Information Assurance (IA) Engineer

Systems, Inc
Hanscom Air Force Base, MA, United States
3 months ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Experienced
Experience required
2 years minimum
Working hours
Regular working hours
Job source

Tech stack

Amazon Web Services Audit Trail Microsoft Azure Cloud Computing CompTIA Security+ Cyber Security Oracle (Applications) Zero Trust Network Access Software Vulnerability Management Google Cloud Cloud Platform System SC Clearance
+1 more
Devsecops

Job description

The Information Assurance (IA) Engineer will provide Risk Management Framework (RMF) engineering and cybersecurity support for the USAF Cloud One (C1) enterprise cloud environment supporting AWS, Azure, Oracle, and GCP at DoD Impact Levels (IL) 2-6. The position directly supports ISSO/ISSM functions, ATO sustainment, continuous monitoring, vulnerability management, and cybersecurity compliance activities in accordance with DoDI 8500.01, DoDI 8510.01 (RMF), AFI 17-101 (RMF), DoD Cloud Computing SRG, and NIST SP 800-53

This role will work closely with Government ISSOs, ISSMs, Authorizing Officials (AOs), Cybersecurity Service Providers (CSSPs), and Cloud One engineering teams to ensure continued ATO compliance, security posture improvement, and rapid remediation of vulnerabilities within the C1 environment.

  • Develop, update, and maintain RMF authorization artifacts in accordance with DoDI 8510.01 and NIST SP 800-53.
  • Provide RMF-required documentation and artifacts to Government ISSO/ISSM in support of Assessment & Authorization (A&A) activities.
  • Maintain and update System Security Plans (SSPs), Security Control Traceability Matrices (SCTMs), POA&Ms, and supporting documentation.
  • Support migration of security control baselines from NIST SP 800-53 Rev 4 to Rev 5, including control re-mapping, gap analysis, control implementation updates, and SSP/POA&M artifact revisions within DoD RMF processes.
  • Support Continuous Authorization to Operate (cATO) within a DevSecOps or cloud-based environment, including implementation of automated control validation, continuous monitoring integration, and real-time POA&M management.
  • Support ATO maintenance and sustainment activities for C1 and DPaaS environments.
  • Support Authority to Use (ATU) conditions and remediation tracking as directed by the AO.
  • Assist Government ISSO/ISSM with maintaining compliance with: *

  • DoDI 8500.01 (Cybersecurity)
  • DoDI 8510.01 (RMF)
  • AFI 17-101 (RMF)
  • DoD Cloud Computing SRG
  • DISA STIG/SRG
  • CNSSI 1253
  • Support security control assessments, audit readiness, and third-party cybersecurity inspections.
  • Maintain audit log configuration, monitoring, and retention compliance.
  • Support incident reporting and documentation in accordance with DFARS 252.204-7012 and 252.239-7010.
  • Ensure compliance with SCCA and Cloud SRG requirements.
  • Support secure configuration of AWS, Azure, Oracle, and GCP cloud environments.

Requirements

  • Bachelor’s degree with 4-8 years of relevant experience, or Master’s degree with 2-6 years of relevant experience. Additional years of experience may be considered in lieu of a degree.
  • Active Secret clearance at a minimum required to start.
  • US citizenship required
  • CompTIA Security+ (IAT Level II) or equivalent required

Preferred Skills

  • Experience with USAF Cloud One or Platform 1
  • Experience with Zero Trust Architecture
  • Cloud certifications in AWS, Azure, Google, or Oracle clouds
  • Automation experience
  • Certifications: CISSP (IAT Level III) or equivalent

Benefits & conditions

Pet insurance, AD&D insurance, 401(k), Health insurance, Paid time off, Vision insurance, Dental insurance, Life insurance, SES provides a competitive salary and the following benefits:

  • Medical
  • Dental
  • Vision
  • AD&D
  • STD
  • LTD
  • Company paid Life Insurance
  • 401k with employer contribution
  • Paid Time Off
  • Pet Insurance

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on indeed.com

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

1:15 min

Key lessons learned from implementing automated mobile DevSecOps

Moataz Nabil Moataz Nabil · LIVE

3:56 min

Leveraging GitOps for AI auditing and instant rollbacks

Jaroslaw Gajewski Jaroslaw Gajewski · WWC Europe 2026

6:10 min

Unlocking free learning credits via Google Cloud Innovators

Asrar Asrar · WWC 2024

2:59 min

Navigating enterprise constraints for AI developer tool deployment

Thomas Froment Thomas Froment · WWC Europe 2026

2:09 min

Shifting security left using the DevSecOps approach

Aarno Aukia · LIVE

6:13 min

Defining cloud proficiency by technical role

Piet Van Dongen · LIVE

Videos

See all

Related articles

See all