Information Assurance Engineer w/ Top Secret Clearance

A3 Consulting Llc
Springfield, United States of America
yesterday

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Working hours
Regular working hours
Languages
English
Experience level
Senior
Compensation
$ 180K

Job location

Springfield, United States of America

Tech stack

Xacta
Agile Methodologies
Configuration Management
Computer Security
Custom Software
Firmware
Identity and Access Management
Information Security Management
Systems Development Life Cycle
Zero Trust Network Access
Software Engineering
Information Security Management System
Information Technology
Nessus
Plan of Action and Milestones
Vulnerability Analysis

Job description

A3 Consulting is seeking a talented Information Assurance Engineer to join our innovative team supporting our Defense-based customer. If you enjoy being the primary authority responsible for managing and maintaining the Assessment and Authorization (A&A) process, operating across SIPRNet and JWICS environments, and ensuring National Security Systems maintain a rigorous and compliant security posture, this role is for you! In this job you will:

  • Function as the team's IA and Cybersecurity expert, owning the RMF process from start to finish within a fast-paced Agile environment.
  • Provide dedicated Information Assurance (IA) / Information Systems Security Engineer (ISSE) support to accomplish and maintain a Continuous Authority to Operate (ATO) for a critical defense based system.
  • Manage, contribute to, and continuously update RMF packages within XACTA by working closely with existing Information System Security Officers (ISSOs), the Development Team, and other stakeholders.
  • Create all necessary accreditation documentation for full ATO submission, including developing and maintaining the System Security Plan (SSP) and other documentation within the Body of Evidence (BoE).
  • Ensure that Configuration Management (CM) for all security-related software, hardware, and firmware is strictly maintained and documented.
  • Analyze vulnerability scan results and remediation efforts.
  • Support assessments, security patching, and maintain compliance with all applicable policies, directives, and best practices.
  • Address relevant security controls utilizing CNSSI 1253 overlays and NIST SP 800-53.
  • Ensure all unmet controls and identified vulnerabilities are addressed and accurately tracked within a Plan of Actions and Milestones (POA&M) to enable full ATO.
  • Ensure system compliance with DISA Security Technical Implementation Guides (STIGs), Information Assurance Vulnerability Alerts (IAVAs), and the DoD Zero Trust Strategy.
  • Report all security-related incidents to the Information Systems Security Manager (ISSM) and initiate protective or corrective measures upon vulnerability discovery.
  • Conduct periodic self-assessments, scans, and tests to identify vulnerabilities.
  • Support assessments and Independent Validation and Verification (IV&V) testing as needed/as required.
  • Support testing exercises (i.e. User, Regression, Smoke, and IV&V Testing) throughout the Software Development Lifecycle (SDLC) to ensure security enhancements and vulnerability patches do not compromise application functionality and performance.
  • Document software defects, bugs, and other issues identified during test exercises.
  • Troubleshoot and resolve issues identified.
  • Collaborate with cross-functional teams, including product managers, developers, and Government stakeholders, to seamlessly implement security requirements into the Agile backlog.
  • Provide expert-level technical assistance, diagnose complex security issues, and conduct root cause analyses for production environments.

Requirements

  • Bachelor's degree in Computer Science, Information Technology, Cybersecurity, or a Related Field.
  • Certification (DoD 8570/8140): IAT/IAM Level II Certification Required
  • 5+ years of experience in Cybersecurity/Information Assurance, with a proven track record of supporting software development in the DoD.
  • Demonstrated proficiency with the DoD Risk Management Framework (RMF) process, CNSSI 1253 control selection, and maintaining Bodies of Evidence (BoE).
  • Comprehensive understanding of DoD policies, directives, and initiatives as they relate to custom application development, including DISA STIGs and Section 508 Compliance.

Desired Qualifications:

  • Direct experience managing packages in XACTA (or similar systems like eMASS) and analyzing scans from Nessus, Tenable, or Retina.
  • Excellent communication and collaboration skills, with the ability to effectively articulate technical concepts, receive feedback, and work collaboratively in a cross-functional Agile team environment.

Security Clearance:

  • Active DoD Top Secret clearance with SCI eligibility required

Benefits & conditions

  • The salary range of this position is $160,000 - $180,000 commensurate with experience and achievement.

Benefit Information:

  • A3 Consulting offers a robust benefits package to include but not limited to medical, dental, and vision benefits, flexible spending and health savings accounts, group life and AD&D, short-term and long-term disability, paid time off, 401k match, paid parental leave, professional development.

A3 Consulting, LLC is an equal opportunity employer. We believe in hiring a diverse workforce and sustaining an inclusive, people-first culture. We are committed to non-discrimination on any protected basis, such as disability and veteran status, or any other basis covered under applicable law.

Equal employment opportunity, including veterans and individuals with disabilities., $160.00

Apply for this position