Information Technology Security Specialist
- Discuss this with your agent
- Open in Claude
- Open in ChatGPT
Role details
Tech stack
+5 more
Job description
Experteer Overview In this role you support government-facing information systems security under close supervision, applying basic technical knowledge to certifications, RMF processes, and continuous monitoring. You collaborate with ISSMs and stakeholders to maintain security documentation and remediation progress. You contribute to vulnerability management, incident response, and contingency planning to safeguard mission-critical systems. This is a hands-on entry to mid-level role with clear growth in RMF lifecycle delivery and audits. Compensation / Benefits * Support system certifications, accreditations, and information security tasks under supervision * Develop and maintain RMF documentation (SSPs, ISCPs, IRPs, BIAs, SCDs, CMPs, PIAs, POA&Ms, AMPs, SIAs) * Create, track, and maintain POA&Ms across multiple information systems * Assist in risk analysis to identify vulnerabilities and threats; recommend mitigations * Assist vulnerability scanning and reporting; validate findings and identify false positives * Contribute to security contingency plans, disaster recovery procedures, and incident response training * Gather artifacts and support Continuous Monitoring Assessments and security audits * Provide cybersecurity guidance to project teams during development, configuration, and maintenance * Prepare and present status reports on findings, POA&M progress, and RMF activities Tasks * Bachelor’s degree or equivalent experience; 3+ years IT experience may substitute for degree * Public Trust clearance prior to start * Experience in IT network/devices, servers, or OS/DB platforms (Linux, Windows, UNIX, Oracle, SQL, etc.) or supporting information systems as Information Security/Cybersecurity professional * Working knowledge of NIST SP 800-30, 800-37, 800-40, 800-53 and RMF frameworks * Familiarity with vulnerability scoring (CVSS) and tools (Nessus, Qualys) * Strong written and verbal communication; detail-oriented with good organizational skills * Desirable certifications: Security+, SSCP, CAP/CGRC, CISA, CISSP, GSEC * Experience with RMF lifecycle documentation and implementation * Knowledge of configuration management and change control processes * Proficiency with Microsoft Office Suite (implied by role) Key requirements *
Requirements
_ identify false positives * Contribute to security contingency plans, disaster recovery procedures, and incident response training * Gather artifacts and support Continuous Monitoring Assessments and security audits * Provide cybersecurity guidance to project teams during development, configuration, and maintenance * Prepare and present status reports on findings, POA&M progress, and RMF activities Tasks * Bachelor’s degree or equivalent experience; 3+ years IT experience may substitute for degree * Public Trust clearance prior to start * Experience in IT network/devices, servers, or OS/DB platforms (Linux, Windows, UNIX, Oracle, SQL, etc.) or supporting information systems as Information Security/Cybersecurity professional * Working knowledge of NIST SP 800-30, 800-37, 800-40, 800-53 and RMF frameworks * Familiarity with vulnerability scoring (CVSS) and tools (Nessus, Qualys) * Strong written and verbal communication; detail-oriented with good organizational skills * Desirable aaaaaaaaa ISCPs, Security+, SSCP, CAP/CGRC, CISA, CISSP, GSEC * Experience with RMF lifecycle documentation and implementation * Knowledge of configuration management and change control processes * Proficiency with Microsoft Office Suite (implied by role) Key requirements *
Apply for this position
This job is hosted externally. Click below to view the full posting and apply.
Apply on us.experteer.comGood distractions
Talks and stories from around this role — technically off-topic, practically not.
Moments
Explore playlistsVideos
See allRelated articles
See all
What Are The Top Skills Required For Azure Developers?
Dev Digest 134 - Where pixels sing?
Walking Into The Era of Supply Chain Risks
Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.