IT Cybersecurity Specialist - US Citizen/Onsite/Tier 3 Investigation
Job Description
Join IvoryCloud supporting DCMA (DoD/DoW) with security engineering and governance work that helps keep authorization on track as the ServiceNow platform evolves. This onsite role is based at the DCMA facility in Fort Lee, Virginia and includes a $90,000 to $125,000 annual salary.
You will architect and implement ServiceNow security controls, maintain SSP and RMF artifacts, and support the system’s Authority to Operate (ATO) by mapping platform configurations to NIST requirements for protecting Controlled Unclassified Information (CUI).
What you will do
- Architect and implement ServiceNow security controls, including RBAC, ACLs, Data Policies, and Edge Encryption, aligned with the DoD Zero Trust Strategy.
- Enforce data segregation between IL4 (Public) and IL5 (CAC-Authenticated) environments, and create and maintain the schema and RBAC matrix covering roles, groups, ACLs, and segregation rules.
- Coordinate with the Government IT Program Manager and Authorizing Official (AO) to ensure required cybersecurity protocols are maintained per local policy.
- Develop and continuously update a comprehensive System Security Plan (SSP) and required RMF artifacts, mapping ServiceNow configuration to NIST SP 800-53 and NIST SP 800-171/172 for CUI protection to achieve and maintain ATO.
- Track and manage POA&M items, preferably within ServiceNow GRC/IRM, documenting vulnerabilities, reporting status, and driving remediation within Government-provided suspense dates.
- Perform continuous monitoring and provide ongoing Security Assessment Reports (SARs) covering vulnerability scans, penetration test reviews, and compliance checks prior to code promotion to keep ATO valid across the system lifecycle.
- Maintain the qualifications and certifications required under DoDM 8140.03 (DCWF) work roles and proficiency levels, and provide documentation upon Government request.
Required qualifications
- U.S. Citizenship (required, non-negotiable).
- Tier 3 background investigation favorably adjudicated (or actively in-progress) for access to CUI.
- Interim or final security clearance granted by the Department of War (DoW) required prior to start of performance.
- Current ADP/IT II clearance in the Defense Information System for Security (DISS) required.
- Minimum 5 years of practical cybersecurity experience, including hands-on architecture and engineering of access-control and data-protection capabilities.
- Location: Fort Lee, Virginia onsite at the DCMA facility.
- Demonstrated expertise applying federal security directives, including NIST SP 800-53 and NIST SP 800-161, and navigating the DoD/DoW RMF to achieve an ATO.
- Demonstrated experience securing ServiceNow in a FedRAMP High and DoD IL4/IL5 environment, including configuring ServiceNow ACLs, Client Scripts, and Data Policies.
- Experience integrating DoW Enterprise Identity, Credential, and Access Management (E-ICAM) and CAC authentication into platform security architecture.
- Ability to architect RBAC, ACLs, Data Policies, and Edge Encryption aligned with the DoD Zero Trust Strategy.
Salary and education
- Salary: USD 90,000 - 125,000 per year
- Education: Bachelor’s degree in Cybersecurity, Computer Science, Computer Engineering, or a related technical discipline
Benefits
- Salaried position and eligible for participation in company and Business Development bonus programs
- 401(k)
- 401(k) matching
- Dental insurance
- Health insurance
- Life insurance
- Paid time off
- Referral program
- Retirement plan
- Vision insurance
Certifications
- Active qualification aligned to DoDM 8140.03 (DCWF) Work Roles and Proficiency Levels for Security Architecture and Engineering (e.g., Security Architect - DCWF 651) - required
- CISSP, CASP+, or an equivalent DoD-approved certification - preferred
Preferred qualifications
- Direct experience supporting DCMA or related programs
- Experience securing ServiceNow SPM/ITSM and Agile Development 2.0 modules within a DoD or Federal enterprise
- Technical familiarity with DoD cloud infrastructure (AWS GovCloud or Microsoft Azure Government) at Impact Level 4 (IL-4) or higher and DevSecOps pipelines
- Experience with ServiceNow GRC/IRM or Security Operations (SecOps) modules
- Familiarity with ServiceNow Out-of-the-Box (OOB) architectural principles
Technologies: ServiceNow, FedRAMP High, DoD IL4, DoD IL5, RBAC, Access Control Lists (ACLs), Client Scripts, Data Policies, Edge Encryption, ServiceNow Governance, Risk, and Compliance (GRC), Integrated Risk Management (IRM), Security Operations (SecOps), ServiceNow GRC/IRM, NIST SP 800-53, NIST SP 800-161, NIST SP 800-171, NIST SP 800-172, Defense Information System for Security (DISS), DoDM 8140.03 (DCWF), CAC authentication, DoW Enterprise Identity, Credential, and Access Management (E-ICAM), System Security Plan (SSP), Risk Management Framework (RMF), Authority to Operate (ATO), Plan of Action and Milestones (POA&M), Security Assessment Reports (SARs).