user avatar

Cybersecurity Assessment and Authorization Subject Matter Expert

VivSoft Technologies LLC

Posted 2 weeks ago

Job Requirements

Remote
Secret Polygraph Unspecified
Career Level not specified
Salary not specified
Join Premium to unlock estimated salaries

Job Description

Title: Cybersecurity Assessment and Authorization Subject Matter Expert (SME)
Location: Remote
Clearance Required: DoD Secret clearance
Position Type: Full-Time

About VivSoft:

At VivSoft, we aim to solve complex federal problems using emerging and open technologies in a collaborative and rewarding environment. VivSoft is a diverse team of strategists, engineers, designers, and creators experienced in building high performance effective softwares, with impactful organizational design and organizational dynamics for software delivery. We build secure Software Factories based on DoD reference designs and NIST Frameworks for Cloud and DevSecOps. These factories deliver AI/ML Applications, Data Science Platforms, Blockchain and Microservices for DoD, Healthcare and Civilian Agencies

Job Summary
The Defense Logistics Agency (DLA) is seeking an experienced Cybersecurity Assessment and Authorization (A&A) Subject Matter Expert (SME) to support the sustainment and security of the Contingency and Adaptive Planning Software Integration System (CAPSIS), a mission‑critical analytics platform operating on the classified SIPRNet.
This role serves as the technical authority for RMF/ATO activities, ensuring continuous compliance with DoD Information Assurance (IA) requirements, NIST 800‑53, DISA STIGs, and CCRI standards throughout the system lifecycle. The SME will work closely with DLA IA, cybersecurity, infrastructure, and program teams while briefing senior leadership on risk posture and authorization status.

Job Responsibilities
  • Serve as a technical SME supporting Cybersecurity Assessment & Authorization programs and CCRI activities
  • Perform advanced cybersecurity assessments, vulnerability assessments, and penetration testing across networks, applications, databases, and IT infrastructures
  • Provide interpretation and expert guidance on DoD cybersecurity regulations, RMF, DISA STIGs, and SCAP
  • Lead or support CCRI inspections and serve as a CCRI Team Lead when assigned
  • Recommend cybersecurity tools and assist in defining requirements and selection criteria
  • Develop and support product-specific STIGs based on applicable DISA SRGs
  • Analyze complex security findings and deliver actionable, innovative remediation strategies
  • Provide expert written reports, technical briefings, and oral presentations to stakeholders
  • Independently plan and execute assignments aligned with long-term cybersecurity goals
  • Contribute to advanced cybersecurity initiatives, including Contingency and Adaptive Planning Software Integration System (CAPSIS) efforts.

Skills Required
  • Must possess an active DoD Secret Clearance
  • 7+ years of IT experience
  • 5+ years of hands-on cybersecurity experience
  • Extensive experience performing CCRI, vulnerability assessments, and penetration testing
  • Strong practical expertise in network implementation and configuration (routers, switches, firewalls)
  • In-depth knowledge of RMF, SCAP, DoD security regulations, and DISA STIGs
  • Proven experience conducting cybersecurity evaluations and compliance inspections
  • Proficiency in security tools and technologies, including NESSUS, SCCM, VULNERATOR, the USCYBERCOM CTO Compliance Program, wireless vulnerability assessment tools, web services (IIS, Apache, Proxy), databases (SQL Server, Oracle), email services (Microsoft Exchange), and conducting phishing exercises, USB detection, and physical security assessments
  • Strong analytical, problem-solving, and documentation skills
  • Excellent written and verbal communication skills

Certifications Required
  • DISA FSO‑certified CCRI Team Lead
  • CCRI certification in one or more assessment domains, including Retina Scan Analysis, Operating Systems (Windows/Unix), Boundary Defense, Internal Defense, DNS, HBSS (ePO, AV, HIPS, ABM, PA), Traditional Security (Common, Basic, NCV, SCV), and Wireless Communications.
  • One or more advanced penetration testing certifications, such as Licensed Penetration Tester (LPT), Certified Expert Penetration Tester (CEPT), Certified Ethical Hacker (CEH), or GIAC Penetration Tester (GPEN).
  • Tenable Certified Nessus Auditor
  • Additional relevant certification from a nationally recognized technical authority

Benefits
  • Comprehensive Medical, Dental, and Vision Plans (Healthcare benefits are 100% employer-paid for employees only)
  • Life Insurance
  • Paid Time Off (Flexible/Combined PTO, Bereavement Leave, 11 Company Paid Holidays)
  • 401K Retirement Plan with employer match
  • Professional Development Training Reimbursement.
group id: 10473000

Similar Jobs


Job Category
IT - Security
Clearance Level
Secret