Nooks
Cybersecurity Support Specialist
Arlington, VA
Apply through hirly
hirly scores this role against your resume, shows its reasoning, then writes a resume and cover letter for it and fills the application with you. Free to start — no card required.
hirly's read of this role
- Seniority
- Mid level
- Country
- US
- Work mode
- On-site / unstated
- First seen by hirly
- 5 Sept 2026
Derived automatically from the posting. Sign up to see how the role scores against your own resume.
the posting
ABOUT NOOKS
Nooks is pioneering Classified-Infrastructure-as-a-Service (CIaaS) — designing, building, and operating Sensitive Compartmented Information Facilities (SCIFs) and other secured, classified environments for the defense and national security community. We work with the agencies, contractors, and mission-driven organizations that keep the nation safe, delivering the physical infrastructure that makes classified work possible. We’re growing fast, operating across multiple markets, and building a company that takes both the mission and the business seriously.
About the Role
Accredited systems generate a constant stream of security work — scans to run, findings to track, documentation to keep current, users to support. As Cybersecurity Support Specialist, you will keep that work moving at a single Nooks site, supporting the security and compliance of classified and unclassified systems alongside the site's Cybersecurity Lead. You will bring two to five years of hands-on practice to a specialist seat, reporting to the Site IT/Cyber Manager as an individual contributor.
Our procedures are real but still maturing — audits, incidents, and new system standups will reshuffle your week, and you will step in wherever the site's security posture needs attention without waiting to be asked.
Key Responsibilities
Security Monitoring & Vulnerability Management
Conduct vulnerability scanning, patch verification, and security configuration checks under the direction of the site Cybersecurity Lead.
Monitor and audit the security posture of classified and unclassified systems, applying Defense Information Systems Agency (DISA) Security Technical Implementation Guides (STIGs).
Track findings and remediation actions to closure, documented to organizational and Department of Defense (DoD) standards.
Compliance Documentation & Support
Maintain cybersecurity documentation — System Security Plans (SSPs), Plans of Action and Milestones (POA&Ms), audit logs, and standard operating procedures.
Record compliance actions and evidence so the site is ready for audits and self-inspections at any time.
Keep artifacts organized so the Cybersecurity Lead can hand assessors current documentation on demand.
User Support & Access Control
Provide Tier 1 support for cybersecurity-related user requests, escalating issues that need deeper analysis.
Manage user accounts, security groups, and permissions in partnership with the site's IT Support Specialist — you both work in this space, so clean records and communication matter.
Support permissions reviews and the implementation of access control policies, including role-based access control.
Incident Response & Security Awareness
Participate in incident response and continuous monitoring — log collection, basic analysis, and security control status reporting.
Reinforce cybersecurity best practices with end users through daily interactions.
Collaborate with IT, personnel security, and physical security teams to keep site operations compliant with DoW requirements.
What Success Looks Like in This Role
Twelve months in, the site's routine security workload — scans, checks, and documentation upkeep — runs on schedule with little prompting. The SSPs, POA&Ms, and audit artifacts you maintain are current enough to hand straight to an assessor. Tier 1 cybersecurity requests get resolved or escalated cleanly, and account and permissions records stay accurate through every review. Handoffs with the IT Support Specialist are smooth because the shared account work is documented and coordinated. The Cybersecurity Lead trusts your work enough to build audit responses on top of it.
Cross-Functional Expectations
Inside IT/Cyber, you will work most closely with your site's Cybersecurity Lead and IT Support Specialist, coordinating daily on shared account and access work. You will partner with Security on personnel and physical security touchpoints, and support Operations, specifically the Site Lead, for site activities.
The Skillset
2–5 years of experience in cybersecurity or system administration.
DoD 8140.03/8570.01 Information Assurance Technical (IAT) Level II certification (e.g., CompTIA Security+), or the ability to obtain one within six months of hire.
Hands-on experience with DISA STIGs and tools such as the Security Content Automation Protocol (SCAP) Compliance Checker and STIG Viewer.
Familiarity with access control, vulnerability management, and system hardening, plus Active Directory — including Group Policy Object (GPO) and Organizational Unit (OU) structure.
Foundational knowledge of Windows and Linux operating systems, networking, and common IT troubleshooting practices.
Associate's or Bachelor's degree in Cybersecurity, Information Technology, or a related field — or equivalent practical experience.
Strong documentation habits, attention to detail, and clear communication across IT and security functions.
Preferred:
Familiarity with monitoring and scanning tools such as Tenable Nessus, ManageEngine, Splunk, antivirus platforms (e.g., ESET, Trellix), and other vulnerability and security information and event management (SIEM) tools.
Prior DoW or cleared-environment exposure.
Eligibility & Clearance
Candidates must be eligible to work in the United States and capable of maintaining eligibility up to the Top Secret/Sensitive Compartmented Information (TS/SCI) level within 45 days of hire.
Salary Range for all departments
Salary Range
$90,000 — $115,000 USD
Is this role actually a fit for you?
hirly answers with a score and its reasoning, then writes the resume and cover letter if you decide to go for it.
Score it against my resume