Senior Information Security Specialist
Summary
A hands-on technical leadership role leading a mid-sized team of ISSOs securing federal applications hosted in AWS: running RMF/ATO authorizations, FISMA/NIST 800-53 control work, vulnerability management, and continuous monitoring. Requires an active CBP, DHS, or Top Secret clearance and hybrid onsite work (3 days/week) in Ashburn, VA.
Information Security Specialist Officer, Technical Lead, #1117
AWS Security • RMF & ATO • NIST 800-53 • Cloud Application Security
Clearance: Active CBP, DHS, or Top Secret Clearance required
Work Arrangement: Hybrid – onsite 3 days/week during standard business hours in Ashburn, VA
About the Role
Dev Technology Group is seeking a Senior Information Security Specialist to lead and develop a mid-sized team of ISSOs supporting the security, compliance, and authorization of mission-critical federal applications and information systems hosted in AWS.
This is a hands-on technical leadership role combining people leadership, federal cybersecurity expertise, and direct collaboration with government and technical stakeholders. You will mentor junior and mid-level ISSOs while partnering with system owners, developers, architects, cloud/infrastructure engineers, security professionals, and government stakeholders throughout the system development lifecycle.
You will provide practical security guidance for AWS-hosted applications, lead Risk Management Framework (RMF) and Authority to Operate (ATO) activities, oversee vulnerability management and continuous monitoring, and translate federal cybersecurity requirements into actionable guidance for technical teams.
What You'll Do
- Lead, mentor, and develop a team of ISSOs by establishing priorities, providing technical direction and coaching, and promoting accountability and consistent security practices.
- Lead and oversee RMF, ATO, security authorization, compliance, vulnerability management, and continuous monitoring activities across a portfolio of federal systems and applications.
- Partner with ISSMs, system owners, assessors, developers, architects, engineers, and government stakeholders to maintain authorizations, identify risks, and address security requirements.
- Lead vulnerability management efforts, prioritizing remediation, developing mitigation strategies, and tracking corrective actions through resolution.
- Develop, assess, document, and support implementation of security controls aligned with FISMA, NIST 800-53, DHS, and client requirements.
- Prepare and maintain security and authorization documentation, including SSPs, ISAs, audit artifacts, and RMF documentation.
- Provide cybersecurity guidance for applications and systems deployed in AWS and integrate security throughout the software development lifecycle.
- Validate security implementation through technical reviews, discussions, interviews, assessments, and tabletop exercises.
- Support security audits, assessments, compliance reviews, and reviews of information systems and network connections.
- Interpret federal and client security policies and translate requirements into practical guidance for technical and development teams.
- Identify and escalate security risks, communicate priorities and remediation status, and provide clear visibility to Dev Technology leadership and government stakeholders.
- Develop and present security metrics, status reports, risk assessments, and executive briefings.
- Establish and improve security processes, procedures, templates, dashboards, and workflows to improve consistency, accountability, and efficiency across the ISSO team.
- Build trusted relationships with government clients through proactive communication, collaboration, and face-to-face engagement.
Required Education, Experience & Skills
- Bachelor's degree and 7+ years of experience securing federal information systems.
- Demonstrated experience leading and mentoring information security professionals, including junior and mid-level ISSOs.
- Experience leading cybersecurity activities in a federal government client environment and working directly with government stakeholders.'
- Strong working knowledge of NIST Risk Management Framework (RMF) and experience supporting federal systems through security authorization and ATO activities.
- Experience developing, implementing, assessing, or documenting security controls aligned with FISMA and NIST 800-53.
- Experience with vulnerability management, continuous monitoring, security assessments, audits, or compliance reviews for federal systems.
- Experience providing cybersecurity guidance for AWS-hosted applications and systems.
- Strong understanding of modern information systems and their technical security considerations.
- Ability to work effectively with developers, architects, engineers, government stakeholders, and technical and non-technical audiences.
- Strong written and verbal communication skills, including the ability to communicate security risks and technical findings and develop/present security documentation and executive briefings.
- Ability to establish priorities, manage competing demands, independently manage security activities, and escalate issues appropriately.
- Proactive, solutions-oriented approach to identifying risks and improving security practices.
- Current CBP, DHS, or Top Secret Clearance.
- Ability to work onsite 3 days per week in Ashburn, VA during standard business hours.
- Cybersecurity certification such as CISSP, CISM, GIAC, Security+, or another recognized cybersecurity certification.
Preferred Education, Experience & Skills
- Experience developing or supporting RMF and authorization artifacts, including SSPs, ISAs, PTAs, ATTs, POA&Ms, and related documentation.
- Experience partnering with application development, cloud engineering, and DevSecOps teams to integrate security throughout the SDLC.
- Experience working in an Agile software development environment using Jira or similar platforms.
- Experience with GRC tools such as CSAM or similar platforms supporting authorization, compliance, vulnerability management, and security activities.
- Understanding of AI concepts and practical applications of AI for cybersecurity operations, risk analysis, compliance, or security program management.
Our estimated salary range for this position is $88,000 - $ 150,000. This presented salary range is not a guarantee of compensation or salary. Offered salary is based on experience, geographic location, and possibly contractual requirements as appropriate to the role. *Salary could fall outside of this range.
Who We Are
Dev Technology is a growing IT company with an employee-centric culture that works on mission-critical projects for the federal government. We partner with our federal customers to deliver technology services and solutions, and to drive our client’s missions forward through innovation. We use Agile and DevSecOps principles to provide services including application development, biometrics and identity management, cloud and infrastructure optimization, IT and legacy modernization, and data management.
As a Washington Post Top Workplace award winner for the past THIRTEEN years in a row, the Top Workplaces USA for the past five years, and a recipient of the Companies As Responsive Employers (CARE) Award for the past six years, Dev Technology employees enjoy:
- Generous and flexible time-off policy
- Flexible work schedules and telework options, including remote work availability for eligible projects
- Career development opportunities including a mentorship program, technical and management training through Dev University, hands-on learning through DevLab, tuition reimbursement, and paid training opportunities
- Industry-leading benefits including a choice of two health plans that include dental and vision, flexible spending account, commuter benefits, life insurance, and more
- 401K matching with a 5% matching contribution
- Regular team and company social events including our annual party, happy hours, fitness challenges, and more
- A focus on community engagement including company wide support activities, employer match for donations, and time off for volunteer efforts
- To learn more about working at Dev Technology, visit Working At Dev Technology Group
Equal Opportunity Employer / Individuals with Disabilities / Protected Veterans
Dev Technology Group operates in the following states: AL, AR, AZ, CO, DC, FL, GA, ID, IL, IN, MD, MA, ME, MI, MN, MO, MS, NC, NJ, OH, OR, PA, SC, TN, TX, VA, WV.
Skills
As published by greenhouse · 29 questions · 2 written answers
Basics
First Name, Last Name, Email, Phone, Resume/CV, Cover Letter, Location
Short answers (7)
- Preferred First Name
- What is your preferred name? (if different than your legal name)
- Please provide your salary expectations for this role.
- LinkedIn and/or GitHub Profile URL optional
- Street Address (Optional Second Line) optional
- City
- Zip
Pick from a list (20)
- This position involves working on a contract for the US Government. The US Government requires US citizenship for this position. **NOTE: This position cannot support a Work Visa or Green Card status. Providing false information regarding your US Citizenship status on this application will result in your application being rejected for this opportunity. Can you meet this requirement?
- Do you currently hold an active CBP, DHS, or Top Secret security clearance?
- If you currently hold a clearance, please indicate which security clearance you currently hold:
- Do you have experience supporting a Federal Government client?
- Do you have a bachelor's degree or higher-level degree?
- Do you have at least 7 years of experience securing government IT systems?
- This is a hybrid position. You must live in the DC/MD/VA area and be able to commute to the office in Ashburn, Virginia, 3 days per week. Are you able to meet this requirement?
- Do you have professional experience leading or mentoring information security professionals, including ISSOs?
- Do you have hands-on experience supporting the NIST Risk Management Framework (RMF) and federal Authority to Operate (ATO) processes?
- Do you have experience developing, implementing, assessing, or documenting security controls aligned with FISMA and NIST 800-53?
- Do you have experience providing cybersecurity guidance for applications or information systems hosted in AWS?
- Do you have experience with vulnerability management, continuous monitoring, security assessments, audits, or compliance reviews for federal information systems?
- As part of our final interview and identity-verification process, candidates may be required to attend an in-person interview at Dev Technology’s headquarters in Reston, Virginia. Any travel reimbursement would be determined on a case-by-case basis and must be approved in advance. If selected for an in-person interview, are you willing and able to participate?
- Dev Technology requires all candidates who receive a verbal offer to successfully complete an identity verification before a written offer can be issued. Are you willing to complete this required step of the hiring process?
- Please acknowledge the following: All new hires are asked to come onsite to our Reston, VA headquarters for orientation. Are you able to meet this requirement?
- Fully Remote position candidates must have a primary address in one of the following states: AL, AR, AZ, CO, DC, FL, GA, ID, IL, IN, MD, MA, ME, MI, MN, MO, MS, NC, NJ, OH, OR, PA, SC, TN, TX, VA, WV. Can you meet this requirement?
- If No, are you willing to relocate to one of the above locations: optional
- State
- By selecting YES, I consent to receive recruiting SMS messages from Dev Technology Group at the phone number provided on my job application.
- Pre-Employment Requirements Acknowledgment I understand that submitting an application does not constitute an offer of employment. If I receive an offer from Dev Technology, the offer will be contingent upon my successful completion of all applicable pre-employment requirements. These requirements may include a background check conducted through HireRight and the successful completion of any required government, agency, or client suitability, public trust, or security clearance process. I understand that I may not begin employment until all required pre-employment conditions have been satisfied and Dev Technology has confirmed that I am authorized to start work. I agree to provide accurate information and promptly complete any documentation or actions required to support these processes. I have read and understand the pre-employment requirements described above.
Written answers (2)
- Please list all your active professional certifications. optional
- Street Address