Senior Information Security Specialist
Summary
Leads cybersecurity initiatives, manages risk, and ensures compliance for government systems by implementing RMF processes, conducting assessments, and maintaining security documentation in a non-remote role based in Washington, D.C.
Pay: $50.64 - $83.55 hourly, depending on experience
Benefits: Medical, Dental, Vision, Paid Time Off, Paid Holidays, Employee Assistance Program, and other company-sponsored benefits
Security Clearance: Ability to obtain and maintain a government security clearance if required
Are you an experienced cybersecurity professional who thrives on protecting mission-critical systems, managing risk, and ensuring compliance in complex environments?
PEMCCO is seeking an Senior Information Security Specialist to lead security, compliance, risk management, and authorization activities supporting government information systems and networks. This role is ideal for a cybersecurity leader who enjoys guiding security initiatives, managing Risk Management Framework (RMF) efforts, assessing risk, and helping organizations maintain strong and compliant security postures.
This opportunity is a strong fit for candidates with experience in information assurance, cybersecurity, information security, RMF, Assessment & Authorization (A&A), compliance management, vulnerability management, continuous monitoring, or system security engineering.
About PEMCCO
PEMCCO supports complex technical and operational programs by providing skilled professionals who help customers achieve mission success. We offer opportunities to work on impactful projects, collaborate with experienced teams, and contribute to innovative solutions that support critical government operations.
Job Overview
As a Senior Information Security Specialist, you will serve as a senior cybersecurity professional responsible for supporting the security and compliance of mission-critical information systems. You will work closely with program leadership, engineers, system administrators, developers, and government stakeholders to ensure cybersecurity requirements are implemented and maintained throughout the system lifecycle.
This position offers the opportunity to lead cybersecurity initiatives, influence risk management decisions, support authorization activities, and play a critical role in protecting systems that support important government missions.
What You'll Do
- Lead information system security activities throughout the system lifecycle
- Manage and support Risk Management Framework (RMF) and Assessment & Authorization (A&A) processes
- Develop, review, and maintain System Security Plans (SSPs), Security Assessment Reports (SARs), Plans of Action & Milestones (POA&Ms), and related cybersecurity documentation
- Conduct security assessments, compliance reviews, vulnerability analyses, and risk assessments
- Evaluate implemented security controls and recommend corrective actions and improvements
- Identify, document, track, and support remediation of security vulnerabilities and compliance deficiencies
- Support continuous monitoring activities and maintain awareness of system security posture
- Coordinate with system owners, engineers, developers, administrators, and stakeholders to ensure security requirements are integrated throughout the system lifecycle
- Advise leadership on cybersecurity risks, compliance requirements, and security strategies
- Support incident response activities, security investigations, and remediation efforts
- Ensure compliance with cybersecurity policies, regulations, standards, and contractual requirements
- Support cybersecurity audits, inspections, and authorization reviews
- Prepare security reports, briefings, risk assessments, and recommendations for leadership and customers
- Provide technical guidance and mentorship to cybersecurity personnel
What You Bring
Required Qualifications
- Bachelor's degree in Cybersecurity, Information Assurance, Information Systems, Information Technology, Computer Science, Engineering, or a related field
- Ten (10) years of experience in information assurance, information security, cybersecurity, system security, RMF, compliance, or a related field
- Advanced knowledge of information assurance and cybersecurity principles
- Advanced knowledge of Risk Management Framework (RMF) processes and security authorization requirements
- Knowledge of NIST, DoD, and federal cybersecurity policies, standards, and regulations
- Knowledge of security controls, vulnerability management, risk assessment, and compliance methodologies
- Ability to identify, assess, and mitigate cybersecurity risks and vulnerabilities
- Ability to interpret and apply security policies, standards, and procedures
- Strong analytical, organizational, and problem-solving skills
- Ability to evaluate security control effectiveness and recommend improvements
- Strong written and verbal communication skills
- Ability to communicate effectively with both technical and non-technical audiences
- Ability to prepare and review security documentation, assessments, and reports
- Ability to lead cybersecurity efforts and coordinate activities among multiple stakeholders
- Ability to obtain and maintain a government security clearance if required
- Must meet applicable DoD 8140 workforce qualification requirements if required by contract
Preferred Experience
- Master's degree in Cybersecurity, Information Assurance, Information Systems, Information Technology, Computer Science, Engineering, or a related discipline
- Experience supporting Department of Defense or Federal Government programs
- Experience leading RMF and Assessment & Authorization activities
- Experience developing and maintaining cybersecurity documentation and authorization packages
- Experience supporting continuous monitoring and vulnerability management programs
- Experience conducting cybersecurity assessments, inspections, audits, and compliance reviews
- Experience mentoring cybersecurity and information assurance professionals
Why Join PEMCCO?
- Support critical government and customer missions through strong cybersecurity leadership
- Play a key role in protecting information systems, networks, and sensitive data
- Lead compliance, authorization, and risk management initiatives that impact mission success
- Collaborate with experienced cybersecurity, engineering, and technology professionals
- Expand your expertise across multiple cybersecurity disciplines
- Mentor and support the development of cybersecurity talent
- Build a rewarding career in a collaborative and mission-focused environment
Work Environment
- Professional office and technical work environments
- Work may be performed at company facilities, customer locations, or designated project sites as needed
- Regular use of computers, cybersecurity tools, and communication systems
- Frequent collaboration with engineers, administrators, program leaders, customers, and stakeholders
Benefits
- Medical Insurance
- Dental Insurance
- Vision Insurance
- Paid Time Off
- Paid Holidays
- Employee Assistance Program
- Additional company-sponsored benefits
Apply Today
If you're an experienced cybersecurity professional looking to lead security initiatives, support mission-critical systems, and help organizations manage risk and maintain compliance, we encourage you to apply.
Join PEMCCO and help protect the systems, networks, and information that support mission success.
Equal Opportunity Employer
PEMCCO, Inc. is an equal opportunity employer. The Company does not discriminate on the basis of race, color, sex, sexual orientation, gender identity or expression, religion, national origin, age, disability, genetic information, military or veteran status, pregnancy, childbirth and related medical conditions, or any other characteristic protected by applicable federal, state, or local law.