> Markdown version of [/jobs/ext/169603-information-security-risk-specialist](https://www.wearedevelopers.com/jobs/ext/169603-information-security-risk-specialist). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Information Security Risk Specialist - **Company:** Booz Allen Hamilton Inc. - **Location:** East Port Orchard, WA, United States - **Experience:** Experienced - **Salary:** $61,900.0 - $141,000.0 - **Contract:** Permanent contract - **Skills:** Unix, Ubuntu (Operating System), Cloud Computing, CompTIA Security+, Cyber Security, Linux, Federal Information Processing Standards (FIPS), Red Hat Enterprise Linux, Security Software, Software Vulnerability Management, Devsecops - **Published:** May 14, 2026 - **Apply:** https://seeker-sp.worksourcewa.com/jobview/GetJob.aspx?JobID=293413592 ## About the Role * 2+ years of experience with program control and governance, system security lifecycle management, authorization, POA&Ms, vulnerability remediation, privacy, Information Systems Security Engineer(ISSE)support, and threat modeling * 2+ years of experience preparing system accreditation documentation required by the Navy or DoD and assessing system vulnerability using approved DoD tools * 2+ years of experience guiding a client through the entire Risk Management Framework(RMF)and Authority to Operate(ATO)process * Knowledge ofpolicymanagement support, change management, cybersecurity engineering, requirements, and cybersecurity tools development * Knowledge of cybersecurity monitoring standards and enterprise security requirements or standards such as FIPS, NIST, Executive Orders, Notices, and Memoranda * Top Secret clearance * HS diploma or GED * Industry certification such as CISSP or CompTIA Security+ Certification Nice If You Have: * Experience maintaining security configurations of production, development, and test systems by applying and configuring security controls * Experience with STIGs * Experience with DevSecOps * Experience with Cloud technologies * Experience with operating systems, including Linux, UNIX, Ubuntu, or Red Hat * Ability to apply cybersecurity engineering methods to solutions development lifecycle activities * Ability to research emerging technology and apply findings to cutting-edge problems * Possession of excellent presentation and collaboration skills ## Description them seem overwhelming to the global enterprise and government agencies. In all of this "cyber noise," how can these organizations understand their risks and how to mitigate them? The answer is you. We need your knowledge as an information security risk spe cia list to help break down complex threats into manageable plans of action. As an Information Security Risk Spe cia list on our team, you'll assist technical leaders with discovering their cyber risks, understanding applicable policies , and developing a mitigation plan. You'll get technical and personnel details from key stakeholders to assess the entire threat landscape. Then, you'll help your team guide your client through a plan of action with presentations, white papers, and milestones and help to translate security concepts so they can make the best decisions to secure their critical infrastructure, and mission-critical systems. ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [DevSecOps: Injecting Security into Mobile CI/CD Pipelines](https://www.wearedevelopers.com/videos/273-devsecops-injecting-security-into-mobile-ci-cd-pipelines) - [Docker network without Docker](https://www.wearedevelopers.com/videos/1418-docker-network-without-docker) - [WeAreDevelopers LIVE - Node and Package Security](https://www.wearedevelopers.com/videos/2138-wearedevelopers-live-node-and-package-security) - [Organizational Change Through The Power Of Why - DevSecOps Enablement](https://www.wearedevelopers.com/videos/478-organizational-change-through-the-power-of-why-devsecops-enablement) - [DevSecOps culture](https://www.wearedevelopers.com/videos/783-devsecops-culture) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [The Overflow: Security and Privacy](https://www.wearedevelopers.com/magazine/715-the-overflow-security-and-privacy) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed)