Information Assurance Specialist

Booz Allen HamiltonArlington, VA
$99,000 - $225,000Remote

About The Position

As an Information Assurance Specialist serving a national defense agency, you will integrate security across the full system lifecycle to ensure the confidentiality, integrity, and availability of data for traditional and cloud‑native architectures including AWS and approved SaaS. You’ll lead the operationalization of RMF/CSRMC in a DevSecOps environment, automate control implementation and evidence collection to achieve and sustain A&A, Assess‑Only, and cATO accreditations, and maintain an authoritative body of evidence in eMASS. You’ll collaborate with control owners and delivery teams to tailor and implement security controls such as container security, serverless, service meshes, or IaC, document shared responsibility and control inheritance, and drive risk‑based remediation through POA&Ms, continuous monitoring, and transparent stakeholder engagement. You’ll also perform advanced SCA/SCA‑V functions, design and execute transparent Security Assessment Plans, analyze near real‑time posture using automated scans, logs, and CaC outputs, validate automated evidence and Policy and Compliance‑as‑Code results, and synthesize mission‑focused risk analysis for the AO such as SAR, RAR, and authorization recommendations. You’ll lead technical incident response for cloud‑native systems, coordinate with SaaS providers during third‑party incidents, and brief program leadership with a strict “no surprises” approach that enables timely, risk‑informed decisions.

Requirements

  • 5+ years of experience with Information Assurance
  • 3+ years of experience directly performing Information Assurance tasks
  • Knowledge of the DoD cybersecurity environment
  • Secret clearance
  • Bachelor’s degree in an IT, Computer Science, or Engineering field
  • DoD 8570/8140 IAM Level II or IAT Level II baseline certification such as CISSP, Security+ CE, CISM, or CASP+ CE

Nice To Haves

  • Experience operating eMASS as the authoritative GRC system of record, maintaining near real‑time security documentation and POA&Ms
  • Experience with Compliance as Code and cloud‑native tools such as AWS Inspector, Security Hub, validating automated evidence against NIST SP 800‑53 and DoD STIGs
  • Experience with vulnerability and software assurance tooling including SAST/DAST, SCA, or container image scanning, and risk‑based remediation before deployment
  • Experience with ICAM enforcement such as DoW eICAM, least‑privilege access controls, and secure SaaS configuration
  • Knowledge of RMF step 1–6 execution, continuous monitoring, and CSRMC automation in DevSecOps pipelines
  • Ability to lead technical incident response for cloud‑native systems and coordinate with third‑party providers to restore mission capability

Responsibilities

  • Integrate security across the full system lifecycle to ensure the confidentiality, integrity, and availability of data for traditional and cloud‑native architectures including AWS and approved SaaS.
  • Lead the operationalization of RMF/CSRMC in a DevSecOps environment.
  • Automate control implementation and evidence collection to achieve and sustain A&A, Assess‑Only, and cATO accreditations.
  • Maintain an authoritative body of evidence in eMASS.
  • Collaborate with control owners and delivery teams to tailor and implement security controls such as container security, serverless, service meshes, or IaC.
  • Document shared responsibility and control inheritance.
  • Drive risk‑based remediation through POA&Ms, continuous monitoring, and transparent stakeholder engagement.
  • Perform advanced SCA/SCA‑V functions.
  • Design and execute transparent Security Assessment Plans.
  • Analyze near real‑time posture using automated scans, logs, and CaC outputs.
  • Validate automated evidence and Policy and Compliance‑as‑Code results.
  • Synthesize mission‑focused risk analysis for the AO such as SAR, RAR, and authorization recommendations.
  • Lead technical incident response for cloud‑native systems.
  • Coordinate with SaaS providers during third‑party incidents.
  • Brief program leadership with a strict “no surprises” approach that enables timely, risk‑informed decisions.

Benefits

  • health, life, disability, financial, and retirement benefits
  • paid leave
  • professional development
  • tuition assistance
  • work-life programs
  • dependent care
  • recognition awards program
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service