Job Requirements
Salt Lake City, UT
Secret Polygraph not specified
Early Career (2+ yrs experience)
$110,000 - $120,000
Job Description
Essential Functions:
Execute and support RMF lifecycle activities (categorization, control selection, implementation, assessment, authorization, and continuous monitoring)
Develop, maintain, and review RMF documentation (e.g., SSPs, SARs, POA&Ms, Security Plans)
Interpret and apply security controls from NIST SP 800-53, CNSSI 1253, and related guidance
Support implementation and validation of Security Technical Implementation Guides (STIGs) and other configuration baselines
Collaborate with cross-functional engineering teams (systems, software, hardware) to ensure security requirements are properly implemented
Interface with internal stakeholders, Authorizing Officials (AOs), and external assessors to support authorization efforts
Track and report compliance status, risks, and remediation activities to program leadership
Contribute to continuous monitoring strategies and ongoing system compliance
Travel up to 10% as needed
Must have a DoD Secret Clearance
Required Qualifications (one of the following):
Bachelor’s degree in cybersecurity, computer science, information systems, or related field with minimum 4 years of prior relevant experience.
Graduate Degree and a minimum of 2 years of prior related experience.
In lieu of a degree, minimum of 8 years of prior related experience.
Required Certifications:
One DoD 8140 / 8570-compliant certification (e.g., Security+, CISSP, SSCP, GSEC), or ability to obtain within 6 months of hire
Preferred Additional Skills:
Strongly Preferred
Exposure to cryptographic systems, FIPS 140-3, or NSA certification processes
Experience with high-assurance or classified systems
Hands-on experience executing RMF within DoD environments
Familiarity with tools such as eMASS or XACTA
Experience applying NIST SP 800-53 security controls and STIGs
Experience supporting Authority to Operate (ATO) processes
Strong technical writing and documentation skills
Systems & Technical Context
Understanding of networking concepts (TCP/IP, network architecture, boundary defense)
Experience working with embedded systems or communications systems
Familiarity with Agile or DevSecOps environments
Experience working in cross-functional engineering teams
Desirable (Nice-to-Have)
Familiarity with TEMPEST, Anti-Tamper, or related system security disciplines
Experience supporting government customers in a SETA/A&AS role
Additional certifications (CISM, CISA, CEH, GIAC, etc.)
Active TS/SCI clearance or ability to obtain
Execute and support RMF lifecycle activities (categorization, control selection, implementation, assessment, authorization, and continuous monitoring)
Develop, maintain, and review RMF documentation (e.g., SSPs, SARs, POA&Ms, Security Plans)
Interpret and apply security controls from NIST SP 800-53, CNSSI 1253, and related guidance
Support implementation and validation of Security Technical Implementation Guides (STIGs) and other configuration baselines
Collaborate with cross-functional engineering teams (systems, software, hardware) to ensure security requirements are properly implemented
Interface with internal stakeholders, Authorizing Officials (AOs), and external assessors to support authorization efforts
Track and report compliance status, risks, and remediation activities to program leadership
Contribute to continuous monitoring strategies and ongoing system compliance
Travel up to 10% as needed
Must have a DoD Secret Clearance
Required Qualifications (one of the following):
Bachelor’s degree in cybersecurity, computer science, information systems, or related field with minimum 4 years of prior relevant experience.
Graduate Degree and a minimum of 2 years of prior related experience.
In lieu of a degree, minimum of 8 years of prior related experience.
Required Certifications:
One DoD 8140 / 8570-compliant certification (e.g., Security+, CISSP, SSCP, GSEC), or ability to obtain within 6 months of hire
Preferred Additional Skills:
Strongly Preferred
Exposure to cryptographic systems, FIPS 140-3, or NSA certification processes
Experience with high-assurance or classified systems
Hands-on experience executing RMF within DoD environments
Familiarity with tools such as eMASS or XACTA
Experience applying NIST SP 800-53 security controls and STIGs
Experience supporting Authority to Operate (ATO) processes
Strong technical writing and documentation skills
Systems & Technical Context
Understanding of networking concepts (TCP/IP, network architecture, boundary defense)
Experience working with embedded systems or communications systems
Familiarity with Agile or DevSecOps environments
Experience working in cross-functional engineering teams
Desirable (Nice-to-Have)
Familiarity with TEMPEST, Anti-Tamper, or related system security disciplines
Experience supporting government customers in a SETA/A&AS role
Additional certifications (CISM, CISA, CEH, GIAC, etc.)
Active TS/SCI clearance or ability to obtain
group id: encode