Information Security Risk Specialist

Booz Allen HamiltonMcLean, VA
$99,000 - $225,000Remote

About The Position

As an Information Security Risk Specialist on our team, you will leverage your expertise to collaborate closely with contractor and DoD government system owners, as well as system administrators and developers, to identify cyber risks, analyze applicable policies, and develop comprehensive mitigation strategies. Utilizing insights from subject matter experts (SMEs) and engineers, you will evaluate technical infrastructure and personnel dynamics to assess the full threat landscape. From there, you will guide clients through actionable remediation plans, delivering clear and impactful solutions through presentations, detailed white papers, and well-defined milestones to ensure effective risk management and cybersecurity resilience. You’ll work with your client to translate security concepts so they can make the best decisions to secure critical DoD systems. This is your opportunity to act as an information security SME while broadening your skills in DevSecOps and cloud security.

Requirements

  • 5+ years of experience working in a professional IT environment
  • 3+ years of experience in cybersecurity and Assessment and Authorization (A&A) supporting DoD environments
  • Experience supporting federal government or DoD ATO packages, performing A&A and RMF, and conducting risk assessments for federal government or DoD systems hosted in AWS, Azure, or hybrid cloud environments
  • Experience performing technical evaluations and security control assessments in cloud-native and containerized environments
  • Experience interfacing with engineering teams to align DevSecOps pipelines with cybersecurity policies
  • Knowledge of compliance testing tools such as ACAS, SCAP, STIGs or SRGs, eMASS, or Xacta
  • Experience with NIST SP 800-53, CNSSI 1253, artifact generation, SSPs, POA&Ms, SAPs, risk assessments, and continuous monitoring
  • TS/SCI clearance
  • HS diploma or GED
  • DoD 8570 Level II Security+ Certification or higher

Nice To Haves

  • Experience with DevSecOps, Path-to-Production, and CI/CD
  • Experience administering Red Hat Enterprise Linux 8 or Windows Server 2012 or higher
  • Experience with cloud tools and container orchestration security
  • Knowledge of STIG and compliance scans
  • Ability to advise stakeholders on cloud security strategies, container orchestration security such as Kubernetes and Rancher, and platform hardening
  • Possession of excellent verbal and written communication skills
  • Bachelor's degree in IT or Cybersecurity

Responsibilities

  • Identify cyber risks
  • Analyze applicable policies
  • Develop comprehensive mitigation strategies
  • Evaluate technical infrastructure and personnel dynamics to assess the full threat landscape
  • Guide clients through actionable remediation plans
  • Deliver clear and impactful solutions through presentations, detailed white papers, and well-defined milestones
  • Translate security concepts for clients to make the best decisions to secure critical DoD systems
  • Act as an information security SME
  • Broaden skills in DevSecOps and cloud security

Benefits

  • health, life, disability, financial, and retirement benefits
  • paid leave
  • professional development
  • tuition assistance
  • work-life programs
  • dependent care
  • recognition awards program
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service