Cyber A&A Engineer (26-205)
Colorado Springs, CO·Posted today
aicybersecuritydocker
<div class="content-intro"><p><img src="https://i.postimg.cc/Wb1SdDgC/Join-the.png" alt="" width="649" style="max-width: 100%;"></p> <hr> <p>Who is <strong>Trace3</strong>?</p> <p>Trace3 is a leading Transformative IT Authority, providing unique technology solutions and consulting services to our clients. Equipped with elite engineering and dynamic innovation, we empower IT executives and their organizations to achieve competitive advantage through a process of Integrate, Automate, Innovate.</p> <p>Our culture at Trace3 embodies the spirit of a startup with the advantage of a scalable business. Employees can grow their career and have fun while doing it!</p> <p>Trace3 is headquartered in Irvine, California. We employ more than 1,200 people all over the United States. Our major field office locations include Denver, Indianapolis, Grand Rapids, Lexington, Los Angeles, Louisville, Texas, San Francisco. </p> <p><strong>Ready to discover the possibilities that live in technology?</strong></p> <p> </p> <p><strong>Come Join Us!</strong></p> <p><strong>Street-Smart</strong> <strong>- <em>Thriving in Dynamic Times</em></strong></p> <p>We are flexible and resilient in a fast-changing environment. We continuously innovate and drive constructive change while keeping a focus on the “big picture.” We exercise sound business judgment in making high-quality decisions in a timely and cost-effective manner. We are highly creative and can dig deep within ourselves to find positive solutions to different problems.</p> <p><strong>Juice - <em>The “Stuff” it takes to be a Needle Mover </em></strong></p> <p>We get things done and drive results. We lead without a title, empowering others through a can-do attitude. We look forward to the goal, mentally mapping out every checkpoint on the pathway to success, and visualizing what the final destination looks and feels like.</p> <p><strong>Teamwork - <em>Humble, Hungry and Smart</em></strong></p> <p>We are humble individuals who understand how our job impacts the company's mission. We treat others with respect, admit mistakes, give credit where it’s due and demonstrate transparency. We “bring the weather” by exhibiting positive leadership and solution-focused thinking. We hug people in their trials, struggles, and failures – not just their success. We appreciate the individuality of the people around us.</p> <hr> <p> </p></div><p><strong>JOB SUMMARY:</strong></p> <p></p> <div>The Cyber A&A Engineer supports Assessment and Authorization (A&A) activities within the Risk Management Framework (RMF) by evaluating cybersecurity controls, identifying system vulnerabilities, and developing required artifacts to achieve and maintain system authorization. This role also performs functions aligned to an Information System Security Officer (ISSO), with a focus on cybersecurity policies, technologies, and compliance within DoD environments.</div> <p><strong>SUMMARY OF ESSENTIAL JOB FUNCTIONS:</strong></p> <ul> <li>Process and track DD Form 2875 user account forms and required training for privileged and non-privileged accounts.</li> <li>Perform annual account validation and coordinate with system administrators on account creation, modification, and removal.</li> <li>Assess systems and networks in virtual environments to identify deviations from approved configurations, enclave policy, or local policy.</li> <li>Conduct compliance audits using passive tools (e.g., STIG Viewer, SCAP) and perform active vulnerability assessments using ACAS.</li> <li>Execute Security Technical Implementation Guide (STIG) assessments and system hardening for Windows, Red Hat Enterprise Linux (RHEL), and networking equipment using ConfigOS.</li> <li>Develop test plans for STIG checks and demonstrate expected outcomes.</li> <li>Update Risk Management Framework (RMF) artifacts to track and remediate system hardening non-compliance.</li> <li>Establish program control processes to mitigate risk and support system assessment and authorization.</li> <li>Support compliance activities including analysis, coordination, certification testing, documentation, inspections, audits, and technology evaluation.</li> <li>Assist in implementing government cybersecurity policies (e.g., NISPOM, NIST, DoD) and recommend process improvements.</li> <li>Validate cybersecurity controls and recommend appropriate safeguards through vulnerability analysis.</li> <li>Support program test milestones through pre-test preparation, participation, analysis of results, and artifact development for authorization activities.</li> <li>Prepare and maintain authorization documentation including:<br> <ul> <li>Test Results (TR)</li> <li>Authorization Boundary Diagrams (ABD)</li> <li>Network topologies and flow diagrams</li> <li>Hardware/software inventories</li> <li>Ports, protocols, and services documentation</li> <li>Plan of Actions and Milestones (POA&M)</li> </ul> </li> <li>Conduct periodic reviews of system audits and track corrective actions through closure.</li> <li>Coordinate with program stakeholders to resolve deficiencies identified during RMF assessments.</li> </ul> <p><strong>REQUIRED SKILLS AND EXPERIENCE:</strong></p> <ul> <li>Security engineering skills with working knowledge of cybersecurity technologies and DoD/Federal cybersecurity policies (e.g., DoDI 8500.01, NIST SP 800-53).</li> <li>Experience with Enterprise Mission Assurance Support Service (eMASS).</li> <li>Understanding of the Risk Management Framework (RMF) cybersecurity lifecycle, including:<br> <ul> <li>Controls and overlays</li> <li>Development of testable requirements</li> <li>Resilient architecture design</li> <li>Configuration, execution, and scripting of audit tools</li> <li>Vulnerability analysis and verification testing for compliance</li> </ul> </li> <li>Knowledge of Software Assurance (SwA), including static and dynamic code analysis (e.g., Fortify, SonarQube).</li> </ul> <p></p> <div> <h3><strong>Preferred Qualifications</strong></h3> <ul> <li class="___ccc16d0 fje8fi8 f1ng9h0j f1bwykku f18jd3zf">Experience performing ISSO-related functions in a DoD or federal environment.</li> <li class="___ccc16d0 fje8fi8 f1ng9h0j f1bwykku f18jd3zf">Windows and Red Hat Enterprise Linux (RHEL) system administration experience.</li> <li class="___ccc16d0 fje8fi8 f1ng9h0j f1bwykku f18jd3zf">Experience working in virtual environments.</li> <li class="___ccc16d0 fje8fi8 f1ng9h0j f1bwykku f18jd3zf">Experience working with Docker and containers.</li> <li class="___ccc16d0 fje8fi8 f1ng9h0j f1bwykku f18jd3zf">Experience administering ACAS and ESS (formerly HBSS).</li> <li class="___ccc16d0 fje8fi8 f1ng9h0j f1bwykku f18jd3zf">Experience using ConfigOS.</li> </ul> </div> <p><strong>EDUCATION: </strong>Bachelors with 3+ or Master with 1+ Years of Experience</p> <p><strong>LOCATION:</strong> Full Time/ On-Site Schriever Base in Colorado Springs, CO</p> <p><strong>CLEARANCE REQUIRMENT: </strong>Top Secret</p> <p><strong>DOD 8570 REQUIREMENT: </strong>IAT - Level II</p> <p><strong>SALARY RANGE: </strong>$105,000 to $122,400<br><br></p> <p><strong>PHYSICAL DEMANDS:</strong></p> <p>The physical demands described here are representative of those that must be met by an employee to successfully perform the essential functions of this position. Reasonable accommodations may be made to enable individuals with disabilities to perform these functions.</p> <p>While performing the duties of this job, the employee is regularly required to:</p> <ul> <li>Remain in a <strong>stationary position</strong> for extended periods of time.</li> <li>Operate a <strong>computer, keyboard, and other office equipment</strong> using hands and fingers.</li> <li>Communicate effectively in person, over the phone, and through electronic means.</li> <li>Occasionally move about the office to access files, office equipment, and meeting spaces.</li> <li>Lift and/or move up to <strong>15 pounds</strong> as needed.</li> <li>Maintain specific vision abilities, including close vision and the ability to adjust focus.</li> </ul> <p><strong>WORK ENVIRONMENT:</strong></p> <p>This position is performed within a <strong>secure, classified workspace</strong>. Employees must comply with all applicable security protocols and access control procedures, including restrictions on personal electronic devices and the handling of sensitive information.</p><div class="content-pay-transparency"><div class="pay-input"><div class="description">Actual salary will be based on a variety of factors, including location, experience, skill set, performance, licensure and certification, and business needs. The range for this position in other geographic locations may differ. Certain positions may also be eligible for variable incentive compensation, such as bonuses or commissions, that is not included in the base salary.</div><div class="title">Estimated Pay Range</div><div class="pay-range"><span>$105,000</span><span class="divider">—</span><span>$122,400 USD</span></div></div></div><div class="content-conclusion"><hr> <p><strong>The Perks</strong></p> <ul> <li>Comprehensive medical, dental and vision plans for you and your dependents</li> <li>401(k) Retirement Plan with Employer Match, 529 College Savings Plan, Health Savings Account, Life Insurance, and Long-Term Disability</li> <li>Competitive Compensation</li> <li>Training and development programs</li> <li>Major offices stocked with snacks and beverages</li> <li>Collaborative and cool culture</li> <li>Work-life balance and generous paid time off</li> </ul> <p> </p> <p><strong>Our Commitment</strong></p> <p>At the core of Trace3's DNA is our people. We are a diverse group of talented individuals who understand the importance of teamwork and demonstrating leadership, character, and passion in all that we do.</p> <p>We’re committed to fostering an inclusive workplace where everyone feels respected, valued, and empowered to grow. We recognize that embracing diversity drives innovation, improves outcomes, fosters collaboration, boosts teammate satisfaction, and builds a more inclusive culture.</p> <p>As an equal opportunity employer, Trace3 bases all employment decisions based on individual qualifications, merit, and business requirements. We do not engage in discrimination on the basis of race, color, religion, sex (including gender identity, sexual orientation, and pregnancy), national origin, age (40 or older), disability, genetic information, or any other characteristic protected by federal, state, or local law.</p> <p>Any demographic information provided is strictly voluntary, kept confidential in accordance with Equal Employment Opportunity (EEO) regulations, and will not be used in employment decisions, including hiring, promotions, or mentorship programs. We are committed to providing equal employment opportunities for all.</p> <p>If you require a reasonable accommodation to complete the application process or participate in an interview, please email <u><a href="mailto:recruiting@trace3.com">recruiting@trace3.com</a></u>.</p> <p> </p> <p><strong>***To all recruitment agencies:</strong> Trace3 does not accept unsolicited agency resumes/CVs. Please do not forward resumes/CVs to our careers email addresses, Trace3 employees or any other company location. Trace3 is not responsible for any fees related to unsolicited resumes/CVs.</p></div>