IT Cybersecurity Specialist
Summary
Supports security architecture, RMF, continuous monitoring, and ATO activities for a DoD program, focusing on implementing ServiceNow security controls, maintaining SSPs, and ensuring NIST/IL4-IL5 compliance.
Leading with our people, Digital Consultants’ mission is to deliver the highest level of professional solutions while being a trusted partner and advisor to our customers. With a culture of practicality, opportunity, and creativity, we remain dedicated to being honest, trustworthy, respectful, and ethical in everything we do. We are a certified SBA 8(a) small, disadvantaged business that supports multiple IT customers within the Federal, civilian, and private sectors. Digital Consultants also offers our employees growth opportunities, competitive wages, and a full benefits package. Our founding principles, Fairness and Common Sense, make working here more than a job; it’s the Digital family.
Digital Consultants seeks an IT Cybersecurity Specialist to support security architecture, Risk Management Framework (RMF), continuous monitoring, and Authority to Operate (ATO) activities for the DCMA Blue List Program and its ServiceNow environment.
Location: Fort Lee, VA
Duties to include:
- Architect and implement ServiceNow-specific security controls, including Role-Based Access Controls (RBAC), Access Control Lists (ACLs), Data Policies, and Edge Encryption, to align with the DoD Zero Trust Strategy and enforce strict data segregation between IL4 and IL5 environments. Create and maintain a detailed schema and RBAC matrix outlining roles, groups, ACLs, and data segregation rules.
- Adhere to local policy and coordinate with the Government office's IT Program Manager and Authorizing Official (AO) to ensure required cybersecurity protocols are maintained and followed.
- Develop and continuously update a comprehensive System Security Plan (SSP) and all required RMF artifacts, mapping ServiceNow platform configurations to NIST SP 800-53, NIST SP 800-171/172 for CUI protection, and DoD IL4/IL5 controls to achieve and maintain the system's ATO.
- Actively track, manage, and update the Plan of Action and Milestones (POA&M), preferably within ServiceNow GRC/IRM, to document, report, and remediate identified vulnerabilities within Government-provided suspense dates.
- Serve as the primary author and developer of the System Security Plan (SSP) and supporting RMF artifacts in direct coordination with the Government IT Program Manager and Authorizing Official (AO) to achieve and maintain the ATO.
- Perform technical remediation of ServiceNow configuration-level vulnerabilities within the Specialist’s scope of control; document and track vulnerabilities in third-party custom code/modules in the POA&M while the responsible implementation/development vendor executes code remediation.
- Conduct continuous monitoring and provide ongoing Security Assessment Reports (SAR) documenting vulnerability scans, penetration test reviews, and compliance checks prior to code promotion, ensuring the ATO remains valid throughout the system lifecycle.
- Meet applicable qualification and certification requirements outlined strictly in DoDM 8140.03. Personnel performing privileged access, cybersecurity, or information assurance functions shall hold certifications appropriate to assigned roles based on DCWF Work Roles and Proficiency Levels, including applicable Foundational and Residential qualifications.
- Provide documentation of personnel certifications and qualifications upon request by the CO or COR.