SAIC

Cyber Analyst-RMF Specialist

SAIC$120K — $160K *
Aerospace & Defense
5 - 7 years of experience
Job Overview by Ladders

Qualifications

  • Active TS/SCI security clearance required.
  • Certification per DoDD 8140.03, Intermediate Level (e.g., CompTIA CySA+, Security+ CE, GSEC).
  • Bachelor's degree or equivalent experience in Information Assurance, Cybersecurity, or Systems Administration.
  • 5+ years of IT and cybersecurity experience.
  • Experience defending identity services and managing Windows/Linux server systems.
  • 2+ years as an ISSO for DoD systems.
  • Proficiency with STIG Viewer and SCAP tools like EvaluateSTIG.

Responsibilities

  • Support the RMF team by maintaining continuous monitoring records in eMASS.
  • Manage compliance scans using ACAS and SCAP tools on enterprise systems.
  • Analyze and remediate vulnerabilities based on scan results.
  • Implement and validate system hardening measures across operating environments.
  • Coordinate responses to Cyber Tasking Orders and STIG compliance issues.
  • Translate technical findings into actionable remediation plans with milestones.
  • Ensure systems remain in a Cyber Operational Readiness Assessment ready state.

Benefits

  • Opportunities for professional development and training.
  • Collaborative work environment with a focus on team success.
  • Access to advanced cybersecurity tools and technologies.
  • Support for work-life balance and flexible scheduling.
Full Job Description
Job Description

Description

Join our team and play a pivotal role in defending North America. We are seeking a highly skilled Cyber Analyst - RMF Specialist in Colorado Springs, COto support the critical North American Aerospace Defense Command and United States Northern Command (N&NC) Information Technology Enterprise Services (NITES) contract in Colorado Springs, CO.

In this role, you will act as a key technical compliance specialist. You will hold administrator-level access to information systems to perform advanced vulnerability and compliance scanning and manage Security Technical Implementation Guide (STIG) compliance. Crucially, you will bridge the gap between technical operations and cyber governance by directly supporting the Risk Management Framework (RMF) team, maintaining up-to-date system records in Enterprise Mission Assurance Support Service (eMASS), and executing rapid response protocols to downward-directed Cyber Tasking Orders (CTASKORDs).

Responsibilities:

The selected candidate will be responsible for the following technical and compliance activities:
  • Directly support the Risk Management Framework (RMF) team by registering, updating, and maintaining continuous monitoring records within the eMASS.
  • Maintain administrator-level access to enterprise information systems to configure, manage, and perform regular Assured Compliance Assessment Solution (ACAS) and Security Content Automation Protocol (SCAP) compliance scans.
  • Analyze scan results to ensure continuous patching and STIG compliance.
  • Implement, track, and validate system hardening measures across Windows, Linux, and network enclaves.
  • Lead the execution, tracking, and operational response to Cyber Tasking Orders (CTASKORDs) and other downward-directed orders when STIG compliance gaps must be urgently addressed.
  • Translate technical scan findings and non-compliant STIG items into actionable Plan of Action and Milestones (POA&Ms), maintaining accurate tracking of remediation milestones.
  • Maintain continuous cyber security posture and system hygiene to ensure systems remain in a Cyber Operational Readiness Assessment (CORA) ready state.
  • Provide clear vulnerability status updates, technical mitigations, and compliance roadmaps to System Owners, technical administration teams, and leadership.

Qualifications

Required Qualifications:
  • Active TS/SCI security clearance.
  • Certification required per DoDD 8140.03, Intermediate Level (e.g., CompTIA CySA+, Security+ CE, GSEC, or equivalent).
  • BS or equivalent work experience in the Information Assurance, Cybersecurity, or Systems Administration field.
  • 5+ years of overall IT and cybersecurity experience.
  • Demonstrated experience with defending identity services, domain environments, Active Directory, and Windows/Linux server systems.
  • 2+ years of experience as an ISSO for DoD systems.
  • Experience using STIG Viewer and SCAP tools, such as EvaluateSTIG.
Desired Qualifications:
  • Familiarity with enterprise vulnerability scanners and continuous network monitoring tools.
  • Previous experience operating in a highly complex, metrics-driven DoD cybersecurity environment.
  • Familiarity with the use of eMASS as a central repository for RMF artifacts.

Target salary range: $120,001 - $160,000. The estimate displayed represents the typical salary range for this position based on experience and other factors.

Overview

SAIC accepts applications on an ongoing basis and there is no deadline.

About SAIC

Science Applications International Corporation (SAIC) is a technology integrator in the technical, engineering, intelligence, and enterprise information technology markets. SAIC has approximately 26,000 employees and operates in more than 70 countries. The company was founded in 1969 and is headquartered in Reston, Virginia. SAIC provides services to the U.S. government, including the Department of Defense, the intelligence community, and civilian agencies. The company also serves commercial customers in the healthcare, energy, and financial services sectors.
Learn more about SAIC
Size
26,000 employees
Market Cap
$6 billion
Industry
Net Income
$206 million
Founded
1969
5 Year Trend
+10.7%
Revenue
$6.8 billion
NASDAQ

Similar Jobs

More Jobs at SAIC

More Aerospace & Defense Jobs

Find similar Cyber Analyst-RMF Specialist jobs: