> Markdown version of [/jobs/ext/1973314-information-assurance-compliance-specialist](https://www.wearedevelopers.com/jobs/ext/1973314-information-assurance-compliance-specialist). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Information Assurance Compliance Specialist - **Company:** Athena Technology Group - **Location:** Philadelphia, PA, United States - **Experience:** Experienced - **Contract:** Permanent contract - **Skills:** Configuration Management, Cyber Security, Networking Hardware, Intrusion Detection and Prevention, Security Information and Event Management, Software Vulnerability Management, Firewalls (Computer Science), Web Content, Navsea, Plan of Action and Milestones, Vulnerability Analysis - **Published:** August 7, 2026 - **Apply:** https://www.clearancejobs.com/jobs/9080138/information-assurance-compliance-specialist ## About the Role Required: * Active Secret clearance (eligible to obtain and maintain a TS clearance) * Masters's degree from an accredited college or university (7 years of experience can substitute for a degree). * 5+ years of professional experience in Information Assurance Compliance. * CISSP or CISM or GSLC or CASP certification * Experience in eMASS Desired: * Previous Experience in NAVY cyber security environments * 2 years experieince in RMF ## Description We are seeking an Information Assurance Compliance Specialist to join our team. You will play a key part in ATG's technical support for Naval Surface Warfare Center Philadelphia Division (NSWCPD) specializing in cybersecurity support, validation support, IT and cyber policy writing and program implementation support. Our team will provide direct support for cybersecurity policy, A&A artifacts, validation, and security posture reviews., * Support evaluation and documentation in eMASS to include the security posture of the system or site being Assessed, Authorized, and maintained. * Develop, submit, and maintain RMF packages in accordance with DoD Instruction 8510.01, NAVSEA Business Rules, DON RMF Process Guides, NAVSEA Standard Operating Procedures (SOPs), and the business rules of cognizant review offices. * Support development the RMF package documentation required for submission in accordance with DoD/NAVSEA directives. Documents may include but are not limited too HW/SW Lists, Authorization Boundary Diagrams, Privacy Impact Assessment (PIA), etc. * Develop or revise existing policies, plans, and strategy documents to meet requirements for RMF Control Families and ensure all IA requirements have been addressed. * Conduct risk and vulnerability assessments of planned and installed systems to identify vulnerabilities, risks and protection needs. * Conduct systems security evaluation, audits, and reviews; determine the residual risk of a package based on package content and assessment results and documenting for the Security Controls Assessor's (SCA) and higher level review. * Execute Security Assessment Plans (SAPs) by conducting on-site testing for afloat and PIT ashore systems. * Develop and maintain in eMASS a Plan of Action and Milestone (POA&M) for all IA-related tasks and deliverables. * Conduct systems security reviews, audits, or evaluations, as appropriate, to ensure accreditation documents are accurate and represent the current risk posture of the system. * Perform analysis of logs, events, and reporting of various data collections tools including: vulnerability monitoring via Assured Compliance Assessment System (ACAS) and related tools, Host Based Security Systems (HBSS), web content filters, Security Information and event management (SIEM), firewall systems, network devices, server devices, workstations, and intrusion detection and prevention systems (ID/PS). * Assess impacts from observed risks and report via the Cybersecurity Program chain of command. * Executing Security Assessment Plans (SAPs) by conducting on-site testing for afloat and PIT ashore systems. Examples include executing STIGs, SRGs, ACAS scanning, and applying patches assets to obtain cybersecurity compliance and remediate vulnerabilities. * Perform the evaluation of system administrator, security engineer, and/or system owner proposed corrections to ensure compliance and best-fit solution. * Present and submit data to management, develop reports, and produce procedural documentation in a comprehensive and cohesive manner. * Perform risk management and security engineering for Research, Development, Testing, and Evaluation (RDT&E) RMF Afloat systems include Information Assurance Vulnerability Management (IAVM) support, remediation, patching, scanning and associated boundary maintenance. * Determine a system's compliance with all applicable Controls and Assessment Procedures (APs) for an assigned DoN system, including developing the appropriate test procedures, if necessary; executing the test procedures; and accurately documenting the results of security testing. * Maintain current vulnerability scan data and residual risk plan of actions and milestones in Vulnerability Remediation Asset Manager (VRAM). * Manage, attend, and support configuration control board practices, as needed. * Ensure RMF artifacts are in compliance with published Navy, NAVSEA Business Rules (OPNAV N2N6 and/or NAVSEA), NIST SP-800-37 and SP-800-53 Rev 4. * Create and verify the accuracy of POA&Ms/RARs as identified by vulnerability actual test results ## Related Videos - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [The What, Why, Who and How of accessibility on the web](https://www.wearedevelopers.com/videos/403-the-what-why-who-and-how-of-accessibility-on-the-web) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Reporting Active Exploits in 24 Hours: Are You Ready for the CRA?](https://www.wearedevelopers.com/videos/100248-reporting-active-exploits-in-24-hours-are-you-ready-for-the-cra) - [One Pipeline, Three Regulator - SBOM Compliance for the Developer](https://www.wearedevelopers.com/videos/100169-one-pipeline-three-regulator-sbom-compliance-for-the-developer) - [Cyber Security: Small, and Large!](https://www.wearedevelopers.com/videos/259-cyber-security-small-and-large) ## Related Articles - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Best Paying Jobs in Technology](https://www.wearedevelopers.com/magazine/256-best-paying-jobs-in-technology) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks) - [The Overflow: Security and Privacy](https://www.wearedevelopers.com/magazine/715-the-overflow-security-and-privacy)