Job Requirements
Quantico, VA
Top Secret Polygraph Unspecified
Mid Level Career (5+ yrs experience)
Salary not specified
Join Premium to unlock estimated salaries
Job Description
Description
Empower AI is seeking a STIG / Compliance Engineer to engineer and sustain DISA STIG-compliant security baselines for the endpoint environment of a Department of War agency across Pre-Production, NIPRNet, SIPRNet, and JWICS enclaves. The engineer analyzes STIG and SRG releases for applicability and impact, translates controls into Group Policy Objects, MECM compliance baselines, and image settings, validates compliance with STIG Viewer and SCAP tooling, analyzes deviations to root cause, and documents mitigations and evidence for RMF packages in eMASS. The role produces the monthly STIG Compliance Report inputs for the endpoint environment and partners with the Patch Management Engineer, ISSO, and image team. This is a salaried, FLSA-exempt position in which you will independently analyze situations, determine the appropriate course of action, and exercise discretion and independent judgment on matters of significance to the program and its customers.
THIS IS AN ONSITE ROLE IN QUANTICO, VA (RKB) WITH UP TO 10% OF TRAVEL INVOLVED.
JOB DUTIES:
REQUIREMENTS:
DESIRED SKILLS:
Empower AI is seeking a STIG / Compliance Engineer to engineer and sustain DISA STIG-compliant security baselines for the endpoint environment of a Department of War agency across Pre-Production, NIPRNet, SIPRNet, and JWICS enclaves. The engineer analyzes STIG and SRG releases for applicability and impact, translates controls into Group Policy Objects, MECM compliance baselines, and image settings, validates compliance with STIG Viewer and SCAP tooling, analyzes deviations to root cause, and documents mitigations and evidence for RMF packages in eMASS. The role produces the monthly STIG Compliance Report inputs for the endpoint environment and partners with the Patch Management Engineer, ISSO, and image team. This is a salaried, FLSA-exempt position in which you will independently analyze situations, determine the appropriate course of action, and exercise discretion and independent judgment on matters of significance to the program and its customers.
THIS IS AN ONSITE ROLE IN QUANTICO, VA (RKB) WITH UP TO 10% OF TRAVEL INVOLVED.
JOB DUTIES:
- Analyze new and updated DISA STIG/SRG releases for applicability and operational impact, and engineer the corresponding Group Policy Objects, MECM compliance baselines, and image configurations for Windows endpoints, browsers, Office, and third-party applications.
- Run and analyze SCAP Compliance Checker and STIG Viewer assessments across the endpoint environment, determine root cause of deviations, decide remediation or documented mitigation, and drive changes through pre-production/Digital Twin validation and Change Management.
- Produce endpoint inputs to the monthly STIG Compliance Report, maintain control implementation statements and evidence in eMASS, and coordinate POA&M entries and risk acceptance requests with the ISSO and Risk Management Support Lead.
- Maintain the endpoint security baseline documentation and evaluate the security impact (CM-4) of proposed endpoint configuration changes.
- Analyze weekly ACAS/Nessus vulnerability scan results for all in-scope systems, identify and prioritize critical and high (CAT I/II/III) vulnerabilities, assign remediation to resolver groups, validate fixes, and produce the weekly Vulnerability Scan Analysis Report.
- Assess STIG compliance for endpoints, servers, printers, communications equipment, and platforms using STIG Viewer, SCAP, and endpoint management compliance data; track deviations and remediation; and produce the monthly STIG Compliance Report.
- Maintain and update POA&M items in eMASS for assigned systems, including milestones, mitigations, risk statements, and evidence of closure, in coordination with ISSOs and system administrators.
- Monitor the endpoint environment's security compliance status (patch compliance, baseline compliance, time-to-remediate) and ensure accurate cybersecurity metrics are fed to the Customer Support Metrics Dashboard.
REQUIREMENTS:
- Bachelor's degree and a minimum of 3 years of related experience (an additional 4 years of related experience may be substituted for the degree).
- Must be a U.S. Citizen.
- Must have an Active Top Secret Clearance (favorably adjudicated T5/T5R) to start; this is a Privileged User position.
- Must be willing and able to obtain TS/SCI eligibility after start, if required by mission needs.
- Must be within investigation scope and/or currently enrolled in Continuous Evaluation / Continuous Vetting.
- Must possess and maintain a current DoD 8570/8140 IAT Level II baseline certification (e.g., CompTIA Security+ CE, CySA+, GSEC, SSCP, or CCNA-Security).
- Demonstrated ability to work independently, analyze problems, determine the appropriate course of action, and exercise discretion and independent judgment with limited day-to-day supervision.
- Minimum of 3 years of experience in cybersecurity analysis, vulnerability management, or RMF continuous monitoring for DoD or Federal systems.
- Hands-on experience with ACAS/Nessus, STIG Viewer, and SCAP Compliance Checker, and interpreting scan and compliance results.
- Working knowledge of NIST SP 800-53 controls, RMF (NIST SP 800-37, DoDI 8510.01), DISA STIGs, and DoD vulnerability management requirements (DoDI 8531.01).
- Experience maintaining POA&Ms and control evidence in eMASS.
- Understanding of Windows and Linux operating systems, Active Directory, networking fundamentals, and endpoint management concepts sufficient to assess and advise on remediation.
- Strong analytical, reporting, and communication skills; ability to produce accurate recurring reports on deadline.
DESIRED SKILLS:
- CompTIA CySA+, Security+ CE, GSEC, or CISSP Associate.
- Experience supporting Department of War (DoW), DoD, or Intelligence Community systems across multiple enclaves.
- Experience with endpoint management compliance reporting (MECM/SCCM, Intune), HBSS/ESS, and SIEM/log analysis tools.
- Familiarity with USCYBERCOM/JFHQ-DODIN orders and directives, IAVM compliance tracking, and cyber incident reporting.
- Familiarity with Power BI for compliance dashboards.
- Experience using ServiceNow (incident, request, knowledge, CMDB, Service Catalog, Virtual Agent) or a comparable enterprise ITSM platform.
group id: 10118911SU