> Markdown version of [/jobs/ext/3036901-information-security-specialist](https://www.wearedevelopers.com/jobs/ext/3036901-information-security-specialist). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Information Security Specialist - **Company:** SHERPA LLC - **Location:** United States - **Experience:** Experienced - **Salary:** $105,000.0 - $115,000.0 - **Contract:** Permanent contract - **Skills:** Microsoft Windows, Artificial Intelligence, Apple Mac Systems, Audit Trail, Cyber Security, Information Systems, Linux, Identity and Access Management, Intrusion Detection and Prevention, Microsoft Security Essentials, Cloud Services, Phishing, Security Information and Event Management, Software Vulnerability Management, Enterprise Software Applications, Microsoft InTune, Information Technology, CIS Benchmarks, Network Server, Plan of Action and Milestones - **Published:** September 23, 2026 - **Apply:** https://www.clearancejobs.com/jobs/9186051/information-security-specialist ## About the Role The position requires hands-on experience with enterprise security tools and processes, including vulnerability management, change management, audit log review, endpoint security, and data protection., * Bachelor's degree in Computer Science, Information Technology, Cybersecurity, or related field * 3-5 years of experience in information security or cybersecurity operations * Experience with Microsoft security technologies, including Microsoft Defender, Microsoft Intune, and Microsoft Purview. * In depth understanding of software and system vulnerability management. * Experience with log aggregation, SIEM tools, or advanced threat detection * Experience with managing the security of Windows and Linux systems in an Enterprise environment. * Experience implementing and maintaining STIGS or CIS Benchmarks Preferred Experience: * Industry certifications such as Security+, CISSP, or equivalent * Experience supporting CMMC/NIST 800-171 or NIST 800-53/RMF * Familiarity with endpoint management and configuration baselines across enterprise systems * Experience working in a regulated environment handling Controlled Unclassified Information (CUI) * Experience with managing MacOS systems in an Enterprise environment * Experience maintaining security controls and working on a change control board. * Experience leveraging AI tools in an enterprise setting. * Experience as a COMSEC custodian About Sherpa 6: At Sherpa 6 we love to solve problems and provide the best solutions for our customers. Our approach to a problem is to find a user-focused and design-driven solution that is simple yet functional and effective. We are a group of enthusiastic forward-thinkers who are excited to build amazing solutions with bleeding-edge technology. We hire people who are forward thinkers, passionate about what they do, love to collaborate and want to constantly learn. We enjoy what we do and we're not afraid to put the extra effort in to accomplish the mission; call us Sherpas. As a Service-Disabled Veteran Owned Small Business, we know what it means to serve. We have made it our mission to be the leaders in solutions that protect and give our Warfighters the edge they need when put into harm's way. Background Screening/Check/Investigation: Successful completion of a background screening/check/investigation will/may be required as a condition of hire., The proposed salary range is reflective across all Sherpa 6 locations, years of experience and skill levels. Salary negotiations will be based on a host of factors including but not limited to your geographic location, prior experience, relevant skills, education, and certifications. ## Description The Information Security Specialist is responsible for maintaining the security posture of the organization's internal information systems and ensuring compliance with applicable cybersecurity frameworks. This role works closely with Security, IT, leadership, and compliance stakeholders to support vulnerability management, audit readiness, incident response, and secure system operations., * Manage system vulnerabilities, including scanning, prioritization, and remediation. * Support patching and configuration enforcement through endpoint management solutions * Provide continuous monitoring of information systems, ensuring audit logs are collected, reviewed, and anomalous activity is identified and mitigated. * Analyze and correlate logs from endpoints, servers, identity systems, and cloud services. * Configure and tune alerting and automated response capabilities for security events. * Perform incident response and reporting for cybersecurity events including malware, phishing, unauthorized access, and data exfiltration. * Maintain Plans of Action & Milestones (POA&M) and track remediation to closure * Ensure all system security documentation (e.g., SSPs, baselines, policies, procedures) is current and audit-ready. * Assist in development and maintenance of security policies, standards, and technical controls. * Review and assess security impact of system changes as part of change control processes * Recommend and implement security configurations across Microsoft 365, endpoint, and identity platforms. * Conduct user activity monitoring and support investigations related to potential insider threat or policy violations. * Run security awareness initiatives, including phishing simulations and training activities. * Prepare reports on the status of vulnerabilities, incidents, and overall security posture. ## Related Videos - [Docker network without Docker](https://www.wearedevelopers.com/videos/1418-docker-network-without-docker) - [Passkeys: Truly Phishing-Resistant? Implementation and Pitfalls](https://www.wearedevelopers.com/videos/100156-passkeys-truly-phishing-resistant-implementation-and-pitfalls) - [Resilient by Design: Building Robust Architectures in High-Stakes Financial Systems](https://www.wearedevelopers.com/videos/2106-resilient-by-design-building-robust-architectures-in-high-stakes-financial-systems) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Checkmate: 5 Real Incidents That Can End a Software Company](https://www.wearedevelopers.com/videos/100126-checkmate-5-real-incidents-that-can-end-a-software-company) - [Docker exec without Docker](https://www.wearedevelopers.com/videos/1094-docker-exec-without-docker) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Best Paying Jobs in Technology](https://www.wearedevelopers.com/magazine/256-best-paying-jobs-in-technology) - [Highest Paying Tech Companies for Developers](https://www.wearedevelopers.com/magazine/220-highest-paying-tech-companies-for-developers) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Top-Paying Tech Jobs (with Salaries)](https://www.wearedevelopers.com/magazine/372-top-paying-tech-jobs-with-salaries)