Sr. Information Assurance Security Specialist

Synergy BIS

$84K — $120K *
US-AnywhereRemote in United States
Information Technology
5 - 7 years of experience
Job Overview by Ladders

Qualifications

  • 5+ years in Information Security focusing on auditing and IT controls design.
  • 5+ years experience with Security Information and Event Management (SIEM).
  • Proven experience with the Risk Management Framework (RMF).
  • Hands-on expertise with Active Directory, Windows/UNIX systems, and relational databases in secure environments.
  • Advanced knowledge of NIST RMF, NIST SP 800-37, 800-53, DHS 4300A, and FISMA compliance.
  • Experience in preparing and maintaining RMF ATO documentation and conducting system assessments.
  • Strong proficiency in evaluating security configurations for federal systems.

Responsibilities

  • Oversee Risk Management Framework (RMF) lifecycle across all ALC-ISD systems.
  • Lead internal and external cybersecurity audits, including readiness assessments.
  • Validate and document security controls within System Security Plans (SSPs) and Security Assessment Reports (SARs).
  • Design vulnerability management strategies and develop comprehensive Plans of Action and Milestones (POA&Ms).
  • Analyze cyber risks and provide guidance on DHS policy compliance and remediation.
  • Coordinate risk assessments and penetration testing to evaluate security posture.
  • Collaborate with teams to align audit processes with enterprise system modernization.

Benefits

  • Work-from-home position offering flexibility.
  • Opportunity to work with USCG, earning public sector experience.
  • Engagement in high-impact cybersecurity initiatives supporting federal compliance.
  • Potential for skills advancement in a variety of cybersecurity frameworks and methodologies.
Full Job Description
Description

This position is designated as work-from-home.

About the Role:

Synergy is seeking a Sr. Information Assurance Security Specialistto support the United States Coast Guard (USCG) at the Aviation Logistics Center (ALC)-Information Systems Division (ISD). The Sr. Information Assurance Security Specialist will lead audit preparation and execution, support continuous RMF lifecycle activities, and oversee compliance with federal cybersecurity requirements across on-premises, virtual, and cloud-hosted systems.

This position will serve as a senior technical advisor in security compliance efforts, guiding cross-functional teams through POA&M development, control remediation, ATO documentation, and continuous monitoring in accordance with NIST 800-53, DHS 4300A, and FISMA standards.

Primary Responsibilities:

  • Oversee the Risk Management Framework (RMF) lifecycle, including assessment, authorization, and continuous monitoring across all ALC-ISD systems.
  • Lead and coordinate internal and external cybersecurity audits, including pre-audit readiness assessments and post-audit remediation tracking.
  • Validate the implementation of security controls (NIST SP 800-53 Rev. 5) and ensure they are effectively documented within System Security Plans (SSPs), Security Assessment Reports (SARs), and related artifacts.
  • Design and implement vulnerability management strategies, assess threat vectors, and develop comprehensive Plans of Action and Milestones (POA&Ms).
  • Analyze cyber risks and provide guidance on remediation strategies aligned with DHS policy and evolving cybersecurity threats.
  • Perform and document risk assessments, penetration testing coordination, and impact analyses to evaluate the security posture of information systems.
  • Collaborate with Security Control Assessors (SCAs), engineers, ISSOs, and DevSecOps teams to ensure audit alignment with enterprise system modernization efforts.
  • Manage and maintain audit packages, compliance dashboards, and evidence repositories using platforms like Jira, Confluence, and SharePoint.
  • Assess and validate configurations of infrastructure (e.g., Windows, Linux, databases, Active Directory) for compliance with security benchmarks (e.g., DISA STIGs, CIS).
  • Draft and update security-related documentation including SOPs, incident response plans, and security test procedures.
  • Serve as a subject matter expert to stakeholders on RMF best practices, ATO sustainment, and security documentation management.


Required Qualifications:

  • Minimum of five (5) years of experience in Information security with auditing and IT controls design experience.
  • Minimum of five (5) years of experience with Security Information and Event Management (SIEM).
  • Minimum of five (5) years of experience in the risk management framework.
  • Hands-on experience with Active Directory, Windows/UNIX systems, and relational databases in secure environments.
  • Advanced knowledge of NIST RMF, NIST SP 800-37, 800-53, DHS 4300A, and FISMA compliance.
  • Experience preparing and maintaining RMF ATO documentation and conducting system assessments.
  • Familiarity with Security Information and Event Management (SIEM) platforms for log analysis and incident monitoring.
  • Proficient in evaluating and documenting security configurations and technical implementations for federal systems.
  • Strong understanding of cybersecurity audit workflows, control testing, and risk-based prioritization of vulnerabilities.
  • Excellent writing and communication skills, capable of producing technical documentation and executive summaries.
  • Experience in Agile or DevSecOps environments, with a strong understanding of security integration within CI/CD pipelines.
  • CompTIA Security+ certification required.


Preferred Qualifications:
  • Additional certifications (Network+, AWS Certified Cloud Practitioner, Microsoft Azure Fundamentals, Certified Information Systems Auditor (CISA), Certified Information Security Manager (CISM), ITIL Foundation, TOGAF, or other cybersecurity architecture certifications) are a plus.
  • Previous support of federal government enterprise systems or DHS/DOD programs is strongly preferred.

Education Requirements:
  • Required: Bachelor's or Associate's degree in Computer Science, Math, Information Technology, Engineering, or related field. Two (2) years of directly relevant experience may substitute for one (1) year of formal education.

Citizenship & Clearance Requirements:
  • Required: U.S. citizenship required
  • Required: Must have an active DoD Secret Clearance.


Target Salary Range

Compensation for roles at Synergy is determined by a variety of factors including, but not limited to, the requirements of the role; level of experience; education and certifications; the individual's combination of knowledge, skills, and abilities; as well as alignment with market data, federal and state laws, and other business and contract considerations. The estimated pay range for this position is: $84,000 - $120,000. The disclosed range has not been adjusted for the applicable geographic differential associated with the location at which the position may be filled. It is not typical for an individual to be hired at or near the top of the range for their role, and compensation decisions are dependent on the facts and circumstances of each case and represent just one component of Synergy's total compensation package for employees.

Candidate AI Policy

Synergy is committed to the responsible and ethical use of AI tools. However, we want to ensure a fair candidate evaluation process based on your own skills and knowledge. As part of this commitment, the use of artificial intelligence (AI) or other tools to assist with responses during interviews (whether in-person or virtual) is prohibited unless permission is explicitly granted. You are expected to be on camera during interviews and assessments. We reserve the right to take your picture to verify your identity and prevent fraud.

Similar Jobs

More Jobs at Synergy BIS

More Information Technology Jobs

Find similar Sr. Information Assurance Security Specialist jobs: