The Office of the Chief Information Officer (OCIO) advances the Department of Energy’s (DOE) mission by establishing and implementing policies, standards, and services that meet mission requirements, balance risk and innovation, and define clear performance expectations across the enterprise information ecosystem. The OCIO is committed to continuously improving information technology (IT) services and strengthening the Department’s cybersecurity posture to enable mission execution while ensuring responsible stewardship of taxpayer dollars through efficient, effective, and innovative management practices.
The A&A Specialist III (Mid-Level) supports this mission by conducting comprehensive assessments of security and privacy controls, identifying risks, and recommending corrective actions to ensure DOE systems meet all required cybersecurity and privacy standards.
- Conduct comprehensive assessments of implemented security and privacy controls and control enhancements to determine effectiveness, including whether controls are implemented correctly, operating as intended, and producing desired outcomes.
- Evaluate and document the severity of deficiencies identified during assessments and recommend appropriate corrective actions to mitigate vulnerabilities.
- Prepare detailed security and privacy assessment reports outlining results, findings, and recommendations, and deliver these to Team Leaders for review and decision-making.
- Assess controls in accordance with assessment procedures defined in approved assessment plans.
- Conduct initial remediation actions on deficient controls and perform reassessments on remediated controls to validate effectiveness.
- Assess both system-specific and inherited controls as part of the Department’s continuous monitoring strategy.
- Apply comprehensive knowledge to multiple complex assignments and contribute to deliverables and performance metrics as required.
- Bachelor’s Degree or four (4) years of equivalent professional experience.
- Minimum of 5–7 years of relevant experience conducting security control assessments, cybersecurity evaluations, or similar technical security work.
- Demonstrated experience assessing security and privacy controls aligned with federal cybersecurity frameworks (e.g., NIST RMF, NIST SP 800-53).
- Ability to analyze technical documentation, identify security gaps, and communicate findings clearly in written reports.
- Strong understanding of continuous monitoring processes and system inheritance concepts.
- Ability to work independently and collaboratively on complex assignments requiring sound judgment and comprehensive technical knowledge.
- Ability to obtain Top Secret Clearance.
This position is contingent upon contract award and funding. Applicants selected may be offered the position; however, they cannot begin work until the contract has been awarded and funding has been confirmed.
Benefits InformationRegular - The company offers a comprehensive benefits program, including medical, dental, vision, life insurance, 401(k) and a range of other voluntary benefits. Paid Time Off (PTO) is offered to regular full-time and part-time employees.
Pay Range$120,000 - $165,000
Job ID2026-25517
Work TypeRemote