IT Cybersecurity Specialist

Digital Consultants, LLC

Richmond (VA)

On-site

USD 120,000 - 190,000

Full time

8 days ago

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

PTO
Group health plans
Income protection and supplemental
401(k) plan with company matching
Health Savings Account (HSA)
Flexible Spending Account (FSA)
Pet insurance options
Employee Assistance Program (EAP)

Job summary

Digital Consultants, LLC seeks a Security Architect to design and implement ServiceNow security controls for DoD IL4/IL5 environments in Fort Lee, VA. You will develop SSPs, RMF artifacts, and ensure continuous monitoring to maintain ATO.

Required qualifications include DoDM 8140.03 DCWF alignment, NIST RMF experience, and DoD CAC eligibility. A Bachelor's in cybersecurity or related field is required, with strong governance and compliance skills.

Qualifications

  • Active qualification aligned with DoDM 8140.03 DCWF for Security Architecture (Foundational/Residential).
  • Experience applying NIST SP 800-53/171/172 and RMF to achieve ATO.
  • U.S. citizenship and DoD CAC access requirements.
  • Bachelor's degree in cybersecurity or related field.

Responsibilities

  • Architect and implement ServiceNow security controls for IL4/IL5 environments.
  • Develop and maintain SSP and RMF artifacts mapping to NIST 800-53/171/172.
  • Monitor POA&M and coordinate with Government PM and AO to meet suspense dates.
  • Lead authoring of SSP and RMF artifacts with government input.
  • Remediate ServiceNow vulnerabilities within scope and track in POA&M.

Skills

Security Architecture
RMF / NIST controls
ServiceNow GRC/IRM
FedRAMP High / IL4/IL5

Education

Bachelor's degree in cybersecurity / related field

Tools

ServiceNow

Job description

Leading with our people, Digital Consultants’ mission is to deliver the highest level of professional solutions while being a trusted partner and advisor to our customers. With a culture of practicality, opportunity, and creativity, we remain dedicated to being honest, trustworthy, respectful, and ethical in everything we do. We are a certified SBA 8(a) small, disadvantaged business that supports multiple IT customers within the Federal, civilian, and private sectors. Digital Consultants also offers our employees growth opportunities, competitive wages, and a full benefits package. Our founding principles, Fairness and Common Sense, make working here more than a job; it’s the Digital family.

Location: Fort Lee, VA

Duties to include:
  • Architect and implement ServiceNow-specific security controls, including Role-Based Access Controls (RBAC), Access Control Lists (ACLs), Data Policies, and Edge Encryption, to align with the DoD Zero Trust Strategy and enforce strict data segregation between IL4 and IL5 environments. Create and maintain a detailed schema and RBAC matrix outlining roles, groups, ACLs, and data segregation rules.
  • Adhere to local policy and coordinate with the Government office's IT Program Manager and Authorizing Official (AO) to ensure required cybersecurity protocols are maintained and followed.
  • Develop and continuously update a comprehensive System Security Plan (SSP) and all required RMF artifacts, mapping ServiceNow platform configurations to NIST SP 800-53, NIST SP 800-171/172 for CUI protection, and DoD IL4/IL5 controls to achieve and maintain the system's ATO.
  • Actively track, manage, and update the Plan of Action and Milestones (POA&M), preferably within ServiceNow GRC/IRM, to document, report, and remediate identified vulnerabilities within Government-provided suspense dates.
  • Serve as the primary author and developer of the System Security Plan (SSP) and supporting RMF artifacts in direct coordination with the Government IT Program Manager and Authorizing Official (AO) to achieve and maintain the ATO.
  • Perform technical remediation of ServiceNow configuration-level vulnerabilities within the Specialist’s scope of control; document and track vulnerabilities in third-party custom code/modules in the POA&M while the responsible implementation/development vendor executes code remediation.
  • Conduct continuous monitoring and provide ongoing Security Assessment Reports (SAR) documenting vulnerability scans, penetration test reviews, and compliance checks prior to code promotion, ensuring the ATO remains valid throughout the system lifecycle.
  • Meet applicable qualification and certification requirements outlined strictly in DoDM 8140.03. Personnel performing privileged access, cybersecurity, or information assurance functions shall hold certifications appropriate to assigned roles based on DCWF Work Roles and Proficiency Levels, including applicable Foundational and Residential qualifications.
  • Provide documentation of personnel certifications and qualifications upon request by the CO or COR.
Requirements
  • Active qualification aligning with DoDM 8140.03 DCWF Work Roles and Proficiency Levels (Foundational and Residential) appropriate for Security Architecture and Engineering (e.g., Security Architect - DCWF 651).
  • Demonstrated expertise applying federal security directives, including NIST SP 800-53 controls, NIST SP 800-161 (SCRM), and navigating the DoW Risk Management Framework (RMF) to achieve an Authority to Operate (ATO).
  • Demonstrated experience securing ServiceNow instances in a FedRAMP High and DoD IL4/IL5 environment, including configuring ServiceNow ACLs, Client Scripts, Data Policies, and integrating DoW Enterprise Identity, Credential, and Access Management (E-ICAM)/CAC authentication.
  • Experience utilizing ServiceNow Governance, Risk, and Compliance (GRC) / Integrated Risk Management (IRM) or Security Operations (SecOps) modules is highly preferred.
  • Clearance: U.S. citizenship required. Personnel shall meet the Tier Three (T3) investigation equivalent (ADP/IT-II) requirement for access to CUI. A completed/current investigation or an investigation in progress is acceptable before commencing work. During onboarding, an individual with an initiated Tier 3 investigation may be granted interim authorization to work, barring unforeseen issues. This also applies to post-award replacement hires. Personnel must obtain a DoW-issued CAC for access to Government spaces and IT systems.
  • Certifications: Active qualification aligning with DoDM 8140.03 DCWF Work Roles and Proficiency Levels (Foundational and Residential) appropriate for Security Architecture and Engineering (e.g., Security Architect - DCWF 651) required.
  • Education: Bachelor's degree in Cybersecurity, Computer Science, Computer Engineering, or a related technical discipline required.
  • Experience: Minimum of five (5) years of practical experience required.
  • Preferred Qualifications: Experience utilizing ServiceNow GRC/IRM or Security Operations (SecOps) modules.
Physical Requirements:

The candidate must be able to travel to other worksites as required and with or without reasonable accommodation, be able to sit, stand, use computers and monitors, and perform duties in an office environment for extended periods. The candidate must be able to lift up to 40 lbs. on occasion (e.g., moving a case of paper or similar task) that may occur occasionally.

Compensation and Benefits:

The company offers the following benefits to permanent, full-time employees:

  • Paid Time Off (PTO)
  • Group health plans
  • Income protection and supplemental benefits
  • 401(k) plan with company matching
  • Health Savings Account (HSA)
  • Flexible Spending Account (FSA)
  • Pet insurance options
  • Employee Assistance Program (EAP)

Digital Consultants, an inclusive and welcoming company, is fully committed to hiring and retaining a diverse workforce without regard to race, color, religion, sex (including pregnancy, gender identity, and sexual orientation), genetic information, national origin, age (40 or older), disability, veteran status or any other protected characteristic.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

IT Cybersecurity Specialist
IT Cybersecurity Specialist

Socket.dev • San Diego (CA)

On-site
USD 110,000 - 180,000
PTO
Health plans
401(k) plan
IT Cybersecurity Specialist
IT Cybersecurity Specialist

Socket.dev • Richmond (VA)

On-site
USD 120,000 - 160,000
PTO
Health plans
401(k) plan with matching
+1
IT Cybersecurity Specialist
IT Cybersecurity Specialist

Digital Consultants, LLC • San Diego (CA)

On-site
USD 120,000 - 160,000
PTO
Health plans
401(k) plan with company matching
+4
IT Cybersecurity Specialist - Contingent
IT Cybersecurity Specialist - Contingent

Contracting Resources Group • Fort Lee (VA)

On-site
USD 110,000 - 150,000
401(k) and Roth retirement plans
Medical, Dental, and Vision Insurance
Supplemental Insurance
+2
IT Cybersecurity Specialist - Contingent
IT Cybersecurity Specialist - Contingent

Contracting Resources Group, Inc. • Fort Lee (NJ)

Hybrid
USD 120,000 - 170,000
401(k)
Roth retirement plan
Medical, Dental, Vision Insurance
+1
IT Cybersecurity Specialist - Contingent
IT Cybersecurity Specialist - Contingent

Contracting Resources Group • San Diego (CA)

On-site
USD 150,000 - 190,000
401(k) plan
Roth retirement
Medical, Dental & Vision insurance
+3
IT Cybersecurity Specialist - Contingent
IT Cybersecurity Specialist - Contingent

Contracting Resources Group, Inc. • San Diego (CA)

Hybrid
USD 120,000 - 180,000
401(k) plan
Medical Insurance
Dental Insurance
+1
IT Project Manager
IT Project Manager

Digital Consultants, LLC • Richmond (VA)

On-site
USD 150,000 - 185,000
PTO
Group health plans
401(k) with company match
+4
IT Project Manager
IT Project Manager

Socket.dev • Richmond (VA)

On-site
USD 120,000 - 170,000
PTO
Health plans
401(k) with company match
+1
ServiceNow Workflow Manager
ServiceNow Workflow Manager

Digital Consultants LLC • Hampton (VA)

On-site
USD 100,000 - 130,000
Paid Time Off (PTO)
Group health plans
401(k) plan with company matching
+1