Information System Security Specialist III

DirectViz Solutions, LLC

$90K — $120K *
Information Technology
5 - 7 years of experience
Job Overview by Ladders

Qualifications

  • 5+ years of experience with Risk Management Framework (RMF) activities.
  • Experience with Security Technical Implementation Guide (STIG) assessments and SCAP benchmarks.
  • Hands-on vulnerability assessment expertise with Assured Compliance Assessment Solution (ACAS).
  • Familiarity with Enterprise Mission Assurance Support Service (eMASS) documentation and processes.
  • Experience developing and managing Plans of Action and Milestones (POA&M).
  • Completion of RMF Step 5 authorization activities in an Information System Security Engineer (ISSE) capacity.
  • Strong communication skills to present cybersecurity information clearly to varied audiences.

Responsibilities

  • Support RMF activities for DoD information systems.
  • Perform STIG assessments using compliance validation tools.
  • Conduct vulnerability assessments leveraging ACAS.
  • Manage RMF documentation and activities in eMASS.
  • Develop and maintain POA&M entries.
  • Assist in RMF Step 5 authorization activities in an ISSE role.
  • Analyze cybersecurity risks and recommend mitigation strategies.

Benefits

  • Collaborative work environment with a focus on complex problem-solving.
  • Opportunities to impact critical Department of Defense systems.
  • Possibility for career advancement in the cybersecurity field.
Full Job Description
Information System Security Specialist III

If you are passionate about cybersecurity, risk management, and protecting mission-critical systems, this is an opportunity to join a dynamic team supporting complex Department of Defense environments. We are seeking an experienced Information System Security Specialist III to support Risk Management Framework (RMF) activities, vulnerability management, compliance initiatives, and security authorization efforts across enterprise systems.

Key Responsibilities
  • Support and execute Risk Management Framework (RMF) activities for DoD information systems.
  • Perform Security Technical Implementation Guide (STIG) assessments using SCAP benchmarks and other compliance validation tools.
  • Conduct vulnerability assessments utilizing Assured Compliance Assessment Solution (ACAS).
  • Manage and maintain RMF documentation and activities within eMASS.
  • Develop, track, and maintain Plans of Action and Milestones (POA&M) entries.
  • Support RMF Step 5 authorization activities while functioning in an Information System Security Engineer (ISSE) capacity.
  • Analyze cybersecurity risks and provide mitigation and risk reduction recommendations to stakeholders and leadership.
  • Collaborate with engineers, system administrators, and cybersecurity teams to ensure systems remain compliant with DoD cybersecurity requirements and security controls.
  • Assist with continuous monitoring, security posture assessments, and remediation efforts.

Required Qualifications
  • Minimum of five (5) years of experience performing Risk Management Framework (RMF) activities.
  • Demonstrated experience performing STIG assessments, including the use of SCAP benchmarks.
  • Hands-on experience conducting vulnerability assessments using ACAS.
  • Experience utilizing Enterprise Mission Assurance Support Service (eMASS).
  • Experience developing and managing POA&M entries.
  • Experience completing RMF Step 5 authorization activities in an ISSE capacity.
  • Strong communication skills with the ability to present cybersecurity risks and remediation recommendations to technical and non-technical stakeholders.

Certifications & Clearance Requirements
  • Minimum certification as 461 (or equivalent as required by the applicable Technical Instruction) at the Intermediate level in accordance with DoDD 8140.01 or successor policy.
  • Must maintain a final adjudicated Tier 5 security investigation with an IT Level I designation in JPAS and/or DISS for all Privileged User responsibilities.
  • Active Secret Clearance required; Top Secret eligibility may be required depending on program needs.
  • U.S. Citizenship required.

Preferred Skills
  • Familiarity with NIST RMF, NIST SP 800-53, and DoD cybersecurity compliance standards.
  • Experience supporting security authorization packages within DoD environments.
  • Knowledge of vulnerability remediation processes and continuous monitoring practices.
  • Ability to work independently while supporting cross-functional technical teams.

Work Location: Viriginia Beach VA

If you thrive on solving complex problems and building meaningful connections, we'd love to hear from you. Join our team and make an impact today!

Physical and Mental Qualifications:
  • Maintain focus and awareness throughout scheduled working hours.
  • Perform tasks requiring prolonged periods of sitting or standing at a desk, utilizing a computer, mouse, and keyboard.
  • Lift and move objects weighing up to 15 pounds as needed.
  • Exhibit excellent verbal and written communication skills, with a strong command of the English language.
  • Demonstrate the ability to work independently while also collaborating effectively as part of a team.
  • Quickly learn and retain routine tasks and processes.
  • Possess strong organizational skills, attention to detail, business correspondence proficiency, and self-management capabilities.
  • Perform the essential functions of the role satisfactorily; reasonable accommodation will be provided for employees with disabilities upon request.
  • Accept and adapt to additional responsibilities or changes to assigned duties as determined by DirectViz Solutions (DVS).

Similar Jobs

More Jobs at DirectViz Solutions, LLC

More Information Technology Jobs

Find similar Information System Security Specialist III jobs: