We use cookies. Find out more about it here. By continuing to browse this site you are agreeing to our use of cookies.
#alert
Back to search results
New

STIG / COMPLIANCE ENGINEER

Empower AI
United States, Virginia, Quantico
Oct 01, 2026

STIG / COMPLIANCE ENGINEER


Job ID

2026-9560




Job Locations

US-VA-Quantico

Category
IT: Information Assurance / Quality / Cyber Security

Type
Regular Full-Time



Overview

Empower AI is AI for government. Empower AI gives federal agency leaders the tools to elevate the potential of their workforce with a direct path for meaningful transformation. Headquartered in Reston, Va., Empower AI leverages three decades of experience solving complex challenges in Health, Defense, and Civilian missions. Our proven Empower AI Platform provides a practical, sustainable path for clients to achieve transformation that is true to who they are, what they do, how they work, with the resources they have. The result is a government workforce that is exponentially more creative and productive. For more information, visit www.Empower.ai.

Empower AI is proud to be recognized as a 2024 Military Friendly Employer by Viqtory, the publisher of G.I. Jobs. This designation reflects the company's commitment to hiring and supporting active-duty and veteran employees.



Responsibilities

Description

Empower AI is seeking a STIG / Compliance Engineer to engineer and sustain DISA STIG-compliant security baselines for the endpoint environment of a Department of War agency across Pre-Production, NIPRNet, SIPRNet, and JWICS enclaves. The engineer analyzes STIG and SRG releases for applicability and impact, translates controls into Group Policy Objects, MECM compliance baselines, and image settings, validates compliance with STIG Viewer and SCAP tooling, analyzes deviations to root cause, and documents mitigations and evidence for RMF packages in eMASS. The role produces the monthly STIG Compliance Report inputs for the endpoint environment and partners with the Patch Management Engineer, ISSO, and image team. This is a salaried, FLSA-exempt position in which you will independently analyze situations, determine the appropriate course of action, and exercise discretion and independent judgment on matters of significance to the program and its customers.

THIS IS AN ONSITE ROLE IN QUANTICO, VA (RKB) WITH UP TO 10% OF TRAVEL INVOLVED.

JOB DUTIES:

    Analyze new and updated DISA STIG/SRG releases for applicability and operational impact, and engineer the corresponding Group Policy Objects, MECM compliance baselines, and image configurations for Windows endpoints, browsers, Office, and third-party applications.
  • Run and analyze SCAP Compliance Checker and STIG Viewer assessments across the endpoint environment, determine root cause of deviations, decide remediation or documented mitigation, and drive changes through pre-production/Digital Twin validation and Change Management.
  • Produce endpoint inputs to the monthly STIG Compliance Report, maintain control implementation statements and evidence in eMASS, and coordinate POA&M entries and risk acceptance requests with the ISSO and Risk Management Support Lead.
  • Maintain the endpoint security baseline documentation and evaluate the security impact (CM-4) of proposed endpoint configuration changes.
  • Analyze weekly ACAS/Nessus vulnerability scan results for all in-scope systems, identify and prioritize critical and high (CAT I/II/III) vulnerabilities, assign remediation to resolver groups, validate fixes, and produce the weekly Vulnerability Scan Analysis Report.
  • Assess STIG compliance for endpoints, servers, printers, communications equipment, and platforms using STIG Viewer, SCAP, and endpoint management compliance data; track deviations and remediation; and produce the monthly STIG Compliance Report.
  • Maintain and update POA&M items in eMASS for assigned systems, including milestones, mitigations, risk statements, and evidence of closure, in coordination with ISSOs and system administrators.
  • Monitor the endpoint environment's security compliance status (patch compliance, baseline compliance, time-to-remediate) and ensure accurate cybersecurity metrics are fed to the Customer Support Metrics Dashboard.


Qualifications

REQUIREMENTS:

  • Bachelor's degree and a minimum of 3 years of related experience (an additional 4 years of related experience may be substituted for the degree).
  • Must be a U.S. Citizen.
  • Must have an Active Top Secret Clearance (favorably adjudicated T5/T5R) to start; this is a Privileged User position.
  • Must be willing and able to obtain TS/SCI eligibility after start, if required by mission needs.
  • Must be within investigation scope and/or currently enrolled in Continuous Evaluation / Continuous Vetting.
  • Must possess and maintain a current DoD 8570/8140 IAT Level II baseline certification (e.g., CompTIA Security+ CE, CySA+, GSEC, SSCP, or CCNA-Security).
  • Demonstrated ability to work independently, analyze problems, determine the appropriate course of action, and exercise discretion and independent judgment with limited day-to-day supervision.
  • Minimum of 3 years of experience in cybersecurity analysis, vulnerability management, or RMF continuous monitoring for DoD or Federal systems.
  • Hands-on experience with ACAS/Nessus, STIG Viewer, and SCAP Compliance Checker, and interpreting scan and compliance results.
  • Working knowledge of NIST SP 800-53 controls, RMF (NIST SP 800-37, DoDI 8510.01), DISA STIGs, and DoD vulnerability management requirements (DoDI 8531.01).
  • Experience maintaining POA&Ms and control evidence in eMASS.
  • Understanding of Windows and Linux operating systems, Active Directory, networking fundamentals, and endpoint management concepts sufficient to assess and advise on remediation.
  • Strong analytical, reporting, and communication skills; ability to produce accurate recurring reports on deadline.

DESIRED SKILLS:

  • CompTIA CySA+, Security+ CE, GSEC, or CISSP Associate.
  • Experience supporting Department of War (DoW), DoD, or Intelligence Community systems across multiple enclaves.
  • Experience with endpoint management compliance reporting (MECM/SCCM, Intune), HBSS/ESS, and SIEM/log analysis tools.
  • Familiarity with USCYBERCOM/JFHQ-DODIN orders and directives, IAVM compliance tracking, and cyber incident reporting.
  • Familiarity with Power BI for compliance dashboards.
  • Experience using ServiceNow (incident, request, knowledge, CMDB, Service Catalog, Virtual Agent) or a comparable enterprise ITSM platform.


About Empower AI

All hiring and promotion decisions at Empower AI are based on merit to bring the best talent available to contribute to our firm's overall success. It is the policy of Empower AI not to discriminate against any applicant for employment, or employee because of age, color, sex, disability, national origin, race, religion, or veteran status. Empower AI is a VEVRAA Federal Contractor.



Pay Band Min

USD $100,410.00/Yr.


Pay Band Max

USD $155,410.00/Yr.


Need help finding the right job?

We can recommend jobs specifically for you!
Click here to get started.
Applied = 0

(web-9db6c7984-5xhmq)