Cybersecurity Engineer

2 weeks ago


Greendale, United States ITS Full time

Job Summary:
ITS, LLC. is seeking a Cybersecurity Engineer to join our Colorado Springs team. This is an exciting opportunity to support the United States Space Force (USSF). The Space Systems Command has the collective USSF mission responsibility for the development, deployment, maintenance, and sustainment of space systems providing early missile warning capability; environmental sensing; precision navigation, guidance, and timing; nuclear event detection; space launch capability; national and military satellite communications capabilities; launch range and network systems; advanced systems; and technology development programs. This position will work in close collaboration with the Information Systems Security Manager (ISSM) and Information Systems Owner (ISO) to ensure security posture is met and maintained, develops security policies, procedures, plans, and all other evidence of compliance with various security controls. Creates and maintains RMF documentation to include Enterprise Mission Assurance Support Service (eMASS) and Information Technology Investment Portfolio Suite (ITIPS) database entries with System Security Plans (SSP), Security Assessment Reports (SAR), Plans of Action & Milestones (POA&M), all other artifacts and documentation tied to the NIST processes. You will provide support to maintain a strong cybersecurity posture for the system until its disposal.

Key Responsibilities:

  • Build, maintain, and track the system’s cybersecurity baselines via eMASS or equivalent, IAW cybersecurity policies, guidance, and plans;
  • Review, assess, create, and update enclave documentation in eMASS and any Configuration Management (CM) system for the ISSM review and approval, such as Security Plan, Security Assessment Plan, Category selection checklist, control results, and POA&Ms
  • Identify, collect, review, and maintain RMF-required artifacts IAW cybersecurity policies, guidance, and plans;
  • Ensure accurate system documentation and configuration logs are maintained to reflect current and prior configuration baselines;
  • Provide written evaluations portraying system progress on RMF compliance IAW cybersecurity guidance (one evaluation for each system per quarter);
  • Maintain cybersecurity data for systems registered in the ITIPS IAW FISMA requirements;
  • Conduct and/or report annual FISMA security reviews, contingency test completion dates, and validation of cybersecurity control compliance, IAW cybersecurity guidance, the organizational cybersecurity strategy, and POA&M
  • Conduct annual control validations (ACVs) for all NC3 systems IAW AF Global Strike Command (AFGSC) cybersecurity guidance and for all non-NC3 systems in a similar manner but in accordance with SMC/ECP policies and schedule;
  • Create and maintain mission common control packages and serve as the common control provider for each mission system;
  • Create and maintain Authority-to-Connect (ATC) guest system packages in eMASS for non-USSF systems connected to SMC/ECP systems;
  • Ensure the required Cybersecurity functional activities and actions during the systems’ O&S phase are conducted IAW.
  • Cybersecurity-related laws and regulations such as the National Cybersecurity Protection Act, FISMA, OMB A1-30 mandate, and EO 13636;
  • Improving Critical Infrastructure Cybersecurity and Resilience, including policies, standards, special publications, instructions, and guidance from the DoD, Military, NIST, CNSS, Defense Information Systems Agency (DISA), and Department of the AF (DAF);
  • Participate in the system’s IPTs and sustainment contractor meetings/teleconferences, change control boards (CCBs), and working groups (WGs) to ensure the continued alignment of cybersecurity requirements in the technical baselines, the system security architecture, information flows, design, and the security controls;
  • Evaluate the system’s sources of changes, such as Deficiency Reports (DRs), Problem Reports (PRs), Change Requests/Proposals (CRs/CPs), Request For Change (RFC), and AF Form 1067s; determine the security impacts of proposed or actual changes to the system, environment, threats, and vulnerabilities; and if any, update all needed RMF artifacts to reflect the changes/revisions;
  • Review and provide inputs to modification packages, program/system documents and support agreements updates, and communications and network infrastructure upgrades to ensure proper cybersecurity configuration modification management and planning support are implemented;
  • Review system’s test plans and test results and, if necessary, observe system testing for security control implementation IAW cybersecurity policies, guidance, and plan;
  • Document all findings. Perform security impact analysis on any system change and appropriately prepare letters of assurance, security impact letters, and risk assessment letters to include exceptions, deviations, or waivers to cybersecurity requirements when applicable;
  • Monitor and adhere to the system’s A&A schedule deadlines IAW the Program Office’s Cybersecurity Plan and IPT’s schedule;
  • Review annually and provide recommended updates to program cybersecurity policies and plans IAW cybersecurity guidance;
  • Review and provide advice on RMF-related memorandums of agreements/ memorandums of understanding/ service level agreements/ interconnection service agreements (MOA/MOU/SLA/ISA) for RMF compliance IAW cybersecurity policies, guidance, and plans;
  • Assist with the cybersecurity vulnerability management plan and risk assessment capability;
  • Receive and review ACAS and SCC reports from the sustainment contractor for each system quarterly and characterize risk for each system semi-annually.
  • Experience with XACTA, FISMA, eMASS, and/or TIPS
  • Experience with DoD RMF functions and processes and/or DISA IASE

Education/Experience:

  • 0-2 years of technical experience in the cybersecurity field or a STEM Bachelor’s Degree
  • IAT or IAM Level 2 Certification per DoD 8570.01M

Clearance Requirement:

  • Secret but TS or TS/SCI, preferably

Salary Note:

  • In compliance with Colorado's Equal Pay for Equal Work Act, the salary range for this role is based on education, experience, and responsibilities.

ITS, LLC. is an equal-opportunity employer to include veterans and individuals with disabilities.

U.S. Citizenship is required.

Explore more InfoSec / Cybersecurity career opportunities

Find even more open roles in Ethical Hacking, Pen Testing, Security Engineering, Threat Research, Vulnerability Management, Cryptography, Digital Forensics and Cyber Security in general - ordered by popularity of job title or skills, toolset and products used - below.

#J-18808-Ljbffr

  • Greendale, United States BorgWarner Full time

    BorgWarner We deliver innovative and sustainable mobility solutions for the vehicle market aiming to support a clean, energy-efficient world. View company page DUTIES: BorgWarner PDS (USA), Inc. seeks a Sr Cybersecurity Engineer based out of our office at 3800 Automation Ave, Auburn Hills, MI 48326. Note, this is a hybrid position whereby the employee will...


  • Greendale, United States ITS Full time

    Prin. Cybersecurity System Integr. & Test Eng ITS, LLC is seeking a Principal Cybersecurity System Integration & Test Engineer to join our team in Colorado Springs, CO. The Principal Cyber Test Engineer will participate in a program which includes establishing methods and techniques, planning tests, develop test scripting, writing procedures and reports, and...

  • Scrum Master

    2 weeks ago


    Greendale, United States Cask Technologies Full time

    Scrum Master - Cybersecurity & Operational Services Cask is a leading Management Consulting firm specializing in delivering business and technical expertise to clients across commercial and government markets. Join the many happy employees at Cask! We have been named a top 5 firm to work for by Consulting Magazine for 5 of the past 6 years. We are seeking a...


  • Greendale, United States Federal Reserve System Full time

    Senior Cybersecurity Third Party Risk Analyst Federal Reserve System The Federal Reserve Board of Governors in Washington DC. View company page Company Federal Reserve Bank of AtlantaAs an employee of the Atlanta Fed, you will help support our mission of promoting the stability and efficiency of the U.S. economy and financial system. Your work will affect...


  • Greendale, United States Pacific Gas And Electric Company Full time

    Pacific Gas and Electric Company Pacific Gas and Electric Company (PG&E) provides natural gas and electric service to residential and business customers in northern and central California. View company page Information Systems Technology Services is a unified organization comprised of various departments which collaborate effectively to deliver high...


  • Greendale, United States Resilience Corp. Full time

    Resilience Learn about the Resilience solution for cybersecurity risk management. It's an enterprise-grade risk management solution. View company page About UsResilience is the next-generation cyber risk company that’s on a mission to help make the world cyber resilient. Founded in 2016 by experts from across the highest tiers of the US military and...


  • Greendale, United States Illumio Full time

    Illumio Protect your network and secure your cloud with Illumio, the leading network security company. Stay safe with our advanced cloud security solutions. View company page Onsite work model of 5 days in office per week in Sunnyvale, CA. This is a unique leadership role within Illumio engineering! In this role, the successful candidate will lead...

  • Security Engineer

    1 week ago


    Greendale, United States AnaVation LLC Full time

    Be Challenged and Make a Difference In a world of technology, people make the difference. We believe if we invest in great people, then great things will happen. At AnaVation, we provide unmatched value to our customers and employees through innovative solutions and an engaging culture. Description of Task to be Performed:AnaVation is looking for a Security...


  • Greendale, United States PingWind Inc Full time

    PingWind is seeking a highly skilled Journeyman Cyber Security Specialist to join our dynamic team. Location: Huntsville, ALRequired Clearance: Secret with TS potentialRequired Education: Bachelor’s degree in relevant field within 3 months of hireRequired Experience: Current or Previous Internship with Cyber Experience Responsibilities· Conducting regular...


  • Greendale, United States PingWind Inc Full time

    Description PingWind is seeking a highly skilled and experienced Senior Information Security Analyst to join our team. As a Security Analyst, you will be responsible for protecting our organization’s information systems and data from security threats. You play a key role in implementing and managing security measures, conducting risk assessments, and...


  • Greendale, United States PingWind Inc Full time

    Description: PingWind is seeking a highly skilled and experienced SME Information Security Analyst to join our team. As a Security Analyst, you will be responsible for protecting our organization’s information systems and data from security threats. You play a key role in implementing and managing security measures, conducting risk assessments, and...


  • Greendale, United States CareerBuilder Full time

    Description PingWind is seeking a highly skilled and experienced Senior Cyber Security Analyst to join our dynamic team. Location: Tampa, FLRequired Clearance: TS with SCI eligibilityRequired Education: Bachelors degree in relevant field.Required Experience: Proven eight plus (8+) years of experience in Cybersecurity role with a focus on senior level...


  • Greendale, United States Aviva Full time

    Aviva Our global corporate website for investors, shareholders, career hunters, the media and people interested in our social purpose. View company page #WeAreCrowdStrike and our mission is to stop breaches. As a global leader in cybersecurity, our team changed the game. Since our inception, our market leading cloud -native platform has offered unparalleled...


  • Greendale, United States HARMAN Full time

    HARMAN International HARMAN International is a global leader in connected car technology, lifestyle audio innovations, design and analytics, cloud services and IoT solutions. View company page #WeAreCrowdStrike and our mission is to stop breaches. As a global leader in cybersecurity, our team changed the game. Since our inception, our market leading cloud...


  • Greendale, United States Character Full time

    Security Software Engineer, Privacy (Senior) Character’s mission is to empower everyone with AGI. Our vision is to enable people with our technology so that they can use Character.AI any moment of any day. Character.AI is one of the world’s leading personal AI platforms. Founded in 2021 by AI pioneers Noam Shazeer and Daniel De Freitas, Character.AI is a...


  • Greendale, United States PingWind Inc Full time

    Location: Tampa, FloridaRequired Clearance: TS-SCICertifications: CEH or GSEC or Security+ requiredRequiredEducation: Bachelor’s degree in Information Systems, Computer Science, Computer Engineering, or another related field. Experience can be used in lieu of education requirementRequiredExperience: Eight+ (8+) years’ experience and a bachelor’s degree...


  • Greendale, United States CockroachDB Full time

    Senior Corporate Security Engineer - New York, NY, Austin, TX, Toronto CockroachDB CockroachDB is a distributed database with standard SQL for cloud applications. CockroachDB powers companies like Comcast, Lush, and Bose. View company page Databases are the beating heart of every business in the world. Cockroach Labs is the team behind CockroachDB , an open...

  • GRC Analyst

    2 weeks ago


    Greendale, United States WHOOP Full time

    WHOOP Monitor your sleep, strain, recovery, and health with the most advanced fitness and health wearable available today. WHOOP helps you discover data-driven insights for a healthier, more empowered life. View company page As a GRC Analyst, you will play a crucial role in supporting the development, implementation, and maintenance of our Governance, Risk,...


  • Greendale, United States Equifax Full time

    Equifax Get credit reports and credit scores for businesses and consumers from Equifax today! We also have identity protection tools with daily monitoring and alerts View company page Equifax is where you can power your possible. If you want to achieve your true potential, chart new paths, develop new skills, collaborate with bright minds, and make a...


  • Greendale, United States Birmingham Water Works Full time

    Responsible for constantly detecting and preventing cyber threats to the company computing environment. Identify weaknesses of the company computing infrastructure (software, hardware, networks) and find creative ways to protect it. Plan, implement, upgrade, or monitor security measures to protect computer networks and information. Ensure appropriate...