Information Assurance Specialist IV
On-siteArlington, Virginia, United States
Job Summary
Serve as Information System Security Officer for assigned DSCA IM&T portfolio systems, ensuring confidentiality, integrity, and availability of data. Lead operationalization of the RMF/Cybersecurity Risk Management Construct within a cloud-native, DevSecOps framework, automating security control implementation and evidence collection to achieve A&A and continuous ATO accreditations. Proactively identify and mitigate security weaknesses while developing Security Assessment Plans and conducting ongoing control assessments beyond periodic checks. Provide actionable risk analysis, validate Policy-as-Code scripts, and maintain accurate eMASS records documenting all findings. Prepare Security Authorization Packages, brief stakeholders on residual risk, and support POA&M development with written mitigation recommendations.
Required Qualifications
- Bachelor's degree from an accredited institution in Information Technology, Computer Science, Engineering, or a related technical discipline
- Current DoW 8570/8140 certification meeting the IAM Level II or IAT Level II baseline requirement (e.g., CISSP, Security+ CE, CISM, CASP+ CE)
- Five (5) years of dedicated Information Assurance experience, with at least three (3) of those years being consecutive
- Three (3) consecutive years directly relevant to the tasks above, demonstrating a hands-on understanding of the DoW cybersecurity environment
- Active Secret clearance
- U.S. citizenship
- Expert knowledge of RMF, NIST SP 800-53, DISA STIGs, and the Cybersecurity Risk Management Construct (CSRMC)
- Master-level proficiency in eMASS as the authoritative system of record for assessment and authorization data
- Familiarity with FedRAMP, DoW Impact Levels, and the DoW Cloud Computing Security Requirements Guide (CCSRG)
- Hands-on experience securing AWS cloud-native architectures and authorized SaaS solutions
- Ability to review and validate Compliance-as-Code (CaC) and Policy-as-Code (PaC) profiles, scripts, and automated compliance evidence
- Skill in risk analysis, POA&M development, and drafting decision-quality authorization documentation (SAP, SAR, Authorization Recommendation Memo)
- Clear, no-surprises reporting and effective collaboration with system owners, ISSMs
Hiring someone like this?
Get your role in front of qualified candidates on Sorce.