S

Systems Planning and Analysis

Provides data-driven national security analytics

Cybersecurity Analyst

Full-TimeUpdated on 10/4/2026Deadline 10/1/27
$85k - $100k/yr
Mid
Colorado Springs, CO, USA
HybridReports to the Colorado Springs work location up to full time, based on customer needs.

About the job

Requirements
  • An active DoD Secret clearance is required at the time of application.
  • A high school diploma and 3–5 years of experience in IT, RMF, or GRC are required; a bachelor's degree is accepted as equivalent to four years of experience.
  • Must meet DoD 8140 Cybersecurity Analyst Mid-Level Education, Training, or Certification qualifications, such as CySA or Security+.
  • Must report to the designated Colorado Springs work location up to full time, based on customer needs.
Responsibilities
  • Work closely with the Information Systems Security Manager and Information Systems Owner to ensure the security posture is met and maintained, and develop security policies, procedures, plans, and compliance evidence for security controls.
  • Create and maintain Risk Management Framework documentation, including eMASS and ITIPS database entries, System Security Plans, Security Assessment Reports, Plans of Action and Milestones, and other NIST-process artifacts, supporting the system's cybersecurity posture through disposal.
  • Build, maintain, and track system cybersecurity baselines using eMASS or an equivalent system, in accordance with cybersecurity policies, guidance, and plans.
  • Review, assess, create, and update enclave documentation in eMASS and configuration-management systems for ISSM review and approval, including security plans, security assessment plans, category-selection checklists, control results, and Plans of Action and Milestones.
  • Identify, collect, review, and maintain Risk Management Framework-required artifacts in accordance with cybersecurity policies, guidance, and plans.
  • Maintain accurate system documentation and configuration logs reflecting current and prior configuration baselines.
  • Provide written evaluations of each system's Risk Management Framework compliance progress quarterly.
  • Maintain cybersecurity data for systems registered in ITIPS in accordance with FISMA requirements.
  • Conduct or report annual FISMA security reviews, contingency-test completion dates, and validation of cybersecurity control compliance in accordance with cybersecurity guidance, organizational cybersecurity strategy, and Plans of Action and Milestones.
  • Conduct annual control validations for NC3 systems in accordance with Air Force Global Strike Command cybersecurity guidance, and for non-NC3 systems in a similar manner under SMC/ECP policies and schedules.
  • Create and maintain mission common-control packages and serve as the common-control provider for each mission system.
  • Create and maintain Authority-to-Connect guest-system packages in eMASS for non-USSF systems connected to SMC/ECP systems.
  • Ensure required cybersecurity functional activities and actions during systems' operations and sustainment phase are conducted in accordance with cybersecurity-related laws and regulations, including the National Cybersecurity Protection Act, FISMA, OMB A1-30 mandate, and Executive Order 13636.
  • Improve critical-infrastructure cybersecurity and resilience using policies, standards, special publications, instructions, and guidance from the DoD, military, NIST, CNSS, DISA, and Department of the Air Force.
  • Participate in system integrated product teams, sustainment-contractor meetings and teleconferences, change-control boards, and working groups to ensure cybersecurity requirements remain aligned with technical baselines, system security architecture, information flows, design, and security controls.
  • Evaluate system change sources, including deficiency reports, problem reports, change requests or proposals, requests for change, and AF Form 1067s; determine security impacts of proposed or actual changes to the system, environment, threats, and vulnerabilities; and update needed Risk Management Framework artifacts to reflect changes or revisions.
  • Review and provide input to modification packages, program and system documents, support-agreement updates, and communications and network-infrastructure upgrades to ensure proper cybersecurity configuration-modification management and planning support.
  • Review system test plans and results and, when necessary, observe system testing for security-control implementation in accordance with cybersecurity policies, guidance, and plans.
  • Document findings; perform security-impact analyses for system changes; and prepare letters of assurance, security-impact letters, and risk-assessment letters, including exceptions, deviations, or waivers to cybersecurity requirements when applicable.
  • Monitor and adhere to the system's authorization and accreditation schedule deadlines in accordance with the Program Office Cybersecurity Plan and integrated product team schedule.
  • Review program cybersecurity policies and plans annually and recommend updates in accordance with cybersecurity guidance.
  • Review and advise on Risk Management Framework-related memorandums of agreement or understanding, service-level agreements, and interconnection service agreements for compliance with cybersecurity policies, guidance, and plans.
  • Assist with the cybersecurity vulnerability-management plan and risk-assessment capability.
  • Receive and review ACAS and SCC reports from the sustainment contractor for each system quarterly and characterize risk for each system semi-annually.
Desired Qualifications
  • Experience with ITIPS.
  • Experience with eMASS.
  • Experience with FISMA.
  • Experience with IASE.
  • Experience with Xacta.
  • An active Top Secret clearance.

About the company

S

Systems Planning and Analysis

View

SPA helps the U.S. government make high-stakes national security decisions by using modeling, simulation, and rigorous analysis. It builds data-driven analyses and forecasts outcomes for programs across the Navy, DoD, Homeland Security, and Energy, including space systems, cyber, and undersea warfare. It differentiates itself through decades of government-focused work, strategic acquisitions (MCR Federal, Intrepid, Group W), and an Office of Innovation that expands capabilities in AI, data science, and digital engineering. Its goal is to deliver accurate analyses and new capabilities quickly to guide defense investments and programs.

Company Size

1,001-5,000

Company Stage

N/A

Total Funding

$20.1M

Headquarters

Alexandria, Virginia

Founded

1972

Get referred to Systems Planning and Analysis

See people who can refer or advise you

Simplify Jobs

Simplify's Take

What believers are saying

  • The September 30, 2026 $126 million Navy award runs through March 2031.
  • SPA added Raj Badhwar as CIO on January 28, 2026, hardening digital infrastructure.
  • Robert Richards joined SPA’s board in July 2026, bringing BlueHalo scaling discipline.

What critics are saying

  • A 2031 NAVSEA recompete loss would gut SPA’s core Naval Special Warfare franchise.
  • Arlington Capital’s ownership pushes integration speed, margin expansion, and an eventual exit.
  • Secret-cleared labor shortages and subcontractor churn threaten delivery across classified programs.

What makes Systems Planning and Analysis unique

  • SPA’s 14,400-square-foot Alexandria Advanced Analytics Lab centralizes classified mission analysis.
  • SPA appointed fellows in AI, cloud, DevSecOps, and digital wargaming in May 2026.
  • SPA won NAVSEA PMS 340 support, extending a relationship dating to 2012.

Help us improve and share your feedback! Did you find this helpful?

Benefits

Health Insurance

Health Savings Account/Flexible Spending Account

Life Insurance

Disability Insurance

Growth & Insights and Company News

Headcount

6 month growth

↑ 27%

1 year growth

↑ 27%

2 year growth

↑ 27%
The Zebra
Sep 30th, 2026
Alexandria's SPA announces $126 million Navy contract.

Alexandria's SPA announces $126 million Navy contract. Press play to listen to this content West End company will support Naval Special Warfare programs; local hiring impact remains unconfirmed. ALEXANDRIA, VA - Systems Planning & Analysis, the national security company headquartered in Alexandria, announced September 30 that it has won a $126 million contract supporting the Navy's Naval Special Warfare Program Office. According to SPA's announcement, the company will serve as prime contractor, providing engineering, technical, administrative and acquisition-management support for the Naval Sea Systems Command office and related programs. The competitively awarded agreement includes a one-year base period and four option years, with performance extending through March 2031. SPA says the award expands a relationship with the office that began in 2012. For Alexandria, a key question is what the work will mean for local employees and job seekers. The Alexandria Economic Development Partnership previously outlined SPA's headquarters expansion plans, including nearly 500 planned jobs and commitments to local hiring and vendors. That earlier expansion is separate from today's contract announcement; a connection between those hiring plans and this award has not been established. This is a developing story. The contract's exact award date, identifying number, initially obligated funding, work locations and impact on Alexandria hiring remain unconfirmed by The Zebra Press. The company's announcement does not establish that $126 million has already been funded or that new local jobs will result. Additional verified information will be added as it becomes available.

Associated Press
May 20th, 2026
SPA appoints four fellows to advance software, cloud, AI and digital wargaming capabilities

Systems Planning & Analysis, an independent provider of analytical insights for national security programmes, has appointed four new Fellows to advance its technical capabilities across key domains. The appointments expand SPA's expertise in software engineering, DevSecOps and cloud, applied artificial intelligence, and digital wargaming. The newly appointed Fellows are Ian Harding (Software Engineering), Steven Hernandez (DevSecOps and Cloud), Amy Soller (Applied Artificial Intelligence), and Phillip Pournelle (Digital Wargaming). These senior subject matter experts will lead the development and integration of advanced capabilities across complex, multi-domain environments for national security clients. The appointments reinforce SPA's focus on accelerating mission-ready solutions, from scalable software systems and secure cloud architectures to AI applications and analytical wargaming tools that inform critical defence and intelligence decisions.

Intelligence Community News
Jan 29th, 2026
SPA taps Raj Badhwar as CIO

SPA taps Raj Badhwar as CIO. On January 28, Systems Planning & Analysis (SPA) announced that Raj Badhwar has joined the company as chief information officer (CIO). Badhwar serves on SPA's executive leadership team and reports to Chief Executive Officer Rich Sawchak. As CIO, Badhwar leads SPA's enterprise information technology (IT) organization, including digital strategy, architecture, engineering, operations, data management, and business intelligence. He focuses on delivering secure, resilient, scalable technology, and cybersecurity platforms in close partnership with SPA's business and mission teams. "Raj brings deep expertise in cybersecurity, cloud, and enterprise IT that will be critical as SPA continues to grow and support increasingly complex national security missions. His leadership will help ensure our technology remains secure, modern, and aligned with both our customers' needs and our long-term strategy," Sawchak said. Badhwar's priorities include strengthening technology capabilities that support SPA's national security customers, increasing efficiency and scalability across the IT organization, and ensuring that technology investments align with mission delivery, business growth, and acquisition activities. "My work at SPA will center on ensuring technology directly supports mission outcomes for our national security customers. That means strengthening security and resilience, simplifying operations as we scale, and advancing our cloud, data, and cybersecurity capabilities in a disciplined and trusted way," noted Badhwar. Badhwar brings more than 30 years of experience leading secure technology and cybersecurity organizations across engineering, defense, financial services, and cloud platforms. Start 2026 ahead of the competition with a paid subscription to IC News. You'll get full access to its searchable archive of 15,000+ articles, plus new articles each weekday.

WashingtonExec
Oct 10th, 2025
SPA Buys Group W

Systems Planning & Analysis has acquired Group W, a data science and defense analytics company that focuses on modeling, simulation and wargaming capabilities to the Defense Department.

EIN Presswire
Oct 9th, 2025
SPA Acquires Group W for Expansion

SPA has acquired Group W, enhancing its capabilities in mission-critical modeling and simulation for defense. This acquisition unites SPA's analytical insights with Group W's expertise in data science and wargaming for the DoD. The merger aims to create a leading defense modeling and simulation company. Legal counsel for SPA was provided by Sheppard Mullin and Morrison Foerster, while Stout and Holland & Knight advised Group W. SPA is backed by Arlington Capital Partners.