> Markdown version of [/jobs/ext/3049168-information-security-risk-specialist](https://www.wearedevelopers.com/jobs/ext/3049168-information-security-risk-specialist). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Information Security Risk Specialist - **Company:** Booz Allen Hamilton Inc. - **Location:** Lexington Park, MD, United States - **Experience:** Experienced - **Salary:** $99,000.0 - $225,000.0 - **Contract:** Permanent contract - **Skills:** Microsoft Word, Microsoft Excel, Cyber Security, Microsoft Office, Microsoft Visio, Microsoft PowerPoint, Security Content Automation Protocol, Data Streaming, SC Clearance - **Published:** September 24, 2026 - **Apply:** https://www.clearancejobs.com/jobs/9189524/information-security-risk-specialist ## About the Role * 3+ years of experience with eMASS * Ability to build vendor and sponsor relationships * Ability to identify security requirements for connected and non-connected systems and unclassified, classified, and National Security Systems (NSS) * Secret clearance * Bachelor's degree * CISSP, CISM, or CCSP Certification Nice If You Have: * 5+ years of experience with eMASS * Experience with Army or National Guard Bureau (NGB) RMF * Experience with Army ATO POA&Ms * Experience as an ISSO, ISSM, or ISSE * Experience with people and team leadership * Experience mentoring in the field of cybersecurity * Experience with Microsoft Office products, including Word, Excel, PowerPoint, and Visio * Experience with eMASSter, Security Technical Implementation Guides (STIG), Evaluate-STIG, Security Content Automation Protocol (SCAP), Assured Compliance Assessment Solution (ACAS), Ports, Protocols and Services Matrix, and Host Based Security System (HBSS) * Ability to manage workflows, system data flows, and architecture diagrams * Master's degree ## Description As an Information Security Risk Specialist on our team, you'll use your experience to work with the DoD to discover their cyber risks, understand applicable policies, and develop a mitigation plan. You'll review technical, environmental, and personnel details from SMEs, engineers, and program managers to assess the entire threat landscape. Then, you'll guide your client through a plan of action with presentations, white papers, and milestones. You'll work with your client to translate security concepts so they can make the best decisions to secure their mission critical systems and critical infrastructure. This is your opportunity to act as an information security subject matter expert while broadening your skills in cybersecurity and Risk Management Framework (RMF). Join us as we protect our military's communications and our nation's cyber infrastructure. ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Developing the Rich Text Editor for DeepL.com](https://www.wearedevelopers.com/videos/1172-developing-the-rich-text-editor-for-deepl-com) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [Organizational Change Through The Power Of Why - DevSecOps Enablement](https://www.wearedevelopers.com/videos/478-organizational-change-through-the-power-of-why-devsecops-enablement) - [Cyber Security: Small, and Large!](https://www.wearedevelopers.com/videos/259-cyber-security-small-and-large) - [Maturity assessment for technicians or how I learned to love OWASP SAMM](https://www.wearedevelopers.com/videos/351-maturity-assessment-for-technicians-or-how-i-learned-to-love-owasp-samm) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [The Overflow: Security and Privacy](https://www.wearedevelopers.com/magazine/715-the-overflow-security-and-privacy) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities)