> Markdown version of [/jobs/ext/2189141-information-assurance-specialist-iv](https://www.wearedevelopers.com/jobs/ext/2189141-information-assurance-specialist-iv). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Information Assurance Specialist IV - **Company:** OneZero Solutions - **Location:** Mechanicsburg, PA, United States - **Experience:** Experienced - **Contract:** Permanent contract - **Skills:** Amazon Web Services, Software as a Service, Cloud Computing Security, Cyber Security, Identity and Access Management, Information Security Management, SAP (Applications), Policy as Code, SC Clearance, Information Technology, Devsecops, Plan of Action and Milestones - **Published:** August 22, 2026 - **Apply:** https://www.clearancejobs.com/jobs/9099943/information-assurance-specialist-iv ## About the Role Bachelor's degree from an accredited institution in Information Technology, Computer Science, Engineering, or a related technical discipline. Current DoW 8570/8140 certification meeting the IAM Level II or IAT Level II baseline requirement (e.g., CISSP, Security+ CE, CISM, CASP+ CE). Five (5) years of dedicated Information Assurance experience, with at least three (3) of those years being consecutive. Three (3) consecutive years directly relevant to the tasks above, demonstrating a hands-on understanding of the DoW cybersecurity environment. Active Secret clearance; U.S. citizenship required., Expert knowledge of RMF, NIST SP 800-53, DISA STIGs, and the Cybersecurity Risk Management Construct (CSRMC). Master-level proficiency in eMASS as the authoritative system of record for assessment and authorization data. Familiarity with FedRAMP, DoW Impact Levels, and the DoW Cloud Computing Security Requirements Guide (CCSRG). Hands-on experience securing AWS cloud-native architectures and authorized SaaS solutions. Ability to review and validate Compliance-as-Code (CaC) and Policy-as-Code (PaC) profiles, scripts, and automated compliance evidence. Skill in risk analysis, POA&M development, and drafting decision-quality authorization documentation (SAP, SAR, Authorization Recommendation Memo). Clear, no-surprises reporting and effective collaboration with system owners, ISSMs ## Description The Information Assurance Specialist IV is key personnel providing senior Information System Security Officer (ISSO), Security Control Assessor (SCA), and Security Controls Validator (SCA-V) support across DSCA's five IM&T. The role ensures the confidentiality, integrity, and availability of data on assigned systems, leads operationalization of RMF/CSRMC in a cloud-native DevSecOps environment, and drives automation of control implementation, evidence collection, and authorization artifacts in support of A&A, Assess Only, and continuous ATO (cATO) outcomes., Serving as ISSO for assigned DSCA IM&T portfolio systems, ensuring confidentiality, integrity, and availability of data residing on or transiting those systems. Leading operationalization of the RMF/Cybersecurity Risk Management Construct (CSRMC) within a cloud-native, DevSecOps framework, and automating security control implementation and evidence collection to achieve and maintain A&A, Assess Only, and cATO accreditations. Proactively identifying and mitigating security weaknesses and maintaining accurate, current security documentation. Developing the Security Assessment Plan (SAP) and conducting ongoing assessments of security controls beyond periodic compliance checks. Providing actionable risk analysis that prioritizes vulnerabilities and control deficiencies, and interpreting and validating outputs of automated validation tools and Policy-as-Code scripts. Developing and maintaining key authorization artifacts, including the Security Assessment Report (SAR), the Authorization Recommendation Memo, and the program's overarching ATO documentation. Performing SCA-V duties: validating security and compliance content, assessing CaC profiles and scripts, and verifying that automated compliance evidence is correctly ingested and reflected. Maintaining the eMASS record as the system of record, documenting all assessment activities, findings, and evidence in a timely and accurate manner. Performing in-depth risk analysis and POA&M support and providing written recommendations for mitigation and validation of proposed corrective actions. Preparing and assembling the Security Authorization Package and briefing the SCA, ISSM, and other stakeholders on assessment results and residual risk. Knowledge, Skill and Abilities ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [DevSecOps: Injecting Security into Mobile CI/CD Pipelines](https://www.wearedevelopers.com/videos/273-devsecops-injecting-security-into-mobile-ci-cd-pipelines) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [Organizational Change Through The Power Of Why - DevSecOps Enablement](https://www.wearedevelopers.com/videos/478-organizational-change-through-the-power-of-why-devsecops-enablement) - [DevSecOps culture](https://www.wearedevelopers.com/videos/783-devsecops-culture) - [You can’t hack what you can’t see](https://www.wearedevelopers.com/videos/41-you-can-t-hack-what-you-can-t-see) ## Related Articles - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again](https://www.wearedevelopers.com/magazine/751-how-we-built-a-worry-free-system-that-runs-for-10-years-and-what-we-d-do-again) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [What Makes WeAreDevelopers World Congress Different From Every Other Tech Event?](https://www.wearedevelopers.com/magazine/701-what-makes-wearedevelopers-world-congress-different-from-every-other-tech-event) - [The Overflow: Security and Privacy](https://www.wearedevelopers.com/magazine/715-the-overflow-security-and-privacy)