DoD Compliance / STIG Specialist
Location: Remote (Primary place of performance is remote; occasional on-site support may be required at JFRC Cheyenne, WY)
Clearance: Must meet minimum DoD SUITABILITY requirements for Entry on Duty (EOD); U.S. Citizenship required
Job Type: Full-time
Contract Type: Government Contract (Base Year: 30 September 2026 - 29 September 2027)
Position Overview
Seeking a highly experienced DoD Compliance / STIG Specialist to provide leadership and technical expertise in Security Technical Implementation Guide (STIG) compliance, FIPS 140-2 encryption validation, and DoD security controls for a government Pure Storage infrastructure environment. This role leads the way towards making storage compliance scalable and part of expected business practices across DoD organizations and various IT communities of practice DoD-wide.
This is a non-personal services contract position. The contractor employee reports directly to the Prime Contractor for HR, disciplinary, and administrative matters, while receiving work direction from the Government Technical Representative and the Contracting Officer's Representative (COR).
This is a remote position with occasional on-site requirements as directed by the Government.
Key Responsibilities
- Perform STIG compliance testing of Pure Storage infrastructure using current version of DoD-approved assessment methods and test reporting tools and formats
- Use the DoD STIG assessment process for storage systems and maintain DoD STIG certification throughout the life of the task order
- Conduct thorough quality checks and reviews of STIG test results completed by HQ compliance teams to ensure accuracy, completeness, and compliance with DoD STIG guidelines
- Perform document remediation for electronic documents and forms (including Microsoft Office suite, Adobe, etc.) using Section 508 Tests for Documents endorsed by the Federal CIO Council Community of Practice
- Provide STIG technical assistance and respond to STIG questions that arise during technical evaluations of Accessibility Conformance Reports (ACR) or Voluntary Product Accessibility Templates (VPAT)
- Develop compliance test plans
- Advise on how to interpret compliance test results and remediate STIG defects
- Provide remediation support for ICT
- Provide STIG technical assistance and respond to STIG questions that arise throughout the system development lifecycle, including:
- Advising project teams and Senior Management on alternative analysis regarding STIG compliance
- Advising on how to use STIG design standards, pattern and code libraries, developer STIG technical guidance, and STIG testing tools
- Advising on STIG review of IT products going through the department's enterprise architecture and network service change processes
- Serve as a back-up to the Government STIG Program Manager, as needed
- Provide back-up support to assist in implementing the Headquarters' STIG Program
- Maintain up-to-date STIG certification throughout the life of the task order
- Participate in events and other activities where presentations or contractor presence is required
- Ensure all materials for events are prepared, delivered, and accessible
Required Qualifications
Education: High School Diploma or equivalent
Certifications:
- DoD STIG Certification (must possess and maintain throughout the life of the task order)
- IAAP CPACC Certification (Certified Professional in Accessibility Core Competencies)
Experience:
- Minimum of two (2) years of experience testing storage systems for conformance to STIG standards
- Minimum of two (2) years of experience testing and remediating electronic documents for STIG standards
- Minimum of three (3) years of experience supporting ICT project and acquisition efforts with addressing STIG requirements at defined stages throughout the project life cycle
Knowledge:
- Broad knowledge of the Revised Section 508 Standards
- Broad knowledge of DoD Security Technical Implementation Guides (STIGs)
- Broad knowledge of NIST SP 800-171 requirements
- Knowledge of FIPS 140-2 encryption validation and root partition encryption
Citizenship: U.S. Citizenship required
Security: Must meet minimum DoD SUITABILITY requirements for Entry on Duty (EOD) unless otherwise indicated
Language: Fluent in written and verbal English
Technical Skills: Proficiency in using compliance testing tools, document remediation tools, and DoD-approved test reporting formats
Preferred Qualifications
- Experience serving as a back-up to a Government STIG Program Manager
- Experience advising project teams and Senior Management on STIG compliance
- Experience with DoD enterprise architecture and network service change processes
- Experience developing and implementing scalable STIG compliance practices across large organizations
- Familiarity with the Harmonized ICT Testing Baseline for Web
- Experience with Accessibility Compliance Management System (ACMS) or similar ticketing systems
- Experience with Pure Storage STIG compliance
Work Role Information
Work Role: DoD Compliance / STIG Specialist
Proficiency Level: Senior/Expert
Additional Requirements
- Must comply with all DoD security regulations and safeguard Controlled Unclassified Information (CUI)
- Must pass background checks and suitability determinations
- Must complete DoD Information Technology Security Awareness Training annually
- Must sign and comply with DoD Rules of Behavior
- Must maintain STIG and IAAP CPACC certification currency
Schedule & Work Conditions
Hours: Up to 40 hours per week, Monday-Friday, normal business hours (7:30 AM - 6:00 PM EST), excluding Federal holidays
Overtime: Only permitted at the Government's discretion
Telework: Remote; occasional on-site support may be required as directed by the Government
Travel: Not authorized
Place of Performance: Remote (primary); JFRC Cheyenne, WY (if on-site support is requested)
Equal Opportunity Employer
We are an equal opportunity employer and do not discriminate on the basis of race, color, religion, sex, gender identity, sexual orientation, national origin, genetics, disability, age, or veteran status.