Senior Information Security Specialist
Ashburn, IL - USA
Job Summary
AWS Security RMF & ATO NIST 800-53 Cloud Application Security
Clearance: Active CBP DHS or Top Secret Clearance required
Work Arrangement: Hybrid onsite 3 days/week during standard business hours in Ashburn VA
Dev Technology Group is seeking a Senior Information Security Specialistto lead and develop a mid-sized team of ISSOs supporting the security compliance and authorization of mission-critical federal applications and information systems hosted in AWS.
This is a hands-on technical leadership role combining people leadership federal cybersecurity expertise and direct collaboration with government and technical stakeholders. You will mentor junior and mid-level ISSOs while partnering with system owners developers architects cloud/infrastructure engineers security professionals and government stakeholders throughout the system development lifecycle.
You will provide practical security guidance for AWS-hosted applications lead Risk Management Framework (RMF) and Authority to Operate (ATO) activities oversee vulnerability management and continuous monitoring and translate federal cybersecurity requirements into actionable guidance for technical teams.
- Lead mentor and develop a team of ISSOs by establishing priorities providing technical direction and coaching and promoting accountability and consistent security practices.
- Lead and overseeRMF ATO security authorization compliance vulnerability management and continuous monitoring activities across a portfolio of federal systems and applications.
- Partner with ISSMs system owners assessors developers architects engineers and government stakeholders to maintain authorizations identify risks and address security requirements.
- Lead vulnerability management efforts prioritizing remediation developing mitigation strategies and tracking corrective actions through resolution.
- Develop assess document and support implementation of security controls aligned withFISMA NIST 800-53 DHS and client requirements.
- Prepare and maintain security and authorization documentation includingSSPs ISAs audit artifacts and RMF documentation.
- Provide cybersecurity guidance for applications and systems deployed inAWS and integrate security throughout the software development lifecycle.
- Validate security implementation through technical reviews discussions interviews assessments and tabletop exercises.
- Support security audits assessments compliance reviews and reviews of information systems and network connections.
- Interpret federal and client security policies and translate requirements into practical guidance for technical and development teams.
- Identify and escalate security risks communicate priorities and remediation status and provide clear visibility to Dev Technology leadership and government stakeholders.
- Develop and presentsecurity metrics status reports risk assessments and executive briefings.
- Establish and improve security processes procedures templates dashboards and workflows to improve consistency accountability and efficiency across the ISSO team.
- Build trusted relationships with government clients through proactive communication collaboration and face-to-face engagement.
- Bachelors degree and 7 years of experience securing federal information systems.
- Demonstrated experienceleading and mentoring information security professionals including junior and mid-level ISSOs.
- Experience leading cybersecurity activities in afederal government client environment and working directly with government stakeholders.
- Strong working knowledge ofNIST Risk Management Framework (RMF) and experience supporting federal systems through security authorization and ATO activities.
- Experience developing implementing assessing or documenting security controls aligned withFISMA and NIST 800-53.
- Experience withvulnerability management continuous monitoring security assessments audits or compliance reviews for federal systems.
- Experience providing cybersecurity guidance forAWS-hosted applications and systems.
- Strong understanding of modern information systems and their technical security considerations.
- Ability to work effectively with developers architects engineers government stakeholders and technical and non-technical audiences.
- Strong written and verbal communication skills including the ability to communicate security risks and technical findings and develop/present security documentation and executive briefings.
- Ability to establish priorities manage competing demands independently manage security activities and escalate issues appropriately.
- Proactive solutions-oriented approach to identifying risks and improving security practices.
- Current CBP DHS or Top Secret Clearance.
- Ability to workonsite 3 days per week in Ashburn VA during standard business hours.
- Cybersecurity certification such asCISSP CISM GIAC Security or another recognized cybersecurity certification.
- Experience developing or supporting RMF and authorization artifacts including SSPs ISAs PTAs ATTs POA&Ms and related documentation.
- Experience partnering withapplication development cloud engineering and DevSecOps teams to integrate security throughout the SDLC.
- Experience working in anAgile software development environment using Jira or similar platforms.
- Experience withGRC tools such as CSAM or similar platforms supporting authorization compliance vulnerability management and security activities.
- Understanding ofAI concepts and practical applications of AI for cybersecurity operations risk analysis compliance or security program management.
Our estimated salary range for this position is $88000 - $ 150000. This presented salary range is not a guarantee of compensation or salary. Offered salary is based on experience geographic location and possibly contractual requirements as appropriate to the role. *Salary could fall outside of this range.
Dev Technology is a growing IT company with an employee-centric culture that works on mission-critical projects for the federal government. We partner with our federal customers to deliver technology services and solutions and to drive our clients missions forward through innovation. We use Agile and DevSecOpsprinciples to provide services including application development biometrics and identity management cloud and infrastructure optimization IT and legacy modernization and data management.
As a Washington Post Top Workplace award winner for the past THIRTEEN years in a row the Top Workplaces USA for the past five years and a recipient of the Companies As Responsive Employers (CARE) Award for the past six years Dev Technology employees enjoy:
- Generous and flexible time-off policy
- Flexible work schedules and telework options including remote work availability for eligible projects
- Career development opportunities including a mentorship program technical and management training through Dev University hands-on learning through DevLab tuition reimbursement and paid training opportunities
- Industry-leading benefits including a choice of two health plans that include dental and vision flexible spending account commuter benefits life insurance and more
- 401K matching with a 5% matching contribution
- Regular team and company social events including our annual party happy hours fitness challenges and more
- A focus on community engagement including company wide support activities employer match for donations and time off for volunteer efforts
- To learn more about working at Dev Technology visit Working At Dev Technology Group
Equal Opportunity Employer / Individuals with Disabilities / Protected Veterans
Dev Technology Group operates in the following states: AL AR AZ CO DC FL GA ID IL IN MD MA ME MI MN MO MS NC NJ OH OR PA SC TN TX VA WV.
Required Experience:
Senior IC