> Markdown version of [/jobs/ext/3029571-information-assurance-systems-administrator](https://www.wearedevelopers.com/jobs/ext/3029571-information-assurance-systems-administrator). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Information Assurance Systems Administrator - **Company:** Booz Allen Hamilton Inc. - **Location:** Easton, KS, United States - **Experience:** Experienced - **Salary:** $69,300.0 - $158,000.0 - **Contract:** Permanent contract - **Skills:** Xacta, Business Software, Cyber Security, Information Systems, Monitoring of Systems, Information Security Management, Intrusion Detection Systems, McAfee VirusScan, Windows Servers, Performance Tuning, Red Hat Enterprise Linux, Software Vulnerability Management, SARS Software Products, Software Security, SC Clearance, Nessus, CIS Benchmarks, McAfee EPolicy, Vulnerability Analysis - **Published:** September 22, 2026 - **Apply:** https://diversityjobs.com/candidate/trackback_apply?vacancyId=[vacid] ## About the Role * 4+ years of experience working with cybersecurity, information assurance, information system security engineering, or IT security * Experience engineering, administering, hardening, patching, and maintaining Windows Server and RHEL systems in cybersecurity or mission environments, including STIG compliance, security baselines, and vulnerability remediation * Experience administering ACAS, Nessus, or vulnerability management and security scanning technologies, including scanner configuration, plugins, repositories, asset discovery, scan analysis, troubleshooting, and remediation coordination, and administering Trellix or McAfee ePolicy Orchestrator (ePO) and AESS technologies, including HIPS, VSE, DLP, security policy configuration and tuning, deployment, troubleshooting, and endpoint security maintenance * Experience with centralized log monitoring, IDS/IPS, and security event monitoring technologies, including analyzing security events and using monitoring results to identify risk and support remediation * Experience supporting classified and releasability environments, segmented networks, exercises, and mission systems with distinct authorization, scanning, monitoring, or security boundaries, and applying NIST RMF and supporting information systems through security control implementation, assessment and authorization, continuous monitoring, remediation, and continued authorization activities * Experience with eMASS, Xacta, or a DoD RMF assessment and authorization management platform, including system profile management, security controls, control evidence, STIG artifacts, scan evidence, POA&Ms, and authorization documentation * Secret clearance * Bachelor's degree * HBSS, ACAS, RHEL, and DoD 8140 Policy Framework Cyber Workforce Certifications * Ability to obtain an ISSM-designated Program Certification such a CISSP, CASP, SecurityX, or CISM Certification, within 6 months of hire date Nice If You Have: * Experience developing, reviewing, or maintaining RMF authorization artifacts, including SSPs, SAPs, SARs, RARs, POA&Ms, ISCM plans or strategies, security authorization packages, and supporting assessment evidence * Experience coordinating cybersecurity activities across technical and government stakeholders, including system administrators, engineers, system owners, ISSMs, managers, and leadership * Experience serving as an ISSO, ISSM, ISSE, security control assessor support specialist, or cybersecurity lead in a DoD environment * Experience performing security scanning or vulnerability assessment of business application code, including interpreting scan results and coordinating remediation of identified application security findings * Experience leading technical working groups, coordinating remediation across multiple teams, and translating cybersecurity policy into operational execution * Knowledge of NIST 800-series security controls and applicable DoD and Army cybersecurity requirements, including STIGs, vulnerability management requirements, and compliance guidance * Ability to communicate technical risk, remediation status, compliance requirements, and issues requiring decisions * Ability to maintain accurate hardware and software inventories, security artifacts, scan evidence, configuration records, and compliance documentation supporting operational security and system authorization * TS/SCI clearance * Completion of AESS-specific Training such as AESS Administration or Advanced ePO Training ## Description Cybersecurity for mission systems requires more than reacting to findings. This role leads the technical and documentation work needed to maintain an effective security posture, move information systems through Risk Management Framework (RMF), and sustain authorization through continuous monitoring, vulnerability management, and coordinated remediation. As an Information Assurance Systems Administrator supporting MCTP, you will work across cybersecurity, system administration, enterprise services, communications, engineering, and government leadership to translate DoD and Army security requirements into executable controls and operational actions. You will help maintain authorization evidence, administer vulnerability scanning capabilities, assess and remediate risk, and keep stakeholders informed through working groups, technical coordination, and program reporting. What You'll Work On: * Engineer, administer, harden, patch, and maintain Windows Server and Red Hat Enterprise Linux (RHEL) cybersecurity infrastructure, including servers supporting the centralized log monitoring solution and other mission cybersecurity services. * Maintain STIGs, hardened security baselines, system health, approved software repositories, and lifecycle updates. * Administer and sustain enterprise cybersecurity toolsets, including ACAS or Nessus, Trellix or McAfee ePO, AESS, HIPS, VSE, DLP, and IDS/IPS. * Configure security policies, plugins or content, repositories, integrations, and monitoring services. * Perform vulnerability scanning, asset discovery, event analysis, troubleshooting, and remediation coordination. * Build and maintain security scanning and monitoring capabilities for classified and releasability environments, including SIMLAN, TestNet, Reference Set systems, exercises, and other authorized mission environments. * Maintain separation between exercise and ATO scanning data, and integrate newly authorized systems and locations into cybersecurity coverage. * Support information systems throughout the RMF lifecycle, including categorization, security-control implementation and assessment, authorization, and authorization sustainment. * Manage eMASS profiles, POA&Ms, STIG evidence, SSPs, SAPs, SARs, RARs, Security Authorization Packages, MOUs or MOAs, and other required authorization artifacts. * Maintain continuous monitoring, compliance, and program cybersecurity readiness through ISCM, IAVM, policies and SOPs, hardware or software inventories, security baselines, applicable DoD or Army guidance, risk and remediation reporting, and coordination with the ISSM, system owners, engineers, administrators, and Enterprise, Commo, and program leadership in support of exercises, WFXs, Reference Set validation, network extensions, and other mission requirements. ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [What makes Cybersecurity different for critical infrastructure?](https://www.wearedevelopers.com/videos/571-what-makes-cybersecurity-different-for-critical-infrastructure) - [One Pipeline, Three Regulator - SBOM Compliance for the Developer](https://www.wearedevelopers.com/videos/100169-one-pipeline-three-regulator-sbom-compliance-for-the-developer) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again](https://www.wearedevelopers.com/magazine/751-how-we-built-a-worry-free-system-that-runs-for-10-years-and-what-we-d-do-again) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [The Overflow: Security and Privacy](https://www.wearedevelopers.com/magazine/715-the-overflow-security-and-privacy)