American Systems logo
American SystemsPosted 2 months ago
EXPIRED

Information Assurance Engineer II

$90,000–$90,000 year

On-siteSan Diego, California, United States

Full TimeBachelors DegreeLarge

Job Summary

Conduct full Risk Management Framework (RMF) lifecycle support for assigned systems, including development, update, and maintenance of security documentation to obtain and sustain Authority to Operate (ATO). Prepare and maintain artifacts such as System Security Plans, POA&Ms, and control evidence within eMASS repositories while validating DISA STIGs and Security Requirements Guides across infrastructure and applications. Execute vulnerability management activities by analyzing scan results from tools like ACAS/Nessus, tracking findings through POA&M management, and coordinating remediation efforts. Implement continuous monitoring strategies to verify system compliance and support security auditing, assessment activities, and external inspections. Review audit logs and security events to identify anomalies, coordinate with technical teams to resolve compliance discrepancies, and provide guidance to stakeholders on cybersecurity best practices.

Required Qualifications

  • Bachelor's degree in Cybersecurity, Information Technology, Information Assurance, Computer Science, or a related field
  • Active Secret Clearance Required
  • 5+ years of relevant experience in information assurance, cybersecurity, RMF, compliance, or a related field
  • Demonstrated experience supporting the RMF process and preparing or maintaining ATO packages
  • Experience working with eMASS or similar compliance/documentation repositories
  • Knowledge of DISA STIGs, SRGs, and security compliance practices across infrastructure and application environments
  • Experience with vulnerability scanning and analysis tools such as ACAS/Nessus
  • Familiarity with POA&M management, remediation tracking, and continuous monitoring practices
  • Experience supporting security assessments, audit readiness, and control validation activities
  • Strong understanding of cybersecurity principles, risk management, and regulatory compliance requirements
  • Ability to analyze complex security requirements and apply them across enterprise and specialized systems

Hiring someone like this?

Get your role in front of qualified candidates on Sorce.

Get started

Apply to this job in one click with Sorce

Find similar roles