Information System Security Specialist III

DirectViz, LLC
Virginia Beach, VA, United States
3 months ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
5 years minimum
Working hours
Regular working hours
Languages
English

Tech stack

Information Systems Information Security Management Security Content Automation Protocol Software Vulnerability Management Vulnerability Analysis

Job description

  • Support and execute Risk Management Framework (RMF) activities for DoD information systems.
  • Perform Security Technical Implementation Guide (STIG) assessments using SCAP benchmarks and other compliance validation tools.
  • Conduct vulnerability assessments utilizing Assured Compliance Assessment Solution (ACAS).
  • Manage and maintain RMF documentation and activities within eMASS.
  • Develop, track, and maintain Plans of Action and Milestones (POA&M) entries.
  • Support RMF Step 5 authorization activities while functioning in an Information System Security Engineer (ISSE) capacity.
  • Analyze cybersecurity risks and provide mitigation and risk reduction recommendations to stakeholders and leadership.
  • Collaborate with engineers, system administrators, and cybersecurity teams to ensure systems remain compliant with DoD cybersecurity requirements and security controls.
  • Assist with continuous monitoring, security posture assessments, and remediation efforts.

Requirements

  • Minimum of five (5) years of experience performing Risk Management Framework (RMF) activities.
  • Demonstrated experience performing STIG assessments, including the use of SCAP benchmarks.
  • Hands-on experience conducting vulnerability assessments using ACAS.
  • Experience utilizing Enterprise Mission Assurance Support Service (eMASS).
  • Experience developing and managing POA&M entries.
  • Experience completing RMF Step 5 authorization activities in an ISSE capacity.
  • Strong communication skills with the ability to present cybersecurity risks and remediation recommendations to technical and non-technical stakeholders.

Certifications & Clearance Requirements

  • Minimum certification as 461 (or equivalent as required by the applicable Technical Instruction) at the Intermediate level in accordance with DoDD 8140.01 or successor policy.
  • Must maintain a final adjudicated Tier 5 security investigation with an IT Level I designation in JPAS and/or DISS for all Privileged User responsibilities.
  • Active Secret Clearance required; Top Secret eligibility may be required depending on program needs.
  • U.S. Citizenship required.

Preferred Skills

  • Familiarity with NIST RMF, NIST SP 800-53, and DoD cybersecurity compliance standards.
  • Experience supporting security authorization packages within DoD environments.
  • Knowledge of vulnerability remediation processes and continuous monitoring practices.
  • Ability to work independently while supporting cross-functional technical teams.

Work Location: Viriginia Beach VA

If you thrive on solving complex problems and building meaningful connections, we’d love to hear from you. Join our team and make an impact today!

Physical and Mental Qualifications:

  • Maintain focus and awareness throughout scheduled working hours.
  • Perform tasks requiring prolonged periods of sitting or standing at a desk, utilizing a computer, mouse, and keyboard.
  • Lift and move objects weighing up to 15 pounds as needed.
  • Exhibit excellent verbal and written communication skills, with a strong command of the English language.
  • Demonstrate the ability to work independently while also collaborating effectively as part of a team.
  • Quickly learn and retain routine tasks and processes.
  • Possess strong organizational skills, attention to detail, business correspondence proficiency, and self-management capabilities.
  • Perform the essential functions of the role satisfactorily; reasonable accommodation will be provided for employees with disabilities upon request.
  • Accept and adapt to additional responsibilities or changes to assigned duties as determined by DirectViz Solutions (DVS).

Benefits & conditions

At DVS, we prioritize our employees as our greatest asset. We offer competitive compensation, comprehensive medical benefits, a 401(k) match, generous PTO accrual, professional development reimbursement, corporate-funded technology certifications, and robust employee recognition and appreciation programs.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on clearancejobs.com

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

4:01 min

Finding personal fulfillment in the cybersecurity industry

LIVE

4:25 min

The growing power and security responsibility of developers

Tino Sokic · WWC 2023

3:17 min

Embedding automated vulnerability analysis within CircleCI workflows

Milecia Mcgregor · LIVE

59 sec

Proving regulatory compliance to auditors and chief officers

Mike Bursell Mike Bursell · WWC Europe 2026

3:22 min

Transitioning from software engineering to security roles

Anna Oliveira · Coffee With Developers

1:03 min

Securing applications against exceptional condition mishandling

Christian Wenz Christian Wenz · WWC Europe 2026

Videos

See all

Related articles

See all