Information Security Risk Specialist

Booz Allen Hamilton•Annapolis Junction, MD
•Onsite

About The Position

Cyber threats are everywhere, and the constantly evolving nature of these threats can make understanding them seem overwhelming. In all of this “cyber noise” how can these organizations understand their risks and how to mitigate them? The answer is an information security risk specialist like you who will break down complex threats into manageable plans of action. As an information security risk specialist on our team, you’ll use your experience to work with senior leaders to discover their cyber risks, understand applicable policies, and develop a mitigation plan. You’ll review technical and personnel details from our tenants to assess the entire threat landscape. Then, you’ll guide our tenants through a plan of action with presentations, whitepapers, and milestones. You’ll work with cloud architects, cybersecurity teams, GRC, networking, platform engineering, and tenant teams to make security controls repeatable and usable. You’ll help ensure that users receive the right platform, understand the controls they inherit, and know what remains their responsibility. This is your opportunity to apply cloud-security expertise while expanding your skills in secure platform engineering, AWS GovCloud, IL5 environments, Infrastructure-as-Code, control inheritance, and enterprise-scale cloud transformation. Join us. The world can’t wait.

Requirements

  • 5+ years of experience securing, hardening, and remediating security vulnerabilities in AWS GovCloud
  • Experience with CMMC, NIST 800-171, DoD security controls, FedRAMP, defense SRG, or cloud security frameworks
  • Experience with cloud networking, routing, segmentation, firewalls, private connectivity, DNS, and network security controls
  • Experience with control inheritance, SSP generation, evidence mapping, or authorization package support
  • Knowledge of AWS organizations, organizational units, service control policies, identity, account governance, and cloud security baselines
  • Ability to translate policy to both senior stakeholders and operations teams who need to implement the controls
  • Public Trust
  • Bachelor's degree

Nice To Haves

  • Experience implementing Infrastructure-as-Code using Terraform, CloudFormation, CDK, or comparable technologies
  • Experience deploying secure landing zones, shared services, platform baselines, or multi-account cloud architectures
  • Experience with AWS Security Hub, GuardDuty, Config, CloudTrail, Network Firewall, Transit Gateway, Cloud WAN, Splunk, Tenable, F5, or comparable technologies
  • Experience supporting cloud migrations, tenant onboarding, account adoption, network-path validation, or platform-parity initiatives
  • Knowledge of IAM Identity Center, federation, Keycloak, Entra ID, privileged access, and identity-boundary design
  • Possession of excellent detail-oriented, organization, and time management skills
  • Possession of excellent verbal and written communication skills
  • CISSP, CCSP, Security+, AWS Security Specialty, CISM, or equivalent Certification

Responsibilities

  • Work with senior leaders to discover their cyber risks, understand applicable policies, and develop a mitigation plan.
  • Review technical and personnel details from tenants to assess the entire threat landscape.
  • Guide tenants through a plan of action with presentations, whitepapers, and milestones.
  • Work with cloud architects, cybersecurity teams, GRC, networking, platform engineering, and tenant teams to make security controls repeatable and usable.
  • Ensure that users receive the right platform, understand the controls they inherit, and know what remains their responsibility.

Benefits

  • health, life, disability, financial, and retirement benefits
  • paid leave
  • professional development
  • tuition assistance
  • work-life programs
  • dependent care
  • recognition awards program
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service