> Markdown version of [/jobs/ext/2141539-cyber-configuration-validator](https://www.wearedevelopers.com/jobs/ext/2141539-cyber-configuration-validator). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Cyber Configuration Validator - **Company:** After School Matters, Inc. - **Location:** Fort Meade, MD, United States - **Experience:** Expert - **Contract:** Permanent contract - **Skills:** Microsoft Windows, Unix, Cyber Security, Computer Networks, Databases, Linux, Network Security, Microsoft Office, NIPRNet, Software Engineering, Software Systems, Systems Integration, SC Clearance - **Published:** August 20, 2026 - **Apply:** https://pdinc.applytojob.com/apply/Eklfo3QizY/Senior-Cyber-Configuration-Validator?source=GS ## About the Role * Bachelor's degree or equivalent work experience Years of Experience: * Five + years of relevant/recent experience with UNIX, Linux, or Windows Hardening and cybersecurity. * Three + years of relevant/recent experience with Microsoft Office Products.. Certification Requirements: * Current 8570/8140 requirement certification Clearance Requirements: * Active Secret Clearance ## Description Oversee and maintain the cyber configuration validation process IAW DoD and DISA policies and procedures for isolated environments, NIPRNet, and SIPRNet networks. Validate cyber configuration validation procedure requirements are followed to ensure DISA J-9 HaC managed operating environments (OEs) meet the responsible Authorizing Official (AO) build specifications in the approved system A&A package prior to full production connectivity to DoD Information Networks (DoDIN). * Provide cyber configuration validation guidance and vulnerability resolution recommendations to DISA and Strategic Partner personnel. Subtask 2 - Cybersecurity Configuration Compliance. Validate the cyber configuration validation checklist and supporting compliance documentation have been provided and verify SRG and STIG documentation is for the latest available version. Ensure OEs are registered in the DISA asset connection tracking database and records are updated whenever the connectivity status for an OE change (no more than five times per year). Request network security scans and validate results. Review DISA directives and orders, SRG, STIG and network scan vulnerabilities, and validate that vulnerabilities in an open state meet policy guidelines. Review and validate the complete installation and configuration of mandated cyber tools on DISA OEs. Verify the owning Strategic Partner has acknowledged the security posture of the submitted OE(s) and provide notification of cyber configuration validation approval or denial decisions to the requester. ~~~~~~~~~~~~~~~ About PD Inc International (PD Inc): PD Inc is a leading high-tech firm as well as an applied think tank and solutions provider. Our team has been providing expertise and solutions to the US Government (Department of Defense, Department of State, Department of Homeland Security, Veterans Affairs, etc.) and to commercial clients for over 20-years. We perform software development and complex technical implementation daily. We conduct R&D, prototyping, and develop hardware and software solutions for our clients. Our qualified personnel--including engineers and technical managers--are capable of performing system integration, technology implementation, and services throughout the federal government and in the private sector. We have a highly innovative environment, and we foster consistent learning and growth. We encourage our employees to innovate while teaching them discipline and principles. ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Docker network without Docker](https://www.wearedevelopers.com/videos/1418-docker-network-without-docker) - [WeAreDevelopers LIVE - Node and Package Security](https://www.wearedevelopers.com/videos/2138-wearedevelopers-live-node-and-package-security) - [What makes Cybersecurity different for critical infrastructure?](https://www.wearedevelopers.com/videos/571-what-makes-cybersecurity-different-for-critical-infrastructure) - [Docker exec without Docker](https://www.wearedevelopers.com/videos/1094-docker-exec-without-docker) - [The Time Paradox: Building Timezone-Safe Python/Django Applications](https://www.wearedevelopers.com/videos/1915-the-time-paradox-building-timezone-safe-python-django-applications) ## Related Articles - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Best Coding Boot Camps in Germany](https://www.wearedevelopers.com/magazine/237-best-coding-boot-camps-in-germany) - [The Overflow: Security and Privacy](https://www.wearedevelopers.com/magazine/715-the-overflow-security-and-privacy) - [Dev Digest 216: CyberSec + Mythos, Stack Overflow for Agents & DOOM in TTF](https://www.wearedevelopers.com/magazine/728-dev-digest-216-cybersec-mythos-stack-overflow-for-agents-doom-in-ttf) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities)