×
Register Here to Apply for Jobs or Post Jobs. X

Information Assurance Specialist III

Job in Arlington, Arlington County, Virginia, 22201, USA
Listing for: OneZero Solutions
Full Time position
Listed on 2026-09-25
Job specializations:
  • IT/Tech
    Cybersecurity, Information Security & Data Protection
Salary/Wage Range or Industry Benchmark: 110000 - 150000 USD Yearly USD 110000.00 150000.00 YEAR
Job Description & How to Apply Below

We are an employee-centric company that truly values our team members and the contributions they make to our customers and the missions they support. We pride ourselves on being forward-leaning thinkers and on building teams that are, and continue to be, technically proficient across a broad range of cyber mission areas. One Zero full-time employees receive a highly competitive benefits package, including health, dental, vision, and life insurance, a 401(k) with company matching, paid time off and holidays, an employee referral program, and educational assistance.

Additional details are available on our website:

Position

Information Assurance Specialist III

Location

Mechanicsburg, PA (preferred) or Arlington, VA (DSCA HQ)

Clearance

Secret

Position Summary

One Zero Solutions is seeking Information Assurance Specialists to support the Defense Security Cooperation Agency (DSCA), the DoD agency responsible for the transfer, sale, and lease of U.S. defense articles and services to international partners. As part of the DSCA Cybersecurity Support Services program, you will deliver hands‑on Risk Management Framework (RMF) and Cybersecurity Risk Management Construct (CSRMC) support across approximately 25 systems - serving in ISSO, Security Control Assessor, and SCA-Validator capacities within a cloud-native, Dev Sec Ops -oriented AWS environment.

This is an execution role at the heart of DSCA's security posture: you will own authorization packages in eMASS, drive controls to compliance, and help move the program from manual assessment toward automated, Compliance-as-Code continuous monitoring.

Key Responsibilities
  • Manage Assessment & Authorization (A&A) packages through the RMF/CSRMC lifecycle in eMASS, maintaining the authorization package as the authoritative GRC record - control implementation details, assessment evidence, and full POA&M lifecycle from creation to closure.
  • Support achievement and maintenance of Assess and Authorize (A&A), Assess Only, and Continuous ATO (cATO) accreditations, including system categorization and control selection, tailoring, and implementation.
  • Assess security control implementation across traditional and cloud-native services (containers, serverless, service meshes, Infrastructure-as-Code) and evaluate SaaS offerings against FedRAMP and DoD Cloud Computing SRG requirements, documenting shared-responsibility and control inheritance.
  • Conduct security control assessments as SCA/SCA-V: execute Security Assessment Plans through interviews, documentation review, configuration inspection, and technical testing; independently validate automated and manual test results before findings are formalized.
  • Develop and maintain RMF documentation - SSPs, control family plans, SAPs, SARs, risk assessments, and POA&M - automating documentation and evidence collection wherever possible.
  • Leverage and interpret Compliance-as-Code (CaC) output (e.g., AWS Inspector, Security Hub, AWS Config) to validate compliance against NIST SP 800‑53 controls and DISA STIGs, and verify automated evidence is accurate and audit‑ready in eMASS.
  • Monitor security posture within CI/CD pipelines (SAST/DAST, software composition analysis, container image scanning) and coordinate remediation with development teams before deployment.
  • Perform risk analysis prioritizing vulnerabilities by mission impact; brief ISSMs, system owners, and Government stakeholders on findings, risk posture, and remediation strategy.
  • Support incident response for cloud-native systems and coordinate with the CSSP and mission partners as required.
Required Qualifications
  • Three (3) years of dedicated Information Assurance experience, with at least two (2) years consecutive, including hands‑on RMF execution, security control assessment, POA&M…
To View & Apply for jobs on this site that accept applications from your location or country, tap the button below to make a Search.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
 
 
 
Search for further Jobs Here:
(Try combinations for better Results! Or enter less keywords for broader Results)
Location
Increase/decrease your Search Radius (miles)
0
200
Filters
Education Level
Experience Level (years)
Posted in last:
Salary