Colorado Springs, CO

Salary
$91,800–$170,900from the description
Posted
Jul 23, 2026
Location
Colorado Springs, CO
Last confirmed open
Jul 24, 2026

What this job asks for AI summary

A cybersecurity engineering role focused on assessing and hardening government systems through compliance audits, vulnerability scanning, and Risk Management Framework (RMF) activities. Day-to-day work involves maintaining authorization documentation in eMASS, conducting security control assessments using tools such as ACAS and STIG Viewer, and coordinating remediation of identified deficiencies. Suits candidates with a DoD security clearance, IAT II certification, and hands-on experience with STIG hardening and federal cybersecurity policy.

Mid level · 2+ years · Colorado Springs, CO · Bachelor's required · Secret clearance · Full-time

Advertised as Principal, but the requirements read as Mid.

Must have (10)
RMFSTIGACAS, Nessus or Tenable.scSCAPSTIG ViewerEvaluate-STIGSTIG ManagerMicrosoft OfficeLinuxeMASS
Nice to have (8)
SIEMRHELAnsible or PythonJiraVMwareElastic StackCISSPOSCP, Osce, Gpen, Gwapt or Gxpn

“or” means any one of them counts — you don't need all of them.

Posted 2 times — it's one opening, so apply once.

We read this from the posting text with AI. Skim the description below before ruling yourself out.

How this req sits in the market our data

What won't set you apart
Linux65%RMF40%

Most people in this occupation already list these. Still required — just not what gets you shortlisted.

What the occupation pays Median $133,758 (middle half $108,740–$165,225). This posting is about at that midpoint.

Estimated from BLS employment for this occupation and area, per-skill prevalence across our listing corpus, and published wage benchmarks — as of Jul 28, 2026. It is a model, not a headcount.

Why we read it this way (8)

This posting covers two levels simultaneously: Level 2 (Cyber Systems Engineer, 2+ years with a Bachelor's) and Level 3 (Principal Cyber Systems Engineer, 5+ years with a Bachelor's). The salary range spans both levels ($91,800–$137,600 for Level 2; $113,900–$170,900 for Level 3). The minimum experience and salary reflect the lower Level 2 gate; the advertised title 'Principal' reflects the upper Level 3 framing.

An active Secret clearance is a hard gate at time of application; Top Secret is listed under Preferred Qualifications.

DoD 8570.01M IAT II certification (Security+ CE, CCNA Security, GSEC, or SSCP) is explicitly required. IAT III (CISSP) is listed as preferred.

The eMASS requirement appears in the Basic Qualifications narrative (working with eMASS records) and is reinforced as a preferred qualification; it is treated as required given the explicit mention in the required duties.

Ansible and Python are listed together as preferred automation tools for STIG/SCAP scanning; they are captured as alternatives on a single preferred skill.

The alt SOC 15-1299 reflects that this role blends security analysis with systems engineering and RMF compliance work, making a pure 15-1212 classification a judgment call.

Ignored 3 non-technology phrase(s) as skills (responsibilities/concepts, not named tools): NIST SP 800-53, NIST SP 800-115, DoD 8570.01M IAT II.

Requires a Secret clearance — the cleared population is a small fraction of this occupation, so the real candidate pool is materially smaller than the estimate below, which does not model clearance.

Read the full posting

The employer publishes the full description on their own site — read it there ↗. Or sign in to read it here — it's free, and it also lets you track this application.

Apply

Apply on employer site ↗