IT Security Specialist

Seneca Resources
Arlington, VA, United States
12 days ago
Apply on www.clearancejobs.com
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Experienced
Experience required
5 years minimum
Working hours
Regular working hours

Tech stack

Configuration Management Cyber Security Information Systems System Configuration Cyber Threat Analysis SC Clearance Information Technology Vulnerability Analysis

Job description

We are seeking a Mid-Level IT Security Specialist to support a mission-critical federal government program based onsite in Arlington, VA. This role is ideal for a cybersecurity professional with strong experience in NIST frameworks, the Risk Management Framework (RMF), STIGs, system hardening, and configuration management.

You will maintain secure configurations across a large portfolio of federal information systems, ensuring compliance with NIST 800-128, federal cybersecurity standards, and internal security policies. This position requires strong technical skill, attention to detail, and the ability to integrate security requirements into complex IT environments., Manage and maintain secure configurations for over 200 federal information systems. Apply Security-Focused Configuration Management (SecCM) to strengthen system security posture. Perform STIG reviews, system hardening, and vulnerability assessments. Identify, document, and track configurations that impact security. Analyze and document the security implications of system configuration changes. Support RMF activities, including security control implementation and continuous monitoring. Produce high-quality documentation: reports, white papers, presentations, and technical findings. Contribute to configuration management and cybersecurity policy development. Support configuration audits, baseline management, and security governance processes.

Requirements

Active Secret clearance. Bachelor’s degree in Cybersecurity, Information Technology, Computer Science, or related field. 5+ years of experience in cybersecurity, configuration management, or related technical roles. Strong hands-on experience with: STIGs & system hardening NIST security frameworks RMF processes Configuration management and SecCM practices Ability to obtain a DoD 8570 Level I certification within 6 months if not already certified., Current DoD 8570 Level I certification (e.g., A+, Network+, SSCP). Broad knowledge of cybersecurity threats, vulnerabilities, and enterprise security technologies. Experience developing cybersecurity policies, secure configuration baselines, or technical documentation. Strong analytical, research, and technical writing skills.

About the company

At Seneca Resources, we are more than just a staffing and consulting firm, we are a trusted career partner. With offices across the U.S. and clients ranging from Fortune 500 companies to government organizations, we provide opportunities that help professionals grow their careers while making an impact. When you work with Seneca, you’re choosing a company that invests in your success, celebrates your achievements, and connects you to meaningful work with leading organizations nationwide. We take the time to understand your goals and match you with roles that align with your skills and career path. Our consultants and contractors enjoy competitive pay, comprehensive health, dental, and vision coverage, 401(k) retirement plans, and the support of a dedicated team who will advocate for you every step of the way. Seneca Resources is proud to be an Equal Opportunity Employer, committed to fostering a diverse and inclusive workplace where all qualified individuals are encouraged to apply.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.clearancejobs.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

1:45 min

Transitioning from software development to security roles

Stefania Chaplin · World Congress 2022

59 sec

Proving regulatory compliance to auditors and chief officers

Mike Bursell Mike Bursell · World Congress 2026 Europe

4:11 min

Introduction to cloud-native application developer security

Micah Silverman · World Congress 2022

3:22 min

Transitioning from software engineering to security roles

Anna Oliveira · Coffee With Developers

2:28 min

Preventing sensitive information disclosure in RAG systems

Deepu Deepu · World Congress 2025

3:44 min

Current industry adoption and future security initiatives

Alexander Allmendinger · LIVE

Videos

See all

Related articles

See all