CSfC Information Systems Security Technical Auditor

Clearance Level
Top Secret
Category
Cyber and IT Risk Management
Location
Ramstein Air Base, Germany
(Onsite Workplace)
Key Skills For Success

Cross Domain Solutions

Information System Security

Risk Management Framework

Technical Auditing

REQ#: RQ212190
Public Trust: None
Requisition Type: Regular
Your Impact

Own your opportunity to work with the largest government agency in the nation. Make an impact by advancing the Department of Defense’s mission to keep our country safe and secure.

Job Description
Position Overview

The Commercial Solutions for Classified (CSfC) Information Systems Security Specialist is responsible for the assessment, review, and lifecycle security oversight of multi-vendor CSfC architectures in accordance with NSA policies and Capability Packages (CPs). This role ensures classified information is protected through layered commercial technologies and supports the maintenance of NSA CSfC Registration, Cross Domain Solution Element (CDS-E) Assessment and Authorization (A&A) approvals, and Authority to Operate (ATO) packages.

This position is assessment-focused and does not perform day-to-day system engineering or operational administration. The role evaluates the implementation and effectiveness of security controls and supporting evidence to support risk-based authorization decisions.

The security specialist works closely with system architects, program managers, ISSOs, ISSEs, and accreditation authorities to ensure solutions meet technical, operational, and security requirements throughout the system lifecycle. A strong technical background is recommended to effectively perform security assessment responsibilities.

Key ResponsibilitiesSystems Security Assessment
  • Conduct technical security assessments as part of the RMF lifecycle, with emphasis on control implementation and effectiveness.
  • Review CSfC solution architectures, enclave boundaries, and data flows to support assessment activities and risk determinations.
  • Identify, prioritize, and track vulnerability scan findings from an assessment and reporting perspective.
  • Review Security Technical Implementation Guides (STIGs) for compliance and assessment purposes.
  • Review Security Information and Event Management (SIEM) solutions to validate appropriate logging, alerting, and monitoring capabilities.
Documentation & Accreditation
  • Develop, review, and maintain security documentation including:
    • eMASS authorization packages
    • NSA CSfC Registration packages
    • Cross-Domain Solution (CDS) Assessment & Authorization (A&A) packages
  • Document and track Plans of Actions and Milestones (POA&M) findings.
Compliance & Risk Management
  • Assess system compliance with applicable policies and frameworks, including:
    • CSfC Capability Packages (Mobile Access and Multi-Site Connectivity)
    • NIST SP 800-53 Rev. 5 security controls
    • Air Force and USAFE-specific cybersecurity policies
  • Conduct security reviews for proposed product substitutions, upgrades, or configuration changes to assess security impact and risk.
Security Leadership
  • Provide technical assessment guidance to engineers, Authorizing Officials (or their designated representatives), and other stakeholders.
  • Interface with NSA CSfC, CDS-E, and AO personnel as required to support assessment and authorization activities.
Required Qualifications
  • Bachelor’s degree in Cybersecurity, Computer Science, Information Systems, or related field, or equivalent experience.
  • 5–10+ years of experience in cybersecurity engineering, security assessment, or related roles.
  • Demonstrated experience assessing technical security controls in complex system environments.
  • Strong understanding of:
    • Encryption technologies including IPsec, VPNs, and certificates
    • Network engineering fundamentals (routing, switching, VLANs)
    • RMF lifecycle, NSA CSfC architecture, and CDS concepts
  • Familiarity with CSfC-approved components such as firewalls, VPN gateways, and cross-domain solutions.
  • Experience supporting NIST RMF and NIST SP 800-53 Rev. 5 implementations.
  • Experience developing or supporting A&A documentation and/or NSA CSfC registration packages.
  • Must meet applicable DoD 8140 requirements for cybersecurity roles.
Preferred Qualifications
  • Experience aligned with IAM Level II or IAT Level II roles.
  • DoD 8570/8140 baseline certification (e.g., CISSP, CASP+, CCSP), or ability to obtain within a defined timeframe.
  • Prior experience supporting or assessing NSA-approved CSfC solutions.
  • Working understanding of technologies such as:
    • Cisco routing, switching, and firewalls
    • Palo Alto firewalls
    • Juniper routing
    • Aruba networking
    • SIEM solutions (PacStar IQ Core preferred)
    • Certificate Authority (CA) solutions
    • Virtual Desktop Infrastructure (VDI) architectures
    • Tenable Nessus (ACAS)
Security Clearance
  • Active Secret clearance required; Top Secret / SCI preferred.
Soft Skills
  • Strong communication skills with both technical and non-technical audiences.
  • Ability to clearly document complex systems and assessment results.
  • Analytical thinker with strong problem-solving abilities.

Comfortable working in fast-paced, high-security environments


GDIT IS YOUR PLACE
At GDIT, the mission is our purpose, and our people are at the center of everything we do.
● Growth: AI-powered career tool that identifies career steps and learning opportunities
● Support: An internal mobility team focused on helping you achieve your career goals
● Rewards: Comprehensive benefits and wellness packages, 401K with company match, and competitive pay and paid time off

● Community: Award-winning culture of innovation and a military-friendly workplace

#DefenseOCONUS


OWN YOUR OPPORTUNITY
Explore a career in cyber at GDIT and you’ll find endless opportunities to grow alongside colleagues who share your focus on defending and protecting what matters.

Work Requirements
Years of Experience

6 + years of related experience

* may vary based on technical training, certification(s), or degree

Certification

Certified Information Systems Security Professional (CISSP) | International Information System Security Certification Consortium (ISC2) - International Information System Security Certification Consortium (ISC2)

Travel Required

Less than 10%

Citizenship

U.S. Citizenship Required

Salary and Benefit Information

The likely salary range for this position is $93,500 - $126,500. This is not, however, a guarantee of compensation or salary. Rather, salary will be set based on experience, geographic location and possibly contractual requirements and could fall outside of this range. Total compensation for international positions varies by tax, social security, and immigration statuses, as well as location. Generally, an international assignment may include allowances, premium uplifts, and/or relocation or transportation benefits, above base salary range noted.
View information about benefits and our total rewards program.

About Our Work

We are GDIT. A global technology and professional services company that delivers technology and mission services to every major agency across the U.S. government, defense and intelligence community. Our 30,000 experts extract the power of technology to create immediate value and deliver solutions at the edge of innovation. We operate across over 50 countries worldwide, offering leading capabilities in digital modernization, AI/ML, cloud, cyber and application development. Together with our customers, we strive to create a safer, smarter world by harnessing the power of deep expertise and advanced technology.

Join our Talent Community to stay up to date on our career opportunities and events at gdit.com/tc.

Equal Opportunity Employer / Individuals with Disabilities / Protected Veterans