← Back to results

poa-m jobs in San Diego

$87,408 – $127,332 · Posted 6 days ago

As a Research Cybersecurity Analyst, you will review research contracts, proposals, and data-use agreements to identify security and compliance requirements, then conduct risk assessments and recommend practical safeguards. You will coordinate security controls across cloud and on-premises research environments, assess architectures for identity management, encryption, and network segmentation, and develop compliance documentation (SSPs, POA&Ms) for sponsor audits and CMMC readiness.… You will work with researchers, IT teams, and compliance partners to interpret regulatory requirements, map them to controls, and explain technical security obligations in practical terms to non-technical stakeholders. Experience in NIST frameworks, security assessments, vulnerability management, and regulated environments (higher education, research, healthcare, government, defense) is especially valued.

San DiegoLast seen 4 days ago
$87,408 – $127,332 · Posted 7 days ago

This role supports research teams at a university by reviewing security requirements in research contracts and proposals, conducting risk and compliance assessments, and recommending practical security approaches. The analyst will coordinate security controls across cloud and on-premises research environments, assess security architectures and configurations, and develop compliance documentation including SSPs and POA&Ms.… The role requires interpreting cybersecurity frameworks (NIST SP 800-171, CMMC, NIST SP 800-53) and communicating technical requirements to researchers and non-technical stakeholders across identity and access management, encryption, vulnerability management, and network security.

San DiegoLast seen 5 days ago
$96,600 – $96,600 · Posted 8 days ago

The Cyber Security Analyst develops and maintains assessment documentation, performs ongoing compliance assessments using tools like ACAS, SCAP, and Trellix, and conducts security audits and Site Based Security Assessments (SBSAs) of NCS Family of Systems. The role requires 5–8 years of cybersecurity experience, current DoD 8140-compliant IAT II certification (Security+ with appropriate CE/OS), and expertise in Risk Management Framework (RMF) v3/v5, System Security Plans (SSPs), POA&Ms, STIG remediation, and eMASS.… Responsibilities include patching verification, configuration and change management compliance, incident reporting, continuous monitoring, and potential appointment as Information System Security Officer (ISSO) within 6 months.

San DiegoLast seen 6 days ago
$164,000 – $328,000 · Posted 9 days ago

Senior Cyber Systems Engineer responsible for developing and maintaining RMF artifacts (SSPs, SARs, SAPs, POA&Ms), coordinating with Navy Authorizing Officials and Security Control Assessors, and managing cybersecurity authorization packages for ATO/IATT/IATO activities. The role involves vulnerability remediation, STIG compliance, access control policy development, patch management, and server/network infrastructure oversight.… Requires mastery of the Risk Management Framework, CI/CD security pipelines, container hardening (Docker/Kubernetes), infrastructure-as-code tools (Terraform, Ansible), and automated security assessment tools (ACAS/Nessus). Serves as Information Systems Security Manager (ISSM) for product ATOs and coordinates with government agencies to ensure DoD and Navy cyber security requirements are met.

San DiegoLast seen 8 days ago
$135,000 – $231,000 · Posted 10 days ago

Lead information systems security for a cleared defense contractor, managing a team of ISSOs and Security Administrators through the RMF process while ensuring compliance with NISPOM, DCSA, and NIST 800-53 standards. Responsibilities include vulnerability management, STIG compliance, security incident investigation, insider threat coordination, and preparation for DCSA assessments.… Requires 8+ years IT experience with 5+ years as an ISSM in a cleared facility, proficiency in Windows/Linux, eMASS, Tenable, SIEM tools, and IAM Level 3 certification (CISSP, CISM, or GSLC). Strong background in container orchestration, infrastructure automation, and DevSecOps methodologies is valued.

San DiegoLast seen 9 days ago
Posted 10 days ago

Lead cybersecurity program delivery for NSWC Corona's Risk Management Framework and continuous authorization services. Manage a team of ISSMs, ISSOs, and cybersecurity analysts while serving as primary interface with Navy leadership and government stakeholders.… Oversee contract lifecycle, financials, and compliance across A&A packages and continuous monitoring; drive process improvements in eMASS workflows and RMF execution. Provide strategic guidance on DoD/Navy cybersecurity policy, emerging threats, and system acquisition integration.

San DiegoLast seen 8 days ago
Posted 10 days ago

Information System Security Officer III responsible for securing assigned networks, enclaves, and platform IT systems through vulnerability assessments, STIG compliance verification, and continuous monitoring. The role requires coordinating with engineers and developers to embed security throughout the system development lifecycle, managing RMF documentation and POA&M entries, conducting daily audit log and SIEM alert reviews, and supporting incident response and cyber inspections.… Must possess TS/SCI clearance, a bachelor's degree in IT/cybersecurity or equivalent experience, six years of hands-on security implementation and vulnerability analysis, and current DoD 8140/8570 IAM Level II certification.

San DiegoLast seen 8 days ago
Posted 17 days ago

ManTech seeks an Information System Security Officer to maintain Assessment & Authorization (A&A) documentation per NIST and DoD standards, track compliance deficiencies via Plans of Action and Milestones, implement continuous monitoring strategies, and oversee audit log systems and patch management. The role requires managing security tools, evaluating system configuration changes, and supporting an Information System Security Manager (ISSM) with compliance and incident response procedures.… Candidates must hold Security+ certification, have 2+ years of RMF and NIST SP 800-53 experience, and possess an active Top Secret clearance with SCI eligibility.

San DiegoLast seen 16 days ago
$76,200 – $114,400 · Posted 23 days ago

Associate-level cybersecurity analyst supporting classified government information system lifecycle activities through security audits, continuous monitoring, and Assessment & Authorization (A&A) work. Responsibilities include conducting system and network security assessments, analyzing compliance with security controls and policies, supporting Security Test & Evaluation (ST&E) activities, and preparing Risk Management Framework documentation.… Requires a Bachelor's or Master's degree, current Secret clearance (or CE Program enrollment), and ability to obtain an IT Program Auditor certification (SecurityX/CASP+, GGRC, GSEC, GSNA, Sec+, or SSCP) within six months.

San DiegoLast seen 21 days ago
$84,000 – $139,950 · Posted 1 month ago

This role performs continuous security monitoring, compliance assessments, and authorization documentation for Department of Defense information systems. The analyst will use tools like ACAS, SCAP, and eMASS to execute Risk Management Framework processes, conduct security audits, manage Plans of Action and Milestones (POA&Ms), and coordinate STIG remediation with system engineers and administrators.… The position requires 5–8 years of cybersecurity experience, current DoD 8140-compliant IAT II certification (Security+), and deep knowledge of RMF, system security plans, and automated compliance scanning. The analyst must be able to work independently, manage competing priorities, and be appointed Information System Security Officer (ISSO) within six months.

San DiegoLast seen 28 days ago
Posted 1 month ago

The Cybersecurity Engineer III will support Assessment and Authorization accreditation efforts, maintaining cybersecurity monitoring operations, performing incident triage, identifying vulnerabilities, and recommending remediation strategies. Responsibilities include analyzing cybersecurity directives and policies (CTOs, FRAGOs, IAVMs, STIG requirements), developing compliance strategies aligned with federal and defense security standards, and performing risk analysis and independent verification of security configurations.… The role requires in-depth Risk Management Framework knowledge, FISMA data reporting support, and use of compliance tracking tools such as VRAM. This position requires a Secret clearance, IAT Level III certification (CASP+, CCNP Security, CISA, CISSP, GCED, or GCIH), and 10+ years of cybersecurity or incident response experience.

San DiegoLast seen 1 month ago
Posted 1 month ago

Senior Principal System Administrator responsible for managing and maintaining a classified development and integration test environment, including Windows and Red Hat Enterprise Linux servers, VMware virtualization infrastructure, and network hardware. The role requires strong Linux and Windows Server administration expertise, cybersecurity compliance knowledge (DISA STIGs, Nessus, PKI), and experience supporting classified networks.… Responsibilities include patching workflows, ePO/McAfee integration, vulnerability scanning, system accreditation support, and maintaining DoD-mandated security posture; some after-hours support for maintenance and incident response required.

San DiegoLast seen 18 days ago
Posted 1 month ago

The Cybersecurity Engineer III will support Assessment and Authorization (A&A) accreditation efforts under the NIWC PAC contract, maintaining cybersecurity monitoring operations, performing incident triage, identifying vulnerabilities, and recommending remediation strategies. Responsibilities include testing and applying security controls, conducting reconnaissance, authoring Plans of Milestones and Actions (POA&Ms), and developing A&A documentation such as System Security Plans (SSP) and Security Assessment Reports (SARs).… The role requires in-depth knowledge of the Risk Management Framework, eMASS workflow, DISA compliance, and security categorization overlays. A minimum of 10+ years of cybersecurity or incident response experience is required, along with security certifications such as CISSP, CASP, CISM, CAP, or GSLC.

San DiegoLast seen 1 month ago
$83,527 – $119,480 · Posted 1 month ago

The Information System Security Officer (ISSO) serves as a steward of classified and high-side information systems, ensuring security compliance and operational resilience in accordance with DoD and DCSA standards. The role involves executing Risk Management Framework (RMF) activities, pursuing Authorization to Operate (ATO) via eMASS, conducting vulnerability scanning with tools like Nessus, and maintaining compliance with NISP and federal requirements.… Responsibilities include hands-on system administration, security monitoring, patch management, data transfer operations, and collaborative work with industrial security teams to integrate technical and administrative controls. Success requires proven experience processing ATO packages, system administration skills, security compliance knowledge, and the ability to balance rigorous security controls with operational effectiveness.

San DiegoLast seen 1 month ago
$100,300 – $135,700 · Posted 1 month ago

Lead Information Assurance and security engineering for Navy tactical networks (CANES), managing end-to-end Risk Management Framework (RMF) authorization, hardening virtualized and cloud network stacks, and ensuring compliance across diverse naval environments. Develop and maintain security authorization artifacts (SSP, SAP/SAR, POA&M, ATO packages in eMASS), apply DISA STIGs and vulnerability management tools (ACAS, NESSUS, SCAP), and provide IA guidance for application integration aligned with DoDAF and Net-Ready KPP baselines.… Support developmental testing, audit response, and continuous monitoring while coordinating with PEO C4I, NIWC Pacific, and Fleet stakeholders. Mentor junior engineers and champion DevSecOps and STIG automation practices.

San DiegoLast seen 1 month ago
$130,000 – $160,000 · Posted 1 month ago

Architect and maintain ServiceNow security controls aligned to DoD Zero Trust architecture in FedRAMP High and DoD IL4/IL5 environments. Configure role-based access controls (RBAC), access control lists (ACLs), data policies, and edge encryption; maintain security matrices and enforce information-level segregation.… Develop System Security Plans (SSPs) and Risk Management Framework (RMF) artifacts to support ATO attainment and sustainment. Conduct vulnerability assessments, continuous monitoring, manage Plans of Action and Milestones (POA&M), and generate security assessment reports.

San DiegoLast seen 1 month ago
Posted 1 month ago

OWT Global seeks a Cybersecurity Analyst to serve as technical authority for ServiceNow platform security, ensuring compliance with federal cybersecurity protocols including NIST SP 800-53 and DoD RMF. Responsibilities include mapping ServiceNow roles and access controls to compliance frameworks, developing and maintaining System Security Plans (SSP) and POA&Ms, supporting vulnerability management and security assessments, and providing advisory support to government personnel on cybersecurity matters.… The role requires five years of practical cybersecurity experience, a Bachelor's degree in Cybersecurity or related field, and relevant certifications (CISSP or Security+ preferred), with strong understanding of ServiceNow architecture and DoD RMF processes.

San DiegoLast seen 1 month ago