:44 min

Current industry adoption and future security initiatives

Alexander Allmendinger · LIVE

Videos

See all

Related articles

See all