As an Information Assurance Specialist serving a national defense agency, you will integrate security across the full system lifecycle to ensure the confidentiality, integrity, and availability of data for traditional and cloud‑native architectures including AWS and approved SaaS. You’ll lead the operationalization of RMF/CSRMC in a DevSecOps environment, automate control implementation and evidence collection to achieve and sustain A&A, Assess‑Only, and cATO accreditations, and maintain an authoritative body of evidence in eMASS. You’ll collaborate with control owners and delivery teams to tailor and implement security controls such as container security, serverless, service meshes, or IaC, document shared responsibility and control inheritance, and drive risk‑based remediation through POA&Ms, continuous monitoring, and transparent stakeholder engagement. You’ll also perform advanced SCA/SCA‑V functions, design and execute transparent Security Assessment Plans, analyze near real‑time posture using automated scans, logs, and CaC outputs, validate automated evidence and Policy and Compliance‑as‑Code results, and synthesize mission‑focused risk analysis for the AO such as SAR, RAR, and authorization recommendations. You’ll lead technical incident response for cloud‑native systems, coordinate with SaaS providers during third‑party incidents, and brief program leadership with a strict “no surprises” approach that enables timely, risk‑informed decisions.
Stand Out From the Crowd
Upload your resume and get instant feedback on how well it matches this job.
Job Type
Full-time
Career Level
Senior