> Markdown version of [/jobs/ext/2598779-cybersecurity-specialist](https://www.wearedevelopers.com/jobs/ext/2598779-cybersecurity-specialist). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Cybersecurity Specialist - **Company:** VMD Systems - **Location:** Colorado Springs, CO, United States (Remote available) - **Experience:** Expert - **Salary:** $120,000.0 - $130,000.0 - **Contract:** Permanent contract - **Skills:** Cyber Security, Information Systems Security Architecture Professional, Information Technology, Plan of Action and Milestones - **Published:** August 19, 2026 - **Apply:** https://jobs.jobvite.com/vmdsystems/job/o5iyAfwf/apply ## About the Role * 5+ years of cybersecurity and compliance experience * Active Certified Information Systems Security Professional (CISSP) or Certified Information Security Manager (CISM) certification * Strong leadership and interpersonal skills to facilitate effective collaboration across a variety of stakeholders * Demonstrated ability to function independently and define the proper methods & procedures * Understanding of guiding cybersecurity principles and control guidance * Effective writing skills to capture issues and recommendations * Strong customer relationship building ability Basic Qualifiers: * Education Requirement: Bachelor's degree * Can Additional Years of Experience Substitute for Degree? Yes * Required Certification(s): Certified Information Systems Security Professional (CISSP) or Certified Information Security Manager (CISM) * Minimum Years of Overall Experience: 5 * Minimum Years of Specific Experience in Field: 5 * Minimum Clearance to Start: Secret * Work Status Allowable: US Citizenship The Type of Person That Will Excel: * You are curious, inquisitive, and have demonstrated a constant eagerness to learn through actions. * You have high attention to detail. * You demonstrate personal accountability and integrity in all actions. * You have a passion for Cybersecurity. * Takes ownership of assigned systems, assessments, deadlines, and deliverables without needing heavy supervision. * Understands that compliance is not just paperwork and is able to connect control requirements to practical Cybersecurity outcomes. * Is comfortable operating in a customer-facing environment and can represent the organization professionally during reviews, audits, assessments, and status meetings. * Is comfortable managing multiple priorities, deadlines, assessments, and documentation efforts - even when new, competing requirements with short timelines come to light. ## Description As a Senior Cybersecurity Specialist you will be responsible to deliver security and compliance expertise leadership to support multiple IT projects, programs, and initiatives. You will be supporting the assessment and authorization (A&A) process, determining current security postures, tracking vulnerabilities and POA&Ms, and identifying potential cybersecurity risk. The Senior Cybersecurity Specialist will be responsible for: * Actively participate and lead meetings to review and assess compliance of systems and technology * Perform risk assessments based on Federal guidelines and industry best practices * Assist teams in identifying vulnerabilities and providing recommendations to reduce cybersecurity risk * Create and mature control-specific procedures for RMF control families by interpreting NIST requirements, identifying system-specific implementation needs, and developing effective procedural documentation that supports both mission operations and defensible compliance. * Articulate and report on cybersecurity risk and compliance to executives and senior leaders * Understand Vulnerability details, both technical and control-based, and craft actionable remediation plans and mitigation strategies * Create, maintain, and track POA&Ms - working with system owners and technical teams to identify corrective actions, document mitigations, monitor remediation progress, and support timely closure of security findings. * Support remediation of control-based POA&Ms by analyzing control weaknesses, recommending corrective actions or mitigations, coordinating with technical teams, and reviewing closure evidence to confirm the weakness has been resolved. * Author A&A documentation to create foundational RMF documentation to support system authorization * Continually improve the cybersecurity risk assessment and POA&M process and program * Aggregate and track cybersecurity POA&Ms and risks across projects, teams, and programs * Respond to and triage security incidents as a key member of the incident response team * Communicate cybersecurity best practices based on policies, standards, and controls ## Related Videos - [What makes Cybersecurity different for critical infrastructure?](https://www.wearedevelopers.com/videos/571-what-makes-cybersecurity-different-for-critical-infrastructure) - [Beyond the Numbers: Engineering Recruiting Excellence Through Quality, Data, and Team Empowerment](https://www.wearedevelopers.com/videos/1491-beyond-the-numbers-engineering-recruiting-excellence-through-quality-data-and-team-empowerment) - [Enabling intelligent logistics automation: home-grown Industrial IoT platform at Austrian Post](https://www.wearedevelopers.com/videos/2018-enabling-intelligent-logistics-automation-home-grown-industrial-iot-platform-at-austrian-post) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [Reporting Active Exploits in 24 Hours: Are You Ready for the CRA?](https://www.wearedevelopers.com/videos/100248-reporting-active-exploits-in-24-hours-are-you-ready-for-the-cra) - [Cyber Security: Small, and Large!](https://www.wearedevelopers.com/videos/259-cyber-security-small-and-large) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [How to Write a CV and Interview if You Don't Fully Qualify For The Job](https://www.wearedevelopers.com/magazine/183-how-to-write-a-cv-and-interview-if-you-don-t-fully-qualify-for-the-job) - [System change: restart as developer?](https://www.wearedevelopers.com/magazine/39-system-change-restart-as-developer) - [What’s the Difference between a Junior, Mid, and Senior Developer?](https://www.wearedevelopers.com/magazine/238-what-s-the-difference-between-a-junior-mid-and-senior-developer)