← Back to results

nist-sp-800-53 jobs in San Diego

$87,408 – $127,332 · Posted 2 days ago

As a Research Cybersecurity Analyst, you will review research contracts, proposals, and data-use agreements to identify security and compliance requirements, then conduct risk assessments and recommend practical safeguards. You will coordinate security controls across cloud and on-premises research environments, assess architectures for identity management, encryption, and network segmentation, and develop compliance documentation (SSPs, POA&Ms) for sponsor audits and CMMC readiness.… You will work with researchers, IT teams, and compliance partners to interpret regulatory requirements, map them to controls, and explain technical security obligations in practical terms to non-technical stakeholders. Experience in NIST frameworks, security assessments, vulnerability management, and regulated environments (higher education, research, healthcare, government, defense) is especially valued.

San DiegoLast seen 1 day ago
$87,408 – $127,332 · Posted 3 days ago

This role supports research teams at a university by reviewing security requirements in research contracts and proposals, conducting risk and compliance assessments, and recommending practical security approaches. The analyst will coordinate security controls across cloud and on-premises research environments, assess security architectures and configurations, and develop compliance documentation including SSPs and POA&Ms.… The role requires interpreting cybersecurity frameworks (NIST SP 800-171, CMMC, NIST SP 800-53) and communicating technical requirements to researchers and non-technical stakeholders across identity and access management, encryption, vulnerability management, and network security.

San DiegoLast seen 1 day ago
$87,408 – $127,332 · Posted 4 days ago

Research Cybersecurity Analyst at San Diego State University responsible for reviewing research proposals, contracts, and data-use agreements to identify cybersecurity and compliance requirements; conducting risk assessments and recommending remediation strategies; coordinating security controls across cloud and on-premises research environments; and developing compliance documentation (SSPs, POA&Ms) to support audits and assessments. The role requires interpreting security frameworks (NIST SP 800-171, CMMC, NIST SP 800-53) and communicating technical requirements to researchers and non-technical stakeholders while evaluating security architectures, access controls, encryption, and vulnerability management.

San DiegoLast seen 2 days ago
$69,300 – $158,000 · Posted 7 days ago

Lead the design and implementation of advanced security capabilities within Microsoft Azure Government, with responsibility for Azure security architecture, Microsoft Sentinel, Defender, Azure Policy, identity, logging, DevSecOps, and Infrastructure as Code. Guide a small engineering team through technical workstreams that strengthen cloud security, modernize cyber operations, improve security telemetry, and advance continuous security assurance aligned with federal requirements.… Move fluidly between architecture and hands-on engineering to drive work from concept through operational adoption, including identifying configuration drift, automating response, and creating measurable evidence of security control effectiveness. Modernize security data and logging architectures to optimize telemetry collection and maintain visibility against sophisticated threats.

San DiegoLast seen 5 days ago
Posted 11 days ago

CyberSecurity Engineer III will design, deploy, and administer Secret and Top Secret infrastructure across on-premises and private cloud environments, managing VMware virtualization, RHEL/Windows systems, and network infrastructure. The role requires implementing security controls per NIST SP 800-53 and DISA guidelines, automating system builds and patching with Ansible and Jenkins, and remediating vulnerabilities using tools like Nessus and Splunk.… You'll collaborate across infrastructure, cybersecurity, and mission teams to maintain secure environments throughout development, accreditation, and operations, with five or more years of infrastructure engineering or systems administration experience required.

San DiegoLast seen 9 days ago
$125,000 – $180,000 · Posted 12 days ago

The IT Cybersecurity Specialist will architect and implement ServiceNow-specific security controls (RBAC, ACLs, Data Policies, Edge Encryption) aligned to DoD Zero Trust Strategy for the Blue UAS Cleared List platform. The role requires developing and maintaining System Security Plans and RMF artifacts, mapping ServiceNow configurations to NIST SP 800-53 and NIST SP 800-171/172 standards, and tracking POA&M to remediate vulnerabilities and maintain Authority to Operate.… The specialist will coordinate with Government IT Program Managers and Authorizing Officials, conduct continuous monitoring, provide Security Assessment Reports, and ensure personnel meet DoDM 8140.03 certification requirements. This position requires a bachelor's degree, five years of practical cybersecurity experience, active DoD security clearance, and demonstrated expertise securing ServiceNow instances in FedRAMP High and DoD IL4/IL5 environments.

San DiegoLast seen 10 days ago
Posted 13 days ago

ManTech seeks an Information System Security Officer to maintain Assessment & Authorization (A&A) documentation per NIST and DoD standards, track compliance deficiencies via Plans of Action and Milestones, implement continuous monitoring strategies, and oversee audit log systems and patch management. The role requires managing security tools, evaluating system configuration changes, and supporting an Information System Security Manager (ISSM) with compliance and incident response procedures.… Candidates must hold Security+ certification, have 2+ years of RMF and NIST SP 800-53 experience, and possess an active Top Secret clearance with SCI eligibility.

San DiegoLast seen 12 days ago
Posted 17 days ago

Design and implement secure system architectures for complex defense and aerospace programs, ensuring compliance with DoD and NIST cybersecurity standards (DORI 8500.02, CNSSI 1253, NIST SP 800-53, NIST SP 800-171). Perform vulnerability assessments, risk management, and security evaluations across hardware and software; develop Risk Management documents and Secure Technical Implementation Guides; serve as liaison between cybersecurity, hardware, software, and program management to identify and remediate security issues.… Requires hands-on understanding of both system operations and hardware-software interactions, with ability to communicate technical security solutions to engineering and leadership teams.

San DiegoLast seen 15 days ago
$150,000 – $185,000 · Posted 22 days ago

As an Information System Security Manager, you will oversee cybersecurity and operations of multiple classified systems, managing personnel and developing enterprise-wide RMF-based information security policies, standards, and procedures. You will maintain compliance with federal and DoD security standards, create and maintain System Security Plans, conduct continuous monitoring, perform risk assessments, and investigate security incidents.… You will coordinate with ISSEs, ISAs, and other security roles to design, procure, build, and accredit complex networks and systems across multiple classification levels. Required: Bachelor's degree in Information Security/IT or equivalent with 10+ years experience, DoD 8570.01-M IAM level III certification (CISSP, CISM, GSLC, or CCISO), RMF and NIST 800-53 expertise, and an active TS/SCI clearance.

San DiegoLast seen 20 days ago
$150,000 – $215,000 · Posted 1 month ago

Senior Software Engineer responsible for architecting and executing deployment of an AI-enabled product suite to government-authorized cloud environments (IL6, JWICS). The role spans full-stack development (React/Node/Python), DevSecOps hardening, security controls implementation (NIST SP 800-53, OSCAL), and compliance documentation.… You'll mentor engineers on secure design, translate between government compliance requirements and engineering execution, and serve as the technical subject matter expert guiding cross-functional teams through a complex, regulated deployment.

San DiegoLast seen 10 days ago
Posted 1 month ago

This Security Engineer role owns continuous cloud security posture management (CSPM) and vulnerability management across AWS accounts, detecting misconfigurations and driving remediation at scale. The person will build reusable Terraform modules, Service Control Policies, and policy-as-code guardrails to make secure-by-default infrastructure; design least-privilege IAM; govern secrets and encryption; and build cloud-native detections (CloudTrail, GuardDuty, Config, Security Hub) with automated remediation.… They'll map technical controls to compliance frameworks (CMMC, NIST SP 800-171, FedRAMP), support the SOC team investigating cloud incidents, and feed findings back into new guardrails. The role requires 3+ years of hands-on cloud security or DevSecOps experience, strong AWS expertise, Terraform and policy-as-code proficiency, and the ability to obtain a U.S. security clearance.

San DiegoLast seen 1 month ago
$86,900 – $198,000 · Posted 1 month ago

Lead the design and implementation of advanced security capabilities within Microsoft Azure Government, driving technical workstreams across Azure security architecture, Microsoft Sentinel, Defender, Azure Policy, identity, logging, and Infrastructure as Code. You will architect cloud security solutions, modernize security data and logging architectures, automate configuration-drift detection and response, and guide a small engineering team from concept through operational adoption.… The role requires 5+ years of Azure security engineering experience, expertise with Azure Government, Sentinel, Defender, Azure Monitor, Terraform, and cloud identity platforms, plus the ability to move between architecture and hands-on engineering work.

San DiegoLast seen 1 month ago
$86,900 – $198,000 · Posted 1 month ago

Lead the design and implementation of advanced security capabilities within Microsoft Azure Government, driving technical workstreams across cloud security architecture, Microsoft Sentinel, Defender, Azure Policy, identity, logging, DevSecOps, and Infrastructure as Code. Modernize security data and logging architectures to collect appropriate telemetry, identify configuration drift, validate security controls, automate response, and create measurable evidence of security posture.… Guide a small engineering team from concept through operational adoption, balancing architecture-level strategy with hands-on engineering execution. This role requires 5+ years of Azure security experience, hands-on expertise with Sentinel, Defender, and Azure Monitor, and the ability to align solutions with federal security requirements.

San DiegoLast seen 1 month ago
$180,000 – $200,000 · Posted 1 month ago

This is a senior infrastructure and cybersecurity engineering role requiring 10+ years of experience designing, administering, and securing hybrid/cloud infrastructure across Linux, Windows Server, containerized, and private cloud environments. The engineer will implement security controls aligned with NIST SP 800-53, DISA STIGs, RMF, and Zero Trust principles, support DevSecOps pipelines and CI/CD automation, and use scripting, configuration management, and Infrastructure as Code to streamline builds, patching, hardening, and compliance.… The role demands collaboration across cybersecurity, software, infrastructure, and mission teams to troubleshoot complex issues, improve security practices, and communicate technical risks and recommendations.

San DiegoLast seen 1 month ago
Posted 1 month ago

This role designs and implements cybersecurity architecture for complex electromagnetic and power systems across defense, space, and commercial programs. The Cybersecurity Architect develops secure network and system architectures aligned to NIST, DoD, and customer standards; performs vulnerability assessments and risk management; and serves as a technical liaison between security, hardware, software, and program teams.… The position requires deep expertise in cyber standards (NIST SP 800-53, NIST SP 800-171, DODI 8500.02, CNSSI 1253), secure system design, and incident response, plus the ability to communicate complex security issues and remediation strategies across all organizational levels.

San DiegoLast seen 1 month ago
Posted 1 month ago

Security Operations Analyst role monitoring and triaging alerts across endpoint, cloud, identity, network, and SaaS using enterprise SIEM and XDR platforms. Responsibilities include investigating alerts, performing root-cause analysis, tuning detections, owning initial response for mid-tier incidents, participating in on-call rotation, running targeted threat hunts, and contributing to playbooks and post-incident reviews.… Requires 2–5 years of hands-on SecOps, SOC, or incident response experience; proficiency with enterprise SIEM query languages, EDR tooling, and scripting in Python/PowerShell/Bash; and solid understanding of MITRE ATT&CK and network fundamentals.

San DiegoLast seen 1 month ago
$110,000 – $155,000 · Posted 1 month ago

The Cybersecurity Analyst will serve as a technical subject matter expert evaluating the cybersecurity posture of drone systems and components submitted to the Blue UAS Cleared List Program. You will review assessment reports, identify vulnerabilities and residual risks, validate remediation plans, and provide technical recommendations on compliance with NIST frameworks and DoD Risk Management Framework requirements.… The role requires expertise in embedded systems security, firmware analysis, wireless communications, encryption, authentication, and supply chain security. You must hold an active DoD 8570/8140 IAM or IAT Level II/III certification (CISSP, CISM, or Security+) and demonstrate proficiency with NIST SP 800-53 and NIST SP 800-161.

San DiegoLast seen 1 month ago
$180,000 – $200,000 · Posted 1 month ago

This role supports cybersecurity engineering and infrastructure security for enterprise, cloud, and classified environments. The engineer will manage vulnerability assessment, system hardening, patching, secure configuration, and DevSecOps pipeline integration across Linux and Windows Server platforms.… Responsibilities include compliance support (RMF, ATO, NIST SP 800-53, DISA STIGs), CI/CD security automation, containerized environment hardening, and infrastructure-as-code implementation. Strong technical depth in cloud platforms (AWS/AWS GovCloud), container orchestration, security tooling, and the ability to communicate complex technical and compliance issues to engineering and mission stakeholders are required.

San DiegoLast seen 1 month ago
$135,000 – $150,000 · Posted 1 month ago

Implement, assess, and authorize security controls for IT management systems under the Risk Management Framework (RMF). Conduct security reconnaissance, identify gaps, develop Plans of Action and Milestones (POA&Ms), and maintain A&A documentation (SSPs, SAPs, SARs).… Manage eMASS compliance, STIG assessments, and coordinate accreditation workflows. Requires 10+ years of cybersecurity experience, an active Secret clearance, IAT Level III certification (CISSP preferred), and hands-on A&A and ATO submission experience.

San DiegoLast seen 1 month ago
$120,000 – $140,000 · Posted 1 month ago

The IT Cybersecurity Specialist will architect and implement ServiceNow security controls aligned with DoD cybersecurity requirements, including Role-Based Access Controls, Data Policies, and Edge Encryption. The role requires developing and maintaining RMF/ATO documentation, mapping configurations to NIST SP 800-53/800-171/172 and DoD IL4/IL5 controls, and managing Plans of Action and Milestones for vulnerability remediation.… The candidate will conduct continuous monitoring activities, compliance checks, and security assessments to maintain the Blue List platform's Authority to Operate and ensure alignment with DoD Zero Trust Strategy and CUI protection requirements.

San DiegoLast seen 1 month ago
Posted 1 month ago

Lead detection operations, incident response, and security operations maturation for a growing security team. Operate SIEM/XDR across endpoint, cloud, identity, network, and SaaS telemetry; conduct complex investigations; tune detections; and drive root-cause analysis and post-incident improvements.… Require 6+ years of hands-on security operations, detection engineering, or incident response experience with deep proficiency in SIEM/XDR query languages, EDR platforms, scripting (Python, PowerShell, Bash), and MITRE ATT&CK framework application. Mentor analysts, define playbooks and runbooks, lead threat hunts, and own SecOps metrics and operational-readiness reporting.

San DiegoLast seen 1 month ago
$140,000 – $180,000 · Posted 1 month ago

The Information Systems Security Manager will develop, implement, and maintain the company's information security policies and compliance programs aligned with NIST SP 800-171, DFARS, ISO 27001, and CMMC requirements. Responsibilities include overseeing Controlled Unclassified Information (CUI) and classified information protection, conducting risk assessments and vulnerability analyses, leading incident response efforts, and serving as primary liaison with government agencies on compliance matters.… The role requires 7+ years of information security management experience with at least 3 years in a leadership position, and extensive knowledge of defense industry security standards and classified information handling protocols. The ISSM will collaborate with DevSecOps, IT, and engineering teams to integrate security controls across operations and maintain continuous Authority to Operate (cATO) pipelines.

San DiegoLast seen 24 days ago
Posted 1 month ago

OWT Global seeks a Cybersecurity Analyst to serve as technical authority for ServiceNow platform security, ensuring compliance with federal cybersecurity protocols including NIST SP 800-53 and DoD RMF. Responsibilities include mapping ServiceNow roles and access controls to compliance frameworks, developing and maintaining System Security Plans (SSP) and POA&Ms, supporting vulnerability management and security assessments, and providing advisory support to government personnel on cybersecurity matters.… The role requires five years of practical cybersecurity experience, a Bachelor's degree in Cybersecurity or related field, and relevant certifications (CISSP or Security+ preferred), with strong understanding of ServiceNow architecture and DoD RMF processes.

San DiegoLast seen 26 days ago
$130,000 – $159,987 · Posted 1 month ago

The RMF Engineer will support DoD Assessment & Authorization activities by developing, maintaining, and managing Risk Management Framework documentation and artifacts throughout the system lifecycle. Key responsibilities include system categorization, creating and updating security plans and control evidence, managing RMF packages in eMASS, assessing security controls, and coordinating with engineering and cybersecurity teams on remediation.… The role requires 3+ years of hands-on DoD RMF experience, deep knowledge of NIST SP 800-53 and RMF processes, and proficiency with authorization management tools. This hybrid position is mostly remote and demands strong technical documentation and stakeholder communication skills.

San DiegoLast seen 1 month ago
$99,000 – $225,000 · Posted 1 month ago

The Security Controls Assessor designs, implements, and manages policies and procedures for database and software security at an expert level. The role requires assessing security controls within operational DoD systems (both OT and IT), reviewing technical implementations across diverse architectures (cloud, hybrid, on-premises, virtualization, AI/ML), and communicating findings on control effectiveness and security impact.… Requires 14+ years of cybersecurity experience, deep knowledge of NIST SP 800-53, DoD Risk Management Framework, and operational system assessment. Requires TS/SCI clearance and bachelor's degree; CISSP, CASP, or master's degree preferred.

San DiegoLast seen 1 month ago