SBG Technology Solutions, Inc. logo
SBG Technology Solutions, Inc.
Posted 59 days agoVerified live 14h ago

Cybersecurity Specialist - Mid/Senior - SBG

Brief overview

Remote
UndergradOr in progress
$130k–$170k/yrStated range
8+ yrsMinimum
FedRAMP High security controlsNIST Risk Management Framework (RMF)Security architecture reviewCloud security engineeringAWS Government cloud environmentVulnerability management assessmentsContinuous monitoring programsIdentity and access management (IAM)Encryption standardsAccess control frameworksAuthorization documentation developmentSystem Security Plans (SSPs)Plan of Action and Milestones (POA&M)Security assessment reportsHIPAA Security RuleAWS Security HubAWS GuardDuty

About the company

SBG Technology Solutions, Inc. logo
SBG Technology Solutions, Inc.sbgts.com

SBG Technology Solutions, Inc.

Job description

Summary

SBG Technology Solutions, Inc. (SBG), a DSS, Inc. company, offers IT Governance, Systems Engineering, Enterprise Modernization, Artificial Intelligence, and Cyber Security innovation to federal and commercial clients nationwide. The Cybersecurity Specialist ensures all applications meet FedRAMP High security and compliance requirements and supports Independent Software Vendors (ISVs) and government applications by identifying security gaps and validating alignment with federal cybersecurity frameworks.

Responsibilities

  • Assesses application security posture, including logging, auditing, and control implementation, against FedRAMP High baseline requirements
  • Supports Authority to Operate (ATO) documentation efforts and compliance readiness activities for applications undergoing onboarding assessment
  • Identifies cybersecurity gaps across assessed applications and recommends prioritized remediation actions with supporting rationale
  • Evaluates application and environment alignment with Zero Trust architecture principles and continuous monitoring requirements
  • Supports development of System Security Plans (SSPs), Plan of Action and Milestones (POA&M) inputs, and related security authorization artifacts
  • Applies Risk Management Framework (RMF) processes to security assessment activities and documents findings in accordance with NIST guidelines
  • Reviews identity, access control, and encryption implementations to verify compliance with applicable standards and FedRAMP controls
  • Conducts vulnerability management reviews and evaluates continuous monitoring capabilities for onboarding candidates
  • Collaborates with cloud architects, program managers, and ISV technical teams to communicate security findings and guide remediation planning
  • Performs other duties as assigned by management in support of SBG Technology Solutions contract objectives

Skills

  • In-depth knowledge of FedRAMP High security controls and the NIST Risk Management Framework (RMF) process
  • Proficiency in security architecture review and cloud security engineering within AWS or comparable government cloud environments
  • Experience conducting vulnerability management assessments and evaluating continuous monitoring programs
  • Working knowledge of identity and access management (IAM), encryption standards, and access control frameworks
  • Ability to develop and review authorization documentation including SSPs, POA&Ms, and security assessment reports
  • Strong analytical and written communication skills; able to document and present security findings clearly to both technical and non-technical audiences
  • Capable of managing concurrent assessment workstreams and delivering findings within defined project timelines
  • Bachelor's degree in Cybersecurity, Information Technology, Computer Science, or a related technical discipline
  • A combination of education and experience will be considered (2 years of relevant experience equivalent to 1 year in a degree program)
  • 8+ years of cybersecurity experience in federal or regulated environments, with demonstrated engagement in FedRAMP or RMF processes
  • Must be a US Citizen
  • Must be able to pass a Federal background check
  • Must be determined suitable for federal employment
  • Familiarity with HIPAA Security Rule requirements and healthcare application security considerations
  • Experience with AWS security tooling (e.g., AWS Security Hub, GuardDuty, CloudTrail, Config)
  • Knowledge of DevSecOps practices and secure software development lifecycle (SSDLC) methodologies
  • Master's degree in Cybersecurity, Information Assurance, or a related field
  • + Certified Information Systems Security Professional (CISSP)
  • + Certified Information Security Manager (CISM)
  • + CompTIA Security+ or equivalent federal baseline certification
  • + AWS Certified Security – Specialty
  • 10+ years of cybersecurity experience including direct responsibility for ATO support or FedRAMP authorization activities

Qualifications

Must Haves

  • In-depth knowledge of FedRAMP High security controls and the NIST Risk Management Framework (RMF) process
  • Proficiency in security architecture review and cloud security engineering within AWS or comparable government cloud environments
  • Experience conducting vulnerability management assessments and evaluating continuous monitoring programs
  • Working knowledge of identity and access management (IAM), encryption standards, and access control frameworks
  • Ability to develop and review authorization documentation including SSPs, POA&Ms, and security assessment reports
  • Strong analytical and written communication skills; able to document and present security findings clearly to both technical and non-technical audiences
  • Capable of managing concurrent assessment workstreams and delivering findings within defined project timelines
  • Bachelor's degree in Cybersecurity, Information Technology, Computer Science, or a related technical discipline
  • A combination of education and experience will be considered (2 years of relevant experience equivalent to 1 year in a degree program)
  • 8+ years of cybersecurity experience in federal or regulated environments, with demonstrated engagement in FedRAMP or RMF processes
  • Must be a US Citizen
  • Must be able to pass a Federal background check
  • Must be determined suitable for federal employment

Nice to Haves

  • Familiarity with HIPAA Security Rule requirements and healthcare application security considerations
  • Experience with AWS security tooling (e.g., AWS Security Hub, GuardDuty, CloudTrail, Config)
  • Knowledge of DevSecOps practices and secure software development lifecycle (SSDLC) methodologies
  • Master's degree in Cybersecurity, Information Assurance, or a related field
  • + Certified Information Systems Security Professional (CISSP)
  • + Certified Information Security Manager (CISM)
  • + CompTIA Security+ or equivalent federal baseline certification
  • + AWS Certified Security – Specialty
  • 10+ years of cybersecurity experience including direct responsibility for ATO support or FedRAMP authorization activities

Benefits

  • RemoteType: Fully Remote

More jobs like this