> Markdown version of [/jobs/ext/1763973-senior-information-security-engineer](https://www.wearedevelopers.com/jobs/ext/1763973-senior-information-security-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Senior Information Security Engineer - **Company:** ASRC Federal Holding Company - **Location:** Huntsville, AL, United States - **Experience:** Expert - **Contract:** Permanent contract - **Skills:** Cyber Security, Information Systems, Security Software, SC Clearance, Information Technology - **Published:** July 2, 2026 - **Apply:** https://dejobs.org/x/x/74F035E71A8A47E288CEB5C392914C6D/job/ ## About the Role The Senior IA Professional will lead a team of intermediate-level personnel, providing guidance and oversight in all aspects of Risk Management Framework (RMF) activities, cybersecurity assessments, and incident response. This role requires a deep understanding of cybersecurity principles, a strong analytical ability, and excellent communication skills to effectively convey complex information to both technical and non-technical audiences., * Minimum of 5 years of experience in cybersecurity, with a focus on policy review, RMF implementation, and compliance. Demonstrated experience leading and mentoring junior staff. * Proficient in: * DoD and Army cybersecurity regulations and policies. * The Risk Management Framework (RMF) process. * Strong analytical and problem-solving skills. * Proficiency in using cybersecurity tools and technologies (eMASS). * Strong written and verbal communication skills, including the ability to prepare and deliver briefings to senior leadership. CLEARANCE LEVEL * SECRET Clearance EDUCATION REQUIRMENTS * Bachelor's degree in information technology, Cybersecurity, Data Science, Information Systems, or Computer Science from an ABET-accredited or CAE-designated institution CERTIFICATION * One of the following required: CISM, CISSO, FITSP-M, GCIA, GCSA, GCIH, GSLC, GICSP, CISSP-ISSMP, or CISSP ## Description ASRC Federal is looking for an experienced IA Policy and Compliance Certified Professional - Senior to support their work with the U.S. Army Contracting Command (ACC) Chief Information Officer (CIO) G6 at Redstone Arsenal, AL. The Senior IA Professional serves as a subject matter expert (SME) and technical leader within the ACC Headquarters (HQ) Cybersecurity Division (CSD). This position is responsible for the development, implementation, and maintenance of cybersecurity policies, standards, and procedures, ensuring compliance with applicable Department of Defense (DoD), Army, and ACC regulations., * Establish, maintain, and retain the Command Cybersecurity Standard Operating Procedures (SOPs) and Tactics, Techniques, and Procedures (TTPs). * Develop and maintain an ACC CIO/G6 Cybersecurity portal for dissemination of key products and documentation. * Lead and oversee the Risk Management Framework (RMF) lifecycle for multiple systems. Work with the Intermediate IA Professionals to maintain current Authority to Operate (ATO) status for these systems and provide RMF guidance and support to other ACC locations with similar systems. * Ensure all Military, Government, and Contractor IT/Cybersecurity personnel maintain records of training and certifications in the approved repository. Administer and maintain the repository, tracking requirements and notifying users of deficiencies. * Provide executive monthly briefings and reports to Senior Level Government Representatives on cybersecurity status and performance metrics (e.g., Cyber Scorecard). Report all deficiencies to the Government on a weekly basis. * Provide plans, strategies, and analysis to support the ACC CIO/G6 Cybersecurity Official with strategic program development. Utilize assessment tools to determine current cybersecurity posture, identify risks, and develop actionable strategies. Align cybersecurity priorities with Army and ACC strategic plans. * Identify, investigate, research, analyze, and report on Cyber-related capabilities and technologies to meet current and emerging command needs. Assess and report on technology solutions for potential integration into the DoDIN or command enclaves. * Conduct research to increase Cyber awareness and protection. Assess the feasibility of emerging ideas and participate in service, joint, and interagency events. Identify emerging Cyber trends and prepare vision documents and strategic studies. * Complete, track, and report completion of Cybersecurity taskers to the responsible HQ ACC Division Chief. * Provide plans, strategies, and analysis to support implementation of privacy standards (AR 340-21) and strategic development of Privacy training and policies. Support the ACC CIO/G6 Privacy Official with program support, incident handling, and reporting. * Attend and participate in Cyber-related working groups, meetings, and briefings as directed by the Government and maintain the Cyber Division calendar. ## Related Videos - [Software Security 101: Secure Coding Basics](https://www.wearedevelopers.com/videos/220-software-security-101-secure-coding-basics) - [Reporting Active Exploits in 24 Hours: Are You Ready for the CRA?](https://www.wearedevelopers.com/videos/100248-reporting-active-exploits-in-24-hours-are-you-ready-for-the-cra) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [What makes Cybersecurity different for critical infrastructure?](https://www.wearedevelopers.com/videos/571-what-makes-cybersecurity-different-for-critical-infrastructure) - [Cyber Security: Small, and Large!](https://www.wearedevelopers.com/videos/259-cyber-security-small-and-large) ## Related Articles - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Best Paying Jobs in Technology](https://www.wearedevelopers.com/magazine/256-best-paying-jobs-in-technology) - [What’s the Difference between a Junior, Mid, and Senior Developer?](https://www.wearedevelopers.com/magazine/238-what-s-the-difference-between-a-junior-mid-and-senior-developer) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [How should you format your IT resume?](https://www.wearedevelopers.com/magazine/68-how-should-you-format-your-it-resume)