Information Security Risk Specialist
Listed on 2026-10-03
-
IT/Tech
Cybersecurity
Join a culture of empowerment and connectivity.
Develop your craftLearn the skills you need to accelerate your career.
Discover benefits that support your life and work.
Innovate with intentionBuild mission-ready tech that protects the nation.
Cyber threats are everywhere, and the constantly evolving nature of these threats can make understanding them seem overwhelming. In all of this “cyber noise” how can these organizations understand their risks and how to mitigate them? The answer is an information security risk specialist like you who will break down complex threats into manageable plans of action.
As an information security risk specialist on our team, you’ll use your experience to work with senior leaders to discover their cyber risks, understand applicable policies, and develop a mitigation plan. You’ll review technical and personnel details from our tenants to assess the entire threat landscape. Then, you’ll guide our tenants through a plan of action with presentations, whitepapers, and milestones.
You’ll work with cloud architects, cybersecurity teams, GRC, networking, platform engineering, and tenant teams to make security controls repeatable and usable. You’ll help ensure that users receive the right platform, understand the controls they inherit, and know what remains their responsibility.
This is your opportunity to apply cloud-security expertise while expanding your skills in secure platform engineering, AWS Gov Cloud, IL5 environments, Infrastructure-as-Code, control inheritance, and enterprise-scale cloud transformation.
Join us. The world can’t wait.
You Have:
- 5+ years of experience securing, hardening, and remediating security vulnerabilities in AWS Gov Cloud
- Experience with CMMC, NIST 800-171, DoD security controls, FedRAMP, defense SRG, or cloud security frameworks
- Experience with cloud networking, routing, segmentation, firewalls, private connectivity, DNS, and network security controls
- Experience with control inheritance, SSP generation, evidence mapping, or authorization package support
- Knowledge of AWS organizations, organizational units, service control policies, identity, account governance, and cloud security baselines
- Ability to translate policy to both senior stakeholders and operations teams who need to implement the controls
- Public Trust
Nice If You Have:
- Experience implementing Infrastructure-as-Code using Terraform, Cloud Formation, CDK, or comparable technologies
- Experience deploying secure landing zones, shared services, platform baselines, or multi-account cloud architectures
- Experience with AWS Security Hub, Guard Duty, Config, Cloud Trail, Network Firewall, Transit Gateway, Cloud WAN, Splunk, Tenable, F5, or comparable technologies
- Experience supporting cloud migrations, tenant onboarding, account adoption, network-path validation, or platform-parity initiatives
- Knowledge of IAM Identity Center, federation, Keycloak, Entra , privileged access, and identity-boundary design
- Possession of excellent detail-oriented, organization, and time management skills
- Possession of excellent verbal and written communication skills
- CISSP, CCSP, Security+, AWS Security Specialty, CISM, or equivalent Certification
Vetting:
Applicants selected will be subject to a government investigation and may need to meet eligibility requirements of the U.S. government client;
Public Trust determination is required.
Compensation
At Booz Allen, we celebrate your contributions, provide you with opportunities and choices, and support your total well-being. Our offerings include health, life, disability, financial, and retirement benefits, as well as paid leave, professional development, tuition assistance, work-life programs, and dependent care. Our recognition awards program acknowledges employees for…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).