OneZero Solutions logo
OneZero SolutionsPosted 1 week ago

Information Assurance Specialist IV

On-siteArlington, Virginia, United States

Full TimeSenior LevelBachelors DegreeSmall

Job Summary

Serve as Information System Security Officer for assigned DSCA IM&T portfolio systems, ensuring confidentiality, integrity, and availability of data. Lead operationalization of the RMF/Cybersecurity Risk Management Construct within a cloud-native, DevSecOps framework, automating security control implementation and evidence collection to achieve A&A and continuous ATO accreditations. Proactively identify and mitigate security weaknesses while developing Security Assessment Plans and conducting ongoing control assessments beyond periodic checks. Provide actionable risk analysis, validate Policy-as-Code scripts, and maintain accurate eMASS records documenting all findings. Prepare Security Authorization Packages, brief stakeholders on residual risk, and support POA&M development with written mitigation recommendations.

Required Qualifications

  • Bachelor's degree from an accredited institution in Information Technology, Computer Science, Engineering, or a related technical discipline
  • Current DoW 8570/8140 certification meeting the IAM Level II or IAT Level II baseline requirement (e.g., CISSP, Security+ CE, CISM, CASP+ CE)
  • Five (5) years of dedicated Information Assurance experience, with at least three (3) of those years being consecutive
  • Three (3) consecutive years directly relevant to the tasks above, demonstrating a hands-on understanding of the DoW cybersecurity environment
  • Active Secret clearance
  • U.S. citizenship
  • Expert knowledge of RMF, NIST SP 800-53, DISA STIGs, and the Cybersecurity Risk Management Construct (CSRMC)
  • Master-level proficiency in eMASS as the authoritative system of record for assessment and authorization data
  • Familiarity with FedRAMP, DoW Impact Levels, and the DoW Cloud Computing Security Requirements Guide (CCSRG)
  • Hands-on experience securing AWS cloud-native architectures and authorized SaaS solutions
  • Ability to review and validate Compliance-as-Code (CaC) and Policy-as-Code (PaC) profiles, scripts, and automated compliance evidence
  • Skill in risk analysis, POA&M development, and drafting decision-quality authorization documentation (SAP, SAR, Authorization Recommendation Memo)
  • Clear, no-surprises reporting and effective collaboration with system owners, ISSMs

Hiring someone like this?

Get your role in front of qualified candidates on Sorce.

Get started

Apply to this job in one click with Sorce

Apply on Sorce