> Markdown version of [/jobs/ext/3541579-information-security-specialist](https://www.wearedevelopers.com/jobs/ext/3541579-information-security-specialist). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Information Security Specialist - **Company:** ASG Inc - **Location:** United States - **Experience:** Expert - **Contract:** Permanent contract - **Skills:** Agile Methodology, Artificial Intelligence, Amazon Web Services, Software System Penetration Testing, Systems Engineering, Confluence, JIRA, Microsoft Azure, Health Informatics, Software Documentation, Cyber Security, Systems Development Life Cycle, Akamai, Software Vulnerability Management, Cloud Platform System, Software Security, Information Technology, Plan of Action and Milestones, Vulnerability Analysis - **Published:** September 30, 2026 - **Apply:** https://www.thejobnetwork.com/job/cd9c7463-7d7f-483d-b5ae-5f72de186413/senior-information-security-specialist-lead ## About the Role * Bachelor's degree or higher in Computer Science, Information Technology, Cybersecurity, Systems Engineering, or a related field (or equivalent professional experience). * 8+ years of information security experience in a federal or enterprise environment, including team leadership. * Experience with FISMA compliance, ATO processes, and continuous Assessment & Authorization (A working understanding of NIST 800-53/37. * Experience co-leading or managing a multi-person security team, including workload distribution and quality oversight of deliverables. * Working knowledge of vulnerability scanning and compliance/POA&M platforms, Jira, Confluence, and FISMA/ATO documentation standards and processes. * Ability to obtain and maintain Program EUA access and required Public Trust clearance. * Strong communication skills and ability to coordinate across multi-disciplinary teams and government stakeholders. Even Better: * Prior Program or HHS security program experience strongly preferred. * Relevant security certification (CISSP, CISM, CEH, CCNA Security, or Security+). * Familiarity with federal control tracking systems (e.g., CFACTS and BOX). * Working knowledge of cloud environments (AWS, Azure) and associated security controls. * Exposure to pen testing, application security, and CDN security services (e.g., Akamai). * Experience providing security and privacy input within Agile development environments. * Knowledge about emerging industry or technology trends such as Artificial Intelligence (AI) frameworks. Clearance Requirement: * Ability to obtain and maintain public trust background investigation/clearance per client requirements. ## Description ASG is seeking an experienced Security Lead to own the Program security posture, compliance artifacts, and coordination with Program Security Oversight leadership. This role shares leadership of the security team with a Co-Lead and directs the work of the Information Security Specialist team, ensuring compliance documentation, vulnerability management, and ATO artifacts are complete, current, and defensible in a complex federal healthcare IT environment. The ideal candidate brings deep federal cybersecurity experience, a track record of leading security teams, and the judgment to represent the program's security posture to executive and government stakeholders. What You Will Do: * Own Task 3 security management deliverables, including compliance documentation, risk register maintenance, and coordination with the Program Security Oversight Leader. * Direct and coordinate the Information Security Specialist team, including workload distribution and quality oversight of security deliverables, alongside the Sr. Information Security Specialist (Co-Lead). * Support Authorization to Operate (ATO) maintenance, continuous Assessment & Authorization (A&A) activities, and FISMA/FedRAMP compliance documentation for Client-managed systems. * Author and review security documentation, including System Security Plans (SSPs), Risk Assessments, and Security Impact Analyses (SIA), prior to submission to Program Security Oversight leadership. * Oversee vulnerability scanning, remediation tracking, and security findings reporting across enterprise tools; review results and recommended corrective actions from the Information Security Specialist team. * Serve as the primary security point of contact with Program Security Oversight Leadership, and maintain collaborative relationships with federal ISSOs, CSPs (e.g., AWS, Azure), system owners, and vendors. * Coordinate with the Tools Management team through the combined Security/Tools scrum cadence. * Track and maintain the centralized Security Risk Register, map vulnerabilities to POA&Ms, and support FISMA/FedRAMP compliance efforts across the program. * Provide guidance and privacy/security insight to Agile teams across projects, and support Privacy and Security Compliance through all stages of the systems development lifecycle (SDLC). * Work within Client system repositories such as CFACTS and BOX. * Oversee declared game day events, ensuring after-action reports and other required game day artifacts are completed by the security team. * Develop and maintain standard operating procedures (SOPs) for repeatable security processes across the team. * Perform additional duties as assigned by the Program Security Oversight Leader. * Perform additional duties assigned. ## Related Videos - [GitOps for the people](https://www.wearedevelopers.com/videos/461-gitops-for-the-people) - [What the Heck is Edge Computing Anyway?](https://www.wearedevelopers.com/videos/593-what-the-heck-is-edge-computing-anyway) - [42 x 2 Canvases Later: Two Years, Two Minds, Many Lessons](https://www.wearedevelopers.com/videos/1458-42-x-2-canvases-later-two-years-two-minds-many-lessons) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Improving quality with Agentic AI with Rovo Dev and Xray](https://www.wearedevelopers.com/videos/2005-improving-quality-with-agentic-ai-with-rovo-dev-and-xray) - [A Founder's Journey : From Startup Chaos to Purposeful Growth](https://www.wearedevelopers.com/videos/1926-a-founder-s-journey-from-startup-chaos-to-purposeful-growth) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Best Paying Jobs in Technology](https://www.wearedevelopers.com/magazine/256-best-paying-jobs-in-technology) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers)