
Information Assurance and Security Engineer
Posted Sep 16

Posted Sep 16
This is a fully remote position, open to applicants in United States.
• Deliver technical and programmatic information assurance services for network and information security systems within the DEERS application portfolio.
• Create, develop, and execute security requirements within business processes, DevSecOps pipelines, OCI cloud migration, and Agile development sprints.
• Prepare and sustain SSPs, SARs, POA&Ms, STIG checklists, and implementation plans utilizing eMASS.
• Formulate ST&E plans and assist in formal security assessments alongside DMDC CSD and Enterprise ISSOs.
• Provide C&A/A&A support, including security and contingency plans, in accordance with DoDI 8510.01 and NIST SP 800-37 RMF.
• Perform risk and vulnerability assessments while devising mitigation strategies.
• Evaluate policies and procedures against federal laws and regulations, advising on compliance-gap remediation.
• Execute security enhancements and assist with IAVA monitoring and monthly resolution tasks.
• Develop, test, and integrate Fortify, Sonatype, and BURP security scanning tools into the DevSecOps pipeline.
• Secure system configurations, carry out STIG and NIST baseline compliance scans, and report findings.
• Conduct security program audits and facilitate 1–3 external audits each year.
• Aid in security architecture and OCI cloud migration at DISA IL-4/IL-5 authorization levels.
• Assist with computer incident investigations and report cyber incidents within mandated timelines.
• Submit and revise POA&Ms based on vulnerability-severity deadlines.
• Support ISCM activities and provide weekly vulnerability scan status updates during IPRs.
• Maintain ATOs and A&I packages throughout the entire RMF lifecycle.
• Implement JFHQ-DODIN and USCYBERCOM CTOs.
• Ensure cybersecurity workforce personnel are screened, trained, and certified according to DoD 8140.03 and CMMC requirements.
• Conduct mandatory security training on OPSEC, CUI, Insider Threat, Privacy Act/PII, IT Security, Counterintelligence, Antiterrorism, and Records Management.
• A minimum of 8 years of experience with a BS/BA; 6 years with an MS/MA; 3 years with a PhD; or 12 years with a high school diploma.
• Capability to obtain and retain DoD Public Trust.
• Practical experience with the DoD Risk Management Framework (RMF) and eMASS.
• Comprehensive knowledge of NIST SP 800-53 Rev 5, NIST SP 800-37, NIST SP 800-171 Rev 2, NIST SP 800-137, FISMA, DoDI 8510.01, and DoDI 8500.01.
• Experience in conducting vulnerability assessments, creating POA&Ms, and managing the complete A&A lifecycle, including ATO package development.
• Familiarity with Fortify, Sonatype, and BURP application security scanning tools.
• Knowledge of OWASP secure coding principles.
• Working knowledge of STIG compliance verification, checklist preparation, and remediation.
• Proven experience in supporting DevSecOps security practices in Agile development settings.
• DoD 8140.03 / DoD 8570.01-M compliant IAT/IAM Level II certification, such as CISSP, CASP+, CEH, Security+, or an equivalent certification.
• Preferred: active Public Trust clearance.
• Preferred: CISSP or equivalent advanced certification.
• Preferred: cloud security experience at FedRAMP Moderate, DISA IL-4, or DISA IL-5 authorization levels; familiarity with OCI security configuration.
• Preferred: knowledge of CMMC.
• Preferred: experience with external DoD financial/operational audits.
• Preferred: familiarity with ServiceNow, JIRA, and SharePoint.
• Preferred: understanding of DFARS 252.204-7012 cyber incident reporting requirements.
• Preferred: experience in implementing JFHQ-DODIN or USCYBERCOM CTOs.
• Preferred: prior S-ISSO experience within a large-scale DoD program environment.
• Potential eligibility for overtime.
• Shift differential.
• Discretionary bonus.
• Equal opportunity employment, including for individuals with disabilities and protected veterans.
Sony Interactive Entertainment
Squads
Neo4j
PingWind Inc. (SDVOSB)
Get handpicked remote jobs straight to your inbox weekly.