> Markdown version of [/jobs/ext/2195987-information-assurance-specialist](https://www.wearedevelopers.com/jobs/ext/2195987-information-assurance-specialist). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Information Assurance Specialist - **Company:** Strategic Inc - **Location:** Alexandria, VA, United States - **Experience:** Experienced - **Contract:** Permanent contract - **Skills:** Cloud Computing, Cyber Security, Identity and Access Management, Security Content Automation Protocol, Nessus, Devsecops, Plan of Action and Milestones, Vulnerability Analysis - **Published:** August 23, 2026 - **Apply:** https://www.clearancejobs.com/jobs/9108026/information-assurance-specialist ## About the Role * Active TS/SCI clearance. * 5+ years of Cybersecurity experience. * 3+ years proficiency in RMF processes. * Experience using and navigating eMASS tool to manage Assessment & Authorization (A&A) process. * Possess DoD 8570.01-M IAM Level I or II certifications such as CISSP, CISA, Security+. * Proficiency in performing risk-based reviews of Security Authorization Package. * Ability to work independently with minimal supervision or guidance. Desired: * Understanding of Army IC architectures, policies, and authorities. * Experience with Nessus Scanner. * Experience with Security Content Automation Protocol (SCAP) tool. * Understanding of DevSecOps, containers, cloud computing infrastructures, platforms, and services. ## Description Strategic ACI is seeking an on-site Information Assurance (IA) Specialist specializing in RMF. The candidate will work as part of a small cybersecurity team. The candidate will manage DoD Risk Management Framework (RMF) processes and will need to be familiar with creating eMASS packages, DISA STIGs, FISMA Compliance Requirements, NIST 800 Series, and the DoD ACAS Scanning tool desired., * Provide guidance in developing, reviewing, and maintaining security body of evidence BOE such as Security Plans (SSP), POA&Ms, STIG checklists, associated artifacts; and provide strategic recommendations in accordance with DoD and Army policies and procedures. * Validate resolution of vulnerabilities documented in the POA&M and provide evidence of resolution for approval. * Support on-site and remote site accreditation testing for networks at CONUS and OCONUS locations - travel up to 25%. * Ensure security-related concerns and incidents are reported to ISSMs and managed timely. * Provide guidance on NIST SP 800-53 publication for managing security controls. * Support the creation or modification of FISMA compliancy documentation such as Contingency Plans, Incident Response Plan, Access Control Plans, etc. * Evaluate system's risk in respect to operation at the network, system, and application level. * Evaluate vulnerability assessment results and STIG results and manage findings in eMASS. * Maintain close contact with government POCs to keep abreast of progress, report concerns or issues, and offer COAs as needed. ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [DevSecOps: Injecting Security into Mobile CI/CD Pipelines](https://www.wearedevelopers.com/videos/273-devsecops-injecting-security-into-mobile-ci-cd-pipelines) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [Organizational Change Through The Power Of Why - DevSecOps Enablement](https://www.wearedevelopers.com/videos/478-organizational-change-through-the-power-of-why-devsecops-enablement) - [Maturity assessment for technicians or how I learned to love OWASP SAMM](https://www.wearedevelopers.com/videos/351-maturity-assessment-for-technicians-or-how-i-learned-to-love-owasp-samm) - [DevSecOps culture](https://www.wearedevelopers.com/videos/783-devsecops-culture) ## Related Articles - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks) - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [The Overflow: Security and Privacy](https://www.wearedevelopers.com/magazine/715-the-overflow-security-and-privacy) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking)