> Markdown version of [/jobs/ext/3139938-information-assurance-compliance-specialist-30427](https://www.wearedevelopers.com/jobs/ext/3139938-information-assurance-compliance-specialist-30427). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Information Assurance Compliance Specialist - 30427 - **Company:** HII Mission Technologies - **Location:** Virginia Beach, VA, United States (Remote available) - **Experience:** Expert - **Salary:** $91,072.0 - $130,104.0 - **Contract:** Permanent contract - **Skills:** Artificial Intelligence, Amazon Web Services, Microsoft Azure, Cloud Computing Security, Configuration Management, Identity and Access Management, Information Security Management, Information Systems Security Architecture Professional, SAP (Applications), Software Vulnerability Management, Information Technology, Plan of Action and Milestones, Vulnerability Analysis - **Published:** September 29, 2026 - **Apply:** https://www.clearancejobs.com/jobs/9202108/information-assurance-compliance-specialist-30427 ## About the Role * 5 years relevant experience with Bachelors in related field; 3 years relevant experience with Masters in related field; 0 years experience with PhD or Juris Doctorate in related field; or High School Diploma or equivalent and 9 years relevant experience. * Advanced, specialized experience in Information Assurance compliance * Advanced knowledge of RMF processes and Navy Assessment & Authorization procedures. * Experience working with Information Assurance tools such as eMASS and Assured Compliance Assessment Solution (ACAS). * DoD 8140 (formerly 8570) IAM Level III certification required: CISSP, CISM, GSLC, or CASP. * Current or active DoD Secret clearance. * Ability to work onsite at Dam Neck, Virginia Beach, VA hybrid schedule. Remote/telework is at the discretion of the government. * Strong written and verbal communication skills for briefing senior government leadership. Preferred Qualifications * Five or more years of experience supporting Navy RMF Assessment & Authorization programs. * Experience supporting NSWCDD DNA, PMS339, or submarine training systems programs. * Knowledge of Navy cybersecurity policies, OPNAV instructions, FISMA reporting, and continuous monitoring requirements. * Experience with cloud security authorizations (AWS, Azure, or other cloud platforms). * Familiarity with NIST SP 800-53 Rev 5, NIST SP 800-37 Rev 2, and Navy RMF guidance. * Experience with STIG compliance validation and IAVM vulnerability management. * CAP (Certified Authorization Professional) or CISSP-ISSAP certification. * Experience mentoring junior cybersecurity professionals / assessors on RMF processes, OQE development, control evaluation techniques, and artifact quality standards. * U.S. Navy background with information assurance, cybersecurity, or authorization experience. * Strong analytical and problem-solving skills with attention to detail. * Ability to manage multiple authorization packages simultaneously across different sponsors. * Experience presenting to Authorizing Officials and senior Navy leadership. Physical Requirements May require working in an office, industrial, shipboard, or laboratory environment. Capable of climbing ladders and tolerating confined spaces and extreme temperature variances. ## Description HII's Mission Technologies division is currently seeking an Information Assurance Compliance Specialist to support Naval Surface Warfare Center Dahlgren Division (NSWCDD) Dam Neck Activity (DNA) cybersecurity programs for Shore-Based Training Systems. This position will provide senior-level compliance and auditor support for Risk Management Framework (RMF) Assessment & Authorization (A&A) processes supporting approximately 80 cloud and shore-based training systems across PMS339, DRPM SUBS (SEA07TR), and RRL sponsors., * Oversee, evaluate, and support documentation, validation, and accreditation processes necessary to ensure information technology (IT) systems meet the organization's information assurance (IA) and security requirements. * Provide senior Auditor support for RMF packages and continuous monitoring purposes as needed in RMF Steps 0-6 for PMS 339 and DRPM SUBS (UWS TR) systems. Provide security controls risk assessments and validations. * Lead annual security reviews and annual testing of security controls; validate control implementation and effectiveness. * Independently assess quality of security control implementation against NIST SP 800-53 requirements and Navy cybersecurity policies. * Review, validate, and approve security artifacts including System Security Plans (SSP), Security Assessment Plans (SAP), Security Assessment Reports (SAR), and Plan of Action and Milestones (POA&M). * Develop and maintain objective quality evidence (OQE) documentation for security control validation and continuous monitoring. * Conduct comprehensive reviews of STIG compliance results, ACAS vulnerability scan outputs, and remediation activities; provide recommendations for risk mitigation. * Assess POA&M entries for accuracy, completeness, and appropriate risk categorization; track vulnerability remediation timelines. * Lead continuous monitoring activities by analyzing security control compliance status, identifying systemic issues, and recommending corrective actions. * Coordinate with Information System Security Managers (ISSM), Technical Area Experts (TAE), Security Control Assessors (SCA), Functional Authority Officials (FAO), and Authorizing Officials (AO). * Review and approve technical documentation including engineering change proposals, baseline descriptions, and configuration management artifacts for security compliance. * Prepare and deliver briefings to senior leadership at TAE, SCA, and FAO/AO checkpoint and authorization signing meetings on system security posture and risk acceptance recommendations. * Develop cyber policies, procedures, compliance reports, and risk analysis documentation. * Ensure appropriate treatment of risk, compliance, and monitoring assurance from internal and external perspectives across multiple systems and sponsors. * Provide expert guidance on Navy cybersecurity policies, instructions, RMF processes, and FISMA reporting requirements. * Utilize Enterprise Mission Assurance Support Service (eMASS) to manage authorization packages, track system status, and maintain compliance artifacts. * Support cross-sponsor activities for PMS339, SUBS, and RRL programs; coordinate workload prioritization across sponsors. * Mentor junior compliance specialists and provide technical guidance on complex authorization issues. * Attend DOW, Navy Authorizing Official (NAO), and PAE Maritime RMF meetings to stay current on evolving RMF processes and procedures. * Support integration of Artificial Intelligence (AI) into the RMF process and emerging cybersecurity requirements. * Review and/or produce white papers, decision option papers, risk analysis, and risk mitigation recommendations. * Attend TAE, SCA, and FAO/AO checkpoint and authorization signing meetings to formally brief leadership on systems' security posture and identify potential cybersecurity issues. * Utilize SIPRnet access 25-60% of the time depending on specific work assignments. * Expected travel up to 10-15% of time for approximately one week per trip to support authorization briefings, stakeholder coordination, or senior-level meetings. ## Related Videos - [Containers in the cloud - State of the Art in 2022](https://www.wearedevelopers.com/videos/410-containers-in-the-cloud-state-of-the-art-in-2022) - [One Pipeline, Three Regulator - SBOM Compliance for the Developer](https://www.wearedevelopers.com/videos/100169-one-pipeline-three-regulator-sbom-compliance-for-the-developer) - [Independently together: how micro-applications improve developer experience + app performance](https://www.wearedevelopers.com/videos/452-independently-together-how-micro-applications-improve-developer-experience-app-performance) - [Developer Tools for Microsoft Azure](https://www.wearedevelopers.com/videos/450-developer-tools-for-microsoft-azure) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Reliable scalability: How Amazon.com scales on AWS](https://www.wearedevelopers.com/videos/983-reliable-scalability-how-amazon-com-scales-on-aws) ## Related Articles - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Best Paying Jobs in Technology](https://www.wearedevelopers.com/magazine/256-best-paying-jobs-in-technology) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again](https://www.wearedevelopers.com/magazine/751-how-we-built-a-worry-free-system-that-runs-for-10-years-and-what-we-d-do-again) - [Is Software Engineering Over-Saturated?](https://www.wearedevelopers.com/magazine/418-is-software-engineering-over-saturated) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities)