> Markdown version of [/jobs/ext/2954281-it-security-specialist](https://www.wearedevelopers.com/jobs/ext/2954281-it-security-specialist). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # IT Security Specialist - **Company:** Seneca Resources - **Location:** Arlington, VA, United States - **Experience:** Experienced - **Contract:** Permanent contract - **Skills:** Configuration Management, Cyber Security, Information Systems, System Configuration, Cyber Threat Analysis, SC Clearance, Information Technology, Vulnerability Analysis - **Published:** September 17, 2026 - **Apply:** https://www.clearancejobs.com/jobs/9171916/it-security-specialist ## About the Role Active Secret clearance. Bachelor's degree in Cybersecurity, Information Technology, Computer Science, or related field. 5+ years of experience in cybersecurity, configuration management, or related technical roles. Strong hands-on experience with: STIGs & system hardening NIST security frameworks RMF processes Configuration management and SecCM practices Ability to obtain a DoD 8570 Level I certification within 6 months if not already certified., Current DoD 8570 Level I certification (e.g., A+, Network+, SSCP). Broad knowledge of cybersecurity threats, vulnerabilities, and enterprise security technologies. Experience developing cybersecurity policies, secure configuration baselines, or technical documentation. Strong analytical, research, and technical writing skills. ## Description We are seeking a Mid-Level IT Security Specialist to support a mission-critical federal government program based onsite in Arlington, VA. This role is ideal for a cybersecurity professional with strong experience in NIST frameworks, the Risk Management Framework (RMF), STIGs, system hardening, and configuration management. You will maintain secure configurations across a large portfolio of federal information systems, ensuring compliance with NIST 800-128, federal cybersecurity standards, and internal security policies. This position requires strong technical skill, attention to detail, and the ability to integrate security requirements into complex IT environments., Manage and maintain secure configurations for over 200 federal information systems. Apply Security-Focused Configuration Management (SecCM) to strengthen system security posture. Perform STIG reviews, system hardening, and vulnerability assessments. Identify, document, and track configurations that impact security. Analyze and document the security implications of system configuration changes. Support RMF activities, including security control implementation and continuous monitoring. Produce high-quality documentation: reports, white papers, presentations, and technical findings. Contribute to configuration management and cybersecurity policy development. Support configuration audits, baseline management, and security governance processes. ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Microservices? Monoliths? An Annoying Discussion!](https://www.wearedevelopers.com/videos/970-microservices-monoliths-an-annoying-discussion) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [Cyber Security: Small, and Large!](https://www.wearedevelopers.com/videos/259-cyber-security-small-and-large) - [Giving AI eyes: How to build a dashboard you can't see](https://www.wearedevelopers.com/videos/100193-giving-ai-eyes-how-to-build-a-dashboard-you-can-t-see) - [Maturity assessment for technicians or how I learned to love OWASP SAMM](https://www.wearedevelopers.com/videos/351-maturity-assessment-for-technicians-or-how-i-learned-to-love-owasp-samm) ## Related Articles - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [The Overflow: Security and Privacy](https://www.wearedevelopers.com/magazine/715-the-overflow-security-and-privacy) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks)