DARC Cyber Systems Engineer
1 day ago
Colorado Springs
Job DescriptionJob Title: DARC Cyber Systems EngineerJob Description The DARC Cyber Systems Engineer plays a key role in assessing, securing, and continuously monitoring complex systems and networks that directly support national security. In this role, you perform detailed cybersecurity assessments, develop and maintain Risk Management Framework (RMF) documentation, and help ensure systems meet stringent Department of Defense and federal cybersecurity requirements. You collaborate closely with engineering teams, program offices, and cybersecurity personnel to translate policy into effective technical controls, drive remediation of vulnerabilities, and support assessment and authorization activities across the program. Responsibilities • Perform assessments of systems and networks to identify deviations from acceptable configurations, enclave policies, and local policies using passive evaluation tools such as STIG Viewer, SCAP, Evaluate-STIG, and STIG Manager., • Author, update, and review security testing documentation, including security assessment plans, test cases, and cyber test methodologies to support continuous monitoring., • Conduct annual security controls assessments and provide input for Security Assessment Reports (SAR) and Risk Assessment Reports (RAR)., • Collaborate with System Program Office (SPO) contractors and government personnel to support RMF Cybersecurity Engineers in updating systems records in eMASS., • Coordinate, collect, prepare, and maintain RMF body-of-evidence documentation related to operational processes, procedures, and site-specific information., • Prepare and update artifacts that support Assessment and Authorization activities, including Plan of Actions and Milestones (POA&M)., • Perform assessments of RMF artifacts and identify where they deviate from RMF control requirements, recommending corrective actions as needed., • Assist in implementing government cybersecurity policy, such as NISPOM, NIST, DoD directives, and Air Force Instructions, by making recommendations on process tailoring, participating in process activities, and documenting results., • Establish and maintain strict program control processes to mitigate risks and support system assessment and authorization, including compliance documentation, certification testing, analysis, coordination, and control of inspections and audits., • Support investigations, software research, hardware introduction and release, and emerging technology research to ensure cybersecurity requirements are met., • Perform analyses to validate established cybersecurity controls and requirements and recommend additional cybersecurity safeguards where appropriate., • Coordinate across the program to address deficiencies identified during RMF assessment activities and track their remediation., • Conduct vulnerability and compliance scans using Assured Compliance Assessment Solution (ACAS), Nessus, and tenable.sc, and analyze findings., • Apply STIG hardening techniques to Linux and RHEL environments to improve system security posture., • Create and maintain technical documentation and analysis reports using Microsoft Office tools., • Support SIEM and log aggregation configurations and usage as needed to enhance monitoring and incident detection capabilities., • Contribute to penetration testing and advanced assessment activities when aligned with program needs and personal certifications., • Perform other cybersecurity engineering duties as assigned to support mission objectives and program requirements.Essential Skills, • Experience with the Risk Management Framework (RMF) Cybersecurity Lifecycle, including generating testable requirements, identifying resilient architecture designs, analyzing vulnerability findings, conducting verification testing of compliance assessments, and configuring, running, and scripting audit tools., • Hands-on experience performing vulnerability and compliance scans using ACAS, Nessus, and tenable.sc., • Proficiency with Security Technical Implementation Guides (STIGs) and STIG hardening of systems., • Linux system administration experience, including configuration and security hardening (RHEL experience is highly relevant)., • Working knowledge of cybersecurity technologies and Department of Defense and federal cybersecurity policies such as DoDI 8500.01, NIST SP 800-53, and NIST SP 800-115., • Technical documentation and analysis experience with strong proficiency in the Microsoft Office tool suite., • Familiarity with POA&M development and management, and experience maintaining RMF artifacts and eMASS records., • Ability to coordinate and maintain RMF body-of-evidence documentation and support Assessment and Authorization activities., • Bachelor’s degree with 2 years of professional experience, or Master’s degree with 0 years of professional experience for Level 2 roles., • Bachelor’s degree with 5 years of professional experience, or Master’s degree with 3 years of professional experience, or PhD with 1 year of professional experience for Level 3 roles., • Current DoD 8570.01M IAT II certification such as Security+ CE, CCNA Security, GSEC, or SSCP., • Active U.S. Government Secret security clearance at the time of application, current and within scope., • Strong security engineering skills with the ability to validate cybersecurity controls and recommend safeguards.Additional Skills & Qualifications, • Experience using or configuring SIEM and log aggregation software, including solutions such as ELK stack., • Experience conducting cybersecurity assessments specifically in RHEL environments., • Understanding of networking concepts including subnetting, firewalls, NAT, ACLs, and VLANs., • Advanced experience with ACAS, Nessus, and tenable.sc, including complex configurations and analysis., • Penetration testing-focused certifications such as OSCP, OSCE, GPEN, GWAPT, or GXPN., • Active Top Secret security clearance., • Experience working with tools such as STIG Viewer, SCAP, Evaluate-STIG, and STIG Manager., • Familiarity with government cybersecurity policies and guidelines including NISPOM, NIST standards, DoD directives, and Air Force Instructions., • Ability to collaborate effectively with cross-functional teams, including program offices, contractors, and government cybersecurity personnel., • Strong analytical and problem-solving skills, with the ability to address complex, technically challenging cybersecurity issues., • Capacity to obtain final clearances and program accesses within a reasonable period as determined by the organization.Work Environment This is a full-time, Monday through Friday, onsite position located in a modern facility near the Colorado Springs Airport (COCO-1 building), with no on-base work required. The role is embedded in the DARC program, where mission-driven professionals tackle high-impact, technically complex challenges that operate at real-world, operational scale. You work closely with elite engineers, leaders, and mission partners in a collaborative environment that values innovation, rigorous problem-solving, and rapid transition from concept to deployment. The culture emphasizes meaningful purpose, accelerated professional growth, and long-term program stability, offering an opportunity to build a career around some of the most important work in national security. You use a range of cybersecurity tools and technologies, including RMF platforms such as eMASS, vulnerability assessment tools like ACAS, Nessus, and tenable.sc, STIG and compliance tools, SIEM and log aggregation solutions, and Linux/RHEL systems, all within a professional office setting. Job Type & Location This is a Contract position based out of Colorado Springs, CO. Pay and Benefits The pay range for this position is $140000.00 - $165000.00/hr. Individual compensation offered for this position within this range will depend on many factors, including qualifications, skills, relevant experience, job knowledge, geographic location, internal equity, and other pertinent job-related factors. Eligibility requirements apply to some benefits and may depend on your job classification and length of employment. Benefits are subject to change and may be subject to specific elections, plan, or program terms. If eligible, the benefits available for this temporary role may include the following: • Medical, dental & vision • Critical Illness, Accident, and Hospital • 401(k) Retirement Plan – Pre-tax and Roth post-tax contributions available • Life Insurance (Voluntary Life & AD&D for the employee and dependents) • Short and long-term disability • Health Spending Account (HSA) • Transportation benefits • Employee Assistance Program • Time Off/Leave (PTO, Vacation or Sick Leave) Workplace Type This is a fully onsite position in Colorado Springs,CO. Application Deadline This position is anticipated to close on Sep 7, 2026. About Actalent Actalent is a global leader in engineering and sciences services and talent solutions. We help visionary companies advance their engineering and science initiatives through access to specialized experts who drive scale, innovation and speed to market. With a network of almost 20,000 consultants and 5,000 clients across the U.S., Canada, Asia and Europe, Actalent serves many of the Fortune 500. We are proud to be an Engineering News-Record (ENR) Top 500 Design Firm for our engineering design services and a ClearlyRated Best of Staffing® winner for both client and talent service. The company is an equal opportunity employer and will consider all applications without regard to race, sex, age, color, religion, national origin, veteran status, disability, sexual orientation, gender identity, genetic information or any characteristic protected by law. If you would like to request a reasonable accommodation, such as the modification or adjustment of the job application process or interviewing process due to a disability, please email actalentaccommodation@actalentservices.com for other accommodation options. San Francisco Fair Chance Ordinance: Pursuant to the San Francisco Fair Chance Ordinance, for all positions located in the city and county of San Francisco, we will consider for employment qualified applicants with arrest and conviction records. Massachusetts Lie Detector: It is unlawful in Massachusetts to require or administer a lie detector test as a condition of employment or continued employment. An employer who violates this law shall be subject to criminal penalties and civil liability. Use of Artificial Intelligence (AI): We may use Artificial Intelligence (AI) to support parts of our hiring process, including sourcing, screening, and evaluating candidates. AI helps assess applications and qualifications, but final decisions are made by our hiring team. By applying, you acknowledge and agree that your application may be reviewed using AI tools.