Business Technology Integrators (BTI) is a Service-Disabled Veteran-Owned Small Business (SDVOSB) with more than 25 years of experience delivering innovative and reliable IT and engineering solutions to the Federal Government. BTI supports mission-critical programs across defense and civilian agencies, with core expertise in cybersecurity, program management, enterprise IT, and technical oversight services.
Roles and Responsibilities:
- The Security Specialist supports the establishment, operation, and continuous monitoring of the system's security posture in accordance with NIST SP 800-53 (Moderate baseline), FISMA, and FedRAMP requirements.
- This role contributes to the development and maintenance of the System Security Plan (SSP), Security Assessment Report (SAR), Plan of Action and Milestones (POA&M) tracking, and contingency and incident response planning.
- The Security Specialist integrates security scanning (SAST, DAST, IAST) into the CI/CD pipeline, reviews scan results, and coordinates remediation of vulnerabilities in accordance with CISA and DOL remediation timelines.
- This role supports penetration testing activities, documents findings and mitigations, and verifies that critical and high vulnerabilities are resolved prior to production deployment.
- The Security Specialist supports protection of Federal Tax Information (FTI) and other sensitive data in accordance with IRS Publication 1075, including FIPS-validated encryption at rest and in transit, access control enforcement, and audit logging.
- This role also supports breach notification procedures, continuous monitoring tooling, and logging practices consistent with OMB M-21-31 and participates in annual contingency and incident response testing.
- The Security Specialist coordinates with development, infrastructure, and AI enablement teams to ensure that new features, environments, and AI-based tools (including chatbots and automated resolution systems) are assessed for security risk, comply with applicable controls, and do not expose non-public Government data without proper authorization.
Experience/Qualifications
- Undergraduate degree from an accredited college or university in Cybersecurity, Computer Science, Information Systems, or a related field.
- Relevant security certifications such as CISSP, CISM, Certified Cloud Security Professional or equivalent.
- At least 8 years of experience in information security, including experience supporting FISMA/FedRAMP authorization activities for Federal information systems.
- Demonstrated experience developing or maintaining System Security Plans (SSPs), Security Assessment Reports (SARs), and POA&M tracking in accordance with NIST SP 800-53.
- Experience integrating security scanning tools (SAST, DAST, IAST) into DevSecOps CI/CD pipelines and triaging scan results and technologies such as Tenable, Trend Micro, AWS Security Tools, Security Hub / Guard Duty & Snyk.io.
- Experience supporting or coordinating penetration testing engagements, including documentation of findings, risk ratings, and remediation verification.
- Experience protecting Federal Tax Information (FTI) or comparably sensitive data in accordance with IRS Publication 1075 or similar regulatory frameworks, including encryption, access control, and audit logging requirements.
- Experience with continuous monitoring tooling, security logging standards (e.g., OMB M-21-31), and incident response/contingency planning and testing.
- Familiarity with cloud security in AWS environments, including security group configuration, IAM policies, and hardened multi-environment architectures (e.g., PROD, DEV, TEST, CAT, DR).
- Experience assessing security and data-handling risk for AI-based tools and automation, including reviewing AI Enablement Plans and ensuring AI tools do not expose non-public Government data without written authorization.
- Strong written communication skills, with demonstrated ability to produce clear security documentation and present findings to technical and non-technical stakeholders.