IT Cybersecurity Specialist - Contingent

Contracting Resources Group

San Diego (CA)

On-site

USD 150,000 - 190,000

Full time

6 days ago
Be an early applicant

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

401(k) plan
Roth retirement
Medical, Dental & Vision insurance
Supplemental Insurance
11 Federal Holidays
PTO

Job summary

Contracting Resources Group seeks two IT Cybersecurity Specialists to architect and implement ServiceNow security controls for the DCMA Blue List contract, including RBAC, ACLs, Data Policies, and Edge Encryption, ensuring IL4/IL5 data segregation.

The role owns platform security engineering and the Authority to Operate (ATO), developing SSP and RMF artifacts and enforcing data segregation between IL4 and IL5 environments while aligning to FedRAMP High and DoD IL4/IL5 requirements.

Qualifications

  • Bachelor's degree in Cybersecurity, Computer Science, or related field.
  • Minimum of five (5) years of practical experience.
  • Active qualification aligning with DoDM 8140.03 DCWF for Security Architecture/Engineering.
  • Experience securing ServiceNow in FedRAMP High/DoD IL4/IL5 environments, including ACLs, Client Scripts and Data Policies.
  • U.S. citizen with favorable Tier 3 investigation on file in DISS at time of offer.

Responsibilities

  • Architect and implement ServiceNow security controls to align with the DoD Zero Trust Strategy and enforce data segregation between IL4 and IL5 environments.
  • Create and maintain an RBAC matrix detailing roles, groups, ACLs, and data segregation rules.
  • Develop and maintain the System Security Plan (SSP) and RMF artifacts mapping ServiceNow configurations to NIST and DoD controls.

Skills

RBAC
ACLs
Data Policies
Edge Encryption
RMF
NIST SP 800-53

Education

Bachelor's degree in Cybersecurity / related field

Tools

ServiceNow
GRC/IRM

Job description

Description: CRG is seeking two IT Cybersecurity Specialists to architect and implement ServiceNow-specific security controls for the DCMA Blue List Program Support Services contract, including Role-Based Access Controls (RBAC), Access Control Lists (ACLs), Data Policies, and Edge Encryption, aligned to the DoD Zero Trust Strategy.

This role owns platform security engineering and the system's Authority to Operate (ATO), developing and maintaining the System Security Plan (SSP) and RMF artifacts, and enforcing strict data segregation between IL4 (Public) and IL5 (CAC-Authenticated) environments.

The ideal candidate will have direct experience securing a ServiceNow instance in a FedRAMP High / DoD IL4-IL5 environment and be comfortable owning POA&M remediation against Government suspense dates.

Responsibilities:
Platform Security Architecture
  • Architect and implement ServiceNow-specific security controls — including RBAC, ACLs, Data Policies, and Edge Encryption — to align with the DoD Zero Trust Strategy and enforce strict data segregation between IL4 (Public) and IL5 (CAC-Authenticated) environments
  • Create and maintain a detailed schema and RBAC matrix outlining all roles, groups, ACLs, and data segregation rules
  • Adhere to local policy and coordinate with the Government office's IT Program Manager and Authorizing Official (AO) to ensure required cybersecurity protocols are maintained and followed
RMF & ATO Management
  • Develop and continuously update a comprehensive System Security Plan (SSP) and all required RMF artifacts, mapping ServiceNow platform configurations to NIST SP 800-53, NIST SP 800-171/172 (CUI protection), and DoD IL4/IL5 controls to achieve and maintain the system's Authority to Operate (ATO)
  • Actively track, manage, and update the Plan of Action and Milestones (POA&M), preferably within ServiceNow GRC/IRM, to document, report, and remediate identified vulnerabilities within Government-provided suspense dates
Continuous Monitoring & Compliance
  • Conduct continuous monitoring and provide ongoing Security Assessment Reports (SAR) documenting vulnerability scans, penetration test reviews, and compliance checks prior to code promotion, ensuring the ATO remains valid throughout the system's lifecycle
  • Ensure all personnel performing tasks under the PWS meet applicable qualification and certification requirements per DoDM 8140.03, and provide documentation of personnel certifications and qualifications upon request by the CO or COR
Required Qualifications:
  • Bachelor's degree required in Cybersecurity, Computer Science, Computer Engineering, or a related technical discipline
  • Minimum of five (5) years of practical experience
  • Active qualification aligning with DoDM 8140.03 DCWF Work Roles and Proficiency Levels (Foundational and Residential) appropriate for Security Architecture and Engineering (e.g., Security Architect - DCWF 651)
  • Demonstrated expertise applying federal security directives, including NIST SP 800-53 controls, NIST SP 800-161 (SCRM), and navigating the DoW Risk Management Framework (RMF) to achieve an Authority to Operate (ATO)
  • Demonstrated experience securing ServiceNow instances in a FedRAMP High and DoD IL4/IL5 environment, including configuring ServiceNow ACLs, Client Scripts, Data Policies, and integrating DoW Enterprise Identity, Credential, and Access Management (E-ICAM)/CAC authentication
  • Must be a U.S. citizen with a favorably adjudicated Tier 3 (ADP/IT-II) investigation on file in DISS at the time of offer
Desired Qualifications:
  • Experience utilizing ServiceNow Governance, Risk, and Compliance (GRC) / Integrated Risk Management (IRM) or Security Operations (SecOps) modules
Benefits

Full-time employees are eligible for 401(k) and Roth retirement plans, Medical, Dental, and Vision Insurance (for employees and families), Supplemental Insurance, 11 Federal Holidays, and at least three weeks of Paid Time Off (PTO), including sick and personal leave.

CRG is an equal opportunity employer. We make employment decisions based on merit, qualifications, and business need. All qualified applicants receive consideration for employment without regard to race, color, religion, sex, national origin, age, disability, status as a protected veteran, or any other state or federally protected category.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

IT Cybersecurity Specialist - Contingent
IT Cybersecurity Specialist - Contingent

Contracting Resources Group, Inc. • San Diego (CA)

Hybrid
USD 120,000 - 180,000
401(k) plan
Medical Insurance
Dental Insurance
+1
IT Cybersecurity Specialist - Contingent
IT Cybersecurity Specialist - Contingent

Contracting Resources Group, Inc. • Fort Lee (NJ)

Hybrid
USD 120,000 - 170,000
401(k)
Roth retirement plan
Medical, Dental, Vision Insurance
+1
IT Cybersecurity Specialist - Defense Contract Management Agency (DCMA)
IT Cybersecurity Specialist - Defense Contract Management Agency (DCMA)

The Leading Niche • San Diego (CA)

Hybrid
USD 130,000 - 180,000
IT Cybersecurity Specialist - Defense Contract Management Agency (DCMA)
IT Cybersecurity Specialist - Defense Contract Management Agency (DCMA)

Socket.dev • San Diego (CA)

On-site
USD 120,000 - 160,000
IT Cybersecurity Specialist / CS Specialist
IT Cybersecurity Specialist / CS Specialist

OWT Global LLC • San Diego (CA)

On-site
USD 110,000 - 160,000
Competitive compensation
Benefits starting day one
401(k) with company match
+2
IT Project Manager (IT PM) - Contingent
IT Project Manager (IT PM) - Contingent

Contracting Resources Group, Inc. • San Diego (CA)

Hybrid
USD 120,000 - 160,000
401(k) and Roth retirement plans
Medical, Dental, and Vision Insurance
Supplemental Insurance
+2
IT Project Manager (IT PM) - Contingent
IT Project Manager (IT PM) - Contingent

Contracting Resources Group, Inc. • Fort Lee (NJ)

Hybrid
USD 110,000 - 150,000
401(k) and Roth plans
Medical, Dental, Vision Insurance
Supplemental Insurance
+2
Cybersecurity Analyst - Contingent
Cybersecurity Analyst - Contingent

Contracting Resources Group • San Diego (CA)

On-site
USD 110,000 - 150,000
401(k) and Roth retirement plans
Medical, Dental, and Vision Insurance
Supplemental Insurance
+2
Cybersecurity Analyst - Contingent
Cybersecurity Analyst - Contingent

Contracting Resources Group, Inc. • Fort Lee (NJ)

Hybrid
USD 90,000 - 130,000
401(k) + Roth
Medical, Dental, and Vision Insurance
Supplemental Insurance
+2
IT Cybersecurity Specialist / CS Specialist
IT Cybersecurity Specialist / CS Specialist

OWT Global, LLC • San Diego (CA), Northern (KY)

Hybrid
USD 100,000 - 150,000
Competitive compensation
401(k) match
PTO & holidays
+5