IT Cybersecurity Specialist - Contingent

Posted Yesterday
Be an Early Applicant
Fort Lee, VA, USA
In-Office
Senior level
Consulting
The Role
Architect and implement ServiceNow security controls for DoD IL4/IL5 environments. Own platform security engineering, ATO management, SSP and RMF artifacts, POA&M remediation, continuous monitoring, vulnerability and compliance reporting, and data segregation. Coordinate with government stakeholders and ensure personnel meet DoD cybersecurity qualification and certification requirements.
Summary Generated by Built In

Description: CRG is seeking two IT Cybersecurity Specialists to architect and implement ServiceNow-specific security controls for the DCMA Blue List Program Support Services contract, including Role-Based Access Controls (RBAC), Access Control Lists (ACLs), Data Policies, and Edge Encryption, aligned to the DoD Zero Trust Strategy.

This role owns platform security engineering and the system's Authority to Operate (ATO), developing and maintaining the System Security Plan (SSP) and RMF artifacts, and enforcing strict data segregation between IL4 (Public) and IL5 (CAC-Authenticated) environments.

The ideal candidate will have direct experience securing a ServiceNow instance in a FedRAMP High / DoD IL4-IL5 environment and be comfortable owning POA&M remediation against Government suspense dates.

Responsibilities:

Platform Security Architecture

  • Architect and implement ServiceNow-specific security controls — including RBAC, ACLs, Data Policies, and Edge Encryption — to align with the DoD Zero Trust Strategy and enforce strict data segregation between IL4 (Public) and IL5 (CAC-Authenticated) environments
  • Create and maintain a detailed schema and RBAC matrix outlining all roles, groups, ACLs, and data segregation rules
  • Adhere to local policy and coordinate with the Government office's IT Program Manager and Authorizing Official (AO) to ensure required cybersecurity protocols are maintained and followed

RMF & ATO Management

  • Develop and continuously update a comprehensive System Security Plan (SSP) and all required RMF artifacts, mapping ServiceNow platform configurations to NIST SP 800-53, NIST SP 800-171/172 (CUI protection), and DoD IL4/IL5 controls to achieve and maintain the system's Authority to Operate (ATO)
  • Actively track, manage, and update the Plan of Action and Milestones (POA&M), preferably within ServiceNow GRC/IRM, to document, report, and remediate identified vulnerabilities within Government-provided suspense dates

Continuous Monitoring & Compliance

  • Conduct continuous monitoring and provide ongoing Security Assessment Reports (SAR) documenting vulnerability scans, penetration test reviews, and compliance checks prior to code promotion, ensuring the ATO remains valid throughout the system's lifecycle
  • Ensure all personnel performing tasks under the PWS meet applicable qualification and certification requirements per DoDM 8140.03, and provide documentation of personnel certifications and qualifications upon request by the CO or COR

Required Qualifications:

  • Bachelor's degree required in Cybersecurity, Computer Science, Computer Engineering, or a related technical discipline
  • Minimum of five (5) years of practical experience
  • Active qualification aligning with DoDM 8140.03 DCWF Work Roles and Proficiency Levels (Foundational and Residential) appropriate for Security Architecture and Engineering (e.g., Security Architect - DCWF 651)
  • Demonstrated expertise applying federal security directives, including NIST SP 800-53 controls, NIST SP 800-161 (SCRM), and navigating the DoW Risk Management Framework (RMF) to achieve an Authority to Operate (ATO)
  • Demonstrated experience securing ServiceNow instances in a FedRAMP High and DoD IL4/IL5 environment, including configuring ServiceNow ACLs, Client Scripts, Data Policies, and integrating DoW Enterprise Identity, Credential, and Access Management (E-ICAM)/CAC authentication
  • Must be a U.S. citizen with a favorably adjudicated Tier 3 (ADP/IT-II) investigation on file in DISS at the time of offer

Desired Qualifications:

  • Experience utilizing ServiceNow Governance, Risk, and Compliance (GRC) / Integrated Risk Management (IRM) or Security Operations (SecOps) modules

Benefits

Full-time employees are eligible for 401(k) and Roth retirement plans, Medical, Dental, and Vision Insurance (for employees and families), Supplemental Insurance, 11 Federal Holidays, and at least three weeks of Paid Time Off (PTO), including sick and personal leave.


CRG is an equal opportunity employer. We make employment decisions based on merit, qualifications, and business need. All qualified applicants receive consideration for employment without regard to race, color, religion, sex, national origin, age, disability, status as a protected veteran, or any other state or federally protected category.

Skills Required

  • Bachelor’s degree in Cybersecurity, Computer Science, Computer Engineering, or a related technical discipline
  • At least five years of practical experience
  • Active DoDM 8140.03 DCWF qualification aligned with Security Architecture and Engineering, such as Security Architect DCWF 651
  • Expertise applying NIST SP 800-53, NIST SP 800-161, and the DoD Risk Management Framework to achieve an Authority to Operate
  • Experience securing ServiceNow instances in FedRAMP High and DoD IL4/IL5 environments
  • Experience configuring ServiceNow ACLs, Client Scripts, Data Policies, and DoD E-ICAM/CAC authentication
  • U.S. citizenship
  • Favorably adjudicated Tier 3 ADP/IT-II investigation recorded in DISS at the time of offer
  • Experience with ServiceNow GRC/IRM or Security Operations modules
Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
HQ: Baltimore, MD
79 Employees
Year Founded: 2002

What We Do

Contracting Resources Group, Inc. (CRG) is a leading management consulting firm, offering federal government contracting solutions to both the private sector and the federal government. CRG’s services include providing program management, program evaluation and training, acquisition support services, communications, market research and analysis, and IT professional solutions. Since 2002, CRG has provided superior performance for over 400 companies, including numerous federal agencies, backed by direct, enthusiastic customer references. Contracts: 8a STARS II GWAC, PSS GSA Schedule, EAGLE II & SeaPort-e

Similar Jobs

PwC Logo PwC

Procurement Senior Manager - Data

Artificial Intelligence • Professional Services • Business Intelligence • Consulting • Cybersecurity • Generative AI
Hybrid
68 Locations
370000 Employees
91K-322K Annually

SailPoint Logo SailPoint

Customer Success Manager

Artificial Intelligence • Cloud • Sales • Security • Software • Cybersecurity • Data Privacy
Remote or Hybrid
United States
2461 Employees
60K-101K Annually

Coursera + Udemy  Logo Coursera + Udemy

Account Director

Artificial Intelligence • Consumer Web • Edtech • Enterprise Web • HR Tech • Social Impact • Generative AI
Remote or Hybrid
United States
1500 Employees
107K-168K Annually

Coursera + Udemy  Logo Coursera + Udemy

Senior Deal Desk Analyst

Artificial Intelligence • Consumer Web • Edtech • Enterprise Web • HR Tech • Social Impact • Generative AI
Remote or Hybrid
United States
1500 Employees
113K-143K Annually

Similar Companies Hiring

Energy CX Thumbnail
Greentech • Professional Services • Business Intelligence • Consulting • Energy • Financial Services • Utilities
Chicago, IL
108 Employees
Quantum Rise Thumbnail
Software • Professional Services • Natural Language Processing • Machine Learning • Consulting • Automation • Artificial Intelligence
Chicago, Illinois
20 Employees
Northslope Thumbnail
Artificial Intelligence • Information Technology • Software • Analytics • Consulting • Generative AI
London, GB
100 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account