Information Assurance Specialist
- Discuss this with your agent
- Open in Claude
- Open in ChatGPT
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Role details
Tech stack
Job description
Strategic ACI is seeking an on-site Information Assurance (IA) Specialist specializing in RMF. The candidate will work as part of a small cybersecurity team. The candidate will manage DoD Risk Management Framework (RMF) processes and will need to be familiar with creating eMASS packages, DISA STIGs, FISMA Compliance Requirements, NIST 800 Series, and the DoD ACAS Scanning tool desired., * Provide guidance in developing, reviewing, and maintaining security body of evidence BOE such as Security Plans (SSP), POA&Ms, STIG checklists, associated artifacts; and provide strategic recommendations in accordance with DoD and Army policies and procedures.
- Validate resolution of vulnerabilities documented in the POA&M and provide evidence of resolution for approval.
- Support on-site and remote site accreditation testing for networks at CONUS and OCONUS locations - travel up to 25%.
- Ensure security-related concerns and incidents are reported to ISSMs and managed timely.
- Provide guidance on NIST SP 800-53 publication for managing security controls.
- Support the creation or modification of FISMA compliancy documentation such as Contingency Plans, Incident Response Plan, Access Control Plans, etc.
- Evaluate system’s risk in respect to operation at the network, system, and application level.
- Evaluate vulnerability assessment results and STIG results and manage findings in eMASS.
- Maintain close contact with government POCs to keep abreast of progress, report concerns or issues, and offer COAs as needed.
Requirements
- Active TS/SCI clearance.
- 5+ years of Cybersecurity experience.
- 3+ years proficiency in RMF processes.
- Experience using and navigating eMASS tool to manage Assessment & Authorization (A&A) process.
- Possess DoD 8570.01-M IAM Level I or II certifications such as CISSP, CISA, Security+.
- Proficiency in performing risk-based reviews of Security Authorization Package.
- Ability to work independently with minimal supervision or guidance.
Desired:
- Understanding of Army IC architectures, policies, and authorities.
- Experience with Nessus Scanner.
- Experience with Security Content Automation Protocol (SCAP) tool.
- Understanding of DevSecOps, containers, cloud computing infrastructures, platforms, and services.
Benefits & conditions
Strategic Alliance Consulting, Inc. believes that our greatest asset is our employees. Our goal is not to meet our staff’s expectations, but to exceed them. Competitive salaries, work-life balance, industry leading benefits packages, and family first values are at the core of Strategic ACI’s culture.
We’re proud the be selected as a 2020 Best Places to Work in the Greater Washington Area by the Washington Business Journal (WBJ), as well as being 1 of 19 Virginia based companies to be awarded the prestigious HIRE Vets Gold Medallion by the Department of Labor for our commitment to veteran hiring, retention, and professional development.
Your Strategic ACI Total Rewards Compensation Package includes:
- Competitive salary
- 100% benefits paid (Includes; health, dental, and vision plan premiums) for all full time employees and their families
- 401k with 5% match vested at day one!
- Profit sharing commensurate with company growth
- PTO - 3 weeks and 3 days per year
- 11 Company Paid Holidays (aligned with Federal Government)
- Long term/Short term disability
- 1.5x salary life insurance
- $100 per month cell phone allowance
- $6000 cash in lieu of benefits per year if employee is insured elsewhere
- Tuition reimbursement of up to $5,250 per year for college or professional certifications
- Casual dress code, company lunches, flexible schedules, employee phone plan discounts
Apply for this position
This job is hosted externally. Click below to view the full posting and apply.
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Good distractions
Talks and stories from around this role — technically off-topic, practically not.
Moments
Explore playlistsVideos
See allRelated articles
See all
Walking Into The Era of Supply Chain Risks
What Are The Top Skills Required For Azure Developers?
Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.
The Overflow: Security and Privacy