> Markdown version of [/jobs/ext/1978328-information-technology-security-specialist](https://www.wearedevelopers.com/jobs/ext/1978328-information-technology-security-specialist). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Information Technology Security Specialist - **Company:** Science Applications International Corporation - **Location:** Oklahoma City, OK, United States - **Experience:** Experienced - **Contract:** Permanent contract - **Skills:** Microsoft Windows, Unix, Configuration Management, Cyber Security, Information Systems, Linux, Disaster Recovery, Microsoft Office, Oracle (Applications), SQL Databases, Software Vulnerability Management, Information Technology, Nessus, Network Server, Qualys, Plan of Action and Milestones, Vulnerability Analysis - **Published:** August 7, 2026 - **Apply:** https://us.experteer.com/career/view-jobs/information-technology-security-specialist-oklahoma-city-ok-usa-58826357 ## About the Role _ identify false positives * Contribute to security contingency plans, disaster recovery procedures, and incident response training * Gather artifacts and support Continuous Monitoring Assessments and security audits * Provide cybersecurity guidance to project teams during development, configuration, and maintenance * Prepare and present status reports on findings, POA&M progress, and RMF activities Tasks * Bachelor's degree or equivalent experience; 3+ years IT experience may substitute for degree * Public Trust clearance prior to start * Experience in IT network/devices, servers, or OS/DB platforms (Linux, Windows, UNIX, Oracle, SQL, etc.) or supporting information systems as Information Security/Cybersecurity professional * Working knowledge of NIST SP 800-30, 800-37, 800-40, 800-53 and RMF frameworks * Familiarity with vulnerability scoring (CVSS) and tools (Nessus, Qualys) * Strong written and verbal communication; detail-oriented with good organizational skills * Desirable aaaaaaaaa ISCPs, Security+, SSCP, CAP/CGRC, CISA, CISSP, GSEC * Experience with RMF lifecycle documentation and implementation * Knowledge of configuration management and change control processes * Proficiency with Microsoft Office Suite (implied by role) Key requirements * ## Description Experteer Overview In this role you support government-facing information systems security under close supervision, applying basic technical knowledge to certifications, RMF processes, and continuous monitoring. You collaborate with ISSMs and stakeholders to maintain security documentation and remediation progress. You contribute to vulnerability management, incident response, and contingency planning to safeguard mission-critical systems. This is a hands-on entry to mid-level role with clear growth in RMF lifecycle delivery and audits. Compensation / Benefits * Support system certifications, accreditations, and information security tasks under supervision * Develop and maintain RMF documentation (SSPs, ISCPs, IRPs, BIAs, SCDs, CMPs, PIAs, POA&Ms, AMPs, SIAs) * Create, track, and maintain POA&Ms across multiple information systems * Assist in risk analysis to identify vulnerabilities and threats; recommend mitigations * Assist vulnerability scanning and reporting; validate findings and identify false positives * Contribute to security contingency plans, disaster recovery procedures, and incident response training * Gather artifacts and support Continuous Monitoring Assessments and security audits * Provide cybersecurity guidance to project teams during development, configuration, and maintenance * Prepare and present status reports on findings, POA&M progress, and RMF activities Tasks * Bachelor's degree or equivalent experience; 3+ years IT experience may substitute for degree * Public Trust clearance prior to start * Experience in IT network/devices, servers, or OS/DB platforms (Linux, Windows, UNIX, Oracle, SQL, etc.) or supporting information systems as Information Security/Cybersecurity professional * Working knowledge of NIST SP 800-30, 800-37, 800-40, 800-53 and RMF frameworks * Familiarity with vulnerability scoring (CVSS) and tools (Nessus, Qualys) * Strong written and verbal communication; detail-oriented with good organizational skills * Desirable certifications: Security+, SSCP, CAP/CGRC, CISA, CISSP, GSEC * Experience with RMF lifecycle documentation and implementation * Knowledge of configuration management and change control processes * Proficiency with Microsoft Office Suite (implied by role) Key requirements * ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Docker network without Docker](https://www.wearedevelopers.com/videos/1418-docker-network-without-docker) - [WeAreDevelopers LIVE - Node and Package Security](https://www.wearedevelopers.com/videos/2138-wearedevelopers-live-node-and-package-security) - [What makes Cybersecurity different for critical infrastructure?](https://www.wearedevelopers.com/videos/571-what-makes-cybersecurity-different-for-critical-infrastructure) - [Docker exec without Docker](https://www.wearedevelopers.com/videos/1094-docker-exec-without-docker) - [The Time Paradox: Building Timezone-Safe Python/Django Applications](https://www.wearedevelopers.com/videos/1915-the-time-paradox-building-timezone-safe-python-django-applications) ## Related Articles - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking)