> Markdown version of [/jobs/ext/2613057-information-assurance-specialist](https://www.wearedevelopers.com/jobs/ext/2613057-information-assurance-specialist). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Information Assurance Specialist - **Company:** Booz Allen Hamilton Inc. - **Location:** Arlington, VA, United States - **Experience:** Experienced - **Salary:** $99,000.0 - $225,000.0 - **Contract:** Permanent contract - **Skills:** Kubernetes Security, Amazon Web Services, Software as a Service, Cyber Security, Identity and Access Management, SC Clearance, Information Technology, Devsecops, Serverless Computing, Static Application Security Testing, Dynamic Application Security Testing - **Published:** August 16, 2026 - **Apply:** https://justjobs.com/main/sendform/8/8/28176/1/17970115?backUrl=%2Fcareer%2F17970115%2FInformation-Assurance-Specialist-Virginia-Arlington ## About the Role * 5+ years of experience with Information Assurance * 3+ years of experience directly performing Information Assurance tasks * Knowledge of the DoD cybersecurity environment * Secret clearance * Bachelor's degree in an IT, Computer Science, or Engineering field * DoD 8570/8140 IAM Level II or IAT Level II baseline certification such as CISSP, Security+ CE, CISM, or CASP+ CE Nice If You Have: * Experience operating eMASS as the authoritative GRC system of record, maintaining near realtime security documentation and POA&Ms * Experience with Compliance as Code and cloudnative tools such as AWS Inspector, Security Hub, validating automated evidence against NIST SP 80053 and DoD STIGs * Experience with vulnerability and software assurance tooling including SAST/DAST, SCA, or container image scanning, and riskbased remediation before deployment * Experience with ICAM enforcement such as DoW eICAM, leastprivilege access controls, and secure SaaS configuration * Knowledge of RMF step 1-6 execution, continuous monitoring, and CSRMC automation in DevSecOps pipelines * Ability to lead technical incident response for cloudnative systems and coordinate with thirdparty providers to restore mission capability ## Description As an Information Assurance Specialist serving a national defense agency, you will integrate security across the full system lifecycle to ensure the confidentiality, integrity, and availability of data for traditional and cloudnative architectures including AWS and approved SaaS. You'll lead the operationalization of RMF/CSRMC in a DevSecOps environment, automate control implementation and evidence collection to achieve and sustain A&A, AssessOnly, and cATO accreditations, and maintain an authoritative body of evidence in eMASS. You'll collaborate with control owners and delivery teams to tailor and implement security controls such as container security, serverless, service meshes, or IaC, document shared responsibility and control inheritance, and drive riskbased remediation through POA&Ms, continuous monitoring, and transparent stakeholder engagement. You'll also perform advanced SCA/SCAV functions, design and execute transparent Security Assessment Plans, analyze near realtime posture using automated scans, logs, and CaC outputs, validate automated evidence and Policy and ComplianceasCode results, and synthesize missionfocused risk analysis for the AO such as SAR, RAR, and authorization recommendations. You'll lead technical incident response for cloudnative systems, coordinate with SaaS providers during thirdparty incidents, and brief program leadership with a strict "no surprises" approach that enables timely, riskinformed decisions. ## Related Videos - [DevSecOps: Injecting Security into Mobile CI/CD Pipelines](https://www.wearedevelopers.com/videos/273-devsecops-injecting-security-into-mobile-ci-cd-pipelines) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [Securing Your Web Application Pipeline From Intruders](https://www.wearedevelopers.com/videos/53-securing-your-web-application-pipeline-from-intruders) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [DevSecOps culture](https://www.wearedevelopers.com/videos/783-devsecops-culture) - [DevSecOps: Security in DevOps](https://www.wearedevelopers.com/videos/36-devsecops-security-in-devops) ## Related Articles - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again](https://www.wearedevelopers.com/magazine/751-how-we-built-a-worry-free-system-that-runs-for-10-years-and-what-we-d-do-again) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [Dev Digest 162: AI careers, MCP, AWS best practices & floppy sweaters](https://www.wearedevelopers.com/magazine/571-dev-digest-162-ai-careers-mcp-aws-best-practices-floppy-sweaters)