> Markdown version of [/jobs/ext/2580328-senior-information-security-infosec-specialist](https://www.wearedevelopers.com/jobs/ext/2580328-senior-information-security-infosec-specialist). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Senior Information Security (INFOSEC) Specialist - **Company:** Acquired Data Solutions - **Location:** Washington, DC, United States - **Experience:** Expert - **Contract:** Permanent contract - **Skills:** Amazon Web Services, Systems Engineering, Cloud Computing, Cloud Computing Security, Cyber Security, Information Systems, Disaster Recovery, Network Diagrams, Zero Trust Network Access, Software Engineering, Software Vulnerability Management, SARS Software Products, Cloud Platform System, Information Technology, Nessus, Checkmarx, Cloud Migration, Devsecops, Vulnerability Analysis - **Published:** August 4, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=d59e40a0751c3ede ## About the Role * Bachelor's degree in information systems engineering, computer science, engineering, business or other related fields, and at least 12 year of experience (with 10 years of related, specialized technical experience) * Experience implementing DoD Risk Management Framework (RMF) and supporting ATOs. * Knowledge of NIST RMF, NIST SP 800-53, DISA STIGs, and DoD cybersecurity policies. * Experience with cloud security, vulnerability management, and continuous monitoring. * Familiarity with AWS or other cloud environments. * Strong technical writing, communications, and problem-solving skills. * DoD Top Secret Clearance or ability to obtain and maintain a DoD Top Secret Clearance. Qualifications - Desired * CISSP, CAP, Security+, CASP+, AWS Security Specialty, or equivalent certification. * Experience with AWS GovCloud. * Experience using Burg Suite, Checkmarx, Nessus, or similar security tools. * Experience with DevSecOps and secure software development. * Knowledge of Zero Trust Architecture and Continuous ATO (cATO). * Experience supporting federal DoD enterprise IT environments. ## Description ADS is seeking a Senior Information Security (INFOSEC) Specialist to support enterprise cybersecurity, Risk Management Framework (RMF), cloud security, and Information Assurance (IA) activities across secure and unclassified environments. This role is responsible for maintaining secure, compliant information systems, supporting cloud Authorizations to Operate (ATOs), implementing cybersecurity best practices, and ensuring compliance with DoD and NIST security requirements. The position also supports cloud modernization, continuous monitoring, vulnerability management, and DevSecOps initiatives., * Lead RMF implementation and support system Authorizations to Operate (ATOs). * Develop and maintain RMF documentation, including SSPs, POA&Ms, SARs, network diagrams, and security procedures. * Support cloud security, cloud migrations, and cloud ATO compliance. * Perform vulnerability assessments, security scanning, and risk analysis. * Monitor security findings, coordinate remediation efforts, and support continuous monitoring activities. * Maintain compliance with DoD, DISA, and NIST cybersecurity requirements. * Support DevSecOps, secure application development, and automated security testing. * Coordinate cybersecurity activities with enterprise IT teams, cloud providers, and other stakeholders. * Support incident response, change management, disaster recovery, and contingency planning. * Provide technical guidance on cybersecurity, RMF, and security engineering best practices. ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [DevSecOps: Injecting Security into Mobile CI/CD Pipelines](https://www.wearedevelopers.com/videos/273-devsecops-injecting-security-into-mobile-ci-cd-pipelines) - [Organizational Change Through The Power Of Why - DevSecOps Enablement](https://www.wearedevelopers.com/videos/478-organizational-change-through-the-power-of-why-devsecops-enablement) - [DevSecOps culture](https://www.wearedevelopers.com/videos/783-devsecops-culture) - [DevSecOps: Security in DevOps](https://www.wearedevelopers.com/videos/36-devsecops-security-in-devops) - [You can’t hack what you can’t see](https://www.wearedevelopers.com/videos/41-you-can-t-hack-what-you-can-t-see) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [Best Paying Jobs in Technology](https://www.wearedevelopers.com/magazine/256-best-paying-jobs-in-technology) - [The Overflow: Security and Privacy](https://www.wearedevelopers.com/magazine/715-the-overflow-security-and-privacy) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed)