> Markdown version of [/jobs/ext/1774375-information-assurance-engineer-w-top-secret-clearance](https://www.wearedevelopers.com/jobs/ext/1774375-information-assurance-engineer-w-top-secret-clearance). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Information Assurance Engineer w/ Top Secret Clearance - **Company:** A3 Consulting Llc - **Location:** Springfield, VA, United States - **Experience:** Expert - **Salary:** $160,000.0 - $180,000.0 - **Contract:** Permanent contract - **Skills:** Xacta, Agile Methodology, Configuration Management, Cyber Security, Custom Software, Firmware, Identity and Access Management, Information Security Management, Systems Development Life Cycle, Zero Trust Network Access, Software Engineering, Information Security Management System, Information Technology, Nessus, Plan of Action and Milestones, Vulnerability Analysis - **Published:** July 23, 2026 - **Apply:** https://www.disabledperson.com/jobs/73817380-information-assurance-engineer-w-top-secret-clearance ## About the Role * Bachelor's degree in Computer Science, Information Technology, Cybersecurity, or a Related Field. * Certification (DoD 8570/8140): IAT/IAM Level II Certification Required * 5+ years of experience in Cybersecurity/Information Assurance, with a proven track record of supporting software development in the DoD. * Demonstrated proficiency with the DoD Risk Management Framework (RMF) process, CNSSI 1253 control selection, and maintaining Bodies of Evidence (BoE). * Comprehensive understanding of DoD policies, directives, and initiatives as they relate to custom application development, including DISA STIGs and Section 508 Compliance. Desired Qualifications: * Direct experience managing packages in XACTA (or similar systems like eMASS) and analyzing scans from Nessus, Tenable, or Retina. * Excellent communication and collaboration skills, with the ability to effectively articulate technical concepts, receive feedback, and work collaboratively in a cross-functional Agile team environment. Security Clearance: * Active DoD Top Secret clearance with SCI eligibility required ## Description A3 Consulting is seeking a talented Information Assurance Engineer to join our innovative team supporting our Defense-based customer. If you enjoy being the primary authority responsible for managing and maintaining the Assessment and Authorization (A&A) process, operating across SIPRNet and JWICS environments, and ensuring National Security Systems maintain a rigorous and compliant security posture, this role is for you! In this job you will: * Function as the team's IA and Cybersecurity expert, owning the RMF process from start to finish within a fast-paced Agile environment. * Provide dedicated Information Assurance (IA) / Information Systems Security Engineer (ISSE) support to accomplish and maintain a Continuous Authority to Operate (ATO) for a critical defense based system. * Manage, contribute to, and continuously update RMF packages within XACTA by working closely with existing Information System Security Officers (ISSOs), the Development Team, and other stakeholders. * Create all necessary accreditation documentation for full ATO submission, including developing and maintaining the System Security Plan (SSP) and other documentation within the Body of Evidence (BoE). * Ensure that Configuration Management (CM) for all security-related software, hardware, and firmware is strictly maintained and documented. * Analyze vulnerability scan results and remediation efforts. * Support assessments, security patching, and maintain compliance with all applicable policies, directives, and best practices. * Address relevant security controls utilizing CNSSI 1253 overlays and NIST SP 800-53. * Ensure all unmet controls and identified vulnerabilities are addressed and accurately tracked within a Plan of Actions and Milestones (POA&M) to enable full ATO. * Ensure system compliance with DISA Security Technical Implementation Guides (STIGs), Information Assurance Vulnerability Alerts (IAVAs), and the DoD Zero Trust Strategy. * Report all security-related incidents to the Information Systems Security Manager (ISSM) and initiate protective or corrective measures upon vulnerability discovery. * Conduct periodic self-assessments, scans, and tests to identify vulnerabilities. * Support assessments and Independent Validation and Verification (IV&V) testing as needed/as required. * Support testing exercises (i.e. User, Regression, Smoke, and IV&V Testing) throughout the Software Development Lifecycle (SDLC) to ensure security enhancements and vulnerability patches do not compromise application functionality and performance. * Document software defects, bugs, and other issues identified during test exercises. * Troubleshoot and resolve issues identified. * Collaborate with cross-functional teams, including product managers, developers, and Government stakeholders, to seamlessly implement security requirements into the Agile backlog. * Provide expert-level technical assistance, diagnose complex security issues, and conduct root cause analyses for production environments. ## Related Videos - [Playing Pong on a shoulder press machine](https://www.wearedevelopers.com/videos/100140-playing-pong-on-a-shoulder-press-machine) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Get security done: streamlining application security with Aikido](https://www.wearedevelopers.com/videos/1638-get-security-done-streamlining-application-security-with-aikido) - [Agent Smith Gets Hardware: Autonomous IoT Hacking From Debug Port to Cloud API](https://www.wearedevelopers.com/videos/100258-agent-smith-gets-hardware-autonomous-iot-hacking-from-debug-port-to-cloud-api) - [One Pipeline, Three Regulator - SBOM Compliance for the Developer](https://www.wearedevelopers.com/videos/100169-one-pipeline-three-regulator-sbom-compliance-for-the-developer) - [When Agents Meet Legacy: Never Change a Running System](https://www.wearedevelopers.com/videos/100320-when-agents-meet-legacy-never-change-a-running-system) ## Related Articles - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [The Overflow: Security and Privacy](https://www.wearedevelopers.com/magazine/715-the-overflow-security-and-privacy) - [Best Paying Jobs in Technology](https://www.wearedevelopers.com/magazine/256-best-paying-jobs-in-technology) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking)