> Markdown version of [/jobs/ext/1925602-senior-information-assurance-specialist](https://www.wearedevelopers.com/jobs/ext/1925602-senior-information-assurance-specialist). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Senior Information Assurance Specialist - **Company:** Copper River Family Of Companies - **Location:** Kettering, OH, United States - **Experience:** Expert - **Salary:** $125,000.0 - $140,000.0 - **Contract:** Permanent contract - **Skills:** Microsoft Word, Microsoft Excel, Data Analysis, Code Review, Cyber Security, Information Systems, Information Security Management, Lookup Table, Microsoft Office, Pivot Tables, Microsoft PowerPoint, Systems Development Life Cycle, Software Vulnerability Management, Information Technology, Nessus, Vulnerability Analysis - **Published:** August 5, 2026 - **Apply:** https://jobs.localjobnetwork.com/apply/add/87943679/1 ## About the Role * Bachelor's degree in Cybersecurity, Information Technology, Computer Science, or related field preferred. * Required Experience: + Experience working with NIST SP 800-53 Revision 5 (preferred) + Hands-on experience supporting DoD Information Systems and cybersecurity processes + Experience developing and supporting Authorization to Operate (ATO) packages + Hands-on experience implementing and assessing Risk Management Framework (RMF) security controls + Experience supporting SIPRNet information system authorization packages, including artifact development, control implementation, and security test documentation + Experience using eMASS to manage RMF and ATO activities + Experience supporting cybersecurity compliance throughout the System Development Life Cycle (SDLC) * Required Skill and Competencies + Strong understanding of DoD Information Assurance principles and cybersecurity compliance requirements + Experience with vulnerability management tools, including Nessus, DISA STIGs, and IAVA compliance + Excellent analytical, organizational, and problem-solving skills + Strong written and verbal communication skills with the ability to explain complex technical concepts to diverse audiences + Advanced proficiency with Microsoft Office Suite, including: o Microsoft Excel (PivotTables, VLOOKUP/XLOOKUP, formulas, and data analysis) o Microsoft Word (professional documentation and technical reports) o Microsoft PowerPoint (executive-level presentations) ## Description TACG is seeking an experienced Senior Information Assurance Specialist to serve as an Information System Security Officer (ISSO) supporting Department of Defense (DoD) information systems. This position is responsible for leading cybersecurity and information assurance initiatives, ensuring compliance with DoD cybersecurity policies, and supporting the full lifecycle of Assessment and Authorization (A&A) activities under the Risk Management Framework (RMF). The ideal candidate possesses extensive experience supporting classified and unclassified information systems, developing Authorization to Operate (ATO) packages, implementing cybersecurity controls, and collaborating with government stakeholders to maintain secure, compliant systems. Responsibilities (include but are not limited to): * Lead the development, maintenance, and submission of Assessment & Authorization (A&A) packages in accordance with the DoD Risk Management Framework (RMF). * Develop and maintain Authorization to Operate (ATO) documentation, including Security Plans, Cybersecurity Strategies, POA&Ms, Security Assessment Reports, and supporting artifacts. * Utilize eMASS, ITIPS, and other DoD cybersecurity tools to manage authorization packages and system compliance. * Conduct continuous monitoring activities throughout the System Development Life Cycle (SDLC) to identify, assess, and mitigate cybersecurity risks. * Perform vulnerability assessments using tools such as Nessus, analyze DISA STIG compliance, review IAVAs, and validate security configurations. * Evaluate system security posture through source code reviews, security testing, and compliance assessments. * Develop, implement, and maintain Information Assurance (IA) policies, procedures, and security architectures aligned with DoD and federal cybersecurity requirements. * Ensure compliance with NIST, FISMA, DoD cybersecurity directives, and applicable security standards. * Serve as the primary cybersecurity liaison between Program Management Offices (PMOs), development teams, system owners, government ISSMs, and other stakeholders. * Review vendor deliverables, assess technical security risks, recommend mitigation strategies, and validate cybersecurity documentation. * Provide guidance and recommendations on cybersecurity best practices to support secure system development and operations. * Communicate technical security concepts effectively to both technical and non-technical stakeholders. ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Is it still C#? Practical systems programming with .NET (war stories included)](https://www.wearedevelopers.com/videos/100138-is-it-still-c-practical-systems-programming-with-net-war-stories-included) - [Are Code Reviews Worth It? Insights from 16 Years of Review Data](https://www.wearedevelopers.com/videos/1135-are-code-reviews-worth-it-insights-from-16-years-of-review-data) - [What makes Cybersecurity different for critical infrastructure?](https://www.wearedevelopers.com/videos/571-what-makes-cybersecurity-different-for-critical-infrastructure) - [NoSQL Data Modeling for Front-end Developers](https://www.wearedevelopers.com/videos/297-nosql-data-modeling-for-front-end-developers) - [Build a CI/CD pipeline to automate code reviews and ensure code quality](https://www.wearedevelopers.com/videos/349-build-a-ci-cd-pipeline-to-automate-code-reviews-and-ensure-code-quality) ## Related Articles - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [The Overflow: Security and Privacy](https://www.wearedevelopers.com/magazine/715-the-overflow-security-and-privacy)