Information Assurance Specialist IV
Listed on 2026-09-12
-
IT/Tech
Cybersecurity, Information Security & Data Protection
We are an employee-centric company that truly values our team members and the contributions they make to our customers and the missions they support. We pride ourselves on being forward-leaning thinkers and on building teams that are, and continue to be, technically proficient across a broad range of cyber mission areas. One Zero full-time employees receive a highly competitive benefits package, including health, dental, vision, and life insurance, a 401(k) with company matching, paid time off and holidays, an employee referral program, and educational assistance.
Additional details are available on our website:
Position Title: Information Assurance Specialist IV
Location: Arlington, VA or Mechanicsburg, PA
Clearance: Secret
Job Summary: The Information Assurance Specialist IV is key personnel providing senior Information System Security Officer (ISSO), Security Control Assessor (SCA), and Security Controls Validator (SCA-V) support across DSCA's five IM&T. The role ensures the confidentiality, integrity, and availability of data on assigned systems, leads operationalization of RMF/CSRMC in a cloud-native Dev Sec Ops environment, and drives automation of control implementation, evidence collection, and authorization artifacts in support of A&A, Assess Only, and continuous ATO (cATO) outcomes.
Education and Experience:
- Bachelor's degree from an accredited institution in Information Technology, Computer Science, Engineering, or a related technical discipline.
- Current DoW 8570/8140 certification meeting the IAM Level II or IAT Level II baseline requirement (e.g., CISSP, Security+ CE, CISM, CASP+ CE).
- Five (5) years of dedicated Information Assurance experience, with at least three (3) of those years being consecutive.
- Three (3) consecutive years directly relevant to the tasks above, demonstrating a hands-on understanding of the DoW cybersecurity environment.
- Active Secret clearance; U.S. citizenship required.
Essential Duties:
- Serving as ISSO for assigned DSCA IM&T portfolio systems, ensuring confidentiality, integrity, and availability of data residing on or transiting those systems.
- Leading operationalization of the RMF/Cybersecurity Risk Management Construct (CSRMC) within a cloud-native, Dev Sec Ops framework, and automating security control implementation and evidence collection to achieve and maintain A&A, Assess Only, and cATO accreditations.
- Proactively identifying and mitigating security weaknesses and maintaining accurate, current security documentation.
- Developing the Security Assessment Plan (SAP) and conducting ongoing assessments of security controls beyond periodic compliance checks.
- Providing actionable risk analysis that prioritizes vulnerabilities and control deficiencies, and interpreting and validating outputs of automated validation tools and Policy-as-Code scripts.
- Developing and maintaining key authorization artifacts, including the Security Assessment Report (SAR), the Authorization Recommendation Memo, and the program's overarching ATO documentation.
- Performing SCA-V duties: validating security and compliance content, assessing CaC profiles and scripts, and verifying that automated compliance evidence is correctly ingested and reflected.
- Maintaining the eMASS record as the system of record, documenting all assessment activities, findings, and evidence in a timely and accurate manner.
- Performing in-depth risk analysis and POA&M support and providing written recommendations for mitigation and validation of proposed corrective actions.
- Preparing and assembling the Security Authorization Package and briefing the SCA, ISSM, and other stakeholders on assessment results and residual risk.
Knowledge, Skill and Abilities:
- Expert knowledge of RMF, NIST SP 800-53, DISA STIGs, and the Cybersecurity Risk Management Construct (CSRMC).
- Master-level proficiency in eMASS as the authoritative system of record for assessment and authorization data.
- Familiarity with FedRAMP, DoW Impact Levels, and the DoW Cloud Computing Security Requirements Guide (CCSRG).
- Hands-on experience securing AWS cloud-native architectures and authorized SaaS solutions.
- Ability to review and validate Compliance-as-Code (CaC) and Policy-as-Code (PaC) profiles, scripts, and automated compliance evidence.
- Skill in risk analysis, POA&M development, and drafting decision-quality authorization documentation (SAP, SAR, Authorization Recommendation Memo).
Clear, no-surprises reporting and effective collaboration with system owners, ISSMs,
One Zero Solutions, LLC is an…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).