Job Requirements
Arlington, VA
Secret Polygraph Unspecified
Career Level not specified
Salary not specified
Join Premium to unlock estimated salaries
Job Description
About SHR Consulting Group
SHR Consulting Group, LLC is a small business delivering enterprise IT, cybersecurity, and program management services to the Department of Defense and federal civilian agencies. We support mission-critical infrastructure at the Pentagon and across the National Capital Region, and we invest in our people through competitive compensation, professional certification support, and long-term career growth on stable, multi-year programs.
Position Summary
We are a rapidly growing organization seeking experienced Cybersecurity Analysts to support cyber compliance, technical security assessments, vulnerability management, cyber hardening, and Risk Management Framework (RMF) activities for a large enterprise Department of Defense environment. Multiple openings are available at Senior and Intermediate levels.
The successful candidate will analyze enterprise security-tool results, validate technical findings, drive remediation, maintain RMF evidence in eMASS, support cyber-readiness activities, and brief technical and Government leadership on risk and compliance status. eMASS is a government-owned application that supports integrated cybersecurity management, dashboard reporting, control-scorecard measurement, and authorization-package development.
Key Responsibilities
Minimum Qualifications
Education
Certification Requirements
Security Clearance
Work Environment
Benefits
SHR Consulting Group, LLC is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability, or protected veteran status.
SHR Consulting Group, LLC is a small business delivering enterprise IT, cybersecurity, and program management services to the Department of Defense and federal civilian agencies. We support mission-critical infrastructure at the Pentagon and across the National Capital Region, and we invest in our people through competitive compensation, professional certification support, and long-term career growth on stable, multi-year programs.
Position Summary
We are a rapidly growing organization seeking experienced Cybersecurity Analysts to support cyber compliance, technical security assessments, vulnerability management, cyber hardening, and Risk Management Framework (RMF) activities for a large enterprise Department of Defense environment. Multiple openings are available at Senior and Intermediate levels.
The successful candidate will analyze enterprise security-tool results, validate technical findings, drive remediation, maintain RMF evidence in eMASS, support cyber-readiness activities, and brief technical and Government leadership on risk and compliance status. eMASS is a government-owned application that supports integrated cybersecurity management, dashboard reporting, control-scorecard measurement, and authorization-package development.
Key Responsibilities
- Perform technical cybersecurity assessments of enterprise Windows, Red Hat Linux, workstation, server, application, network, and supporting infrastructure environments.
- Analyze and validate findings from ACAS, HBSS/ESS, Trellix, Axonius, Evaluate-STIG, Splunk, Tanium, SCAP, STIG Viewer, and other approved Enterprise Security Services (ESS) tools.
- Assess systems against DISA STIGs, IAVM notices, DoD cyber tasking, and approved security baselines; identify vulnerabilities, configuration deviations, missing patches, security-tool coverage gaps, and asset discrepancies.
- Coordinate with system administrators, engineers, system owners, and platform teams to implement and validate patches, Group Policy changes, certificate updates, endpoint-security changes, and secure-configuration remediations.
- Drive assigned systems toward compliance with DISA STIGs, IAVMs, applicable DoD orders, and organizational remediation timelines.
- Develop, maintain, and track Plans of Action and Milestones (POA&Ms) for unresolved vulnerabilities and compliance deviations, including technical details, risk impact, mitigation actions, responsible parties, milestones, and planned completion dates.
- Support RMF activities in accordance with DoDI 8510.01 and NIST guidance, including eMASS updates, control implementation statements, evidence collection, security-control validation, assessment artifacts, risk records, and authorization-package support.
- Validate security controls against NIST SP 800-53 requirements and document results in eMASS, SharePoint, or other approved repositories.
- Support CCORI, CORA, CSSP, and Cyber Hardening Mission activities through pre-assessment validation, checklist management, evidence preparation, corrective-action tracking, remediation coordination, and closure verification.
- Monitor approved DoD, DISA, JSP, and organizational channels for IAVMs, cyber orders, security directives, and other tasking; disseminate actions to responsible teams and track execution through closure.
- Provide DTO support by reviewing, analyzing, coordinating, tracking, and validating closure of DISA Task Orders, including required security configuration changes, firewall-rule updates, ports/protocols/services changes, vulnerability mitigations, technical documentation, validation testing, and completion evidence in accordance with established DoD, DISA, JSP, and program procedures.
- Maintain and validate required security-tool coverage across managed assets, ensuring ESS/HBSS, ACAS, Splunk, Tanium, and other required tools are installed, properly configured, communicating with management consoles, and tracked to resolution when reporting issues occur.
- Support patch and hot-fix deployment across multiple operating-system platforms using MECM, Group Policy, PowerShell, Tanium, Red Hat Satellite Server, YUM, or equivalent enterprise-management tools.
- Develop cyber-compliance metrics, remediation trackers, dashboards, and executive-ready reports for monthly program reviews and leadership briefings.
- Apply advanced Microsoft Excel skills-including formulas, pivot tables, XLOOKUP/VLOOKUP, conditional logic, data reconciliation, charts, and trend analysis-to evaluate vulnerability trends, compliance posture, risk scores, overdue actions, and remediation performance.
- Brief technical teams, program management, and Government leadership on technical findings, enterprise risk, compliance trends, remediation status, and decisions required.
- Support Systems Security Reviews, independent control testing, audit preparation, inspection response, and continuous-monitoring activities.
Minimum Qualifications
- Demonstrated ability and experience in daily operations and maintenance of large, complex IT projects and IT staff similar in size and scope to this order
- Three (3) or more years of experience securing operating systems against DISA STIGs and configuring/maintaining host firewalls; experience hardening Windows Server and Red Hat Linux platforms required.
- Working knowledge of the DoD IAVM program, the DISA Vulnerability Management System (VMS), and the Continuous Monitoring Risk Scoring (CMRS) system.
- Knowledge of DoD vulnerability scanning standards and tools, defense-in-depth concepts, and incident response, auditing, and CNDSP practices.
- Hands-on experience with cyber tools, including HBSS/ESS, ACAS (Tenable), Splunk, and Tanium.
- Experience supporting RMF (NIST SP 800-37), NIST SP 800-53R control documentation and validation, and accreditation programs such as FISMA, OMB, DoD IG inspections, and ACA.
- Experience deploying patches and hot fixes against required deadlines using MECM, Group Policy, PowerShell, Red Hat Satellite/YUM, or Tanium.
- For the Senior variant: 5+ years of experience and ACAS administrator certification/experience are strongly preferred.
- Strong analytical, written, and verbal communication skills with the ability to brief technical risk to Government leadership.
Education
- Bachelor's degree in Computer Engineering, Computer Information Systems, Telecommunications, Management Information Systems, Cybersecurity, or a related field; or equivalent combination of education and three (3)+ recent years of documented relevant experience.
Certification Requirements
- Must meet DoD 8570.01-M / DoD 8140 IAT Level II baseline certification requirements prior to start (e.g., Security+ CE, CCNA-Security, CySA+, GICSP, GSEC, or equivalent). Computing Environment certification appropriate to the role is also required.
Security Clearance
- Active Secret clearance required at minimum. U.S. citizenship required.
Work Environment
- 100% onsite at a government facility within the National Capital Region (NCR), primarily at the Pentagon, Crystal Gateway, Taylor Building, Mark Center, or other JSP-designated alternate site. Must be local to the DC Metro Area with reliable transportation.
Benefits
- Competitive salary commensurate with experience and clearance level
- Comprehensive medical, dental, and vision coverage
- 401(k) with company contribution
- Paid time off and eleven federal holidays
- Certification reimbursement and training support (DoD 8140 baseline and computing environment certifications)
- Life and disability insurance
SHR Consulting Group, LLC is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability, or protected veteran status.
group id: 10409777