ASRC Federal Holding Company logo

Lead Information Assurance Security Specialist

ASRC Federal Holding Company
  • Fort Meade, MD
  • Autofill and Review
6 days ago

Job Description

ASRC Federal is seeking a Lead Information Assurance Security Specialist.

This is a contingent position supporting ASRC Federal's pursuit of the Defense Information Systems Agency Joint Planning and Execution Services and Joint Capabilities Requirements Manager Sustainment Services program.

JPES/JCRM supports mission-critical Global Force Management planning, execution coordination, operational data management, and interoperability for globally distributed Department of Defense users and command organizations. The program encompasses Agile software sustainment and enhancement, secure cloud and platform operations, system integration, testing and release management, cybersecurity compliance, and operational mission support.

The technical environment includes classified SIPR and Azure IL6 enclaves, Kubernetes, Red Hat Enterprise Linux, Java/Spring, React, PostgreSQL EDB, transitional Oracle integration, REST APIs, ELK observability, and DevSecOps pipelines integrated with DISA's C2FS/C2SF environment. The work requires close collaboration with DISA program, engineering, product, security, and operational-user stakeholders.

This is a full-time position located onsite at Fort Meade, Maryland. The position requires U.S. citizenship, an active Secret security clearance, and less than 10% travel. Employment is contingent upon contract award and Government approval of key personnel.

Job Description:The Lead Information Assurance Security Specialist will serve as the senior cybersecurity and mission-assurance authority for the DISA JPES/JCRM program. The position will lead implementation and sustainment of the Risk Management Framework across classified, containerized, cloud-hosted, and multi-enclave environments.

The Lead IA Specialist will maintain the program's security posture, direct RMF and eMASS activities, support ATO sustainment, manage vulnerability and POA&M remediation, and ensure security requirements are integrated into Agile development and DevSecOps delivery. The position will work closely with application, platform, database, integration, and Government cybersecurity personnel to implement security by design without disrupting operational delivery.

Primary Responsibilities:

Lead RMF lifecycle activities and maintain required artifacts in eMASS.Support initial and ongoing ATO authorization and continuous-monitoring activities.Implement, assess, and validate STIGs for RHEL, Kubernetes, Tomcat, PostgreSQL, and web-application components.Direct ACAS/Nessus vulnerability scanning and analysis.Coordinate application-security testing using tools such as Fortify or equivalent SAST/DAST capabilities.Manage POA&M development, remediation, closure evidence, and risk-acceptance coordination.Translate cybersecurity findings into prioritized Agile backlog and sprint-remediation activities.Support security architecture for REST APIs, data exchange, DevSecOps pipelines, and external DoD interfaces.Coordinate IAVM compliance, patching, configuration validation, audit support, and security-control evidence.Advise technical teams on secure implementation patterns for Azure IL6, Kubernetes, databases, and multi-enclave deployments.Provide security status, risks, metrics, and recommendations to program and Government leadership.

Minimum Qualifications:

Bachelor's degree in engineering, cybersecurity, computer science, information technology, or a related discipline; four additional years of experience may be accepted in lieu of a degree.At least 10 years of Information Assurance, RMF, or cybersecurity experience in DoD environments.Direct experience with RMF, eMASS, ATO sustainment, STIG validation, vulnerability management, and POA&M remediation.Experience securing containerized applications and Kubernetes environments.Experience integrating cybersecurity controls and scanning into DevSecOps delivery.Experience with Azure IL6, SIPR, or comparable classified DoD-hosted environments.Security+ or other applicable DoD 8140 qualification required.CISSP preferred.Active Secret clearance required at time of hire.

Numbers & Facts

LocationFort Meade, MD
IndustryAerospace and Defense
Company Size5,000 to 9,999 employees
Year Founded2003
Websitehttp://www.asrcfederal.com

Benefits

Military Leave, On Site Cafeteria, Parking, Prescription Drug Coverage, Professional Development, 401K, Employee Referral Program, Flexible Spending Accounts, Employee Events, Tuition Reimbursement, Work From Home, Life Insurance, Merchandise Discounts

About Company

ASRC Federal comprises a family of companies that provide mission-critical services to federal government agencies dedicated to defense, civil and intelligence support. Our customer-focused service delivery model and emphasis on operational excellence are foundational elements infused in all our companies. The reliability and quality of day-in, day-out service delivery from our family of companies ensure our customers that we keep our sights on their mission-critical priorities.

Skills

  • Agile Programming Methodologiesunmatched
  • Application Programming Interface (API)unmatched
  • Applications Securityunmatched
  • Backlog Prioritizationunmatched
  • CISSP - Certified Information Systems Security Professionalunmatched
  • Cloud Computingunmatched
  • CompTIA Security+unmatched
  • Computer Scienceunmatched
  • Computer Securityunmatched
  • Data Managementunmatched
  • Defense Information Systems Agency (DISA)unmatched
  • DoD Directive 8140unmatched
  • DoD Directive 8570unmatched
  • Governmentunmatched
  • Government Contractsunmatched
  • Information Technology & Information Systemsunmatched
  • Information/Data Security (InfoSec)unmatched
  • Integration Testingunmatched
  • Internet Applicationunmatched
  • Internet Securityunmatched
  • Interoperabilityunmatched
  • Java Platform Enterprise Edition (Java EE/J2EE)unmatched
  • Leadershipunmatched
  • Maintain Complianceunmatched
  • Metricsunmatched
  • Microsoft Windows Azureunmatched
  • Nessusunmatched
  • Operational Supportunmatched
  • Operations Managementunmatched
  • Oracleunmatched
  • PostgreSQLunmatched
  • REST (Representational State Transfer)unmatched
  • React.jsunmatched
  • Red Hat Linux Operating Systemunmatched
  • Release Management/Engineeringunmatched
  • Requirements Managementunmatched
  • Riskunmatched
  • Risk Management Framework (RMF)unmatched
  • Secret Clearanceunmatched
  • Security Analysisunmatched
  • Security Architectureunmatched
  • Security Auditingunmatched
  • Security Clearanceunmatched
  • Security Designunmatched
  • Software Administrationunmatched
  • Software Patchesunmatched
  • Software Testingunmatched
  • System Integration (SI)unmatched
  • System Testunmatched
  • Test Toolsunmatched
  • Tomcatunmatched
  • United States Citizenunmatched
  • United States Department of Defense (DoD)unmatched
  • Vulnerability Scannersunmatched
  • Willing to Travelunmatched

Be found by employers

5,500+ employers search our resume database daily. Add yours to get found by recruiters looking for candidates like you.

Level up your application

Professional resume templates

Browse dozens of recruiter approved resume templates, layouts and formats. Choose your favorite and make it your own in minutes.

Free resume templates

Free resume builder

Improve your existing resume or start from scratch and create a standout, ATS-friendly resume. Add job-specific content, download and apply.

Free resume builder