> Markdown version of [/jobs/ext/2734514-it-cybersecurity-specialist](https://www.wearedevelopers.com/jobs/ext/2734514-it-cybersecurity-specialist). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # IT Cybersecurity Specialist - **Company:** Inc. (osi) - **Location:** San Diego, CA, United States - **Experience:** Expert - **Contract:** Permanent contract - **Skills:** Access Control List, CompTIA Security+, Cyber Security, Information Systems, Computer Engineering, Identity and Access Management, Open Systems Interconnection (OSI), Role-Based Access Control, Zero Trust Network Access, Software Deployment, Software Vulnerability Management, Information Security Management System, Client Side Scripting, Information Technology, Servicenow, Plan of Action and Milestones, Vulnerability Analysis - **Published:** September 5, 2026 - **Apply:** https://osivision.gnahiring.com/job/1055727/it-cybersecurity-specialist ## About the Role * Bachelor's degree in Cybersecurity, Computer Science, Computer Engineering, Information Technology, Information Systems, or a related technical discipline. * Minimum of five years of practical cybersecurity experience. * Active Secret security clearance. * Demonstrated experience applying Department of Defense cybersecurity workforce qualification requirements, including DoDM 8140.03 and applicable Defense Cyber Workforce Framework work roles. * Demonstrated expertise applying NIST SP 800-53 security controls and supporting Risk Management Framework activities associated with achieving and maintaining an Authority to Operate. * Knowledge of NIST SP 800-161 supply chain risk management requirements. * Experience securing or administering ServiceNow environments supporting Federal Government or Department of Defense requirements. * Demonstrated hands-on experience configuring ServiceNow security controls, including ACLs, Client Scripts, Data Policies, user roles, groups, and access permissions. * Experience implementing identity, credential, and access management controls, including CAC-based or other strong authentication mechanisms. * Experience developing or maintaining System Security Plans, POA&Ms, security assessment documentation, vulnerability management records, and RMF artifacts. * Knowledge of Controlled Unclassified Information security requirements and applicable NIST SP 800-171/172 controls. * Experience supporting continuous monitoring, vulnerability scanning, security assessments, penetration-test reviews, or compliance verification activities. * Ability to meet applicable Department of Defense cybersecurity workforce qualification and certification requirements. * Strong technical writing, analytical, documentation, and communication skills., * Experience securing ServiceNow environments operating at FedRAMP High or within Department of Defense Impact Level environments. * Experience using ServiceNow Governance, Risk, and Compliance (GRC), Integrated Risk Management (IRM), or Security Operations (SecOps) modules. * Experience using ServiceNow to support POA&M tracking, vulnerability remediation, compliance monitoring, or RMF workflows. * Experience supporting Department of Defense system authorization activities. * Familiarity with enterprise identity, credential, and access management architectures. * Relevant cybersecurity certifications aligned with applicable DoDM 8140.03 workforce requirements. ## Description The IT Cybersecurity Specialist will support a Federal Government defense program by designing, implementing, and sustaining cybersecurity controls for a ServiceNow environment. The position will help protect Controlled Unclassified Information (CUI), support Department of Defense cybersecurity requirements, apply Zero Trust principles, and coordinate with Government cybersecurity and IT stakeholders to maintain system compliance. The IT Cybersecurity Specialist will develop and maintain Risk Management Framework (RMF) documentation, support vulnerability remediation, conduct continuous monitoring activities, and help maintain the system's Authority to Operate (ATO) throughout its lifecycle. This position requires hands-on ServiceNow security experience and strong knowledge of Federal cybersecurity frameworks, access controls, identity management, and system authorization processes., * Architect, configure, and maintain ServiceNow security controls, including Role-Based Access Controls (RBAC), Access Control Lists (ACLs), Data Policies, Client Scripts, encryption controls, and related security configurations. * Align ServiceNow security configurations with applicable Department of Defense Zero Trust principles and Federal cybersecurity requirements. * Implement and maintain appropriate data segregation, access restrictions, authentication controls, and security boundaries within controlled Government environments. * Create and maintain detailed security documentation, including security schemas, access-control matrices, system roles, groups, ACLs, and data-segregation rules. * Coordinate with Government IT, cybersecurity, security architecture, and authorization stakeholders to maintain required cybersecurity protocols and compliance requirements. * Develop, maintain, and update the System Security Plan (SSP) and required Risk Management Framework documentation supporting system authorization and sustainment. * Map ServiceNow platform configurations and security controls to applicable NIST Special Publication 800-53 requirements and other Federal cybersecurity standards. * Support implementation of CUI security requirements consistent with NIST SP 800-171, NIST SP 800-172, and applicable Department of Defense security controls. * Develop, track, manage, and update Plans of Action and Milestones (POA&Ms) documenting cybersecurity findings, corrective actions, remediation activities, and closure status. * Support vulnerability management activities, including reviewing scan results, coordinating remediation, tracking findings, and validating corrective actions. * Conduct or support continuous monitoring activities, security reviews, configuration assessments, penetration-test reviews, compliance checks, and other security assessment activities. * Prepare or support Security Assessment Reports, cybersecurity status reports, compliance documentation, and other security-related deliverables. * Review proposed system or application changes for potential cybersecurity impacts prior to implementation or production deployment. * Support maintenance of cybersecurity workforce qualification and certification documentation in accordance with applicable Department of Defense workforce requirements. * Maintain awareness of emerging cybersecurity threats, vulnerabilities, Federal requirements, and ServiceNow security capabilities that may affect program operations., This is an anticipated position contingent upon contract award, Government approval, funding, security requirements, and final program requirements. Submission of an application does not constitute an offer of employment. ## Related Videos - [Applying Agile Principles to Incident Management ](https://www.wearedevelopers.com/videos/101-applying-agile-principles-to-incident-management) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [Organizational Change Through The Power Of Why - DevSecOps Enablement](https://www.wearedevelopers.com/videos/478-organizational-change-through-the-power-of-why-devsecops-enablement) - [What makes Cybersecurity different for critical infrastructure?](https://www.wearedevelopers.com/videos/571-what-makes-cybersecurity-different-for-critical-infrastructure) - [AI in Production: applied AI & enterprise use cases](https://www.wearedevelopers.com/videos/100130-ai-in-production-applied-ai-enterprise-use-cases) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks) - [How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again](https://www.wearedevelopers.com/magazine/751-how-we-built-a-worry-free-system-that-runs-for-10-years-and-what-we-d-do-again) - [Is Software Engineering Over-Saturated?](https://www.wearedevelopers.com/magazine/418-is-software-engineering-over-saturated)