> Markdown version of [/jobs/ext/1925963-information-assurance-subject-matter-expert](https://www.wearedevelopers.com/jobs/ext/1925963-information-assurance-subject-matter-expert). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Information Assurance Subject Matter Expert - **Company:** Premier Enterprise - **Location:** Washington, DC, United States (Remote available) - **Experience:** Expert - **Contract:** Permanent contract - **Skills:** Cyber Security, Information Systems, Information Security Management, Information Technology, Workday, Plan of Action and Milestones - **Published:** August 5, 2026 - **Apply:** https://www.clearancejobs.com/jobs/9076722/information-assurance-subject-matter-expert ## About the Role · Preferably Bachelor's of Science in Engineering or Computer Science. · At least one of these certifications CISSP, CISA, or CISM. Experience Requirements: · A minimum of seven (7) years IT experience with knowledge of federal government information security regulations and demonstrated hands-on security control assessment experience. · A minimum of five (5) years experience in conducting Security Assessment and Authorization projects · Working knowledge with NIST Special Publications 800-53, 800-53A, 800-37, and FISMA. · Seasoned Security Analyst and having developed numerous Security Test and Evaluation plans and reports. ## Description Provide Information Technology Security/Assurance Services in support of federal government client, in assessing the organization's information security posture. Research, develop, implement, test and review organization's information security controls in order to protect information and prevent unauthorized access. Inform users about security measures, explain potential threats, implement security measures and monitor networks. Define, create and maintain the documentation for Security Authorization of each information system in accordance with government requirements. Assess the impacts on system modifications and technological advances. Review systems in order to identify potential security weaknesses, recommend improvements to amend vulnerabilities, implement changes and document upgrades. Standard workday is 8 hours / day; 40 hours per week., · Participate in Security Test and Evaluation of networks, operating systems, databases, and applications at various government offices. · Development of Security Test and Evaluation Plans. · Review and evaluate IT and Information Security operational procedures. · Review and evaluation of Information Security Policies, Risk Assessment Reports, System Security Plans, Contingency Plans, Incident Response Plan, existing Security Test and Evaluation Plans/Reports, and other documentation. · Review and determine weaknesses in the information security program. · Conduct risk assessment to determine the level of risk to the IT environment. · Assess security policies, standards, and guidelines. · Identify vulnerabilities and provide corrective recommendations in the form of a Plan of Action and Milestone (POA&M). · Review ATO packages for FedRAMP certified systems. Conduct monthly risk assessments reviews of FedRAMP certified systems. ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Destigmatizing the Workplace: Building Real Inclusion](https://www.wearedevelopers.com/videos/1492-destigmatizing-the-workplace-building-real-inclusion) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [Microservices? Monoliths? An Annoying Discussion!](https://www.wearedevelopers.com/videos/970-microservices-monoliths-an-annoying-discussion) - [What makes Cybersecurity different for critical infrastructure?](https://www.wearedevelopers.com/videos/571-what-makes-cybersecurity-different-for-critical-infrastructure) - [The Future of Employee Wellbeing: Benefits, Trust & Performance](https://www.wearedevelopers.com/videos/1808-the-future-of-employee-wellbeing-benefits-trust-performance) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Best Paying Jobs in Technology](https://www.wearedevelopers.com/magazine/256-best-paying-jobs-in-technology) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [7 Important Tips That Every Software Developer Should Know](https://www.wearedevelopers.com/magazine/101-7-important-tips-that-every-software-developer-should-know) - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities)