Job Number: R0204421
Information Security Specialist
The Opportunity:
Cyber threats are everywhere, and the constantly evolving nature of these threats can make understanding them seem overwhelming to government agencies. In all of this “cyber noise,” how can these organizations understand their risks and how to mitigate them? The answer is you—an Information Security Risk Specialist who will break down complex threats into manageable plans of action.
As an Information Security Risk Specialist on our team, you’ll use your experience to work with organizations to discover their cyber risks, understand applicable policies, and develop a mitigation plan. You’ll review technical, environmental, and personnel details to assess the entire threat landscape. Then, you’ll guide your client through a plan of action with presentations, white papers, and milestones.
You’ll work with your client to translate security concepts, so they can make the best decisions to secure their mission critical systems. This is your opportunity to act as an information security subject matter expert while broadening your skills in emerging technologies.
Work with us as we protect our nation’s cyber infrastructure.
Join us. The world can’t wait.
You Have:
- 5+ years of experience working with cybersecurity in a DoD environment
- 3+ years of experience leading and implementing the Assessment and Authorization process under Risk Management Framework for new and existing information systems
- 3+ years of experience reviewing assessment reports and assisting projects in identifying security risks, including technical and non-technical, and developing effective mitigation strategies, including Plan of Action and Milestones
- 3+ years of experience managing ATO packages in eMASS or Xacta
- 3+ years of experience in developing and implementing risk management strategies
- 2+ years of experience authoring technical reports, presentations, and briefs based on performed cybersecurity or risk assessments, including communication of findings and recommendations
- Knowledge of the NIST SP 800 series and testing NIST 800-53 security controls
- Secret clearance
- HS diploma or GED
Nice If You Have:
- 3+ years of experience with Burp Suite supporting Static Application Security Testing (SAST), Dynamic Application Security Testing (DAST), and IDE Plug-in environments
- Experience with ATO
- Experience with securing enterprise web applications and OWASP Top 10, CVSS, CWE, WASC, and SANS-25
- Knowledge of Risk Management Framework (RMF)
- Knowledge of customer IT systems, requirements, and processes for information assurance, assessment, and authorization activities
- Ability to communicate with a diverse set of stakeholders and changing requirements while ensuring quality delivery of RMF packages
- Ability to manage system vulnerabilities and track in system Plan of Action and Milestones (POAMs)
- Ability to work independently and as part of a team
- Possession of excellent verbal and written communication skills
- Advanced Cybersecurity Certifications, including Security +, Network +, or CISSP
Clearance:
Applicants selected will be subject to a security investigation and may need to meet eligibility requirements for access to classified information; Secret clearance is required.
Compensation
At Booz Allen, we celebrate your contributions, provide you with opportunities and choices, and support your total well-being. Our offerings include health, life, disability, financial, and retirement benefits, as well as paid leave, professional development, tuition assistance, work-life programs, and dependent care. Our recognition awards program acknowledges employees for exceptional performance and superior demonstration of our values. Full-time and part-time employees working at least 20 hours a week on a regular basis are eligible to participate in Booz Allen’s benefit programs. Individuals that do not meet the threshold are only eligible for select offerings, not inclusive of health benefits. We encourage you to learn more about our total benefits by visiting the Resource page on our Careers site and reviewing Our Employee Benefits page.
Salary at Booz Allen is determined by various factors, including but not limited to location, the individual’s particular combination of education, knowledge, skills, competencies, and experience, as well as contract-specific affordability and organizational requirements. The projected compensation range for this position is $75,600.00 to $172,000.00 (annualized USD). The estimate displayed represents the typical salary range for this position and is just one component of Booz Allen’s total compensation package for employees. This posting will close within 90 days from the Posting Date.
Work Model
Our people-first culture prioritizes the benefits of flexibility and collaboration, whether that happens in person or remotely.
- If this position is listed as remote or hybrid, you’ll periodically work from a Booz Allen or client site facility.
- If this position is listed as onsite, you’ll work with colleagues and clients in person, as needed for the specific role.
EEO Commitment
We’re an equal employment opportunity/affirmative action employer that empowers our people to fearlessly drive change – no matter their race, color, ethnicity, religion, sex (including pregnancy, childbirth, lactation, or related medical conditions), national origin, ancestry, age, marital status, sexual orientation, gender identity and expression, disability, veteran status, military or uniformed service member status, genetic information, or any other status protected by applicable federal, state, local, or international law.