Whatnot

IT Cybersecurity Specialist

Whatnot$95K — $115K *
Aerospace & Defense
5 - 7 years of experience
Job Overview by Ladders

Qualifications

  • Active qualification in accordance with DoDM 8140.03 DCWF Work Roles and Proficiency Levels for Security Architecture and Engineering.
  • Expertise in federal security directives and Risk Management Framework (RMF) navigation for ATO achievement.
  • Experience securing ServiceNow in FedRAMP High and DoD IL4/IL5 environments, including configuration of ACLs and authentication integrations.
  • Familiarity with ServiceNow GRC/IRM or SecOps modules is highly preferred.
  • U.S. citizenship required with Tier Three (T3) investigation clearance for CUI access.
  • Bachelor's degree in Cybersecurity, Computer Science, or related field required.
  • Minimum of five years of practical experience in a pertinent role.

Responsibilities

  • Architect and implement security controls for ServiceNow aligned with DoD Zero Trust Strategy.
  • Coordinate with IT Program Manager to ensure adherence to cybersecurity protocols.
  • Develop and maintain System Security Plan (SSP) and RMF artifacts, ensuring compliance with NIST standards.
  • Track and manage Plan of Action and Milestones (POA&M) within ServiceNow GRC/IRM.
  • Author and develop SSP and RMF artifacts, working directly with government officials to maintain ATO.
  • Remediate configuration-level vulnerabilities in ServiceNow and track third-party code vulnerabilities.
  • Conduct continuous monitoring, documenting vulnerability assessments and compliance for code promotions.

Benefits

  • Paid Time Off (PTO)
  • Group health plans
  • Income protection and supplemental benefits
  • 401(k) plan with company matching
  • Health Savings Account (HSA)
  • Flexible Spending Account (FSA)
  • Pet insurance options
  • Employee Assistance Program (EAP)
Full Job Description
Digital Consultants seeks an IT Cybersecurity Specialist to support security architecture, Risk Management Framework (RMF), continuous monitoring, and Authority to Operate (ATO) activities for the DCMA Blue List Program and its ServiceNow environment.

Duties to include:
  • Architect and implement ServiceNow-specific security controls, including Role-Based Access Controls (RBAC), Access Control Lists (ACLs), Data Policies, and Edge Encryption, to align with the DoD Zero Trust Strategy and enforce strict data segregation between IL4 and IL5 environments. Create and maintain a detailed schema and RBAC matrix outlining roles, groups, ACLs, and data segregation rules.
  • Adhere to local policy and coordinate with the Government office's IT Program Manager and Authorizing Official (AO) to ensure required cybersecurity protocols are maintained and followed.
  • Develop and continuously update a comprehensive System Security Plan (SSP) and all required RMF artifacts, mapping ServiceNow platform configurations to NIST SP 800-53, NIST SP 800-171/172 for CUI protection, and DoD IL4/IL5 controls to achieve and maintain the system's ATO.
  • Actively track, manage, and update the Plan of Action and Milestones (POA&M), preferably within ServiceNow GRC/IRM, to document, report, and remediate identified vulnerabilities within Government-provided suspense dates.
  • Serve as the primary author and developer of the System Security Plan (SSP) and supporting RMF artifacts in direct coordination with the Government IT Program Manager and Authorizing Official (AO) to achieve and maintain the ATO.
  • Perform technical remediation of ServiceNow configuration-level vulnerabilities within the Specialist's scope of control; document and track vulnerabilities in third-party custom code/modules in the POA&M while the responsible implementation/development vendor executes code remediation.
  • Conduct continuous monitoring and provide ongoing Security Assessment Reports (SAR) documenting vulnerability scans, penetration test reviews, and compliance checks prior to code promotion, ensuring the ATO remains valid throughout the system lifecycle.
  • Meet applicable qualification and certification requirements outlined strictly in DoDM 8140.03. Personnel performing privileged access, cybersecurity, or information assurance functions shall hold certifications appropriate to assigned roles based on DCWF Work Roles and Proficiency Levels, including applicable Foundational and Residential qualifications.
  • Provide documentation of personnel certifications and qualifications upon request by the CO or COR.


Requirements

  • Active qualification aligning with DoDM 8140.03 DCWF Work Roles and Proficiency Levels (Foundational and Residential) appropriate for Security Architecture and Engineering (e.g., Security Architect - DCWF 651).
  • Demonstrated expertise applying federal security directives, including NIST SP 800-53 controls, NIST SP 800-161 (SCRM), and navigating the DoW Risk Management Framework (RMF) to achieve an Authority to Operate (ATO).
  • Demonstrated experience securing ServiceNow instances in a FedRAMP High and DoD IL4/IL5 environment, including configuring ServiceNow ACLs, Client Scripts, Data Policies, and integrating DoW Enterprise Identity, Credential, and Access Management (E-ICAM)/CAC authentication.
  • Experience utilizing ServiceNow Governance, Risk, and Compliance (GRC) / Integrated Risk Management (IRM) or Security Operations (SecOps) modules is highly preferred.
  • Clearance: U.S. citizenship required. Personnel shall meet the Tier Three (T3) investigation equivalent (ADP/IT-II) requirement for access to CUI. A completed/current investigation or an investigation in progress is acceptable before commencing work. During onboarding, an individual with an initiated Tier 3 investigation may be granted interim authorization to work, barring unforeseen issues. This also applies to post-award replacement hires. Personnel must obtain a DoW-issued CAC for access to Government spaces and IT systems.
  • Certifications: Active qualification aligning with DoDM 8140.03 DCWF Work Roles and Proficiency Levels (Foundational and Residential) appropriate for Security Architecture and Engineering (e.g., Security Architect - DCWF 651) required.
  • Education: Bachelor's degree in Cybersecurity, Computer Science, Computer Engineering, or a related technical discipline required.
  • Experience: Minimum of five (5) years of practical experience required.
  • Preferred Qualifications: Experience utilizing ServiceNow GRC/IRM or Security Operations (SecOps) modules.

Physical Requirements: The candidate must be able to travel to other worksites as required and with or without reasonable accommodation, be able to sit, stand, use computers and monitors, and perform duties in an office environment for extended periods. The candidate must be able to lift up to 40 lbs. on occasion (e.g., moving a case of paper or similar task) that may occur occasionally.

Compensation and Benefits: The company offers the following benefits to permanent, full-time employees:
  • Paid Time Off (PTO)
  • Group health plans
  • Income protection and supplemental benefits
  • 401(k) plan with company matching
  • Health Savings Account (HSA)
  • Flexible Spending Account (FSA)
  • Pet insurance options
  • Employee Assistance Program (EAP)

About Whatnot

Whatnot is a Los Angeles-based startup that creates a place where avid collectors could come together over shared interests. Whatnot is a marketplace to buy and sell authentic collectible items. Whatnot was founded in 2019, in California.

Whatnot Careers

Joining Whatnot presents an unparalleled opportunity to become part of a leading team in the marketplace, where innovation meets diversity and professional growth. Whatnot is renowned for its unique culture that fosters leadership and promotes career advancement through continuous learning and development.

Explore Job Opportunities

Whatnot is actively seeking talented individuals who are eager to drive innovation and lead in a dynamic environment. The company offers a variety of job opportunities that cater to professionals looking to make a significant impact in their fields. With positions ranging from technology to marketing, Whatnot ensures that every team member’s skills are harnessed effectively.

Experience Professional Growth

At Whatnot, growth is not just a possibility—it is an expectation. The company is committed to the professional development of its employees through robust training programs, including leadership development and diversity training. These initiatives are designed to enhance skills and prepare individuals for future challenges and opportunities.

Engage in Meaningful Work

Every position at Whatnot is designed to challenge team members while contributing to the company’s overarching goals of innovation and service excellence. Employees are encouraged to take ownership of their projects and drive results that influence the company’s trajectory and success.

Internship Programs

For those starting their career journey, Whatnot offers internship programs that provide a comprehensive learning experience. Interns at Whatnot gain hands-on experience, working alongside seasoned professionals and participating in projects that offer real-world applications of their studies.

Benefits and Culture

Whatnot is dedicated to supporting its team members not only in their professional lives but also in their personal growth and well-being. The company offers competitive benefits packages that address health, financial security, and work-life balance. Whatnot’s culture is built on a foundation of respect and inclusion, where diversity is celebrated and every voice is heard.

Join the Team

Whatnot is hiring! Explore open positions that match your skills and interests. The company values curious, creative, and solution-driven team players. Prepare your resume and ready yourself for an interview where you can showcase your abilities and fit for the team.

Networking and Career Advancement

Whatnot believes in the power of networking to unlock new opportunities and insights. Employees are encouraged to engage with industry leaders and peers through various professional networking events sponsored by the company. These connections can lead to innovative ideas and collaborations that propel both personal and company growth.

Stay Connected

Keep up to date with the latest from Whatnot by following the company’s career blog. Gain insider perspectives, career tips, and industry-leading insights that you can apply to your professional life. Personalize your subscription to receive job alerts and the latest news tailored to your preferences.

Discover Whatnot

Whatnot invites you to explore the exciting and rewarding opportunities that await. Join a team where your career aspirations can be realized through dedication, hard work, and a commitment to excellence.
Learn more about Whatnot
Size
251 employees
Industry

Similar Jobs

More Jobs at Whatnot

More Aerospace & Defense Jobs

Find similar IT Cybersecurity Specialist jobs: