Cybersecurity Analyst - Contingent

Posted Yesterday
Be an Early Applicant
Fort Lee, VA, USA
In-Office
Senior level
Consulting
The Role
Evaluate cybersecurity submissions for the DCMA Blue List Program, focusing on embedded systems, firmware, wireless communications, supply chain security, and component-level risks. Review assessment reports, penetration testing results, vulnerability assessments, remediation plans, and technical evidence. Identify vulnerabilities, threats, attack vectors, and residual risks, then provide recommendations on mitigation, technical acceptance, policy implementation, and assessment requirements to Government decision-makers and stakeholders.
Summary Generated by Built In

CRG is seeking two Cybersecurity Analysts to serve as technical subject matter experts (SMEs) supporting the cybersecurity evaluation of product submissions to the DCMA Blue List Program. This is a distinct role from the IT Cybersecurity Specialist position — the Cybersecurity Analyst is a policy and technical assessment function, not a ServiceNow platform security role.

Analysts provide advisory support on cybersecurity requirements, technical standards, and assessment methodologies applicable to Blue List technologies, evaluating submitted assessments for embedded systems, firmware, wireless communications, supply chain security, and related component-level risks.

The ideal candidate will have experience interpreting penetration testing results, vulnerability assessments, and firmware analyses, and translating them into clear technical risk recommendations for Government decision-makers.

Responsibilities:

Technical Assessment & SME Support

  • Serve as technical subject matter experts (SMEs) supporting the cybersecurity evaluation of product submissions
  • Provide technical expertise and advisory support to the Government Blue List Program regarding cybersecurity requirements, technical standards, risk management, and assessment methodologies applicable to Blue List technologies
  • Possess demonstrated knowledge of cybersecurity principles applicable to embedded systems, software, firmware, wireless communications, networking, encryption, authentication, supply chain security, and other technologies relevant to the Blue List Program
  • Possess experience interpreting cybersecurity assessment methodologies, penetration testing results, vulnerability assessments, software assurance evaluations, and firmware analyses sufficient to evaluate cybersecurity risks associated with Blue List candidate technologies

Assessment Review & Validation

  • Review cybersecurity assessment reports, supporting technical documentation, and assessment evidence to evaluate the completeness, technical sufficiency, and adequacy of assessments in support of Government technical acceptance decisions
  • Provide technical recommendations regarding cybersecurity findings, risk mitigation strategies, assessment requirements, technical acceptance, and the applicability of cybersecurity requirements to Blue List candidate technologies
  • Verify and validate whether a company's submitted remediation plan would sufficiently mitigate any cyber vulnerabilities identified in provided assessments

Risk Identification & Advisory

  • Identify cybersecurity vulnerabilities, threats, attack vectors, and residual risks that may adversely affect DoW missions, warfighter safety, national security, operational resilience, or the confidentiality, integrity, and availability of Government information and systems
  • Maintain awareness of applicable Federal statutes, DoW policies, NDAA requirements, cybersecurity frameworks, industry best practices, and Government processes relevant to the Blue List Program
  • Provide technical consultation and advisory support to Government personnel and stakeholders regarding cybersecurity matters affecting Blue List technologies, assessments, policy implementation, and program execution
  • Monitor emerging cybersecurity threats, vulnerabilities, technologies, and policy developments affecting small unmanned systems and provide recommendations to support the continued evolution of the Blue List Program

Required Qualifications:

  • Bachelor's degree required in Cybersecurity, Computer Science, Computer Engineering, or a related technical discipline
  • Active certification required: DoW 8570/8140 IAM or IAT Level II or III (e.g., CISSP, CISM, or CompTIA Security+)
  • Must be a U.S. citizen with a favorably adjudicated Tier 3 (ADP/IT-II) investigation on file in DISS at the time of offer

Desired Qualifications:

Minimum of five (5) years of practical experience

Benefits

Full-time employees are eligible for 401(k) and Roth retirement plans, Medical, Dental, and Vision Insurance (for employees and families), Supplemental Insurance, 11 Federal Holidays, and at least three weeks of Paid Time Off (PTO), including sick and personal leave.


CRG is an equal opportunity employer. We make employment decisions based on merit, qualifications, and business need. All qualified applicants receive consideration for employment without regard to race, color, religion, sex, national origin, age, disability, status as a protected veteran, or any other state or federally protected category.

Skills Required

  • Bachelor's degree in Cybersecurity, Computer Science, Computer Engineering, or a related technical discipline
  • Active DoD 8570/8140 IAM or IAT Level II or III certification, such as CISSP, CISM, or CompTIA Security+
  • U.S. citizenship
  • Favorably adjudicated Tier 3 ADP/IT-II investigation on file in DISS at the time of offer
  • At least five years of practical experience
Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
HQ: Baltimore, MD
79 Employees
Year Founded: 2002

What We Do

Contracting Resources Group, Inc. (CRG) is a leading management consulting firm, offering federal government contracting solutions to both the private sector and the federal government. CRG’s services include providing program management, program evaluation and training, acquisition support services, communications, market research and analysis, and IT professional solutions. Since 2002, CRG has provided superior performance for over 400 companies, including numerous federal agencies, backed by direct, enthusiastic customer references. Contracts: 8a STARS II GWAC, PSS GSA Schedule, EAGLE II & SeaPort-e

Similar Jobs

PwC Logo PwC

Procurement Senior Manager - Data

Artificial Intelligence • Professional Services • Business Intelligence • Consulting • Cybersecurity • Generative AI
Hybrid
68 Locations
370000 Employees
91K-322K Annually

SailPoint Logo SailPoint

Customer Success Manager

Artificial Intelligence • Cloud • Sales • Security • Software • Cybersecurity • Data Privacy
Remote or Hybrid
United States
2461 Employees
60K-101K Annually

Coursera + Udemy  Logo Coursera + Udemy

Account Director

Artificial Intelligence • Consumer Web • Edtech • Enterprise Web • HR Tech • Social Impact • Generative AI
Remote or Hybrid
United States
1500 Employees
107K-168K Annually

Coursera + Udemy  Logo Coursera + Udemy

Senior Deal Desk Analyst

Artificial Intelligence • Consumer Web • Edtech • Enterprise Web • HR Tech • Social Impact • Generative AI
Remote or Hybrid
United States
1500 Employees
113K-143K Annually

Similar Companies Hiring

Energy CX Thumbnail
Greentech • Professional Services • Business Intelligence • Consulting • Energy • Financial Services • Utilities
Chicago, IL
108 Employees
Quantum Rise Thumbnail
Software • Professional Services • Natural Language Processing • Machine Learning • Consulting • Automation • Artificial Intelligence
Chicago, Illinois
20 Employees
Northslope Thumbnail
Artificial Intelligence • Information Technology • Software • Analytics • Consulting • Generative AI
London, GB
100 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account