Trace3
Cyber Assessment and Authorization Engineer (26-367)
About this role
Trace3 seeks a Cyber Assessment and Authorization Engineer to analyze security scans (ACAS, SCC, ConfigOS) and manage continuous system authorization activities. The role involves collaborating with stakeholders to assess vulnerabilities, generate remediation responses, conduct risk analysis, and maintain authorization packages using eMASS/Xacta.
What you'll do
- Analyze ACAS, SCC, and ConfigOS security scans and controls for ongoing system authorization
- Collaborate with program teams and external stakeholders to identify and assess system vulnerabilities
- Generate engineering responses and mitigation strategies for system Plans of Action and Milestones (POA&Ms)
- Conduct risk analysis and provide recommendations for Risk Acceptance Requests (RARs)
- Support account management activities and maintain authorization documentation
- Create and maintain system authorization packages in eMASS/Xacta platforms
What they're looking for
- Assessment & Authorization (A&A) framework expertise
- ACAS and SCC scan analysis and interpretation
- Risk Management Framework (RMF) and NIST 800-53 controls
- eMASS and Xacta platform proficiency
- STIG review and compliance analysis
- Security documentation and technical writing
- DoD cybersecurity standards (DoDI 8500.2)
- Cross Domain Solutions (CDS) accreditation experience
Opens the application — the Jobs AI extension fills it for you. Set up autofill
Opens the official application on the employer’s site. No login required.
Trace3
Trace3 builds and optimizes complex defense and military systems, including battle management platforms, sensor resource management solutions, and enterprise system architectures for DoD programs. The company is hiring Systems Engineers, Performance Assessment Engineers, Software Engineers, and Test Engineers to design, develop, analyze, and validate these critical defense systems.
- Website
- trace3.com
Likely interview questions
- Walk us through your experience analyzing ACAS and SCC scan outputs and translating findings into remediation strategies.
- Describe a complex POA&M you've developed—what was the vulnerability, your recommended fix, and how you justified risk acceptance?