> Markdown version of [/jobs/ext/2603486-information-security-risk-specialist](https://www.wearedevelopers.com/jobs/ext/2603486-information-security-risk-specialist). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Information Security Risk Specialist - **Company:** Booz Allen Hamilton Inc. - **Location:** McLean, VA, United States - **Experience:** Experienced - **Contract:** Permanent contract - **Skills:** Xacta, Amazon Web Services, Microsoft Azure, Cloud Computing Security, Cloud Engineering, Cyber Security, Security Content Automation Protocol, Devsecops - **Published:** August 9, 2026 - **Apply:** https://us.experteer.com/career/view-jobs/information-security-risk-specialist-mclean-va-usa-58896914 ## About the Role plans secure DoD systems Tasks * 5+ years in IT * 3+ years in cybersecurity and A&A for DoD environments * Experience supporting federal government or DoD ATO, RMF, and risk assessments in AWS/Azure/hybrid clouds * Experience with cloud-native and containerized security evaluations * Interface with engineering teams to align DevSecOps with cybersecurity policies * Knowledge of ACAS, SCAP, STIGs, SRGs, eMASS, or Xacta * Experience with NIST SP 800-53, CNSSI 1253, artifacts, SSPs, POA&Ms, SAPs, risk assessments, and continuous monitoring * TS/SCI clearance * HS diploma or GED * DoD 8570 Level II Security+ or higher Key requirements * health benefits * life and disability benefits * retirement benefits * paid leave * professional development * tuition assistance ## Description Experteer Overview As an Information Security Risk Specialist, you will collaborate with DoD system owners, engineers, and contractors to identify cyber risks and craft comprehensive mitigation plans. You translate security concepts for leadership, guide remediation programs, and deliver actionable deliverables such as presentations and white papers. You work to align DevSecOps and cloud security with government policies, contributing to DoD cybersecurity resilience. This role offers you to deepen SME expertise while shaping risk management across DoD environments. Compensation / Benefits * Identify cyber risks with DoD system owners and stakeholders * Analyze applicable policies and assess threat landscape * Develop and guide remediation plans with clear milestones * Deliver findings and recommendations via presentations and white papers * Collaborate with SMEs and engineers to align security with DevSecOps and cloud architecture * Translate security concepts for decision-makers to enable secure DoD systems Tasks * 5+ years in IT * 3+ years in cybersecurity and A&A for DoD environments * Experience supporting federal government or DoD ATO, RMF, and risk assessments in AWS/Azure/hybrid clouds * Experience with cloud-native and containerized security evaluations * Interface with engineering teams to align DevSecOps with cybersecurity policies * Knowledge of ACAS, SCAP, STIGs, SRGs, eMASS, or Xacta * Experience with NIST SP 800-53, CNSSI 1253, artifacts, SSPs, POA&Ms, SAPs, risk assessments, and continuous monitoring * TS/SCI clearance * HS diploma or GED * DoD 8570 Level II Security+ or higher Key requirements * health benefits * life and disability benefits * retirement benefits * paid leave * professional development * tuition assistance ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [DevSecOps: Injecting Security into Mobile CI/CD Pipelines](https://www.wearedevelopers.com/videos/273-devsecops-injecting-security-into-mobile-ci-cd-pipelines) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [Organizational Change Through The Power Of Why - DevSecOps Enablement](https://www.wearedevelopers.com/videos/478-organizational-change-through-the-power-of-why-devsecops-enablement) - [DevSecOps culture](https://www.wearedevelopers.com/videos/783-devsecops-culture) - [DevSecOps: Security in DevOps](https://www.wearedevelopers.com/videos/36-devsecops-security-in-devops) ## Related Articles - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed)