Information Assurance Specialist III

OneZero Solutions

Arlington (VA)

On-site

USD 110,000 - 150,000

Full time

14 days+
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Benefits offered by this job

Health insurance
Dental insurance
Vision insurance
Life insurance
401(k) with company matching
Paid time off & holidays
Employee referral program
Educational assistance

Job summary

OneZero Solutions is recruiting Information Assurance Specialists to support the DSCA, delivering Risk Management Framework (RMF) and Cybersecurity Risk Management Construct (CSRMC) across ~25 systems. You will serve as ISSO, SCA-Validator, and work within a cloud-native AWS DevSecOps environment, owning authorization packages in eMASS and driving automated compliance.

This role requires on-site work at DSCA facilities in Mechanicsburg, PA or Arlington, VA, and an active SECRET clearance.

Qualifications

  • Minimum 3 years in Information Assurance with RMF execution and POA&M management.
  • Active DoD 8570/8140‑compliant certification (612/722) — Security+ CE minimum.
  • Active SECRET clearance and US citizenship at start of performance.
  • Knowledge of NIST SP 800-53 Rev 5 and RMF, FISMA, and DoD policy.

Responsibilities

  • Manage A&A packages through RMF/CSRMC lifecycle in eMASS.
  • Support A&A, ATO, and cATO accreditations and attestations.
  • Assess security controls across cloud-native and traditional services.
  • Conduct SCA/SCA-V assessments with plan execution and validation.
  • Develop RMF documentation: SSPs, SAPs, SARs, POA&M, risk assessments.
  • Leverage CaC outputs to validate compliance in eMASS.
  • Monitor CI/CD security tooling and coordinate remediation.
  • Brief stakeholders on findings, risk posture, and remediation strategy.
  • Support incident response for cloud-native systems.

Skills

RMF execution
Security control assessment
POA&M management
Continuous monitoring
NIST 800-53

Education

Bachelor's degree in IT/CS/Engineering/Cybersecurity

Tools

eMASS
AWS Security Hub
AWS Inspector
AWS Config
ACAS/Tenable Nessus

Job description

We are an employee-centric company that truly values our team members and the contributions they make to our customers and the missions they support. We pride ourselves on being forward-leaning thinkers and on building teams that are, and continue to be, technically proficient across a broad range of cyber mission areas. OneZero full-time employees receive a highly competitive benefits package, including health, dental, vision, and life insurance, a 401(k) with company matching, paid time off and holidays, an employee referral program, and educational assistance.

Additional details are available on our website: https://www.onezerollc.com/careers/

Position

Information Assurance Specialist III

Location

Mechanicsburg, PA (preferred) or Arlington, VA (DSCA HQ)

Clearance

Secret

Position Summary

OneZero Solutions is seeking Information Assurance Specialists to support the Defense Security Cooperation Agency (DSCA), the DoD agency responsible for the transfer, sale, and lease of U.S. defense articles and services to international partners. As part of the DSCA Cybersecurity Support Services program, you will deliver hands‑on Risk Management Framework (RMF) and Cybersecurity Risk Management Construct (CSRMC) support across approximately 25 systems - serving in ISSO, Security Control Assessor, and SCA-Validator capacities within a cloud-native, DevSecOps-oriented AWS environment. This is an execution role at the heart of DSCA's security posture: you will own authorization packages in eMASS, drive controls to compliance, and help move the program from manual assessment toward automated, Compliance-as-Code continuous monitoring.

Key Responsibilities
  • Manage Assessment & Authorization (A&A) packages through the RMF/CSRMC lifecycle in eMASS, maintaining the authorization package as the authoritative GRC record - control implementation details, assessment evidence, and full POA&M lifecycle from creation to closure.
  • Support achievement and maintenance of Assess and Authorize (A&A), Assess Only, and Continuous ATO (cATO) accreditations, including system categorization and control selection, tailoring, and implementation.
  • Assess security control implementation across traditional and cloud-native services (containers, serverless, service meshes, Infrastructure-as-Code) and evaluate SaaS offerings against FedRAMP and DoD Cloud Computing SRG requirements, documenting shared-responsibility and control inheritance.
  • Conduct security control assessments as SCA/SCA-V: execute Security Assessment Plans through interviews, documentation review, configuration inspection, and technical testing; independently validate automated and manual test results before findings are formalized.
  • Develop and maintain RMF documentation - SSPs, control family plans, SAPs, SARs, risk assessments, and POA&M - automating documentation and evidence collection wherever possible.
  • Leverage and interpret Compliance-as-Code (CaC) output (e.g., AWS Inspector, Security Hub, AWS Config) to validate compliance against NIST SP 800‑53 controls and DISA STIGs, and verify automated evidence is accurate and audit‑ready in eMASS.
  • Monitor security posture within CI/CD pipelines (SAST/DAST, software composition analysis, container image scanning) and coordinate remediation with development teams before deployment.
  • Perform risk analysis prioritizing vulnerabilities by mission impact; brief ISSMs, system owners, and Government stakeholders on findings, risk posture, and remediation strategy.
  • Support incident response for cloud-native systems and coordinate with the CSSP and mission partners as required.
Required Qualifications
  • Three (3) years of dedicated Information Assurance experience, with at least two (2) years consecutive, including hands‑on RMF execution, security control assessment, POA&M management, and continuous monitoring.
  • Current DoD 8570/8140‑qualifying certification appropriate to the assigned DCWF work role (612/722) - CompTIA Security+ CE minimum.
  • Active SECRET security clearance (favorably adjudicated T3 investigation) and U.S. citizenship - required at start of performance.
  • Working knowledge of NIST SP 800-53 (Rev 5), NIST SP 800-37/RMF, FISMA, and DoD cybersecurity policy (DoDI 8510.01).
  • Ability to work on site at DSCA Mechanicsburg, PA or Arlington, VA as required, including for SIPR‑designated work.
Preferred Qualifications
  • eMASS experience (package management, control records, POA&M administration).
  • Experience securing or assessing AWS environments (GovCloud, AWS-native security tooling: Security Hub, Inspector, GuardDuty, Config) and familiarity with FedRAMP and the DoD Cloud Computing SRG.
  • Exposure to DevSecOps pipelines, Infrastructure-as-Code, or Policy/Compliance-as-Code approaches to control validation.
  • Vulnerability management experience with ACAS/Tenable Nessus and DISA STIG/SCAP compliance scanning.
  • CISSP, CISM, CGRC/CAP, CySA+, or CASP+/SecurityX certification.
Technical Skills

eMASS · NIST SP 800-53/800-37 · DISA STIGs & SCAP · ACAS/Tenable Nessus · AWS security services (Security Hub, Inspector, GuardDuty, Config, CloudTrail) · POA&M management · SSP/SAP/SAR development · continuous monitoring (ISCM) · CI/CD security tooling (SAST/DAST/SCA) · Microsoft Office suite

Security Clearance

Active SECRET clearance required (temporary/interim SECRET eligibility adjudicated by DCSA AVS may be accepted). Investigation must be current within 5 years or enrolled in Continuous Evaluation. All personnel must be U.S. citizens.

Education

Bachelor's degree in Information Technology, Computer Science, Engineering, Cybersecurity, or a related technical discipline desired. Equivalent additional dedicated IA experience (two additional years) may substitute for the degree.

Work Environment

Hybrid, at Government discretion, anchored to DSCA facilities in Mechanicsburg, PA (preferred duty station - the majority of the DSCA cybersecurity team is located there) or Arlington, VA.

OneZero Solutions, LLC is an Equal Opportunity employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, age, pregnancy, genetic information, disability, status as a protected veteran, or any other protected category under applicable federal, state, and local laws.

To request an accommodation, please contact us at recruiting@onezerollc.com or call (202) 987-2580.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Information Assurance Specialist IV
Information Assurance Specialist IV

OneZero Solutions • Arlington (VA)

On-site
USD 120,000 - 150,000
Health Insurance
Dental Insurance
Vision Insurance
+5
Subject Matter Expert III - Information Systems Security Engineer
Subject Matter Expert III - Information Systems Security Engineer

OneZero Solutions • Arlington (VA)

On-site
USD 140,000 - 180,000
Health insurance
Dental insurance
Vision insurance
+5
Info Assurance Specialist III: RMF & Cloud Security Lead
Info Assurance Specialist III: RMF & Cloud Security Lead

OneZero Solutions • Arlington (VA)

Hybrid
USD 110,000 - 150,000
Health insurance
Dental insurance
Vision insurance
+5
Cybersecurity SME Level II
Cybersecurity SME Level II

OneZero Solutions • Alexandria (VA)

On-site
USD 120,000 - 150,000
Health insurance
Dental insurance
Vision insurance
+6
Security Control Assessor (SME), Level III
Security Control Assessor (SME), Level III

OneZero Solutions • Baltimore (MD)

On-site
USD 120,000 - 180,000
Health insurance
401(k) with company matching
Paid time off
Information System Security Officer (SME), Level III
Information System Security Officer (SME), Level III

OneZero Solutions • Baltimore (MD)

On-site
USD 120,000 - 160,000
Health insurance
Dental insurance
Vision insurance
+5
Cybersecurity SME Level III
Cybersecurity SME Level III

OneZero Solutions • Alexandria (VA)

On-site
USD 120,000 - 180,000
Health insurance
Dental insurance
Vision insurance
+5
DHS Information Systems Security Officer (ISSO) Senior
DHS Information Systems Security Officer (ISSO) Senior

OneZero Solutions • Washington

On-site
USD 120,000 - 150,000
Health insurance
401K with company matching
PTO & paid holidays
+2
Program Manager III
Program Manager III

OneZero Solutions • Arlington (VA)

On-site
USD 120,000 - 180,000
Health insurance
Dental
Vision
+6
DHS Program Manager, Cybersecurity
DHS Program Manager, Cybersecurity

OneZero Solutions • Washington

On-site
USD 120,000 - 160,000
Health/dental/vision insurance
401K with company matching
Paid time off & paid holidays