Information Security Risk Specialist

Booz Allen Hamilton Inc.
Fort Belvoir, VA, United States
25 days ago
Apply on us.experteer.com
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Experienced
Experience required
3 years minimum
Working hours
Regular working hours

Tech stack

Xacta Amazon Web Services Microsoft Azure Cloud Computing Security Cloud Engineering Cyber Security Security Content Automation Protocol Devsecops

Job description

Experteer Overview As an Information Security Risk Specialist, you will collaborate with DoD system owners, engineers, and contractors to identify cyber risks and craft comprehensive mitigation plans. You translate security concepts for leadership, guide remediation programs, and deliver actionable deliverables such as presentations and white papers. You work to align DevSecOps and cloud security with government policies, contributing to DoD cybersecurity resilience. This role offers you to deepen SME expertise while shaping risk management across DoD environments. Compensation / Benefits * Identify cyber risks with DoD system owners and stakeholders * Analyze applicable policies and assess threat landscape * Develop and guide remediation plans with clear milestones * Deliver findings and recommendations via presentations and white papers * Collaborate with SMEs and engineers to align security with DevSecOps and cloud architecture * Translate security concepts for decision-makers to enable secure DoD systems Tasks * 5+ years in IT * 3+ years in cybersecurity and A&A for DoD environments * Experience supporting federal government or DoD ATO, RMF, and risk assessments in AWS/Azure/hybrid clouds * Experience with cloud-native and containerized security evaluations * Interface with engineering teams to align DevSecOps with cybersecurity policies * Knowledge of ACAS, SCAP, STIGs, SRGs, eMASS, or Xacta * Experience with NIST SP 800-53, CNSSI 1253, artifacts, SSPs, POA&Ms, SAPs, risk assessments, and continuous monitoring * TS/SCI clearance * HS diploma or GED * DoD 8570 Level II Security+ or higher Key requirements * health benefits * life and disability benefits * retirement benefits * paid leave * professional development * tuition assistance

Requirements

plans secure DoD systems Tasks * 5+ years in IT * 3+ years in cybersecurity and A&A for DoD environments * Experience supporting federal government or DoD ATO, RMF, and risk assessments in AWS/Azure/hybrid clouds * Experience with cloud-native and containerized security evaluations * Interface with engineering teams to align DevSecOps with cybersecurity policies * Knowledge of ACAS, SCAP, STIGs, SRGs, eMASS, or Xacta * Experience with NIST SP 800-53, CNSSI 1253, artifacts, SSPs, POA&Ms, SAPs, risk assessments, and continuous monitoring * TS/SCI clearance * HS diploma or GED * DoD 8570 Level II Security+ or higher Key requirements * health benefits * life and disability benefits * retirement benefits * paid leave * professional development * tuition assistance

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on us.experteer.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

1:53 min

Transitioning toward DevSecOps with dynamic scanning and secrets management

Christoph Ruggenthaler · LIVE

4:11 min

Introduction to cloud-native application developer security

Micah Silverman · World Congress 2022

1:15 min

Key lessons learned from implementing automated mobile DevSecOps

Moataz Nabil Moataz Nabil · LIVE

2:07 min

Integrating security practices for devsecops adoption

Nevelina Aleksandrova · LIVE

3:22 min

Transitioning from software engineering to security roles

Anna Oliveira · Coffee With Developers

3:44 min

Current industry adoption and future security initiatives

Alexander Allmendinger · LIVE

Videos

See all

Related articles

See all