> Markdown version of [/jobs/ext/3539652-information-security-risk-specialist](https://www.wearedevelopers.com/jobs/ext/3539652-information-security-risk-specialist). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Information Security Risk Specialist - **Company:** Booz Allen Hamilton Inc. - **Location:** Annapolis Junction, MD, United States - **Experience:** Expert - **Salary:** $99,000.0 - $225,000.0 - **Contract:** Permanent contract - **Skills:** Amazon Web Services, Cloud Computing, Cloud Computing Security, CompTIA Security+, Domain Name System (DNS), Identity and Access Management, Network Security, Routing, Cloud Platform System, Okta, Firewalls (Computer Science), Cloudformation, Cybercrime, Cloud Migration, Terraform, Splunk - **Published:** September 30, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=af2d482d28a081c2 ## About the Role * 5+ years of experience securing, hardening, and remediating security vulnerabilities in AWS GovCloud * Experience with CMMC, NIST 800-171, DoD security controls, FedRAMP, defense SRG, or cloud security frameworks * Experience with cloud networking, routing, segmentation, firewalls, private connectivity, DNS, and network security controls * Experience with control inheritance, SSP generation, evidence mapping, or authorization package support * Knowledge of AWS organizations, organizational units, service control policies, identity, account governance, and cloud security baselines * Ability to translate policy to both senior stakeholders and operations teams who need to implement the controls * Public Trust * Bachelor's degree Nice If You Have: * Experience implementing Infrastructure-as-Code using Terraform, CloudFormation, CDK, or comparable technologies * Experience deploying secure landing zones, shared services, platform baselines, or multi-account cloud architectures * Experience with AWS Security Hub, GuardDuty, Config, CloudTrail, Network Firewall, Transit Gateway, Cloud WAN, Splunk, Tenable, F5, or comparable technologies * Experience supporting cloud migrations, tenant onboarding, account adoption, network-path validation, or platform-parity initiatives * Knowledge of IAM Identity Center, federation, Keycloak, Entra ID, privileged access, and identity-boundary design * Possession of excellent detail-oriented, organization, and time management skills * Possession of excellent verbal and written communication skills * CISSP, CCSP, Security+, AWS Security Specialty, CISM, or equivalent Certification Vetting: Applicants selected will be subject to a government investigation and may need to meet eligibility requirements of the U.S. government client; Public Trust determination is required. ## Description Cyber threats are everywhere, and the constantly evolving nature of these threats can make understanding them seem overwhelming. In all of this "cyber noise" how can these organizations understand their risks and how to mitigate them? The answer is an information security risk specialist like you who will break down complex threats into manageable plans of action. As an information security risk specialist on our team, you'll use your experience to work with senior leaders to discover their cyber risks, understand applicable policies, and develop a mitigation plan. You'll review technical and personnel details from our tenants to assess the entire threat landscape. Then, you'll guide our tenants through a plan of action with presentations, whitepapers, and milestones. You'll work with cloud architects, cybersecurity teams, GRC, networking, platform engineering, and tenant teams to make security controls repeatable and usable. You'll help ensure that users receive the right platform, understand the controls they inherit, and know what remains their responsibility. This is your opportunity to apply cloud-security expertise while expanding your skills in secure platform engineering, AWS GovCloud, IL5 environments, Infrastructure-as-Code, control inheritance, and enterprise-scale cloud transformation. ## Related Videos - [Our journey with Spring Boot in a microservice architecture](https://www.wearedevelopers.com/videos/511-our-journey-with-spring-boot-in-a-microservice-architecture) - [Creating a routing app with Google Maps API from scratch](https://www.wearedevelopers.com/videos/831-creating-a-routing-app-with-google-maps-api-from-scratch) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [You can’t hack what you can’t see](https://www.wearedevelopers.com/videos/41-you-can-t-hack-what-you-can-t-see) - [A Technical Introduction to Bitcoin's 2nd Layer- The Lightning Network](https://www.wearedevelopers.com/videos/15-a-technical-introduction-to-bitcoin-s-2nd-layer-the-lightning-network) - [Evolving your APIs, a step-by-step approach](https://www.wearedevelopers.com/videos/434-evolving-your-apis-a-step-by-step-approach) ## Related Articles - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing)