Information Assurance Engineer

Alesig Consulting LLC
United States
3 months ago

Role details

Contract type
Contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
5 years minimum
Working hours
Regular working hours
Job source

Tech stack

Business Systems CompTIA Security+ Information Systems Security Content Automation Protocol Information Technology

Job description

Work as part of a team, being responsible and accountable for individual production and overall team performance supporting Risk Management Framework (RMF) efforts for 13 Business Systems. Each package consists of at least 450 security controls and approximately 2,000 assessment procedures., * Support the RMF Process.

  • Use DoD Enterprise Mission Assurance Support Service (eMASS) for the RMF process.
  • Update eMASS to ensure each package’s status is current.
  • Ensure that security documents always reflect the current status of the associated information system, which may require daily or weekly updates.
  • Maintain a schedule of RMF-related activities and the Authority to Operate (ATO) status for each package.
  • Develop new system security documentation and update existing system security documentation to facilitate achieving Business Systems’ ATO.
  • Request, gather and formalize inputs for all RMF-required documentation (e.g., Security Plan, Plan of Action & Milestones (POA&M), Security Design Document, etc.) from other organizations (e.g., program management offices, systems management offices, system administrators, functional managers, etc.) to fully complete all system RMF requirements.
  • Complete and submit for review packages no later than 90 days prior to expiration of the system’s accreditation.
  • Monitor the status of the RMF packages through the ATO phases.
  • Compile Interim Authority to Test (IATT) packages for the business systems.
  • Assess control effectiveness; document changes to the system and environment of operation; conduct risk assessments and impact analyses; and report on the security and privacy posture of the system.
  • Initiate re-accreditation efforts.
  • Maintain a comprehensive list of all POA&Ms.
  • Monitor Business Systems for Security Technical Implementation Guides (STIG) compliance.
  • Ingest the STIGs into the corresponding eMASS package and associate STIG findings with the appropriate RMF control.
  • Submit all RMF Workflows via eMASS on the respective program’s behalf.

Requirements

  • Secret Clearance Required (Interim Secret is acceptable)
  • Active CompTIA Security+ (or equivalent IAT II Certification) is required
  • Proven experience and proficiency working with eMASS.
  • Demonstrated understanding of the RMF process.
  • Proficient utilizing Security Content Automation Protocol (SCAP) scans or STIG Viewer and reviewing manual STIGs.

Education & Work Experience

  • Bachelor’s Degree in a computer-science related field is preferred
  • 5+ years of relevant IT experience

Preferred Qualifications

  • CGRC (Certified in Governance, Risk and Compliance)

Physical Requirements

Employees must be able to sit at a workstation for extended periods of time. They should be able to use their hands to handle or feel objects, tools, or controls, as well as reach with their hands and arms. The ability to talk, see, and hear is also required. Employees must be capable of working on a desktop or laptop computer for long durations. Occasionally, they may need to lift and move moderate amounts of weight, typically no more than 20 pounds. Regular and predictable attendance is essential.

The physical demands described here are representative of those that must be met by an employee to successfully perform the essential functions of this job. Alesig will make reasonable accommodations to enable individuals with disabilities to perform the essential functions and in compliance with the Americans with Disabilities Act of 1990.

Pre-Employment Screening Requirements

Must be able to successfully complete Alesig Consulting’s pre-employment screening process and any additional pre-employment screens required for your position by the client.

If hired for the position, you must be able to provide proof of eligibility to work in the United States.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on indeed.com

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

3:22 min

Transitioning from software engineering to security roles

Anna Oliveira · Coffee With Developers

59 sec

Proving regulatory compliance to auditors and chief officers

Mike Bursell Mike Bursell · World Congress 2026 Europe

4:30 min

Solving impossible enterprise problems instead of retrofitting applications

Dona Sarkar +1 · Coffee With Developers

2:28 min

Preventing sensitive information disclosure in RAG systems

Deepu Deepu · World Congress 2025

1:08 min

The inability to secure sensitive information in system prompts

Sebastian Schrittwieser · World Congress 2023

4:01 min

Finding personal fulfillment in the cybersecurity industry

LIVE

Videos

See all

Related articles

See all