CACI International Inc→
Cybersecurity Specialist at CACI International Inc in Reston, VA
Skills
Job Description
Summary: CACI International Inc. is seeking Cybersecurity Specialists to protect critical enterprise systems and support secure global operations. The role involves implementing security controls, managing cybersecurity risk, supporting compliance and Risk Management Framework activities, and strengthening the security posture of enterprise, cloud, application, and network environments.
Responsibilities:
- Implement, maintain, and assess cybersecurity controls across enterprise IT systems, cloud environments, applications, and network infrastructure
- Support Risk Management Framework (RMF) activities throughout the system lifecycle, including authorization packages, security documentation, assessments, and continuous monitoring
- Develop, review, and maintain System Security Plans (SSPs), Security Assessment Reports (SARs), Plans of Action and Milestones (POA&Ms), security policies, procedures, and supporting documentation
- Conduct security assessments, vulnerability analysis, compliance reviews, and risk assessments to identify and mitigate cybersecurity threats
- Coordinate vulnerability remediation efforts with engineering and operations teams while tracking corrective actions to completion
- Monitor enterprise security posture using cybersecurity tools, vulnerability scanners, endpoint protection platforms, and security monitoring solutions
- Support security accreditation activities, audits, inspections, and compliance reporting
- Evaluate proposed system changes to determine security impacts and recommend appropriate safeguards
- Participate in incident response activities, forensic support, root cause analysis, and lessons learned documentation
- Collaborate with system administrators, network engineers, cloud engineers, software developers, and Government stakeholders to integrate cybersecurity throughout system design and operations
- Support implementation of Zero Trust principles, cloud security best practices, identity and access management, encryption, and secure configuration standards
- Develop security metrics, dashboards, and reports to communicate cybersecurity performance and risk
- Senior-level professionals may lead cybersecurity engineering efforts, oversee RMF activities, serve as Information System Security Officers (ISSOs), mentor junior staff, and advise Government leadership on enterprise cybersecurity strategy and compliance
Required Qualifications:
- High School diploma with relevant experience or bachelor's degree in Cybersecurity, Information Assurance, Computer Science, Information Technology, Engineering, or a related technical discipline
- Active Secret Clearance
- Experience supporting cybersecurity, information assurance, system security engineering, network security, or information systems security
- Knowledge of cybersecurity principles, risk management, security controls, and secure system design
- Familiarity with vulnerability management, security monitoring, and cybersecurity best practices
- Experience developing technical documentation and communicating cybersecurity risks to technical and non-technical stakeholders
- Strong analytical, troubleshooting, and problem-solving skills
- Excellent written and verbal communication skills
- Ability to obtain and maintain any required Government security clearance
Preferred Qualifications:
- Experience supporting Federal Government or Department of State cybersecurity programs
- Experience serving as an Information System Security Officer (ISSO) or Information System Security Manager (ISSM)
- Experience implementing the NIST Risk Management Framework (RMF) and supporting Authority to Operate (ATO) processes
- Familiarity with NIST SP 800-53, NIST SP 800-171, FISMA, FedRAMP, and other Federal cybersecurity standards
- Experience with vulnerability management tools such as Tenable Nessus, Tenable Security Center, Qualys, or similar platforms
- Experience using security information and event management (SIEM) tools such as Microsoft Sentinel, Splunk Enterprise Security, IBM QRadar, or Microsoft Defender XDR
- Knowledge of cloud security technologies supporting Microsoft Azure, AWS, or Google Cloud Platform (GCP)
- Experience supporting endpoint security, identity and access management (IAM), multi-factor authentication (MFA), PKI, and privileged access management (PAM)
Required Skills: Cybersecurity, Information Assurance, System Security Engineering, Network Security, Risk Management, Security Controls, Secure System Design, Vulnerability Management, Security Monitoring, NIST Risk Management Framework (RMF), Security Information and Event Management (SIEM), Written and Verbal Communication
Benefits: A unique flexible time off benefit, Robust learning resources, Healthcare benefits, Wellness benefits, Financial benefits, Retirement benefits, Family support benefits, Continuing education benefits, Time off benefits