What are the responsibilities and job description for the Cyber A&A Engineer position at Davis Strategic Innovations Inc.?
Job Description Cyber A&A Engineer Location: Colorado Springs, CO, primarily at Schriever Space Force Base Work arrangement: On-site Clearance: Active, final DoD Top Secret clearance required at start Certification: IAT Level II or higher required at start About the Role DSI is seeking a Cybersecurity Assessment & Authorization (A&A) Engineer to support the ongoing authorization and security of a complex defense mission system. This position combines hands-on vulnerability analysis, security control assessments, risk analysis, and authorization documentation. You will work with cybersecurity and engineering teams, customer representatives, and external stakeholders to evaluate system vulnerabilities, document risks, and develop engineering responses that support system security and mission requirements.
Responsibilities Analyze Assured Compliance Assessment Solution (ACAS), SCAP Compliance Checker (SCC), and ConfigOS scan results to identify vulnerabilities, configuration issues, and security control deficiencies. Review Security Technical Implementation Guides (STIGs), Risk Management Framework (RMF) controls, and supporting evidence to assess compliance and support continuous system authorization. Develop engineering responses for Plans of Action and Milestones (POA&Ms) and perform risk analysis supporting Risk Acceptance Requests (RARs).
Assess account management practices and collaborate with system owners and engineering teams to address identified security concerns. Assist with creating and maintaining system authorization packages in eMASS and Xacta. Prepare technical documentation and communicate assessment findings, risks, and recommended corrective actions to internal and external stakeholders.
Required Qualifications Bachelor's degree in a related discipline and 5 years of relevant experience; an advanced degree and 3 years of relevant experience; or an equivalent combination of education and experience. Active, final DoD Top Secret clearance and the required Level II or higher cybersecurity certification at the time of hire. Strong cybersecurity engineering skills and working knowledge of RMF, NIST SP 800-53 security controls, and applicable DoD cybersecurity requirements.
Thorough understanding of ACAS and SCC outputs, including hands-on experience reviewing vulnerability scan data, STIGs, and RMF controls. Experience with eMASS and the assessment and authorization of Cross Domain Solutions (CDS). Strong technical writing and verbal communication skills, with the ability to work independently under general direction and collaborate across technical teams.
Preferred Qualifications Experience managing Cyber Tasking Orders (CTOs), Information Assurance Vulnerability Management (IAVM) requirements, and POA&Ms. Experience supporting third-party assessors and auditors, conducting cybersecurity self-assessments, and analyzing STIG compliance. Experience managing and auditing user accounts.
Understanding of patch and configuration management across complex enterprise environments containing diverse systems and technologies.