Position Title: IT Cybersecurity Specialist / Cybersecurity Analyst – Blue UAS, ServiceNow RMF and ATO, and Unmanned Systems Product Assessment
Location: San Diego, CA – DCMA Facility (2 positions); Fort Lee, VA – DCMA Facility (2 positions)
Work Type: Full-time, on-site at a DCMA facility.
Position Overview
The Defense Contract Management Agency (DCMA) Special Programs Command, Unmanned Systems-Experimental (US-X), requires cybersecurity professionals to support Phase 1 development of the Blue List Program, the Department of War's cleared list of Blue UAS (Unmanned Aircraft Systems) platforms transferred from the Defense Innovation Unit (DIU) to DCMA.
Roles and Responsibilities
- Architect and implement ServiceNow-specific security controls, including Role-Based Access Controls (RBAC), Access Control Lists (ACLs), Data Policies, and Edge Encryption, to explicitly align with the DoD Zero Trust Strategy.
- Enforce strict data segregation between IL4 (Public) and IL5 (CAC-Authenticated) environments on the Blue List platform, and create and maintain a detailed schema and RBAC matrix outlining all roles, groups, ACLs, and data segregation rules.
- Develop and continuously update a comprehensive System Security Plan (SSP) and all required Risk Management Framework (RMF) artifacts, mapping ServiceNow platform configurations to NIST SP 800-53, NIST SP 800-171 and 800-172 for the protection of Controlled Unclassified Information (CUI), and DoD IL4 and IL5 controls to achieve and maintain the system's Authority to Operate (ATO).
- Actively track, manage, and update the Plan of Action and Milestones (POA&M), preferably within ServiceNow GRC/IRM, to document, report, and remediate identified vulnerabilities within Government-provided suspense dates.
- Conduct continuous monitoring and provide ongoing Security Assessment Reports (SAR) documenting vulnerability scans, penetration test reviews, and compliance checks prior to code promotion, ensuring the ATO remains valid throughout the system's lifecycle.
- Adhere to local policy and coordinate with the Government office's IT Program Manager and Authorizing Official (AO) to ensure required cybersecurity protocols are maintained and followed.
- Serve as a technical subject matter expert supporting the cybersecurity evaluation of product submissions to the Blue List Program.
- Review cybersecurity assessment reports, supporting technical documentation, and assessment evidence to evaluate the completeness, technical sufficiency, and adequacy of assessments in support of Government technical acceptance decisions.
- Interpret cybersecurity assessment methodologies, penetration testing results, vulnerability assessments, software assurance evaluations, firmware analyses, and other technical assessment data sufficient to evaluate cybersecurity risks associated with Blue List candidate technologies.
- Apply knowledge of cybersecurity principles relevant to embedded systems, software, firmware, wireless communications, networking, encryption, authentication, supply chain security, and other technologies relevant to the Blue List Program.
- Identify cybersecurity vulnerabilities, threats, attack vectors, and residual risks that may adversely affect DoW missions, warfighter safety, national security, operational resilience, or the confidentiality, integrity, and availability of Government information and systems.
- Verify and validate whether a submitting company's remediation plan would sufficiently mitigate cyber vulnerabilities identified in provided assessments.
- Provide technical recommendations regarding cybersecurity findings, risk mitigation strategies, assessment requirements, technical acceptance, and the applicability of cybersecurity requirements to Blue List candidate technologies.
- Provide technical expertise, consultation, and advisory support to the Government Blue List Program and its stakeholders regarding cybersecurity requirements, technical standards, risk management, assessment methodologies, and policy implementation.
- Maintain awareness of applicable Federal statutes, DoW policies, National Defense Authorization Act (NDAA) requirements, cybersecurity frameworks, industry best practices, and Government processes relevant to the Blue List Program.
- Monitor emerging cybersecurity threats, vulnerabilities, technologies, and policy developments affecting small unmanned systems and related technologies, and provide recommendations supporting the continued evolution and improvement of the Blue List Program.
- Report 100 % of validated cybersecurity incidents or spills to the COR or Government IT Program Manager within 24 hours of discovery, and support a standard of zero validated unauthorized data leaks subject to randomized security and access control audits by the Government.
Required Qualifications
All candidates must meet the following requirements:
- Demonstrated expertise applying federal security directives, including NIST SP 800-53 controls, NIST SP 800-161 (SCRM), and navigating the DoW Risk Management Framework (RMF) to achieve an Authority to Operate (ATO).
- U.S. citizenship.
- Minimum of five (5) years of practical experience.
- Demonstrated experience securing ServiceNow instances in a FedRAMP High and DoD IL4/IL5 environment, including configuring ServiceNow Access Control Lists (ACLs), Client Scripts, Data Policies, and integrating DoW Enterprise Identity, Credential, and Access Management (E-ICAM)/CAC authentication.
- Active DoW 8570/8140 IAM or IAT Level II or III certification (e.g., CISSP, CISM, or CompTIA Security+).
- Experience interpreting cybersecurity assessment methodologies, penetration testing results, vulnerability assessments, software assurance evaluations, firmware analyses, and other technical assessment data.
Required Education
Bachelor's degree in Cybersecurity, Computer Science, Computer Engineering, or a related technical discipline.
Preferred Qualifications
- Minimum of five (5) years of practical experience for candidates qualifying under Pathway B.
- Experience utilizing ServiceNow Governance, Risk, and Compliance (GRC) / Integrated Risk Management (IRM) or Security Operations (SecOps) modules is highly preferred.
- Qualification under both Pathway A and Pathway B.
Required Clearance Level
Active Public Trust Clearance.
Benefits
- Comprehensive Group Health Plans (Medical, Dental, and Vision) coverage.
- Company-paid Short-Term and Long-Term Disability, Life, and AD&D Insurance.
- Flexible Spending Accounts and Supplemental Plans Available.
- Company-paid Training and Development Programs.
- Generous Paid Time Off and Holiday Pay.
- 401k Retirement Plan with Company Match.
- Critical Illness and Accident Insurance.
- Employee Assistance Program.
About INTECON
Founded in 1999, INTECON has been a trusted leader in delivering cutting-edge technology and strategic solutions for defense, security, and mission-critical operations for over two decades. As an integral part of Aspetto, we go beyond conventional government contracting – driving innovation, anticipating challenges, and developing forward-thinking solutions that enhance operational effectiveness and national security.
Leveraging Aspetto's deep expertise in acquisition, design, deployment, and sustainment, INTECON ensures strategic superiority and mission success for our clients. Our ISO 9001:2015 certification reflects our unwavering commitment to quality, precision, and operational excellence. With a robust suite of capabilities including Enterprise IT & Cloud-Based Technologies, Software Development & Cybersecurity, Data & Analytics, Intelligence & Professional Services, Logistics, and Tactical Equipment. We empower organizations with agile, scalable, and mission-driven solutions.
At INTECON, our dedication to integrity, ingenuity, and client-focused execution positions us as a premier partner in defense and technology. Together with Aspetto, we continue to set new standards of excellence, ensuring the security, resilience, and success of those we serve.
INTECON is proud to be an Equal Opportunity Employer committed to fostering diversity and inclusivity. We firmly uphold the principle of Equal Pay for Equal Work, without regard to race, color, creed, religion, national origin, sex, sexual orientation, gender identity and expression, age, disability, eligible veteran status, or any other protected characteristic. We welcome qualified applicants from all backgrounds and strive to create a workplace where everyone feels valued and respected.
Compensation Disclaimer: The salary range listed reflects a broad span to account for variations in experience, education, certifications, security clearance level, and other job-related factors. Final compensation will be determined based on the candidate's qualifications, relevant experience, and alignment with both company guidelines and contractual rate restrictions established by the Government or customer.
Benefits:
- 401(k) matching
- Dental insurance
- Employee assistance program
- Health insurance
- Professional development assistance
- Tuition reimbursement
- Vision insurance
Application Question(s):
- What is your current annual salary?
- What is your desired annual salary?
- Do you have demonstrated experience securing ServiceNow instances?
- Do you hold an active Public Trust Clearance?
Education:
License/Certification:
- DoD 8570/8140 IAM or IAT Level II or III certification (Required)
Work Location: In person