> Markdown version of [/jobs/ext/2719277-information-assurance-specialist-iii](https://www.wearedevelopers.com/jobs/ext/2719277-information-assurance-specialist-iii). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Information Assurance Specialist III - **Company:** OneZero Solutions - **Location:** Arlington, VA, United States - **Experience:** Experienced - **Salary:** $110,000.0 - $125,000.0 - **Contract:** Permanent contract - **Skills:** Amazon Web Services, Software as a Service, Cloud Computing, Cloud Computing Security, CompTIA Security+, Cyber Security, Continuous Integration, Microsoft Office, Package Management Systems, SAP (Applications), Security Content Automation Protocol, SARS Software Products, SC Clearance, Information Technology, Tenable Nessus, Opsworks, Devsecops, Serverless Computing, Plan of Action and Milestones, Static Application Security Testing, Dynamic Application Security Testing - **Published:** September 4, 2026 - **Apply:** https://www.careerjet.com/jobad/usc24a8d6bf2a1801407cc460434736ebf ## About the Role Assess Only, and Continuous ATO (cATO) accreditations, including system categorization and control selection, tailoring, and implementation.Assess security control implementation across traditional and cloud-native services (containers, serverless, service meshes, Infrastructure-as-Code) and evaluate SaaS offerings against FedRAMP and DoD Cloud Computing SRG requirements, documenting shared-responsibility and control inheritance.Conduct security control assessments as SCA/SCA-V: execute Security Assessment Plans through interviews, documentation review, configuration inspection, and technical testing; independently validate automated and manual test results before findings are formalized.Develop and maintain RMF documentation - SSPs, control family plans, SAPs, SARs, risk assessments, and POA&Ms - automating documentation and evidence collection wherever possible.Leverage and interpret Compliance-as-Code (CaC) output (e.g., AWS Inspector, Security Hub, AWS Config) to validate compliance against NIST SP 800-53 controls and DISA STIGs, and verify automated evidence is accurate and audit-ready in eMASS.Monitor security posture within CI/CD pipelines (SAST/DAST, software composition analysis, container image scanning) and coordinate remediation with development teams before deployment.Perform risk analysis prioritizing vulnerabilities by mission impact; brief ISSMs, system owners, and Government stakeholders on findings, risk posture, and remediation strategy.Support incident response for cloud-native systems and coordinate with the CSSP and mission partners as required.Required QualificationsThree (3) years of dedicated Information Assurance experience, with at least two (2) years consecutive, including hands-on RMF execution, security control assessment, POA&M management, and continuous monitoring.Current DoD 8570/8140-qualifying certification appropriate to the assigned DCWF work role (612/722) - CompTIA Security+ CE minimum.Active SECRET security clearance (favorably adjudicated T3 investigation) and U.S. citizenship - required at start of performance.Working knowledge of NIST SP 800-53 (Rev 5), NIST SP 800-37/RMF, FISMA, and DoD cybersecurity policy (DoDI 8510.01).Ability to work on site at DSCA Mechanicsburg, PA or Arlington, VA as required, including for SIPR-designated work.Preferred QualificationseMASS experience (package management, control records, POA&M administration).Experience securing or assessing AWS environments (GovCloud, AWS-native security tooling: Security Hub, Inspector, GuardDuty, Config) and familiarity with FedRAMP and the DoD Cloud Computing SRG.Exposure to DevSecOps pipelines, Infrastructure-as-Code, or Policy/Compliance-as-Code approaches to control validation.Vulnerability management experience with ACAS/Tenable Nessus and DISA STIG/SCAP compliance scanning.CISSP, CISM, CGRC/CAP, CySA+, or CASP+/SecurityX certification.Technical SkillseMASS · NIST SP 800-53/800-37 · DISA STIGs & SCAP · ACAS/Tenable Nessus · AWS security services (Security Hub, Inspector, GuardDuty, Config, CloudTrail) · POA&M management · SSP/SAP/SAR development · continuous monitoring (ISCM) · CI/CD security tooling (SAST/DAST/SCA) · Microsoft Office suiteSecurity ClearanceActive SECRET clearance required (temporary/interim SECRET eligibility adjudicated by DCSA AVS may be accepted). Investigation must be current within 5 years or enrolled in Continuous Evaluation. All personnel must be U.S. citizens.EducationBachelor's degree in Information Technology, Computer Science, Engineering, Cybersecurity, or a related technical discipline desired. Equivalent additional dedicated IA experience (two additional years) may substitute for the degree.Work EnvironmentHybrid, at Government discretion, anchored to DSCA facilities in Mechanicsburg, PA (preferred duty station - the majority of the DSCA cybersecurity team is located there) or Arlington, VA. OneZero Solutions, LLC is an Equal ## Description articles and services to international partners. As part of the DSCA Cybersecurity Support Services program, you will deliver hands-on Risk Management Framework (RMF) and Cybersecurity Risk Management Construct (CSRMC) support across approximately 25 systems - serving in ISSO, Security Control Assessor, and SCA-Validator capacities within a cloud-native, DevSecOps-oriented AWS environment. This is an execution role at the heart of DSCA's security posture: you will own authorization packages in eMASS, drive controls to compliance, and help move the program from manual assessment toward automated, Compliance-as-Code continuous monitoring.Key ResponsibilitiesManage Assessment & Authorization (A&A) packages through the RMF/CSRMC lifecycle in eMASS, maintaining the authorization package as the authoritative GRC record - control implementation details, assessment evidence, and full POA&M lifecycle from creation to closure.Support achievement and maintenance of Assess and Authorize (A&A) ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [DevSecOps: Injecting Security into Mobile CI/CD Pipelines](https://www.wearedevelopers.com/videos/273-devsecops-injecting-security-into-mobile-ci-cd-pipelines) - [DevSecOps culture](https://www.wearedevelopers.com/videos/783-devsecops-culture) - [Maturity assessment for technicians or how I learned to love OWASP SAMM](https://www.wearedevelopers.com/videos/351-maturity-assessment-for-technicians-or-how-i-learned-to-love-owasp-samm) - [You can’t hack what you can’t see](https://www.wearedevelopers.com/videos/41-you-can-t-hack-what-you-can-t-see) - [DevSecOps: Security in DevOps](https://www.wearedevelopers.com/videos/36-devsecops-security-in-devops) ## Related Articles - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [The Overflow: Security and Privacy](https://www.wearedevelopers.com/magazine/715-the-overflow-security-and-privacy) - [How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again](https://www.wearedevelopers.com/magazine/751-how-we-built-a-worry-free-system-that-runs-for-10-years-and-what-we-d-do-again)