Cybersecurity Specialist - Mid/Senior - SBG

DOCUMENT STORAGE SYSTEMS INC

Alexandria (VA)

On-site

USD 130,000 - 170,000

Full time

14 days+
Application generator

A complete application in a minute — tailored resume and cover letter, ready to send.

Get past ATS filters

Job summary

SBG Technology Solutions, Inc. seeks a Cybersecurity Specialist to ensure FedRAMP High compliance for the DSS Health Cloud onboarding in an AWS GovCloud enclave. You will identify security gaps, support ATO documentation, and align with NIST frameworks throughout the process.

Responsibilities include assessing security posture, collaborating with cloud architects and ISV teams, and guiding remediation actions to maintain continuous monitoring and secure configurations.

Qualifications

  • In-depth knowledge of FedRAMP High security controls and the NIST RMF process.
  • Proficiency in security architecture review and cloud security engineering within AWS or comparable government cloud environments.
  • Experience conducting vulnerability management assessments and evaluating continuous monitoring programs.
  • Working knowledge of IAM, encryption standards, and access control frameworks.
  • Ability to develop and review authorization documentation including SSPs, POA&Ms, and security assessment reports.
  • Strong analytical and written communication skills; able to document and present security findings clearly to both technical and non-technical audiences.
  • Capable of managing concurrent assessment workstreams and delivering findings within defined project timelines.

Responsibilities

  • Assesses security posture against FedRAMP High baseline requirements.
  • Supports Authority to Operate (ATO) documentation and compliance readiness for onboarding.
  • Identifies cybersecurity gaps and recommends remediation actions with rationale.
  • Evaluates alignment with Zero Trust and continuous monitoring requirements.
  • Supports development of SSPs, POA&Ms, and related security artifacts.
  • Applies RMF processes to security assessment activities and documents findings per NIST guidelines.
  • Reviews identity, access control, and encryption implementations for standards compliance.
  • Conducts vulnerability management reviews and evaluates continuous monitoring.
  • Collaborates with cloud architects, program managers, and ISV teams to communicate findings and guide remediation.

Skills

FedRAMP High controls
NIST RMF process
security architecture review
cloud security engineering
vulnerability management
identity and access management
encryption standards
access control frameworks
SSP/POA&M documentation
analytical/written communication
manage concurrent workstreams

Education

Bachelor's degree in Cybersecurity/IT/CS
Education + experience equivalent (2y->1y)
Master's degree in Cybersecurity/IA

Tools

AWS Security Hub
GuardDuty
CloudTrail
Config

Job description

Job Details

Level: Experienced

Job Location: SBG Corporate Office - Alexandria, VA 22314

Position Type: Full Time

Education Level: 4 Year Degree

Salary Range: $130,000.00 - $170,000.00

Travel Percentage: Up to 25%

Job Shift: Day

Job Category: Cybersecurity

SBG Technology Solutions, Inc. (SBG), a DSS, Inc. company, offers IT Governance, Systems Engineering, Enterprise Modernization, Artificial Intelligence, and Cyber Security innovation to federal and commercial clients nationwide.

Overview

The Cybersecurity Specialist ensures all applications meet FedRAMP High security and compliance requirements throughout the assessment and onboarding process for DSS Health Cloud, a FedRAMP High authorized healthcare-focused platform hosted in an AWS Government enclave environment. This role supports Independent Software Vendors (ISVs) and government applications by identifying security gaps, supporting authorization documentation, and validating alignment with applicable federal cybersecurity frameworks.

The Cybersecurity Specialist will:
  • Assesses application security posture, including logging, auditing, and control implementation, against FedRAMP High baseline requirements
  • Supports Authority to Operate (ATO) documentation efforts and compliance readiness activities for applications undergoing onboarding assessment
  • Identifies cybersecurity gaps across assessed applications and recommends prioritized remediation actions with supporting rationale
  • Evaluates application and environment alignment with Zero Trust architecture principles and continuous monitoring requirements
  • Supports development of System Security Plans (SSPs), Plan of Action and Milestones (POA&M) inputs, and related security authorization artifacts
  • Applies Risk Management Framework (RMF) processes to security assessment activities and documents findings in accordance with NIST guidelines
  • Reviews identity, access control, and encryption implementations to verify compliance with applicable standards and FedRAMP controls
  • Conducts vulnerability management reviews and evaluates continuous monitoring capabilities for onboarding candidates
  • Collaborates with cloud architects, program managers, and ISV technical teams to communicate security findings and guide remediation planning
Other Duties:
  • Performs other duties as assigned by management in support of SBG Technology Solutions contract objectives

Travel requirements: occasional travel as required by project needs (estimated up to 10% per year)

Conditions of Employment:
  • Must be a US Citizen
  • Must be able to pass a Federal background check
  • Must be determined suitable for federal employment
Security and Privacy Duties and Responsibilities

Individuals working for SBG Technology Solutions, Inc, a DSS, Inc. will be subject to security and privacy requirements as explained in HIPAA, FedRAMP, and NIST 800-53. Additionally, they are required to undergo specific FedRAMP training to ensure compliance with all associated controls and responsibilities in the day-to-day performance of their duties. Individuals working in departments that are considered to be in the high-risk category will be required to undergo advanced training based on their role and level of access. Individuals with access to modify data and the configuration baseline will require further training.

The preceding functions are examples of the work performed by employees assigned to this job classification. Management reserves the right to add, modify, change or rescind work assignments and make a reasonable accommodation as needed.

QualificationsRequired Skills:
  • In-depth knowledge of FedRAMP High security controls and the NIST Risk Management Framework (RMF) process
  • Proficiency in security architecture review and cloud security engineering within AWS or comparable government cloud environments
  • Experience conducting vulnerability management assessments and evaluating continuous monitoring programs
  • Working knowledge of identity and access management (IAM), encryption standards, and access control frameworks
  • Ability to develop and review authorization documentation including SSPs, POA&Ms, and security assessment reports
  • Strong analytical and written communication skills; able to document and present security findings clearly to both technical and non-technical audiences
  • Capable of managing concurrent assessment workstreams and delivering findings within defined project timelines
Preferred Skills:
  • Familiarity with HIPAA Security Rule requirements and healthcare application security considerations
  • Experience with AWS security tooling (e.g., AWS Security Hub, GuardDuty, CloudTrail, Config)
  • Knowledge of DevSecOps practices and secure software development lifecycle (SSDLC) methodologies
Education:
Required
  • Bachelor's degree in Cybersecurity, Information Technology, Computer Science, or a related technical discipline
  • A combination of education and experience will be considered (2 years of relevant experience equivalent to 1 year in a degree program)
Desired
  • Master's degree in Cybersecurity, Information Assurance, or a related field
Certification(s), Licenses:
  • Certified Information Systems Security Professional (CISSP)
  • Certified Information Security Manager (CISM)
  • CompTIA Security+ or equivalent federal baseline certification
  • AWS Certified Security – Specialty
Years of experience in a similar role:
Required
  • 8+ years of cybersecurity experience in federal or regulated environments, with demonstrated engagement in FedRAMP or RMF processes
Desired
  • 10+ years of cybersecurity experience including direct responsibility for ATO support or FedRAMP authorization activities
Physical Demands:
  • Standing 5% per day
  • Sitting 90% per day
  • Walking 5% per day
  • Stooping Minimal
  • Lifting Up to 10 lbs. unassisted, several times a day (laptop, office equipment, office supplies, etc.)
  • Computer Work 85% per day
  • Telephone Work 15% per day
  • Reading 20% per day
  • Other, please specify
  • Travel unassisted up to ___% per year, via common carrier and/or personal automobile.

SBGTS, Inc. is an Equal Opportunity Employer

If you need an accommodation seeking employment with SBGTS, Inc., please e-mail jobs@dssinc.com or call (561) 284-7333. Accommodations are made on a case-by-case basis.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Cybersecurity Specialist - Mid/Senior - SBG
Cybersecurity Specialist - Mid/Senior - SBG

Document Storage Systems • Alexandria (VA)

On-site
USD 130,000 - 170,000
Cybersecurity Specialist - Mid/Senior - SBG
Cybersecurity Specialist - Mid/Senior - SBG

SBG Technology Solutions, Inc. • Alexandria (VA), Northern (KY)

Hybrid
USD 130,000 - 170,000
Cybersecurity Specialist - Mid/Senior - SBG
Cybersecurity Specialist - Mid/Senior - SBG

SBG Technology Solutions • Alexandria (VA)

On-site
USD 110,000 - 160,000
Cloud Architect - Mid/Senior -SBG REMOTE
Cloud Architect - Mid/Senior -SBG REMOTE

SBG Technology Solutions, Inc. • Alexandria (VA), Northern (KY)

Hybrid
USD 130,000 - 170,000
Solutions Architect - SBG
Solutions Architect - SBG

Document Storage Systems • Alexandria (VA)

On-site
USD 140,000 - 160,000
Information System Security Manager (ISSM) – TS/SCI
Information System Security Manager (ISSM) – TS/SCI

Strategic Business Systems, Inc (SBS) • Arlington (VA)

On-site
USD 160,000 - 220,000
Market-competitive salary
Telework options when permitted
Paid time off
Information System Security Manager (ISSM) – TS/SCI
Information System Security Manager (ISSM) – TS/SCI

Strategic Business Systems (SBS) • Arlington (VA)

On-site
USD 160,000 - 220,000
Medical benefits
401(k) plan with match
Paid time off
Senior Security Analyst – ATO / RMF (Active TS/SCI Clearance)
Senior Security Analyst – ATO / RMF (Active TS/SCI Clearance)

Strategic Business Systems • Chantilly (VA)

On-site
USD 140,000 - 195,000
Telework and flexible schedule where
401(k) retirement plan with company 4%
Paid Time Off and holidays
+1
Cybersecurity Analyst, RMF & ATO
Cybersecurity Analyst, RMF & ATO

JBS International • Virginia Beach (VA)

Hybrid
USD 90,000 - 140,000
Cybersecurity Analyst, RMF & ATO
Cybersecurity Analyst, RMF & ATO

JBS International • Hayward Park (CA)

Hybrid
USD 120,000 - 150,000