Security Specialist

Cherokee Federal

Washington (District of Columbia)

On-site

USD 160,000 - 175,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Medical
Dental
Vision
401K
Other benefits

Job summary

HESFP, LLC, part of Cherokee Federal, seeks a Security Specialist to support security, assessment, and authorization of enterprise cloud environments in a regulated federal setting. You will conduct control assessments, support A&A/ATO activities, and collaborate with architects, engineers, and stakeholders to deliver secure cloud solutions powering mission-critical operations.

Required is U.S. citizenship, active TS/SCI clearance, and a minimum of seven years in information assurance or RMF.

Qualifications

  • Bachelor's degree and minimum seven years of Information Assurance, cybersecurity, RMF, or ATO experience.
  • Experience conducting security assessments utilizing NIST SP 800-53 and 800-37.
  • Experience supporting A&A/ATO activities and continuous monitoring artifacts.

Responsibilities

  • Conduct security control assessments in line with NIST SP 800-53 and 800-37.
  • Support A&A/ATO activities including SSPs and POA&Ms and gov stakeholders.
  • Perform cybersecurity vulnerability assessments of enterprise cloud environments.
  • Evaluate security requirements and recommend secure solutions.
  • Develop and maintain cybersecurity plans, policies, and procedures for compliance.
  • Collaborate with engineering and platform teams to implement security controls.
  • Support continuous monitoring, audits, and compliance reporting.
  • Assist with RMF implementation and documentation updates.
  • Review system configurations for compliance with federal requirements.
  • Support IAM initiatives, secure configurations, logging, and monitoring.
  • Document assessment findings, risk analyses, and remediation actions.
  • Participate in Agile planning and technical reviews.
  • Work with leadership to improve security processes and operations.
  • Support Salesforce and other SaaS/PaaS security implementations.

Skills

Security assessment
RMF/ATO knowledge
NIST SP 800-53
NIST SP 800-37
Cloud security basics
Documentation & communication
Security certifications (preferred)

Education

Bachelor's degree

Tools

SSP
POA&M
Security assessment tools

Job description

Security Specialist

As required by our governmental client, this position requires being a U.S. Citizen AND an active TS/SCI clearance

As our Security Specialist, you'll support the security, assessment, and authorization of enterprise cloud environments that power mission-critical operations in a regulated federal environment. You'll perform security control assessments, vulnerability evaluations, and compliance activities that strengthen the organization's cybersecurity posture while supporting Assessment & Authorization (A&A/ATO) efforts. Along the way, you'll partner closely with the Senior Security Architect, engineers, platform administrators, and program stakeholders to deliver secure, compliant cloud solutions that support the customer's mission.

Details, Compensation & Benefits

Estimated Starting Salary Range for Security Specialist: $160-175k

Pay commensurate with experience.

Full time benefits include:

  • Medical
  • Dental
  • Vision
  • 401K
  • other possible benefits as provided

Benefits are subject to change with or without notice.

Onsite 5 days a week is required. Greater Washington, DC area.

Security Specialist Responsibilities Include
  • Conduct comprehensive assessments of management, operational, and technical security controls in accordance with NIST SP 800-53 and NIST SP 800-37.
  • Support Assessment & Authorization (A&A/ATO) activities, including System Security Plans (SSPs), Plans of Action & Milestones (POA&Ms), security artifacts, and coordination with government stakeholders.
  • Perform cybersecurity vulnerability assessments of enterprise cloud applications, infrastructure, and supporting systems.
  • Analyze security requirements and recommend technical solutions that strengthen the organization's overall cybersecurity posture.
  • Develop and maintain cybersecurity plans, policies, standards, and procedures supporting federal regulatory compliance.
  • Collaborate with engineering, infrastructure, and Salesforce platform teams to implement security controls and remediate identified findings.
  • Support continuous monitoring activities, security assessments, audits, and compliance reporting throughout the system lifecycle.
  • Evaluate cloud environments using industry-standard security tools and methodologies to identify vulnerabilities and recommend corrective actions.
  • Assist with RMF implementation activities, including security control validation, documentation updates, and ongoing authorization support.
  • Review system configurations to ensure compliance with NIST, agency security policies, and federal cybersecurity requirements.
  • Support identity and access management initiatives, secure configuration management, logging, auditing, and security monitoring.
  • Document assessment findings, technical recommendations, risk analyses, and remediation activities.
  • Participate in Agile delivery activities, planning sessions, technical reviews, and documentation efforts.
  • Collaborate with program leadership and technical teams to continuously improve security processes and operational effectiveness.
  • Support enterprise cloud environments, including Salesforce and other SaaS/PaaS platforms, ensuring secure implementation and ongoing compliance.
Security Specialist Experience, Education, Skills, Abilities Requested
  • Bachelor's degree and a minimum of seven (7) years of Information Assurance, cybersecurity, RMF, or Assessment & Authorization (ATO) experience.
  • Demonstrated experience conducting security assessments utilizing NIST SP 800-53 and NIST SP 800-37.
  • Experience supporting Assessment & Authorization (A&A/ATO) activities, including development and maintenance of SSPs, POA&Ms, security assessment documentation, and continuous monitoring artifacts.
  • Experience performing cybersecurity vulnerability assessments and supporting remediation efforts within enterprise cloud environments.
  • Working knowledge of Risk Management Framework (RMF), federal cybersecurity policies, and cloud security best practices.
  • Experience supporting cloud platforms such as AWS, AWS GovCloud, Azure Government, or comparable enterprise cloud environments.
  • Experience supporting Salesforce or other SaaS/PaaS platforms, including security controls, access management, and secure platform configuration, is highly desirable.
  • Strong documentation, analytical, and communication skills developed in regulated, high-security environments.
  • Security certifications such as Security+, CySA+, CISSP, CCSP, or CISM are preferred.
  • Must be a U.S. Citizen and hold an active TS/SCI clearance.
  • Must pass pre-employment qualifications of Cherokee Federal.
Company Information

HESFP, LLC is a part of Cherokee Federal - the division of tribally owned federal contracting companies owned by Cherokee Nation Businesses. As a trusted partner for more than 60 federal clients, Cherokee Federal LLCs are focused on building a brighter future, solving complex challenges, and serving the government's mission with compassion and heart. To learn more about HESFP, visit cherokee-federal.com.

#CherokeeFederal #LI-KB1

Cherokee Federal is a military friendly employer. Veterans and active military transitioning to civilian status are encouraged to apply.

Similar searchable job titles
  • Information Assurance Analyst
  • Information System Security Officer (ISSO)
  • Cybersecurity Analyst
  • RMF Analyst
  • ATO Security Analyst
  • Cloud Security Analyst
Keywords
  • RMF
  • ATO
  • NIST SP 800-53
  • NIST SP 800-37
  • SSP
  • POA&M
  • Information Assurance
  • Cloud Security
  • Salesforce Security
  • TS/SCI
Legal Disclaimer

All qualified applicants will receive consideration for employment without regard to protected veteran status, disability or any other status protected under applicable federal, state or local law.

Many of our job openings require access to government buildings or military installations. Candidates must pass pre-employment qualifications of Cherokee Federal.

Please Note: This position is pending a contract award.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Security Specialist
Security Specialist

Hesfp, Llc • Washington

On-site
USD 160,000 - 175,000
Medical
Dental
Vision
+1
Security Architect
Security Architect

Cherokee Federal • Washington

On-site
USD 160,000 - 190,000
Medical benefits
Dental benefits
Vision benefits
+1
Security Architect
Security Architect

Hesfp, Llc • Washington, Northern (KY)

Hybrid
USD 160,000 - 190,000
Medical
Dental
Vision
+1
Cloud Security A&A Specialist — TS/SCI, US Citizen
Cloud Security A&A Specialist — TS/SCI, US Citizen

Cherokee Federal • Washington

On-site
USD 160,000 - 175,000
Medical
Dental
Vision
+2
Cybersecurity Vulnerability Management Lead
Cybersecurity Vulnerability Management Lead

Cherokee Federal • United States

On-site
USD 150,000 - 210,000
Salesforce Developer
Salesforce Developer

Hesfp, Llc • Washington

On-site
USD 140,000 - 150,000
Medical benefits
Dental benefits
Vision benefits
+1
AWS Engineer
AWS Engineer

Cherokee Federal • Almont (CO)

On-site
USD 100,000 - 140,000
Medical Insurance
Dental Insurance
Vision Insurance
+1
Cybersecurity Engineering Specialist III
Cybersecurity Engineering Specialist III

Cherokee Federal • Springfield (VA)

On-site
USD 150,000 - 155,000
Medical
Dental
Vision
+1
Cyber Security Operations Specialist (Adv. Cyber Analytics)
Cyber Security Operations Specialist (Adv. Cyber Analytics)

Cherokee Federal • St. Louis (MO)

On-site
USD 110,000 - 118,000
Medical insurance
Dental
Vision
+1
AWS Engineer
AWS Engineer

Hesfp, Llc • Northern (KY)

Hybrid
USD 100,000 - 140,000