> Markdown version of [/jobs/ext/3331892-senior-information-security-specialist](https://www.wearedevelopers.com/jobs/ext/3331892-senior-information-security-specialist). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Senior Information Security Specialist - **Company:** DEV TECH INC. - **Location:** Ashburn, VA, United States (Remote available) - **Experience:** Expert - **Salary:** $88,000.0 - $150,000.0 - **Contract:** Permanent contract - **Skills:** Agile Methodology, Artificial Intelligence, Amazon Web Services, JIRA, Cloud Engineering, CompTIA Security+, Cyber Security, Information Systems, Network Connections, Systems Development Life Cycle, Smartsuite, Software Engineering, Software Vulnerability Management, Devsecops - **Published:** September 16, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=43d6c154d68fc0f0 ## About the Role * Bachelor's degree and 7+ years of experience securing federal information systems. * Demonstrated experience leading and mentoring information security professionals, including junior and mid-level ISSOs. * Experience leading cybersecurity activities in a federal government client environment and working directly with government stakeholders.' * Strong working knowledge of NIST Risk Management Framework (RMF) and experience supporting federal systems through security authorization and ATO activities. * Experience developing, implementing, assessing, or documenting security controls aligned with FISMA and NIST 800-53. * Experience with vulnerability management, continuous monitoring, security assessments, audits, or compliance reviews for federal systems. * Experience providing cybersecurity guidance for AWS-hosted applications and systems. * Strong understanding of modern information systems and their technical security considerations. * Ability to work effectively with developers, architects, engineers, government stakeholders, and technical and non-technical audiences. * Strong written and verbal communication skills, including the ability to communicate security risks and technical findings and develop/present security documentation and executive briefings. * Ability to establish priorities, manage competing demands, independently manage security activities, and escalate issues appropriately. * Proactive, solutions-oriented approach to identifying risks and improving security practices. * Current CBP, DHS, or Top Secret Clearance. * Ability to work onsite 3 days per week in Ashburn, VA during standard business hours. * Cybersecurity certification such as CISSP, CISM, GIAC, Security+, or another recognized cybersecurity certification. Preferred Education, Experience & Skills * Experience developing or supporting RMF and authorization artifacts, including SSPs, ISAs, PTAs, ATTs, POA&Ms, and related documentation. * Experience partnering with application development, cloud engineering, and DevSecOps teams to integrate security throughout the SDLC. * Experience working in an Agile software development environment using Jira or similar platforms. * Experience with GRC tools such as CSAM or similar platforms supporting authorization, compliance, vulnerability management, and security activities. * Understanding of AI concepts and practical applications of AI for cybersecurity operations, risk analysis, compliance, or security program management. Our estimated salary range for this position is $88,000 - $ 150,000. This presented salary range is not a guarantee of compensation or salary. Offered salary is based on experience, geographic location, and possibly contractual requirements as appropriate to the role. *Salary could fall outside of this range. ## Description Dev Technology Group is seeking a Senior Information Security Specialist to lead and develop a mid-sized team of ISSOs supporting the security, compliance, and authorization of mission-critical federal applications and information systems hosted in AWS. This is a hands-on technical leadership role combining people leadership, federal cybersecurity expertise, and direct collaboration with government and technical stakeholders. You will mentor junior and mid-level ISSOs while partnering with system owners, developers, architects, cloud/infrastructure engineers, security professionals, and government stakeholders throughout the system development lifecycle. You will provide practical security guidance for AWS-hosted applications, lead Risk Management Framework (RMF) and Authority to Operate (ATO) activities, oversee vulnerability management and continuous monitoring, and translate federal cybersecurity requirements into actionable guidance for technical teams., * Lead, mentor, and develop a team of ISSOs by establishing priorities, providing technical direction and coaching, and promoting accountability and consistent security practices. * Lead and oversee RMF, ATO, security authorization, compliance, vulnerability management, and continuous monitoring activities across a portfolio of federal systems and applications. * Partner with ISSMs, system owners, assessors, developers, architects, engineers, and government stakeholders to maintain authorizations, identify risks, and address security requirements. * Lead vulnerability management efforts, prioritizing remediation, developing mitigation strategies, and tracking corrective actions through resolution. * Develop, assess, document, and support implementation of security controls aligned with FISMA, NIST 800-53, DHS, and client requirements. * Prepare and maintain security and authorization documentation, including SSPs, ISAs, audit artifacts, and RMF documentation. * Provide cybersecurity guidance for applications and systems deployed in AWS and integrate security throughout the software development lifecycle. * Validate security implementation through technical reviews, discussions, interviews, assessments, and tabletop exercises. * Support security audits, assessments, compliance reviews, and reviews of information systems and network connections. * Interpret federal and client security policies and translate requirements into practical guidance for technical and development teams. * Identify and escalate security risks, communicate priorities and remediation status, and provide clear visibility to Dev Technology leadership and government stakeholders. * Develop and present security metrics, status reports, risk assessments, and executive briefings. * Establish and improve security processes, procedures, templates, dashboards, and workflows to improve consistency, accountability, and efficiency across the ISSO team. * Build trusted relationships with government clients through proactive communication, collaboration, and face-to-face engagement. ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [DevSecOps: Injecting Security into Mobile CI/CD Pipelines](https://www.wearedevelopers.com/videos/273-devsecops-injecting-security-into-mobile-ci-cd-pipelines) - [GitOps for the people](https://www.wearedevelopers.com/videos/461-gitops-for-the-people) - [DevSecOps culture](https://www.wearedevelopers.com/videos/783-devsecops-culture) - [You can’t hack what you can’t see](https://www.wearedevelopers.com/videos/41-you-can-t-hack-what-you-can-t-see) - [DevSecOps: Security in DevOps](https://www.wearedevelopers.com/videos/36-devsecops-security-in-devops) ## Related Articles - [Best Paying Jobs in Technology](https://www.wearedevelopers.com/magazine/256-best-paying-jobs-in-technology) - [Top-Paying Tech Jobs (with Salaries)](https://www.wearedevelopers.com/magazine/372-top-paying-tech-jobs-with-salaries) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Highest Paying Tech Companies for Developers](https://www.wearedevelopers.com/magazine/220-highest-paying-tech-companies-for-developers) - [What’s the Difference between a Junior, Mid, and Senior Developer?](https://www.wearedevelopers.com/magazine/238-what-s-the-difference-between-a-junior-mid-and-senior-developer) - [How Much Does a Software Engineer Make? Realistic Software Engineering Salaries](https://www.wearedevelopers.com/magazine/425-how-much-does-a-software-engineer-make-realistic-software-engineering-salaries)