> Markdown version of [/jobs/ext/2636289-it-security-specialist](https://www.wearedevelopers.com/jobs/ext/2636289-it-security-specialist). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # IT Security Specialist - **Company:** KMS Solutions, LLC - **Location:** Alexandria, VA, United States (Remote available) - **Experience:** Expert - **Salary:** $110,000.0 - $140,000.0 - **Contract:** Permanent contract - **Skills:** Microsoft Word, Microsoft Excel, Microsoft Windows, Systems Engineering, Microsoft Outlook, Cyber Security, Information Systems, Linux, Identity and Access Management, Microsoft Office, Nmap, Package Development Process, Microsoft PowerPoint, Security Content Automation Protocol, Systems Integration, SC Clearance, Navsea, Information Technology, Workday, Vulnerability Analysis - **Published:** August 10, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=c334b74f1635c636 ## About the Role * Bachelor's degree in cybersecurity, information systems, engineering, mathematics, or related discipline. * Greater than 5 years of relevant Cybersecurity experience. * DoD 8570.01M IAT/IAM Level II certification (e.g., Security+). * Operating Systems certification (Windows or Linux). * Experience with RMF, A&A processes, and cybersecurity validation of DoD IT systems. * Experience using eMASS. * Equivalent combinations of education and experience will be considered. Preferred Education and Experience * Experience supporting DoD or Navy cybersecurity programs (NSW/SOF or undersea systems preferred). * Navy Qualified Validator (NQV). * Experience with NIST RMF, Navy cybersecurity policy, and DIACAP-to-RMF transitions. * Systems engineering or system integration experience. Competencies * Proficiency in Microsoft Office, specifically, Word, Excel, PowerPoint, and Outlook software. * Excellent verbal and written communication skills; ability to clearly articulate technical requirements. * Ability to independently perform cybersecurity assessments and analyses. * Thoroughness, attention to detail, and disciplined documentation habits. * Ability to work collaboratively across engineering, acquisition, and cybersecurity teams. * Must be highly reliable and demonstrate personal initiative to operate in a fast-paced environment with changing priorities., * This position requires the ability to obtain and/or maintain a Secret DoD Security Clearance and required access to all worksite locations. Security clearances may only be granted to U.S. citizens. * Legally authorized to work in the United States at the time of hire and throughout employment., While performing the duties of this job, the employee is regularly required to talk and hear. The employee is frequently required to stand, walk, use hands to finger, handle or feel, and reach with hands and arms. Must be able to lift up to 20 lbs. Position Type/Expected Hours of Work: The typical workday is eight hours in length. Some flexibility in hours is allowed, with concurrence from the supervisor. Attendance at mandatory meetings is required. Must be available during the core work hours as determined by the contract/location and must account for the required number of hours in a pay period to maintain Full-time status. ## Description KMS solutions, LLC is seeking a highly motivated individual for an IT Security Specialist position providing cybersecurity, information assurance, and Risk Management Framework (RMF) support to NAVSEA PMS 340 programs. The role ensures that PMS 340 systems comply with DoD, DoN, NAVSEA, NIST, and CNSSI cybersecurity requirements throughout development, acquisition, modernization, and sustainment. Responsibilities include supporting RMF package development, conducting security control assessments, assisting with system accreditation, performing vulnerability analysis, supporting Cybersecurity Test & Evaluation (T&E) phases, and providing cybersecurity engineering support across NSW/SOF undersea, surface, and mission systems., Reasonable accommodations may be made to enable individuals with disabilities to perform essential functions. * Support development, maintenance, and updates of RMF accreditation packages and documentation for PMS 340 systems. * Review, validate, and update System Security Plans (SSPs), POA&Ms, Security Assessment Reports, and risk assessments. * Conduct security control assessments in accordance with NIST SP 800-53, SP 800-53A, CNSSI 1253, DoD RMF, DoN cybersecurity guidance, and NAVSEA business rules. * Perform vulnerability analysis using ACAS, SCAP, and Nmap, supporting compliance validation for PMS 340 systems. * Support Cybersecurity Test & Evaluation phases: Cooperative Vulnerability Identification, Adversarial Testing, Vulnerability & Penetration Assessment, and Adversarial Assessment. * Assist system accreditation processes, ensuring PMS 340 systems meet DoD IA and cybersecurity requirements. * Ensure proper evaluation of cybersecurity risk, compliance, and monitoring across undersea, surface, air, and expeditionary systems within PMS 340. * Coordinate cybersecurity activities and meetings with government stakeholders, including NAVSEA 03 and NSW/SOF program partners. * Prepare cybersecurity reports, briefs, and technical documentation supporting program decisions. ## Related Videos - [Docker network without Docker](https://www.wearedevelopers.com/videos/1418-docker-network-without-docker) - [What makes Cybersecurity different for critical infrastructure?](https://www.wearedevelopers.com/videos/571-what-makes-cybersecurity-different-for-critical-infrastructure) - [Docker exec without Docker](https://www.wearedevelopers.com/videos/1094-docker-exec-without-docker) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Checkmate: 5 Real Incidents That Can End a Software Company](https://www.wearedevelopers.com/videos/100126-checkmate-5-real-incidents-that-can-end-a-software-company) - [Discover the open source trio you didn’t expect: .NET and PostgreSQL on Linux](https://www.wearedevelopers.com/videos/2042-discover-the-open-source-trio-you-didn-t-expect-net-and-postgresql-on-linux) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [The Overflow: Security and Privacy](https://www.wearedevelopers.com/magazine/715-the-overflow-security-and-privacy)