... STIG compliance), user onboarding, and logistics/shipping of devices for a mixed Apple/Windows environment. • Procure, fulfill, and ship FIPS-compliant YubiKeys alongside user laptops during ...
... STIG compliance), user onboarding, and logistics/shipping of devices for a mixed Apple/Windows environment. • Procure, fulfill, and ship FIPS-compliant YubiKeys alongside user laptops during ...
Senior Navy Qualified Validator
Virginia Beach, VA · On-site
$95K - $122K/yr
Responsibilities : • validating Navy RMF Packages as a Navy Qualified Validator (NQV) • Performing STIG assessments to include using SCAP benchmarks and Evaluate STIG • Performing vulnerability ...
Senior Navy Qualified Validator
Virginia Beach, VA · On-site
$95K - $122K/yr
Responsibilities : • validating Navy RMF Packages as a Navy Qualified Validator (NQV) • Performing STIG assessments to include using SCAP benchmarks and Evaluate STIG • Performing vulnerability ...
Mid-Level Transport Network Engineer
Arlington, VA · On-site
$59K - $106K/yr
Leidos is seeking a Network Engineer execute patch testing, STIG compliance assessments, and lab validation for assigned network infrastructure domain. Work independently with minimal oversight to ...
New
Mid-Level Transport Network Engineer
Arlington, VA · On-site
$59K - $106K/yr
Leidos is seeking a Network Engineer execute patch testing, STIG compliance assessments, and lab validation for assigned network infrastructure domain. Work independently with minimal oversight to ...
New
Implement and assess STIG and SRGs. • Perform and develop vulnerability assessments with automated tools such as Assured Compliance Assessment Solution (ACAS), Security Content Automation Protocol ...
Implement and assess STIG and SRGs. • Perform and develop vulnerability assessments with automated tools such as Assured Compliance Assessment Solution (ACAS), Security Content Automation Protocol ...
Information Systems Security Engineer - Intermediate (ISSE) -- Secret Clearance Required
Jacksonville, FL · On-site
... STIG, ensuring accurate configuration, execution, validation, and reporting of results. • May support systems undergoing the acquisition lifecycle by assessing cybersecurity risks, identifying ...
Information Systems Security Engineer - Intermediate (ISSE) -- Secret Clearance Required
Jacksonville, FL · On-site
... STIG, ensuring accurate configuration, execution, validation, and reporting of results. • May support systems undergoing the acquisition lifecycle by assessing cybersecurity risks, identifying ...
Sr. Cloud DevSecOps Engineer
Irvine, CA · On-site
$59.75 - $80/hr
Ensure NIST 800-53 and STIG compliance across infrastructure, pipelines, and AMIs * Establish unified tooling, SOPs, and self-service platform capabilities, integrating Lockheed Martin blueprints ...
Sr. Cloud DevSecOps Engineer
Irvine, CA · On-site
$59.75 - $80/hr
Ensure NIST 800-53 and STIG compliance across infrastructure, pipelines, and AMIs * Establish unified tooling, SOPs, and self-service platform capabilities, integrating Lockheed Martin blueprints ...
Information Systems Security Engineer - Intermediate (ISSE) -- Secret Clearance Required
Newport, RI · On-site
... STIG, ensuring accurate configuration, execution, validation, and reporting of results. • May support systems undergoing the acquisition lifecycle by assessing cybersecurity risks, identifying ...
Information Systems Security Engineer - Intermediate (ISSE) -- Secret Clearance Required
Newport, RI · On-site
... STIG, ensuring accurate configuration, execution, validation, and reporting of results. • May support systems undergoing the acquisition lifecycle by assessing cybersecurity risks, identifying ...
Senior Systems Security Engineer with Security Clearance
Dahlgren, VA · On-site
$116K - $160K/yr
Conduct STIG scans, RMF compliance checks, and accreditation documentation. Perform system hardening, vulnerability assessments, and penetration testing. Collaborate with engineers, ISSOs, and ...
Senior Systems Security Engineer with Security Clearance
Dahlgren, VA · On-site
$116K - $160K/yr
Conduct STIG scans, RMF compliance checks, and accreditation documentation. Perform system hardening, vulnerability assessments, and penetration testing. Collaborate with engineers, ISSOs, and ...
Implement and assess STIG and SRGs. • Perform and develop vulnerability assessments with automated tools such as Assured Compliance Assessment Solution (ACAS), Security Content Automation Protocol ...
Implement and assess STIG and SRGs. • Perform and develop vulnerability assessments with automated tools such as Assured Compliance Assessment Solution (ACAS), Security Content Automation Protocol ...
Information Systems Security Engineer - Intermediate (ISSE) - Secret Clearance Required
San Diego, CA · On-site
$155K - $165K/yr
Perform vulnerability scanning and assessment activities using tools such as ACAS and Evaluate-STIG, ensuring accurate configuration, execution, validation, and reporting of results. * May support ...
Information Systems Security Engineer - Intermediate (ISSE) - Secret Clearance Required
San Diego, CA · On-site
$155K - $165K/yr
Perform vulnerability scanning and assessment activities using tools such as ACAS and Evaluate-STIG, ensuring accurate configuration, execution, validation, and reporting of results. * May support ...
Information Systems Security Engineer - Intermediate (ISSE) - Se with Security Clearance
Newport, RI · On-site
Perform vulnerability scanning and assessment activities using tools such as ACAS and Evaluate-STIG, ensuring accurate configuration, execution, validation, and reporting of results. * May support ...
Information Systems Security Engineer - Intermediate (ISSE) - Se with Security Clearance
Newport, RI · On-site
Perform vulnerability scanning and assessment activities using tools such as ACAS and Evaluate-STIG, ensuring accurate configuration, execution, validation, and reporting of results. * May support ...
Support DISA STIG validation, SCAP benchmarks, security baselines, and device hardening requirements. * Conduct, review, and validate vulnerability scans using ACAS, Tenable Nessus, STIG Viewer, and ...
Support DISA STIG validation, SCAP benchmarks, security baselines, and device hardening requirements. * Conduct, review, and validate vulnerability scans using ACAS, Tenable Nessus, STIG Viewer, and ...
Cybersecurity Engineer - Cloud
CO · On-site +1
The role implements JSIG/NIST/STIG baselines, engineers secure multi classification cloud designs, validates Capability Provider and External cyber artifacts, and ensures all required evidence is ...
Cybersecurity Engineer - Cloud
CO · On-site +1
The role implements JSIG/NIST/STIG baselines, engineers secure multi classification cloud designs, validates Capability Provider and External cyber artifacts, and ensures all required evidence is ...
Sr. System Administrator
Arlington, VA · On-site
$98K - $134K/yr
Harden Windows operating systems to STIG compliance * Experience managing Active Directory architecture and replication in a multi domain environment * Experience with Active Directory design
Sr. System Administrator
Arlington, VA · On-site
$98K - $134K/yr
Harden Windows operating systems to STIG compliance * Experience managing Active Directory architecture and replication in a multi domain environment * Experience with Active Directory design
Information Systems Security Engineer - Intermediate (ISSE) - Se with Security Clearance
Jacksonville, FL · On-site
Perform vulnerability scanning and assessment activities using tools such as ACAS and Evaluate-STIG, ensuring accurate configuration, execution, validation, and reporting of results. * May support ...
Information Systems Security Engineer - Intermediate (ISSE) - Se with Security Clearance
Jacksonville, FL · On-site
Perform vulnerability scanning and assessment activities using tools such as ACAS and Evaluate-STIG, ensuring accurate configuration, execution, validation, and reporting of results. * May support ...
Cybersecurity Engineer / Cybersecurity Subject Matter Expert (SM with Security Clearance
Fort Belvoir, VA · On-site
Review, analyze, and maintain DISA STIG compliance artifacts, including STIG Viewer checklists (.CKL files), supporting evidence, and remediation status. * Execute, review, and interpret ...
Cybersecurity Engineer / Cybersecurity Subject Matter Expert (SM with Security Clearance
Fort Belvoir, VA · On-site
Review, analyze, and maintain DISA STIG compliance artifacts, including STIG Viewer checklists (.CKL files), supporting evidence, and remediation status. * Execute, review, and interpret ...
Experience maintaining harden Windows operating systems to STIG compliance, desired * Experience managing Active Directory architecture and replication in a multi domain environment, desired
Experience maintaining harden Windows operating systems to STIG compliance, desired * Experience managing Active Directory architecture and replication in a multi domain environment, desired
Desktop Support Specialist
Fort Belvoir, VA · On-site
$75K - $82K/yr
Experience maintaining harden Windows operating systems to STIG compliance, desired * Experience managing Active Directory architecture and replication in a multi domain environment, desired
Desktop Support Specialist
Fort Belvoir, VA · On-site
$75K - $82K/yr
Experience maintaining harden Windows operating systems to STIG compliance, desired * Experience managing Active Directory architecture and replication in a multi domain environment, desired
Sr. Devsecops with Security Clearance
Reston, VA · On-site
$119K - $163K/yr
Develop CI/CD pipelines from scratch in GitLab CI and Jenkins with integrated security scanning and STIG compliance validation, providing expert guidance to development teams on pipeline ...
Posted today
Sr. Devsecops with Security Clearance
Reston, VA · On-site
$119K - $163K/yr
Develop CI/CD pipelines from scratch in GitLab CI and Jenkins with integrated security scanning and STIG compliance validation, providing expert guidance to development teams on pipeline ...
Posted today
... per STIG requirements. • Develop and maintain Plans of Actions and Milestones (POA&M) in Enterprise Mission Assurance Support Service (eMASS). • Develop and maintain system level IT and CS ...
... per STIG requirements. • Develop and maintain Plans of Actions and Milestones (POA&M) in Enterprise Mission Assurance Support Service (eMASS). • Develop and maintain system level IT and CS ...
STIG information
See salary details
$30.5K - $32.5K
4% of jobs
$32.5K - $34.6K
5% of jobs
$34.6K - $36.6K
6% of jobs
$36.6K - $38.7K
4% of jobs
$38.7K - $40.7K
3% of jobs
$41K is the 25th percentile. Wages below this are outliers.
$40.7K - $42.8K
13% of jobs
$42.8K - $44.8K
13% of jobs
The median wage is $45K / yr.
$44.8K - $46.9K
16% of jobs
$48.1K is the 75th percentile. Wages above this are outliers.
$46.9K - $48.9K
17% of jobs
$48.9K - $51K
12% of jobs
$51K - $53K
6% of jobs
$30.5K
$44.2K
$53K
How much do stig jobs pay per year?
What is a Stig?
What is the difference between Stig vs Security Analyst?
| Aspect | Stig | Security Analyst |
|---|---|---|
| Credentials | Typically no formal certification required, but familiarity with security standards helps | Often requires certifications like CompTIA Security+, CISSP, or CEH |
| Work Environment | Primarily used in government and military settings for security compliance | Commonly employed in corporate, government, and private sectors for security monitoring |
| Employer & Industry Usage | Used by agencies following DoD and federal standards | Used across industries to analyze and improve security posture |
While a Stig (Security Technical Implementation Guide) is a set of security standards and checklists, a Security Analyst actively monitors, assesses, and responds to security threats. The Stig provides guidelines that Security Analysts implement to ensure compliance and security best practices.
What are some typical challenges faced by Stig drivers during high-performance testing days?
What are the key skills and qualifications needed to thrive as a Stig, and why are they important?

Full-time
Re-posted 16 days ago
Job description
DigiFlight, Inc. is seeking a System Administrator/SOC Analyst to manage various security and system administration tasks. The role involves overseeing hardware procurement, security tooling administration, and providing SOC services, ensuring compliance with security standards and effective IT support.
Responsibilities:
• Manage the procurement, image hardening (STIG compliance), user onboarding, and logistics/shipping of devices for a mixed Apple/Windows environment.
• Procure, fulfill, and ship FIPS-compliant YubiKeys alongside user laptops during onboarding.
• Execute the initial build and ongoing IT administration of required security tooling, including Endpoint Detection and Response (EDR), Data Loss Prevention (DLP), Mobile Device Management (MDM), and Security Information and Event Management (SIEM).
• Google Workspace administration, User and Group account management, and managing the Chrome Enterprise Browser.
• Provide Tier 1 (and potentially Tier 2) Managed Security Operations Center (SOC) services across the outlined security stack.
• Provide ongoing STIG configuration management and vulnerability scanning of all laptops, feeding reporting data directly into a monthly report.
• Provide ongoing IT administration and support for existing, in-place FedRAMP High applications, specifically Entra ID GCCH, Box for Government, and GovSlack.
Qualifications:
Required:
• At least 7 years of system admin experience.
• Understanding of hardening endpoints.
• Familiar with gathering reports from system and tools such as SEIM, SOAR, EDR, DLP, MDM.
• Familiar with Workspace Admin Console.
• Strong expertise in endpoint provisioning and lifecycle management, including STIG hardening, imaging, and logistics for both Apple and Windows devices.
• Proficiency in administering secure authentication hardware and processes, configuring, and deploying FIPS compliant YubiKeys within a controlled onboarding workflow.
• Hands-on experience implementing and managing enterprise security tooling (EDR, DLP, MDM, SIEM), including initial buildout, integration, and ongoing system administration.
• Ability to deliver Tier 1–2 SOC functions, including monitoring, triage, escalation, and analysis across a multicomponent security stack.
• Knowledge of vulnerability management frameworks and FedRAMP High/CMMC requirements, including STIG compliance, vulnerability scanning, POA&M reporting, and secure administration of platforms like Entra ID GCCH, Box for Government, and GovSlack.
• Understanding of how to manage Google Workspace Admin Console and Chrome Enterprise Browser.
Company:
DigiFlight, Inc. | 856 followers on LinkedIn. DigiFlight, Inc. Founded in 1999, the company is headquartered in Columbia, USA, with a team of 51-200 employees. The company is currently Growth Stage.
About DigiFlight
Sourced by ZipRecruiter
Industry
It services
Company size
51 - 200 Employees
Headquarters location
Columbia, MD, US
Year founded
1999