> Markdown version of [/jobs/ext/3135809-information-systems-security-specialists-30424](https://www.wearedevelopers.com/jobs/ext/3135809-information-systems-security-specialists-30424). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Information Systems Security Specialists - 30424 - **Company:** HII Mission Technologies - **Location:** Virginia Beach, VA, United States (Remote available) - **Experience:** Experienced - **Salary:** $89,889.0 - $128,414.0 - **Contract:** Permanent contract - **Skills:** Artificial Intelligence, Amazon Web Services, Systems Engineering, Microsoft Azure, Cloud Computing, Cloud Computing Security, Configuration Management, Cyber Security, Information Security Management, Software Vulnerability Management, Tenable Nessus, Plan of Action and Milestones - **Published:** September 29, 2026 - **Apply:** https://www.clearancejobs.com/jobs/9202109/information-systems-security-specialists-30424 ## About the Role * 6 years relevant experience with Bachelors in related field; 4 years relevant experience with Masters in related field; or High School Diploma or equivalent and 10 years relevant experience. * Experience in Cybersecurity, Engineering, Test & Evaluation (T&E), or Assessment & Authorization (A&A) related field. * Demonstrated working knowledge of the Risk Management Framework (RMF) process and/or prior experience with Defense Information Assurance Certification and Accreditation Process (DIACAP). * Familiarity with security policies and guidance documents to assist with preparation and maintenance of process artifacts and traceability documents for compliance with Authority to Operate (ATO) requirements. * Experience working with Information Assurance tools such as Enterprise Mission Assurance Support Service (eMASS) and Assured Compliance Assessment Solution (ACAS). * DoD 8140 (formerly 8570) IAT Level II or III certification (Security+, CASP, GSEC, or SSCP preferred). * Current or active DoD Secret clearance. * Ability to work onsite at Dam Neck, Virginia Beach, VA hybrid schedule. Remote/telework is at the discretion of the government., * Experience supporting Navy shore-based training systems or cloud-based training environments. * Knowledge of Navy cybersecurity policies, instructions, and continuous monitoring requirements. * Experience with STIG compliance testing and vulnerability remediation. * Experience with cloud security (AWS, Azure, or other platforms). * Familiarity with Navy authorization processes and working with Navy Authorizing Officials. * U.S. Navy background with information assurance or training systems experience. * Strong written and verbal communication skills for briefing technical and non-technical audiences. Physical Requirements Job performance will normally require only minor lifting and carrying of boxes of records or equipment. ## Description HII's Mission Technologies division is currently seeking four (4) Information Systems Security Specialists to support Naval Surface Warfare Center Dahlgren Division (NSWCDD) Dam Neck Activity (DNA) cybersecurity operations for Shore-Based Training Systems. These positions will serve as Information Systems Security Officers (ISSO) and Information Systems Security Engineers (ISSE) supporting Risk Management Framework (RMF) Assessment & Authorization (A&A) for approximately 80 cloud and shore-based training systems across PMS339, DRPM SUBS (SEA07TR), and RRL program sponsors., * Serve as Department of Navy (DON) Information Systems Security Engineer/Officer (ISSE/ISSO) supporting RMF Assessment & Authorization (A&A) and other ISSE/ISSO responsibilities in accordance with applicable Navy policies and instructions. * Categorize cloud and shore-based training systems and information types according to applicable Navy policies and instructions. * Establish and maintain security baselines for cloud instances and containers in support of RMF (step 0-6) A&A and in accordance with applicable Navy policies and instructions. * Perform annual security reviews and annual testing of security controls for assigned systems. * Manage Plan of Action and Milestones (POA&M) entries and ensure vulnerabilities are properly tracked, mitigated, and resolved. * Plan and perform cybersecurity testing to assess security controls and record security control compliance status. * Assess quality of security control implementation against requirements and conduct vulnerability and compliance management and scanning in support of continuous monitoring efforts. * Support development of technical artifacts, engineering documentation, network drawings, and use of Assessment and Authorization (A&A) tools including eMASS. * Conduct Security Technical Implementation Guide (STIG) testing using Evaluate-STIG and other scanning tools; produce STIG checklists and compliance reports. * Process and analyze Assured Compliance Assessment Solution (ACAS) vulnerability scans; develop remediation plans and track resolution. * Support coordination efforts and liaison activities for all aspects of RMF A&A, cyber engineering, and system lifecycle management processes with stakeholders. * Provide cyber technical and security engineering expertise across systems' lifecycle including RMF, Annual Security Controls reviews, Information Assurance Vulnerability Management (IAVM), and annual Federal Information Security Modernization Act (FISMA) reporting. * Identify, report, and resolve security violations; identify secure solutions to isolate incidents; and ensure secure recovery and functionality of systems. * Review and/or produce white papers, decision option papers, Concept of Operations (CONOPS), engineering change proposals (ECPs), systems engineering plans, baseline plans, integration plans, and technical reports. * Develop documentation to support ongoing system security operations, maintenance, and specific problem resolution. * Attend Configuration Control Board (CCB) meetings dealing with infrastructure/network upgrades, including major and minor hardware/software that will potentially affect approved baselines. * Attend DOW, Navy Authorizing Official (NAO), and PAE Maritime RMF meetings to provide system-level technical updates, discuss RMF control implementation, and support readiness for authorization milestones. * Support Test and Evaluation (T&E), Developmental Test and Evaluation (DT&E), and Operational Test and Evaluation (OT&E) activities as needed. * Support integration of Artificial Intelligence (AI) into the RMF process. * Provide analytical and technical security recommendations to the Program Office/Package Submitting Office (PSO). * Assist in implementation and management of cybersecurity policies supporting the Information System Security Manager (ISSM), Technical Area Expert (TAE), Security Control Assessor (SCA), Functional Authority Official (FAO), Authorizing Official (AO), and facility director. * Expected travel up to 10-15% of time for approximately one week per trip to support on-site assessments, stakeholder coordination, or authorization briefings. ## Related Videos - [Developer Tools for Microsoft Azure](https://www.wearedevelopers.com/videos/450-developer-tools-for-microsoft-azure) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [What makes Cybersecurity different for critical infrastructure?](https://www.wearedevelopers.com/videos/571-what-makes-cybersecurity-different-for-critical-infrastructure) - [Cyber Security: Small, and Large!](https://www.wearedevelopers.com/videos/259-cyber-security-small-and-large) - [Checkmate: 5 Real Incidents That Can End a Software Company](https://www.wearedevelopers.com/videos/100126-checkmate-5-real-incidents-that-can-end-a-software-company) ## Related Articles - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Best Paying Jobs in Technology](https://www.wearedevelopers.com/magazine/256-best-paying-jobs-in-technology) - [Is Software Engineering Over-Saturated?](https://www.wearedevelopers.com/magazine/418-is-software-engineering-over-saturated) - [How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again](https://www.wearedevelopers.com/magazine/751-how-we-built-a-worry-free-system-that-runs-for-10-years-and-what-we-d-do-again) - [IT Salaries in UK](https://www.wearedevelopers.com/magazine/288-it-salaries-in-uk)