IT Cybersecurity Specialist
OSI VISION LLC Fort Lee, Virginia, United States
IT Services and IT Consulting · 51-200 employees
About the role
The IT Cybersecurity Specialist will design, implement, and sustain cybersecurity controls for a ServiceNow environment within a Federal Government defense program. Responsibilities include maintaining RMF documentation, supporting vulnerability remediation, and ensuring compliance with NIST and Department of Defense standards.
What they look for
Requirements
Candidates must possess a Bachelor's degree in a technical field and at least five years of practical cybersecurity experience. An active Secret security clearance and hands-on experience with ServiceNow security configurations are required.
Full description
Anticipated Opportunity – Federal Government Program
Important Hiring Notice: This position is being posted in anticipation of a potential upcoming contract award. The position is not immediately available. Osi Vision anticipates that hiring for this role may begin approximately 30–90 days from the date of posting, subject to contract award, Government direction, funding, and program start requirements. Candidates who apply may be contacted in advance to discuss qualifications, availability, clearance status, and interest.
Job Summary
The IT Cybersecurity Specialist will support a Federal Government defense program by designing, implementing, and sustaining cybersecurity controls for a ServiceNow environment. The position will help protect Controlled Unclassified Information (CUI), support Department of Defense cybersecurity requirements, apply Zero Trust principles, and coordinate with Government cybersecurity and IT stakeholders to maintain system compliance.
The IT Cybersecurity Specialist will develop and maintain Risk Management Framework (RMF) documentation, support vulnerability remediation, conduct continuous monitoring activities, and help maintain the system's Authority to Operate (ATO) throughout its lifecycle. This position requires hands-on ServiceNow security experience and strong knowledge of Federal cybersecurity frameworks, access controls, identity management, and system authorization processes.
Essential Duties and Responsibilities
- Architect, configure, and maintain ServiceNow security controls, including Role-Based Access Controls (RBAC), Access Control Lists (ACLs), Data Policies, Client Scripts, encryption controls, and related security configurations.
- Align ServiceNow security configurations with applicable Department of Defense Zero Trust principles and Federal cybersecurity requirements.
- Implement and maintain appropriate data segregation, access restrictions, authentication controls, and security boundaries within controlled Government environments.
- Create and maintain detailed security documentation, including security schemas, access-control matrices, system roles, groups, ACLs, and data-segregation rules.
- Coordinate with Government IT, cybersecurity, security architecture, and authorization stakeholders to maintain required cybersecurity protocols and compliance requirements.
- Develop, maintain, and update the System Security Plan (SSP) and required Risk Management Framework documentation supporting system authorization and sustainment.
- Map ServiceNow platform configurations and security controls to applicable NIST Special Publication 800-53 requirements and other Federal cybersecurity standards.
- Support implementation of CUI security requirements consistent with NIST SP 800-171, NIST SP 800-172, and applicable Department of Defense security controls.
- Develop, track, manage, and update Plans of Action and Milestones (POA&Ms) documenting cybersecurity findings, corrective actions, remediation activities, and closure status.
- Support vulnerability management activities, including reviewing scan results, coordinating remediation, tracking findings, and validating corrective actions.
- Conduct or support continuous monitoring activities, security reviews, configuration assessments, penetration-test reviews, compliance checks, and other security assessment activities.
- Prepare or support Security Assessment Reports, cybersecurity status reports, compliance documentation, and other security-related deliverables.
- Review proposed system or application changes for potential cybersecurity impacts prior to implementation or production deployment.
- Support maintenance of cybersecurity workforce qualification and certification documentation in accordance with applicable Department of Defense workforce requirements.
- Maintain awareness of emerging cybersecurity threats, vulnerabilities, Federal requirements, and ServiceNow security capabilities that may affect program operations.
Required Qualifications
- Bachelor's degree in Cybersecurity, Computer Science, Computer Engineering, Information Technology, Information Systems, or a related technical discipline.
- Minimum of five years of practical cybersecurity experience.
- Active Secret security clearance.
- Demonstrated experience applying Department of Defense cybersecurity workforce qualification requirements, including DoDM 8140.03 and applicable Defense Cyber Workforce Framework work roles.
- Demonstrated expertise applying NIST SP 800-53 security controls and supporting Risk Management Framework activities associated with achieving and maintaining an Authority to Operate.
- Knowledge of NIST SP 800-161 supply chain risk management requirements.
- Experience securing or administering ServiceNow environments supporting Federal Government or Department of Defense requirements.
- Demonstrated hands-on experience configuring ServiceNow security controls, including ACLs, Client Scripts, Data Policies, user roles, groups, and access permissions.
- Experience implementing identity, credential, and access management controls, including CAC-based or other strong authentication mechanisms.
- Experience developing or maintaining System Security Plans, POA&Ms, security assessment documentation, vulnerability management records, and RMF artifacts.
- Knowledge of Controlled Unclassified Information security requirements and applicable NIST SP 800-171/172 controls.
- Experience supporting continuous monitoring, vulnerability scanning, security assessments, penetration-test reviews, or compliance verification activities.
- Ability to meet applicable Department of Defense cybersecurity workforce qualification and certification requirements.
- Strong technical writing, analytical, documentation, and communication skills.
Preferred Qualifications
- Experience securing ServiceNow environments operating at FedRAMP High or within Department of Defense Impact Level environments.
- Experience using ServiceNow Governance, Risk, and Compliance (GRC), Integrated Risk Management (IRM), or Security Operations (SecOps) modules.
- Experience using ServiceNow to support POA&M tracking, vulnerability remediation, compliance monitoring, or RMF workflows.
- Experience supporting Department of Defense system authorization activities.
- Familiarity with enterprise identity, credential, and access management architectures.
- Relevant cybersecurity certifications aligned with applicable DoDM 8140.03 workforce requirements.
Employment Contingency
This is an anticipated position contingent upon contract award, Government approval, funding, security requirements, and final program requirements. Submission of an application does not constitute an offer of employment.
Osi Vision is proactively identifying qualified candidates for this potential requirement. Applicants may be contacted during the pre-award or transition period to discuss qualifications, active security clearance status, availability, compensation expectations, and potential start dates.
The anticipated hiring timeframe is approximately 30–90 days, but the actual start date may change based on Government and contract requirements.
Similar roles
-
Senior Cybersecurity Analyst
Tlingit Haida Tribal Business Corporation Falls Church, Virginia, United States · $91K–$124K/yr
-
Senior Security Engineer (Attack Surface Identification)
Coupang Seattle, Washington, United States · $108K–$232K/yr
-
Cybersecurity and Systems Administrator
Walton Global Holdings, LLC Scottsdale, Arizona, United States · $100K–$125K/yr
-
Sr. Cyber Security Engineer, Exposure Management
Community Health Systems Professional Services Corporation Franklin, Tennessee, United States
-
Senior Security Engineer IS - Identity and Access Management, Remote
Providence Renton, Washington, United States · $113K–$254K/yr
-
Data Center Security Engineer - WIDS
CoreWeave Livingston, New Jersey, United States · $122K–$179K/yr