Point your AI agent at freehire and let it find you a job.

Get the CLI →

IT Security Specialist II

NewBe an early applicant

Summary

Remote IT Security Specialist who conducts Risk Management Framework (RMF) security assessments for federal High/Moderate systems: scanning for vulnerabilities, evaluating security controls, maintaining CSAM compliance records, and supporting POA&M remediation using NIST, FISMA, and STIG frameworks.

About the Opportunity

The IT Security Specialist II supports timely, high-quality security assessments for High and Moderate systems under the Risk Management Framework (RMF) in a remote environment. This role assesses vulnerabilities, evaluates security controls, operates security scanning and monitoring tools, maintains security artifacts and CSAM records, and supports POA&M remediation and evidence retesting.

Success in this role means maintaining a secure, compliant, and well-documented environment by applying NIST, FISMA, STIG, and agency-specific requirements, collaborating effectively with system teams and federal stakeholders, and consistently delivering accurate work within established timelines.

What You'll Do

The IT Security Specialist II conducts security assessments, monitors and remediates vulnerabilities, maintains compliance documentation and CSAM records, supports POA&M activities, and collaborates with system teams to ensure federal security requirements are met

Responsibilities include:

  • Operate and maintain security scanning and monitoring tools to identify vulnerabilities and monitor system security.
  • Collect, organize, and maintain security artifacts for compliance and audit purposes.
  • Update and maintain IT security policies, procedures, SOPs, templates, and checklists for security operations and assessments.
  • Document and maintain CSAM entries to reflect current system compliance status.
  • Assist with POA&M updates, including tracking remediation progress and retesting evidence to verify resolution of findings.
  • Support vulnerability management and remediation activities, ensuring compliance with STIGs, NIST standards, and federal cybersecurity policies.
  • Review all relevant system and core security documentation for assessments.
  • Document computer security and emergency measures policies, procedures, and tests.
  • Perform security risk assessments and evaluate system security controls to ensure effective security measures and compliance.
  • Collaborate with program managers, developers, and infrastructure teams to embed security throughout the system lifecycle.
  • Train and mentor junior staff in cybersecurity best practices and federal compliance requirements.
  • Perform other duties and responsibilities as assigned


What You'll Bring

Required Qualifications

  • Bachelor’s degree in Engineering, Information Technology, Business, or a related field (or equivalent work experience).
  • 2-4 years of experience in IT security, with at least 3 years supporting federal government systems.
  • Experience with Security Repository Tools, such as Cyber Security Assessment and Management (CSAM)
  • Experience with NIST SP 800-37, NIST 800-53, FISMA A&A, and federal IT security policies and standards
  • Proficiency in applying IT security concepts, methodologies, principles, procedures and using industry-standard IT security tools
  • Proficiency with enterprise architecture methodologies, concepts, procedures, principles, and tool
  • Familiarity with scanning and monitoring tools and conducting security assessments in cloud environments
  • Proficiency in Microsoft Office suite (Word, Excel, PowerPoint, Visio and Project)
  • Strong verbal and written communication skills, and ability to adapt to changing environments while working with federal clients and system teams.

Preferred Qualifications

  • Relevant professional certifications: CISSP, CEH, CISM, CCSP, CISA, CompTIA Security+
  • Additional industry certifications (e.g., AWS Certified Security – Specialty, Microsoft Certified: Azure Security Engineer Associate)•
  • Experience with network, endpoint, cloud, and identity/access security, including penetration testing.
  • Experience developing and maintaining IT security documentation, including authorization packages, policies, SOPs, and templates.
  • Maintain awareness of evolving cybersecurity threats, standards, and best practices

Work authorization/security clearance requirements

  • Ability to obtain security clearance

Work environment

  • This work will be completed in a remote environment.


Physical demands

  • Prolonged periods of sitting at a desk and working on a computer.


Travel required: No


Proficiency Requirement

  • The employee is expected to demonstrate proficiency in all essential job functions, tools, and processes related to this position within the first 90 days of employment. This includes acquiring a thorough understanding of job-specific responsibilities, systems, and workflows as outlined during onboarding and training. Failure to meet this requirement may result in additional training, reassessment, or other actions as deemed necessary by management.

See also

Security jobs by country — openings, pay and top skills →

Tailor your CV for this role?

We couldn't check your fit for this role — add a CV to your profile to see it next time.

A new version of freehire is available