Cyber A&A Engineer (26-205)

Posted Yesterday
Be an Early Applicant
Colorado Springs, CO, USA
In-Office
105K-122K Annually
Mid level
Big Data • Cloud
The Role
Support RMF Assessment & Authorization (A&A) activities in DoD environments: perform STIG/SCAP/ACAS vulnerability assessments, system hardening, develop and update RMF artifacts (TR, ABD, POA&M, inventories), validate controls, coordinate remediation, and assist ISSO functions. Maintain authorization documentation, execute compliance audits, and support certification testing and program control processes to achieve and sustain system authorization.
Summary Generated by Built In

Who is Trace3?

Trace3 is a leading Transformative IT Authority, providing unique technology solutions and consulting services to our clients. Equipped with elite engineering and dynamic innovation, we empower IT executives and their organizations to achieve competitive advantage through a process of Integrate, Automate, Innovate.

Our culture at Trace3 embodies the spirit of a startup with the advantage of a scalable business. Employees can grow their career and have fun while doing it!

Trace3 is headquartered in Irvine, California. We employ more than 1,200 people all over the United States. Our major field office locations include Denver, Indianapolis, Grand Rapids, Lexington, Los Angeles, Louisville, Texas, San Francisco.  

Ready to discover the possibilities that live in technology?


Come Join Us!

Street-Smart Thriving in Dynamic Times

We are flexible and resilient in a fast-changing environment. We continuously innovate and drive constructive change while keeping a focus on the “big picture.” We exercise sound business judgment in making high-quality decisions in a timely and cost-effective manner. We are highly creative and can dig deep within ourselves to find positive solutions to different problems.

Juice - The “Stuff” it takes to be a Needle Mover

We get things done and drive results. We lead without a title, empowering others through a can-do attitude. We look forward to the goal, mentally mapping out every checkpoint on the pathway to success, and visualizing what the final destination looks and feels like.

Teamwork - Humble, Hungry and Smart

We are humble individuals who understand how our job impacts the company's mission. We treat others with respect, admit mistakes, give credit where it’s due and demonstrate transparency. We “bring the weather” by exhibiting positive leadership and solution-focused thinking. We hug people in their trials, struggles, and failures – not just their success. We appreciate the individuality of the people around us.


JOB SUMMARY:

The Cyber A&A Engineer supports Assessment and Authorization (A&A) activities within the Risk Management Framework (RMF) by evaluating cybersecurity controls, identifying system vulnerabilities, and developing required artifacts to achieve and maintain system authorization. This role also performs functions aligned to an Information System Security Officer (ISSO), with a focus on cybersecurity policies, technologies, and compliance within DoD environments.

SUMMARY OF ESSENTIAL JOB FUNCTIONS:

  • Process and track DD Form 2875 user account forms and required training for privileged and non-privileged accounts.
  • Perform annual account validation and coordinate with system administrators on account creation, modification, and removal.
  • Assess systems and networks in virtual environments to identify deviations from approved configurations, enclave policy, or local policy.
  • Conduct compliance audits using passive tools (e.g., STIG Viewer, SCAP) and perform active vulnerability assessments using ACAS.
  • Execute Security Technical Implementation Guide (STIG) assessments and system hardening for Windows, Red Hat Enterprise Linux (RHEL), and networking equipment using ConfigOS.
  • Develop test plans for STIG checks and demonstrate expected outcomes.
  • Update Risk Management Framework (RMF) artifacts to track and remediate system hardening non-compliance.
  • Establish program control processes to mitigate risk and support system assessment and authorization.
  • Support compliance activities including analysis, coordination, certification testing, documentation, inspections, audits, and technology evaluation.
  • Assist in implementing government cybersecurity policies (e.g., NISPOM, NIST, DoD) and recommend process improvements.
  • Validate cybersecurity controls and recommend appropriate safeguards through vulnerability analysis.
  • Support program test milestones through pre-test preparation, participation, analysis of results, and artifact development for authorization activities.
  • Prepare and maintain authorization documentation including:
    • Test Results (TR)
    • Authorization Boundary Diagrams (ABD)
    • Network topologies and flow diagrams
    • Hardware/software inventories
    • Ports, protocols, and services documentation
    • Plan of Actions and Milestones (POA&M)
  • Conduct periodic reviews of system audits and track corrective actions through closure.
  • Coordinate with program stakeholders to resolve deficiencies identified during RMF assessments.

REQUIRED SKILLS AND EXPERIENCE:

  • Security engineering skills with working knowledge of cybersecurity technologies and DoD/Federal cybersecurity policies (e.g., DoDI 8500.01, NIST SP 800-53).
  • Experience with Enterprise Mission Assurance Support Service (eMASS).
  • Understanding of the Risk Management Framework (RMF) cybersecurity lifecycle, including:
    • Controls and overlays
    • Development of testable requirements
    • Resilient architecture design
    • Configuration, execution, and scripting of audit tools
    • Vulnerability analysis and verification testing for compliance
  • Knowledge of Software Assurance (SwA), including static and dynamic code analysis (e.g., Fortify, SonarQube).
Preferred Qualifications
  • Experience performing ISSO-related functions in a DoD or federal environment.
  • Windows and Red Hat Enterprise Linux (RHEL) system administration experience.
  • Experience working in virtual environments.
  • Experience working with Docker and containers.
  • Experience administering ACAS and ESS (formerly HBSS).
  • Experience using ConfigOS.

EDUCATION: Bachelors with  3+ or Master with  1+ Years of Experience

LOCATION: Full Time/ On-Site Schriever Base in Colorado Springs, CO

CLEARANCE REQUIRMENT:  Top Secret

DOD 8570 REQUIREMENT: IAT - Level II

SALARY RANGE: $105,000 to $122,400

PHYSICAL DEMANDS:

The physical demands described here are representative of those that must be met by an employee to successfully perform the essential functions of this position. Reasonable accommodations may be made to enable individuals with disabilities to perform these functions.

While performing the duties of this job, the employee is regularly required to:

  • Remain in a stationary position for extended periods of time.
  • Operate a computer, keyboard, and other office equipment using hands and fingers.
  • Communicate effectively in person, over the phone, and through electronic means.
  • Occasionally move about the office to access files, office equipment, and meeting spaces.
  • Lift and/or move up to 15 pounds as needed.
  • Maintain specific vision abilities, including close vision and the ability to adjust focus.

WORK ENVIRONMENT:

This position is performed within a secure, classified workspace. Employees must comply with all applicable security protocols and access control procedures, including restrictions on personal electronic devices and the handling of sensitive information.

Actual salary will be based on a variety of factors, including location, experience, skill set, performance, licensure and certification, and business needs. The range for this position in other geographic locations may differ. Certain positions may also be eligible for variable incentive compensation, such as bonuses or commissions, that is not included in the base salary.
Estimated Pay Range
$105,000$122,400 USD

The Perks

  • Comprehensive medical, dental and vision plans for you and your dependents
  • 401(k) Retirement Plan with Employer Match, 529 College Savings Plan, Health Savings Account, Life Insurance, and Long-Term Disability
  • Competitive Compensation
  • Training and development programs
  • Major offices stocked with snacks and beverages
  • Collaborative and cool culture
  • Work-life balance and generous paid time off

Our Commitment

At the core of Trace3's DNA is our people. We are a diverse group of talented individuals who understand the importance of teamwork and demonstrating leadership, character, and passion in all that we do.

We’re committed to fostering an inclusive workplace where everyone feels respected, valued, and empowered to grow. We recognize that embracing diversity drives innovation, improves outcomes, fosters collaboration, boosts teammate satisfaction, and builds a more inclusive culture.

As an equal opportunity employer, Trace3 bases all employment decisions based on individual qualifications, merit, and business requirements. We do not engage in discrimination on the basis of race, color, religion, sex (including gender identity, sexual orientation, and pregnancy), national origin, age (40 or older), disability, genetic information, or any other characteristic protected by federal, state, or local law.

Any demographic information provided is strictly voluntary, kept confidential in accordance with Equal Employment Opportunity (EEO) regulations, and will not be used in employment decisions, including hiring, promotions, or mentorship programs. We are committed to providing equal employment opportunities for all.

If you require a reasonable accommodation to complete the application process or participate in an interview, please email [email protected].


***To all recruitment agencies: Trace3 does not accept unsolicited agency resumes/CVs. Please do not forward resumes/CVs to our careers email addresses, Trace3 employees or any other company location. Trace3 is not responsible for any fees related to unsolicited resumes/CVs.

Skills Required

  • Security engineering skills with working knowledge of DoDI 8500.01 and NIST SP 800-53
  • Experience with eMASS
  • Understanding of the Risk Management Framework (RMF) lifecycle, controls, overlays, and development of testable requirements
  • Configuration, execution, and scripting of audit tools and vulnerability analysis/verification testing for compliance
  • Knowledge of Software Assurance (static and dynamic code analysis) such as Fortify and SonarQube
  • Bachelor's degree with 3+ years experience, or Master's degree with 1+ years experience
  • Top Secret security clearance
  • DOD 8570 IAT - Level II certification/qualification
  • Experience performing ISSO-related functions in DoD or federal environments
  • Windows and Red Hat Enterprise Linux (RHEL) system administration experience
  • Experience working in virtual environments
  • Experience with Docker and containers
  • Experience administering ACAS and ESS (HBSS)
  • Experience using ConfigOS

Trace3 Compensation & Benefits Highlights

The following summarizes recurring compensation and benefits themes identified from responses generated by popular LLMs to common candidate questions about Trace3 and has not been reviewed or approved by Trace3.

  • Leave & Time Off Breadth PTO is offered as flexible or unlimited for many salaried roles, with company language emphasizing generous time off and work-life balance. Remote-work programs and flexible schedules reinforce practical access to time away.
  • Healthcare Strength Core coverage includes medical, dental, vision, HSA, life insurance, and long‑term disability, with multiple plan options in some locations. Mental‑health benefits and first‑of‑month eligibility contribute to a comprehensive offering.
  • Strong & Reliable Incentives Revenue and presales roles feature competitive base pay with meaningful on‑target earnings potential, and performance bonuses are part of the total rewards mix. This structure can deliver strong outcomes for high performers.

Trace3 Insights

Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
Grand Rapids, MI
944 Employees

What We Do

Trace3, a pioneer in business transformation solutions, empowers organizations to lead their market space by keeping pace with the rapid changes in IT innovations ensuring relevance to specific business initiatives required to maximize revenue generation by leveraging the latest Silicon Valley, cloud, big data and datacenter technologies maximizing organizational health. We have a unique ability to deliver optimal solutions combined with our talented team and over 10 years of documented best practices that unify people, process and technology. Over 2,000 globally recognized companies trust in Trace3 to stay relevant and innovative in today’s highly competitive market.

Similar Jobs

Northrop Grumman Logo Northrop Grumman

Systems Engineer

Aerospace • Logistics • Security • Software • Cybersecurity
In-Office
Schriever AFB, CO, USA
85636 Employees
114K-171K Annually

EchoStar Logo EchoStar

Senior Atlassian Administrator

Aerospace • Cloud • Digital Media • Information Technology • Mobile • News + Entertainment • Generative AI
In-Office
Littleton, CO, USA
14500 Employees
96K-138K Annually

EchoStar Logo EchoStar

Brand Manager

Aerospace • Cloud • Digital Media • Information Technology • Mobile • News + Entertainment • Generative AI
In-Office
Littleton, CO, USA
14500 Employees
110K-157K Annually

Wells Fargo Logo Wells Fargo

Personal Banker, Longmont, CO

Fintech • Financial Services
Hybrid
Longmont, CO, USA
205000 Employees
21-28 Hourly

Similar Companies Hiring

Prolaio Thumbnail
Artificial Intelligence • Big Data • Healthtech • Mobile • Wearables • Analytics
Chicago, IL
82 Employees
Yooz Thumbnail
Software • Machine Learning • Fintech • Financial Services • Cloud • Automation • Artificial Intelligence
Aimargues, FR
470 Employees
Amplify Platform Thumbnail
Fintech • Financial Services • Consulting • Cloud • Business Intelligence • Big Data Analytics
Scottsdale, AZ
62 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account