> Markdown version of [/jobs/ext/2593495-information-security-risk-specialist](https://www.wearedevelopers.com/jobs/ext/2593495-information-security-risk-specialist). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Information Security Risk Specialist - **Company:** Booz Allen Hamilton Inc. - **Location:** Littleton, MA, United States - **Experience:** Experienced - **Salary:** $61,900.0 - $141,000.0 - **Contract:** Permanent contract - **Skills:** Xacta, Kubernetes Security, Amazon Web Services, Confluence, JIRA, Microsoft Azure, Cloud Computing, Cloud Computing Security, Cyber Security, Information Systems, Elasticsearch, Identity and Access Management, Security Information and Event Management, Software Engineering, Software Vulnerability Management, SC Clearance, Kubernetes, Information Technology, Atlassian Tools, Splunk, Docker - **Published:** August 14, 2026 - **Apply:** https://justjobs.com/main/sendform/8/8/28176/1/17928133?backUrl=%2Fcareer%2F17928133%2FInformation-Security-Risk-Specialist-Massachusetts-Lexington ## About the Role * 3+ years of experience in a cybersecurity role * 2+ years of experience with the DoD RMF accreditation processes * Experience with RMF, STIGs, NIST 800-53, NIST 800-37, AWS, Xacta, or eMASS * Experience implementing and maintaining security controls * Ability to work through challenging security requirements and maintain compliance * Ability to develop technical documentation to support accreditation efforts * Secret clearance * Bachelor's degree in Cybersecurity, Information Technology, Computer Science, Information Systems, Data Science, or Software Engineering * DoD 8140 IAM Level 1 Certification Nice If You Have: * Experience implementing and maintaining security controls in a cloud-based environment * Experience with Cloud Security, including AWS, Azure, or GovCloud * Experience with Container Security, including Kubernetes or Docker * Experience with SIEM or SOAR, including Splunk, ElasticSearch, or OpenSearch * Experience with Atlassian Suite, including Jira or Confluence * Experience with Vulnerability Management tools and processes * Experience with STIGs and Cloud SRGs * Experience as an ISSM, ISSO, or ISSE ## Description Conduct security assessments on DoD cloud environments using the Risk Management Framework (RMF). Assist in providing guidance on policies and procedures to ensure compliance within an accreditation boundary. Implement security strategies to control and manage organizational information risks. Assess information systems to determine risk exposure and develop documentation addressing system security requirements. Enhance information security education within the organization and team. Monitor the latest security technologies to ensure that project personnel remain in the know. ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Docker Compose: Rediscovered](https://www.wearedevelopers.com/videos/1978-docker-compose-rediscovered) - [Improving quality with Agentic AI with Rovo Dev and Xray](https://www.wearedevelopers.com/videos/2005-improving-quality-with-agentic-ai-with-rovo-dev-and-xray) - [Organizational Change Through The Power Of Why - DevSecOps Enablement](https://www.wearedevelopers.com/videos/478-organizational-change-through-the-power-of-why-devsecops-enablement) - [Docker build without Docker](https://www.wearedevelopers.com/videos/100114-docker-build-without-docker) - [Collaboration Quantified: Lessons from Open Source Developer Networks](https://www.wearedevelopers.com/videos/1422-collaboration-quantified-lessons-from-open-source-developer-networks) ## Related Articles - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [The Overflow: Security and Privacy](https://www.wearedevelopers.com/magazine/715-the-overflow-security-and-privacy) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities)