Digital Consultants, LLC Logo

Digital Consultants, LLC

IT Cybersecurity Specialist

Posted 4 Days Ago
Be an Early Applicant
In-Office
San Diego, CA
Senior level
In-Office
San Diego, CA
Senior level
Support ServiceNow security architecture, RMF compliance, continuous monitoring, vulnerability remediation, and ATO activities for DoD environments. Develop SSPs, SARs, POA&Ms, and other RMF artifacts; implement RBAC, ACLs, data policies, encryption, and IL4/IL5 segregation; coordinate with government program managers and authorizing officials; and ensure compliance with NIST, FedRAMP, DoD, and DoDM 8140.03 requirements.
The summary above was generated by AI

Description

Leading with our people, Digital Consultants’ mission is to deliver the highest level of professional solutions while being a trusted partner and advisor to our customers. With a culture of practicality, opportunity, and creativity, we remain dedicated to being honest, trustworthy, respectful, and ethical in everything we do. We are a certified SBA 8(a) small, disadvantaged business that supports multiple IT customers within the Federal, civilian, and private sectors. Digital Consultants also offers our employees growth opportunities, competitive wages, and a full benefits package. Our founding principles, Fairness and Common Sense, make working here more than a job; it’s the Digital family.

Digital Consultants seeks an IT Cybersecurity Specialist to support security architecture, Risk Management Framework (RMF), continuous monitoring, and Authority to Operate (ATO) activities for the DCMA Blue List Program and its ServiceNow environment.

Duties to include: 

  • Architect and implement ServiceNow-specific security controls, including Role-Based Access Controls (RBAC), Access Control Lists (ACLs), Data Policies, and Edge Encryption, to align with the DoD Zero Trust Strategy and enforce strict data segregation between IL4 and IL5 environments. Create and maintain a detailed schema and RBAC matrix outlining roles, groups, ACLs, and data segregation rules. 
  • Adhere to local policy and coordinate with the Government office's IT Program Manager and Authorizing Official (AO) to ensure required cybersecurity protocols are maintained and followed. 
  • Develop and continuously update a comprehensive System Security Plan (SSP) and all required RMF artifacts, mapping ServiceNow platform configurations to NIST SP 800-53, NIST SP 800-171/172 for CUI protection, and DoD IL4/IL5 controls to achieve and maintain the system's ATO.
  • Actively track, manage, and update the Plan of Action and Milestones (POA&M), preferably within ServiceNow GRC/IRM, to document, report, and remediate identified vulnerabilities within Government-provided suspense dates. 
  • Serve as the primary author and developer of the System Security Plan (SSP) and supporting RMF artifacts in direct coordination with the Government IT Program Manager and Authorizing Official (AO) to achieve and maintain the ATO. 
  • Perform technical remediation of ServiceNow configuration-level vulnerabilities within the Specialist’s scope of control; document and track vulnerabilities in third-party custom code/modules in the POA&M while the responsible implementation/development vendor executes code remediation. 
  • Conduct continuous monitoring and provide ongoing Security Assessment Reports (SAR) documenting vulnerability scans, penetration test reviews, and compliance checks prior to code promotion, ensuring the ATO remains valid throughout the system lifecycle. 
  • Meet applicable qualification and certification requirements outlined strictly in DoDM 8140.03. Personnel performing privileged access, cybersecurity, or information assurance functions shall hold certifications appropriate to assigned roles based on DCWF Work Roles and Proficiency Levels, including applicable Foundational and Residential qualifications. 
  • Provide documentation of personnel certifications and qualifications upon request by the CO or COR. 

Requirements

  • Active qualification aligning with DoDM 8140.03 DCWF Work Roles and Proficiency Levels (Foundational and Residential) appropriate for Security Architecture and Engineering (e.g., Security Architect - DCWF 651). 
  • Demonstrated expertise applying federal security directives, including NIST SP 800-53 controls, NIST SP 800-161 (SCRM), and navigating the DoW Risk Management Framework (RMF) to achieve an Authority to Operate (ATO). 
  • Demonstrated experience securing ServiceNow instances in a FedRAMP High and DoD IL4/IL5 environment, including configuring ServiceNow ACLs, Client Scripts, Data Policies, and integrating DoW Enterprise Identity, Credential, and Access Management (E-ICAM)/CAC authentication. 
  • Experience utilizing ServiceNow Governance, Risk, and Compliance (GRC) / Integrated Risk Management (IRM) or Security Operations (SecOps) modules is highly preferred.
  • Clearance: U.S. citizenship required. Personnel shall meet the Tier Three (T3) investigation equivalent (ADP/IT-II) requirement for access to CUI. A completed/current investigation or an investigation in progress is acceptable before commencing work. During onboarding, an individual with an initiated Tier 3 investigation may be granted interim authorization to work, barring unforeseen issues. This also applies to post-award replacement hires. Personnel must obtain a DoW-issued CAC for access to Government spaces and IT systems.
  • Certifications: Active qualification aligning with DoDM 8140.03 DCWF Work Roles and Proficiency Levels (Foundational and Residential) appropriate for Security Architecture and Engineering (e.g., Security Architect - DCWF 651) required. 
  • Education: Bachelor's degree in Cybersecurity, Computer Science, Computer Engineering, or a related technical discipline required. 
  • Experience: Minimum of five (5) years of practical experience required. 
  • Preferred Qualifications: Experience utilizing ServiceNow GRC/IRM or Security Operations (SecOps) modules. 

Physical Requirements: The candidate must be able to travel to other worksites as required and with or without reasonable accommodation, be able to sit, stand, use computers and monitors, and perform duties in an office environment for extended periods. The candidate must be able to lift up to 40 lbs. on occasion (e.g., moving a case of paper or similar task) that may occur occasionally.

Compensation and Benefits: The company offers the following benefits to permanent, full-time employees: 

  • Paid Time Off (PTO) 
  • Group health plans 
  • Income protection and supplemental benefits 
  • 401(k) plan with company matching 
  • Health Savings Account (HSA) 
  • Flexible Spending Account (FSA) 
  • Pet insurance options 
  • Employee Assistance Program (EAP) 

Digital Consultants, an inclusive and welcoming company, is fully committed to hiring and retaining a diverse workforce without regard to race, color, religion, sex (including pregnancy, gender identity, and sexual orientation), genetic information, national origin, age (40 or older), disability, veteran status or any other protected characteristic.

We provide reasonable accommodation to individuals who require assistance at any stage of the employment process. If you need assistance navigating Digital Consultants' job openings or applying for a position, please email [email protected] or call 571-306-3444. Please provide your contact information so we can assist you. 

Similar Jobs

Senior level
Consulting
Architects and implements ServiceNow security controls for DoD IL4/IL5 environments, including RBAC, ACLs, data policies, encryption, and identity integration. Owns ATO and RMF activities by maintaining SSPs, POA&Ms, SARs, and compliance artifacts mapped to NIST and DoD requirements. Conducts continuous monitoring, vulnerability remediation, and penetration-test reviews while coordinating with government program managers and authorizing officials. Ensures personnel qualifications and cybersecurity certifications meet DoD requirements.
Top Skills: Access Control Lists (Acls)Cac AuthenticationData PoliciesDissEdge EncryptionRole-Based Access Control (Rbac)ServicenowServicenow Grc/IrmServicenow Security Operations (Secops)
120K-140K
Senior level
Machine Learning • Consulting • Cybersecurity • Big Data Analytics
Supports cybersecurity architecture, ServiceNow security configuration, RMF and ATO documentation, POA&M and vulnerability management, continuous monitoring, compliance assessments, and identity and access controls for a DoD Blue List program. The role secures ServiceNow environments across DoD IL4/IL5 and FedRAMP High contexts, maintains NIST and CUI control mappings, coordinates remediation and authorization activities, and documents security evidence, risks, and workforce qualifications.
Top Skills: Access Control Lists (Acls)Authority To Operate (Ato)Cac AuthenticationCuiData PoliciesDod Enterprise Identity Credential And Access ManagementDod Il4Dod Il5Dod Zero TrustEdge EncryptionFedramp HighNist Sp 800-161Nist Sp 800-171Nist Sp 800-172Nist Sp 800-53Risk Management Framework (Rmf)Role-Based Access Control (Rbac)ServicenowServicenow Grc/IrmServicenow Security Operations
14 Days Ago
In-Office
130K-160K Annually
Senior level
130K-160K Annually
Senior level
Information Technology
Architect and configure ServiceNow security controls aligned to DoD Zero Trust, enforce IL4/IL5 segregation, manage RBAC/ACLs and CAC/E-ICAM integrations, develop SSPs and RMF artifacts, support ATO attainment/sustainment, manage POA&M, perform vulnerability assessments and continuous monitoring, produce Security Assessment Reports, and coordinate with Government PMs and AOs.
Top Skills: AclsAtoCacContinuous MonitoringDod Il4Dod Il5Dodm 8140.03 DcwfE-IcamEdge EncryptionFedramp HighNist 800-161Nist 800-171Nist 800-172Nist 800-53Poa&MRbacRmfServicenowServicenow GrcServicenow IrmServicenow SecopsSspVulnerability Assessment

What you need to know about the Los Angeles Tech Scene

Los Angeles is a global leader in entertainment, so it’s no surprise that many of the biggest players in streaming, digital media and game development call the city home. But the city boasts plenty of non-entertainment innovation as well, with tech companies spanning verticals like AI, fintech, e-commerce and biotech. With major universities like Caltech, UCLA, USC and the nearby UC Irvine, the city has a steady supply of top-flight tech and engineering talent — not counting the graduates flocking to Los Angeles from across the world to enjoy its beaches, culture and year-round temperate climate.

Key Facts About Los Angeles Tech

  • Number of Tech Workers: 375,800; 5.5% of overall workforce (2024 CompTIA survey)
  • Major Tech Employers: Snap, Netflix, SpaceX, Disney, Google
  • Key Industries: Artificial intelligence, adtech, media, software, game development
  • Funding Landscape: $11.6 billion in venture capital funding in 2024 (Pitchbook)
  • Notable Investors: Strong Ventures, Fifth Wall, Upfront Ventures, Mucker Capital, Kittyhawk Ventures
  • Research Centers and Universities: California Institute of Technology, UCLA, University of Southern California, UC Irvine, Pepperdine, California Institute for Immunology and Immunotherapy, Center for Quantum Science and Engineering

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account