> Markdown version of [/jobs/ext/1454168-cyber-information-assurance-security-specialist-lead](https://www.wearedevelopers.com/jobs/ext/1454168-cyber-information-assurance-security-specialist-lead). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Cyber Information Assurance/Security Specialist Lead - **Company:** Applied Information Sciences, Inc. - **Location:** Alexandria, VA, United States - **Experience:** Expert - **Salary:** $120,000.0 - $181,000.0 - **Contract:** Permanent contract - **Skills:** Cloud Computing Security, Cyber Security, Information Systems, Federal Information Processing Standards (FIPS), Information Security Management, IT Management, Information Systems Security Architecture Professional, Package Development Process, RSA (Cryptosystem), Software Requirements Analysis, SARS Software Products, Data Analytics, RSA Archer Platform - **Published:** July 26, 2026 - **Apply:** https://jobs.localjobnetwork.com/apply/add/86120873/1 ## About the Role * Master of Science in Information Management Systems or related field. * Minimum of 7 years of experience in IT and cybersecurity. * Certifications: * Certified Information Systems Security Professional (CISSP) * Certified Information Systems Auditor (CISA) * * Minimum of 3 years of experience supporting an Information Security program within a Federal Agency. * Hands-on experience with: + FISMA, FedRAMP, FIPS, and NIST SP 800-series + Risk Management Framework (RMF) + NIST Cybersecurity Framework (CSF) + Security Assessment & Authorization (SA&A / A&A) processes + Federal security compliance and reporting + RSA Archer eGRC or similar GRC platforms * Ability to translate technical system requirements into actionable, risk-based security guidance. * Strong communication, analytical, and stakeholder management skills. * Clearance: Secret Nice to Have Skills * Experience coordinating with senior federal security officials (AOs, ISSOs, CISOs). * Knowledge of cloud security, modernization efforts, and FedRAMP-authorized services. * Experience leading or mentoring security analysts, engineers, and compliance specialists. * Certification: Project Management Professional (PMP) ## Description At AIS, we are dedicated to providing our employees with diverse opportunities to grow their careers while supporting a variety of impactful projects. For this position, we are seeking a talented individual to join AIS as a Lead Security Engineer. * Core Knowledge & Skills: Develops strategic security plans, applies advanced cryptography, manages security programs, and designs secure cloud architectures. * Work & Complexity: Leads strategic projects, integrates security into business processes, develops risk management strategies, and ensures compliance. * Quality & Independence: Delivers strategic projects, develops innovative solutions, maintains high standards, and ensures stakeholder satisfaction. * Teamwork & Communication: Leads and mentors teams, aligns efforts with organizational goals, manages performance, and develops training programs. * Consulting & Engagement: Provides high-level consulting, leads innovation initiatives, develops technology roadmaps, and manages vendor contracts. As your initial project assignment, you will support the unique needs of our client as a Cyber Information Assurance/Security Specialist Lead. Project Summary The Cyber Information Assurance / Security Specialist Lead is responsible for providing strategic leadership and expert-level support for federal information security programs. This role ensures compliance with federal cybersecurity requirements, oversees governance, risk, and compliance (GRC) activities, supports system accreditation efforts, and drives the implementation of security frameworks across the enterprise. The ideal candidate brings deep knowledge of federal cybersecurity regulations, hands-on experience executing the Risk Management Framework (RMF), and extensive engagement with key security stakeholders across federal agencies. This is a proposal-based position; employment is contingent upon contract award and funding availability., Information Assurance & Security Leadership * Lead the planning, execution, and continuous improvement of federal information security programs. * Provide expert guidance on compliance with FISMA, FedRAMP, FIPS, and NIST Special Publications. * Manage security assessment and authorization (A&A) activities, including documentation, testing, reporting, and authorization package development. * Oversee the implementation and operationalization of the Risk Management Framework (RMF) and the NIST Cybersecurity Framework (CSF) across systems and services. Risk Management & Compliance * Manage IT Governance, Risk, and Compliance (GRC) programs to support enterprise security posture. * Utilize the RSA Archer eGRC tool to maintain risk registers, track compliance status, manage POA&Ms, and support audit readiness. * Translate technical requirements from system engineers and developers into actionable, data-driven, and risk-based security recommendations. * Evaluate and analyze security controls to ensure alignment with federal standards and organizational risk tolerances. Stakeholder Engagement & Relationship Management * Build and sustain strong working relationships with: + System Owners + Information System Security Officers (ISSOs) + Authorizing Officials (AOs) + Chief Information Security Officers (CISOs) * Serve as a senior advisor to leadership and stakeholders on cybersecurity risk, compliance needs, and mitigation strategies. * Facilitate briefings, security reviews, and status updates for executive and technical audiences. Security Program Execution * Coordinate and lead security reviews, risk assessments, and audits to ensure compliance with federal cybersecurity policies. * Support the development and maintenance of security documentation, including SSPs, SARs, RARs, and POA&Ms. * Identify gaps in security controls, recommend improvements, and oversee the implementation of corrective actions. * Provide mentorship and direction to junior analysts and security staff. ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Your Manager Doesn’t Come with a User Manual (But You Can Totally Write One)](https://www.wearedevelopers.com/videos/1495-your-manager-doesn-t-come-with-a-user-manual-but-you-can-totally-write-one) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [PySpark - Combining Machine Learning & Big Data](https://www.wearedevelopers.com/videos/44-pyspark-combining-machine-learning-big-data) - [What makes Cybersecurity different for critical infrastructure?](https://www.wearedevelopers.com/videos/571-what-makes-cybersecurity-different-for-critical-infrastructure) - [Engineering/Manager Pendulum: Generating compound interest on your career](https://www.wearedevelopers.com/videos/100348-engineering-manager-pendulum-generating-compound-interest-on-your-career) ## Related Articles - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [Best Paying Jobs in Technology](https://www.wearedevelopers.com/magazine/256-best-paying-jobs-in-technology) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again](https://www.wearedevelopers.com/magazine/751-how-we-built-a-worry-free-system-that-runs-for-10-years-and-what-we-d-do-again)