Senior Information Security (INFOSEC) Specialist

Acquired Data Solutions
Washington, DC, United States
about 1 month ago
Apply on www.indeed.com
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Working hours
Regular working hours
Job source

Tech stack

Amazon Web Services Systems Engineering Cloud Computing Cloud Computing Security Cyber Security Information Systems Disaster Recovery Network Diagrams Zero Trust Network Access Software Engineering Software Vulnerability Management SARS Software Products
+7 more
Cloud Platform System Information Technology Nessus Checkmarx Cloud Migration Devsecops Vulnerability Analysis

Job description

ADS is seeking a Senior Information Security (INFOSEC) Specialist to support enterprise cybersecurity, Risk Management Framework (RMF), cloud security, and Information Assurance (IA) activities across secure and unclassified environments. This role is responsible for maintaining secure, compliant information systems, supporting cloud Authorizations to Operate (ATOs), implementing cybersecurity best practices, and ensuring compliance with DoD and NIST security requirements. The position also supports cloud modernization, continuous monitoring, vulnerability management, and DevSecOps initiatives., * Lead RMF implementation and support system Authorizations to Operate (ATOs).

  • Develop and maintain RMF documentation, including SSPs, POA&Ms, SARs, network diagrams, and security procedures.
  • Support cloud security, cloud migrations, and cloud ATO compliance.
  • Perform vulnerability assessments, security scanning, and risk analysis.
  • Monitor security findings, coordinate remediation efforts, and support continuous monitoring activities.
  • Maintain compliance with DoD, DISA, and NIST cybersecurity requirements.
  • Support DevSecOps, secure application development, and automated security testing.
  • Coordinate cybersecurity activities with enterprise IT teams, cloud providers, and other stakeholders.
  • Support incident response, change management, disaster recovery, and contingency planning.
  • Provide technical guidance on cybersecurity, RMF, and security engineering best practices.

Requirements

  • Bachelor’s degree in information systems engineering, computer science, engineering, business or other related fields, and at least 12 year of experience (with 10 years of related, specialized technical experience)
  • Experience implementing DoD Risk Management Framework (RMF) and supporting ATOs.
  • Knowledge of NIST RMF, NIST SP 800-53, DISA STIGs, and DoD cybersecurity policies.
  • Experience with cloud security, vulnerability management, and continuous monitoring.
  • Familiarity with AWS or other cloud environments.
  • Strong technical writing, communications, and problem-solving skills.
  • DoD Top Secret Clearance or ability to obtain and maintain a DoD Top Secret Clearance.

Qualifications - Desired

  • CISSP, CAP, Security+, CASP+, AWS Security Specialty, or equivalent certification.
  • Experience with AWS GovCloud.
  • Experience using Burg Suite, Checkmarx, Nessus, or similar security tools.
  • Experience with DevSecOps and secure software development.
  • Knowledge of Zero Trust Architecture and Continuous ATO (cATO).
  • Experience supporting federal DoD enterprise IT environments.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.indeed.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

1:15 min

Key lessons learned from implementing automated mobile DevSecOps

Moataz Nabil Moataz Nabil · LIVE

1:45 min

Transitioning from software development to security roles

Stefania Chaplin · World Congress 2022

2:09 min

Shifting security left using the DevSecOps approach

Aarno Aukia · LIVE

3:22 min

Transitioning from software engineering to security roles

Anna Oliveira · Coffee With Developers

4:01 min

Finding personal fulfillment in the cybersecurity industry

LIVE

2:07 min

Integrating security practices for devsecops adoption

Nevelina Aleksandrova · LIVE

Videos

See all

Related articles

See all