> Markdown version of [/jobs/ext/2844735-ncyber-security-stig-tester](https://www.wearedevelopers.com/jobs/ext/2844735-ncyber-security-stig-tester). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # nCyber Security STIG Tester - **Company:** Nabout Leidos - **Location:** Meade, KS, United States - **Experience:** Expert - **Salary:** $107,900.0 - $195,050.0 - **Contract:** Permanent contract - **Skills:** Xacta, Network Administration, Systems Development Life Cycle, Security Content Automation Protocol, Software Construction, Information Technology, Plan of Action and Milestones, Vulnerability Analysis - **Published:** September 11, 2026 - **Apply:** https://jobs.military.com/career/333487/cyber-security-stig-tester-maryland-md-odenton ## About the Role u2022 Bachelor's degree and 8+ years of experience; additional years of directly applicable experience may be accepted in lieu of a degree.\n \u2022 Prior relevant experience working with STIG Compliance, SCAP tools, vulnerability assessments and reporting.\n \u2022 Have experience performing various types of vulnerability and assessment scans with multiple tools.\n \u2022 Have experience using eMASS and/or Xacta.\n \u2022 Solid understanding of the Risk Management Framework (RMF) and the System Development Life Cycle (SDLC).\n \u2022 Understanding of hardware and software engineering best practices.\n \u2022 Demonstrated analytical and problem-solving skills.\n \u2022 Must meet eligibility requirements for work assignment on specified contract.\n \u2022 Applicants selected will be subject to a government security investigation and must meet eligibility requirements.\n \u2022 Current DoD 8570 IAT II Certification is required. (Sec+.)\n \n \nPREFERRED QUALIFICATIONS:\n \u2022 Ability to identify needed changes to processes and activities and help to implement continuous improvement solutions.\n \u2022 ACAS training completed.\n \u2022 Ability to work successfully as part of a virtual team.\n ## Description u2022 Ensure STIG Checklists are up to date and settings are enforced with minimal operational impact for all systems (workstations, servers, network) within the environment. \n \u2022 Support systems within GMS to have an up to date and complete STIG Checklist; educate systems/network administrators regarding completion/edits as required. \n \u2022 Examine results of STIG testing and pass results to system owners and system administrators.\n \u2022 Track response times to STIG findings and report on the security briefing.\n \u2022 Support POA&M analysis and coordination efforts, as required, including eMASS updates.\n \u2022 Perform cybersecurity lab testing/hardening activities supporting deployment of/updates to computer systems and applications. \n \u2022 Review data from ACAS/ESS scans and set tickets to add new equipment into scans as necessary.\n \u2022 Maintain SOP's for testing and reporting activities. \n \u2022 Support functional testing as necessary for new technology. \n \u2022 Support testing events and preparation for testing events.\n \u2022 Perform vulnerability/risk analyses of computer systems and applications during all phases of the system development life cycle.\n \u2022 Support Authorizing Official (AO) actions by ensuring all testing related security testing artifacts are presented in accordance with RMF as defined in NIST 800-37 revision 2 and related agency specific RMF requirements.\n \u2022 Have experience performing various types of vulnerability and assessment scans with multiple tools.\n \n ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Demystifying application networking in the cloud](https://www.wearedevelopers.com/videos/675-demystifying-application-networking-in-the-cloud) - [None of Us Is As Dumb As All of Us: Community And Knowledge Go Hand In Hand](https://www.wearedevelopers.com/videos/100296-none-of-us-is-as-dumb-as-all-of-us-community-and-knowledge-go-hand-in-hand) - [Securing Your Web Application Pipeline From Intruders](https://www.wearedevelopers.com/videos/53-securing-your-web-application-pipeline-from-intruders) - [Embracing the Hybrid Cloud: Unlocking Success with Ansible](https://www.wearedevelopers.com/videos/932-embracing-the-hybrid-cloud-unlocking-success-with-ansible) - [Quantum Computing - The tiny and the big challenges](https://www.wearedevelopers.com/videos/934-quantum-computing-the-tiny-and-the-big-challenges) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Dev Digest 216: CyberSec + Mythos, Stack Overflow for Agents & DOOM in TTF](https://www.wearedevelopers.com/magazine/728-dev-digest-216-cybersec-mythos-stack-overflow-for-agents-doom-in-ttf) - [The 8 Best Code Testing Tools](https://www.wearedevelopers.com/magazine/402-the-8-best-code-testing-tools) - [Dev Digest 234: How X's Feed Works, Top 10 CI/CD Risks & Meat Proxies](https://www.wearedevelopers.com/magazine/755-dev-digest-234-how-x-s-feed-works-top-10-ci-cd-risks-meat-proxies) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed)