Sr. Information Assurance Specialist

NR Labs LLC

Washington, Northern (District of Columbia, KY)

Hybrid

USD 140,000 - 190,000

Full time

13 hours ago
Be an early applicant
Application generator

Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.

Get past ATS filters

Job summary

NR Labs LLC is seeking a Senior Information Assurance Specialist to lead RMF execution, ATO management, and IA governance for a federal modernization program. You will oversee System Security Plans, Security Assessment Reports, POA&Ms, and ATO packages, coordinating with automation engineers to implement PaC across AWS GovCloud, Azure Government, and GCP.

You will interact with Authorizing Officials and agency leadership on IA strategy and risk posture, while mentoring junior IA staff and

Qualifications

  • Bachelor’s degree from an accredited IT/CS/Engineering program.
  • Current DoD 8570 / 8140 IAM Level II or higher baseline certification.
  • Five years of dedicated Information Assurance experience, with at least three consecutive years.
  • RMF authorization and ATO experience in DoD or federal environments.
  • Knowledge of NIST SP 800-53, RMF, DoDI 8510.01, DISA STIGs, and cloud baselines.
  • Experience supervising junior IA staff and interfacing with officials on risk decisions.

Responsibilities

  • Lead security risk assessments across agency networks, systems, apps, and emerging tech.
  • Develop, test, and operate enterprise security tooling across cloud and legacy environments.
  • Plan RMF authorization efforts: System Security Plans, assessment reports, POA&Ms, and ATO packages.
  • Act as technical authority across multiple project lines and mentor junior IA staff.
  • Translate security requirements into automated, version-controlled compliance checks (PaC).
  • Oversee continuous monitoring outputs from multiple cloud services and ensure remediation per risk tolerance.
  • Interface with AOs, ISSMs, and leadership on IA strategy and ATO posture.

Skills

Information Assurance
RMF expertise
Policy-as-Code

Education

Bachelor’s degree in IT/CS/Engineering

Tools

AWS GovCloud
Azure Government
GCP

Job description

The candidate will serve as a senior Information Assurance Specialist responsible for leading Risk Management Framework (RMF) execution, Authority to Operate (ATO) management, and Information Assurance governance across a federal cybersecurity modernization program. They will plan and lead major IA work assignments across a multi-cloud General Support System (GSS) spanning AWS GovCloud, Azure Government Community Cloud (GCC), Google Cloud Platform (GCP), and centralized cloud administration, functioning as the technical authority across multiple project lines and supervising junior IA personnel.

The ideal candidate will champion the program's transition from manual, document-driven compliance to engineering-driven Governance, Risk, and Compliance (GRC). They will own the strategy and quality of System Security Plans, Security Assessment Reports, POA&Ms, and ATO packages, and partner with automation engineers to translate security requirements into machine-readable code aligned with DoDI 8510.01 (RMF), NIST SP 800-53, and DISA STIGs.

They will interface directly with Authorizing Officials (AOs), Information System Security Managers (ISSMs), and agency leadership on IA strategy, ATO posture, and risk acceptance decisions, ensuring continuous monitoring outputs from AWS Security Hub, Microsoft Defender for Cloud, and GCP Security Command Center are correlated, prioritized, and remediated in accordance with agency risk tolerance.

Role Responsibilities:
  • Lead the identification and assessment of security risks, threats, and vulnerabilities across agency networks, systems, applications, and emerging technology initiatives.
  • Direct the development, testing, and operation of enterprise security tooling - including firewalls, intrusion detection systems, anti-virus platforms, and software deployment systems - across cloud and legacy environments.
  • Plan and lead RMF authorization efforts: own the strategy and quality of System Security Plans, Security Assessment Reports, POA&Ms, and ATO packages.
  • Function as the technical expert across multiple project assignments, evaluating performance results and recommending changes affecting short-term project growth and long-term IA posture.
  • Translate agency security requirements into automated, version-controlled compliance checks aligned with DoDI 8510.01 (RMF), NIST SP 800-53, and DISA STIGs, partnering with automation engineers on Policy-as-Code (PaC) implementation.
  • Oversee continuous monitoring outputs from AWS Security Hub, Microsoft Defender for Cloud, GCP Security Command Center, and other DoD-approved services; ensure findings are correlated, prioritized, and remediated in accordance with agency risk tolerance.
  • Apply current IA policy, tactics, techniques, and doctrine to agency reporting requirements; support the development and implementation of IA doctrine and policies.
  • Interface with Authorizing Officials, ISSMs, and agency leadership on IA strategy, ATO posture, and risk acceptance decisions.
  • Mentor and supervise junior IA personnel; contribute to governance meetings, stakeholder workshops, and workforce training that sustain enterprise adoption of automated controls and achieve cross-training of at least 90% of the agency GRC team within 12 months.
Required Education & Qualifications:
  • Bachelor’s degree from an accredited institution in Information Technology, Computer Science, Engineering or related technical discipline
  • Current DoD 8570 / 8140 IAM Level II or higher baseline certification (CISSP, Security+ CE, CISM, CASP+CE, or equivalent).
  • Five (5) years of dedicated Information Assurance experience, with at least three (3) of those being consecutive.
  • Required three (3) consecutive years of experience relevant to the tasks and demonstrating recent (within the last year) hands‑on understanding of the DoW cybersecurity environment.
  • Demonstrated experience leading RMF authorization activities and ATO efforts in DoD or federal environments.
  • Comprehensive knowledge of NIST SP 800-53, NIST RMF, DoDI 8510.01, DISA STIGs, and DoD-approved cloud security baselines.
  • Experience supervising junior IA staff and serving as a technical authority across concurrent project lines.
  • Experience interfacing with Authorizing Officials, ISSMs, and senior government stakeholders on risk and ATO decisions.
  • Experience producing high-quality, technically accurate IA artifacts that support enterprise security and privacy objectives.
Desired Skills:
  • Experience supporting Authorizations to Operate for cloud and hybrid environments using NIST RMF and DoD-specific baselines.
  • Experience implementing Policy-as-Code (PaC) frameworks to automate control enforcement, compliance validation, and security evidence collection.
  • Familiarity with multi-cloud architectures spanning AWS GovCloud, Azure Government, and Google Cloud Platform.
  • Familiarity with Open Security Controls Assessment Language (OSCAL) and machine-readable representation of control catalogs and assessment results.
  • Experience introducing automation, engineering practices, and innovation into GRC programs to improve efficiency and reduce manual work.
Clearance and Location Requirements:
  • Active U.S. Security Clearance is required.
  • This hybrid role requires onsite work at a Department of Defense (DoD) facility.
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Information Assurance Engineer
Information Assurance Engineer

Agile IT Synergy, LLC • Tampa (FL)

On-site
USD 90,000 - 130,000
Senior Information Assurance Engineer
Senior Information Assurance Engineer

Expression Networks • Fort Meade (MD)

On-site
USD 110,000 - 155,000
401k matching
Medical/dental/vision insurance
Education reimbursement
+4
Sr. Cybersecurity Automation Architect / SME
Sr. Cybersecurity Automation Architect / SME

NR Labs LLC • Washington, Northern (KY)

Hybrid
USD 140,000 - 190,000
Information System Security Officer Sr. (Cloud)
Information System Security Officer Sr. (Cloud)

ECS • Washington

On-site
USD 120,000 - 150,000
Cybersecurity Specialist
Cybersecurity Specialist

Career Listings • Fort Belvoir (VA)

On-site
USD 110,000 - 170,000
401(k)
401(k) matching
Dental insurance
+6
Information Assurance Specialist I (Information Security Analyst)
Information Assurance Specialist I (Information Security Analyst)

By Light Professional IT Services • Butlerville (IN)

On-site
USD 70,000 - 90,000
Information System Security Officer (ISSO) – TS/SCI
Information System Security Officer (ISSO) – TS/SCI

Strategic Business Systems (SBS) • Herndon (VA)

On-site
USD 140,000 - 190,000
Medical, dental, vision coverage
401(k) retirement plan with company匹配
Paid time off and holidays
+2
Information Security Analyst
Information Security Analyst

Caliber Systems Inc. • Washington, Northern (KY)

Hybrid
USD 89,000 - 110,000
Senior Security Engineer
Senior Security Engineer

Inadev-Corporatio • Reston (VA)

Hybrid
USD 120,000 - 160,000
Information Assurance Security Engineer
Information Assurance Security Engineer

Jobtailor • Town of Montana (WI)

On-site
USD 100,000 - 160,000