New

Senior Information Security Specialist

Ashburn, VA (Hybrid)

Information Security Specialist Officer, Technical Lead, #1117

AWS Security • RMF & ATO • NIST 800-53 • Cloud Application Security

Clearance: Active CBP, DHS, or Top Secret Clearance required
Work Arrangement: Hybrid – onsite 3 days/week during standard business hours in Ashburn, VA

About the Role

Dev Technology Group is seeking a Senior Information Security Specialist to lead and develop a mid-sized team of ISSOs supporting the security, compliance, and authorization of mission-critical federal applications and information systems hosted in AWS.

This is a hands-on technical leadership role combining people leadership, federal cybersecurity expertise, and direct collaboration with government and technical stakeholders. You will mentor junior and mid-level ISSOs while partnering with system owners, developers, architects, cloud/infrastructure engineers, security professionals, and government stakeholders throughout the system development lifecycle.

You will provide practical security guidance for AWS-hosted applications, lead Risk Management Framework (RMF) and Authority to Operate (ATO) activities, oversee vulnerability management and continuous monitoring, and translate federal cybersecurity requirements into actionable guidance for technical teams.

What You'll Do

  • Lead, mentor, and develop a team of ISSOs by establishing priorities, providing technical direction and coaching, and promoting accountability and consistent security practices.
  • Lead and oversee RMF, ATO, security authorization, compliance, vulnerability management, and continuous monitoring activities across a portfolio of federal systems and applications.
  • Partner with ISSMs, system owners, assessors, developers, architects, engineers, and government stakeholders to maintain authorizations, identify risks, and address security requirements.
  • Lead vulnerability management efforts, prioritizing remediation, developing mitigation strategies, and tracking corrective actions through resolution.
  • Develop, assess, document, and support implementation of security controls aligned with FISMA, NIST 800-53, DHS, and client requirements.
  • Prepare and maintain security and authorization documentation, including SSPs, ISAs, audit artifacts, and RMF documentation.
  • Provide cybersecurity guidance for applications and systems deployed in AWS and integrate security throughout the software development lifecycle.
  • Validate security implementation through technical reviews, discussions, interviews, assessments, and tabletop exercises.
  • Support security audits, assessments, compliance reviews, and reviews of information systems and network connections.
  • Interpret federal and client security policies and translate requirements into practical guidance for technical and development teams.
  • Identify and escalate security risks, communicate priorities and remediation status, and provide clear visibility to Dev Technology leadership and government stakeholders.
  • Develop and present security metrics, status reports, risk assessments, and executive briefings.
  • Establish and improve security processes, procedures, templates, dashboards, and workflows to improve consistency, accountability, and efficiency across the ISSO team.
  • Build trusted relationships with government clients through proactive communication, collaboration, and face-to-face engagement.

Required Education, Experience & Skills

  • Bachelor's degree and 7+ years of experience securing federal information systems.
  • Demonstrated experience leading and mentoring information security professionals, including junior and mid-level ISSOs.
  • Experience leading cybersecurity activities in a federal government client environment and working directly with government stakeholders.'
  • Strong working knowledge of NIST Risk Management Framework (RMF) and experience supporting federal systems through security authorization and ATO activities.
  • Experience developing, implementing, assessing, or documenting security controls aligned with FISMA and NIST 800-53.
  • Experience with vulnerability management, continuous monitoring, security assessments, audits, or compliance reviews for federal systems.
  • Experience providing cybersecurity guidance for AWS-hosted applications and systems.
  • Strong understanding of modern information systems and their technical security considerations.
  • Ability to work effectively with developers, architects, engineers, government stakeholders, and technical and non-technical audiences.
  • Strong written and verbal communication skills, including the ability to communicate security risks and technical findings and develop/present security documentation and executive briefings.
  • Ability to establish priorities, manage competing demands, independently manage security activities, and escalate issues appropriately.
  • Proactive, solutions-oriented approach to identifying risks and improving security practices.
  • Current CBP, DHS, or Top Secret Clearance.
  • Ability to work onsite 3 days per week in Ashburn, VA during standard business hours.
  • Cybersecurity certification such as CISSP, CISM, GIAC, Security+, or another recognized cybersecurity certification.

Preferred Education, Experience & Skills

  • Experience developing or supporting RMF and authorization artifacts, including SSPs, ISAs, PTAs, ATTs, POA&Ms, and related documentation.
  • Experience partnering with application development, cloud engineering, and DevSecOps teams to integrate security throughout the SDLC.
  • Experience working in an Agile software development environment using Jira or similar platforms.
  • Experience with GRC tools such as CSAM or similar platforms supporting authorization, compliance, vulnerability management, and security activities.
  • Understanding of AI concepts and practical applications of AI for cybersecurity operations, risk analysis, compliance, or security program management.

 

Our estimated salary range for this position is $88,000 - $ 150,000. This presented salary range is not a guarantee of compensation or salary. Offered salary is based on experience, geographic location, and possibly contractual requirements as appropriate to the role. *Salary could fall outside of this range. 

 

 

 

 

 

 

Who We Are

Dev Technology is a growing IT company with an employee-centric culture that works on mission-critical projects for the federal government. We partner with our federal customers to deliver technology services and solutions, and to drive our client’s missions forward through innovation. We use Agile and DevSecOps principles to provide services including application development, biometrics and identity management, cloud and infrastructure optimization, IT and legacy modernization, and data management.   

As a Washington Post Top Workplace award winner for the past THIRTEEN years in a row, the Top Workplaces USA for the past five years, and a recipient of the Companies As Responsive Employers (CARE) Award for the past six years, Dev Technology employees enjoy:   

  • Generous and flexible time-off policy
  • Flexible work schedules and telework options, including remote work availability for eligible projects
  • Career development opportunities including a mentorship program, technical and management training through Dev University, hands-on learning through DevLab, tuition reimbursement, and paid training opportunities
  • Industry-leading benefits including a choice of two health plans that include dental and vision, flexible spending account, commuter benefits, life insurance, and more
  • 401K matching with a 5% matching contribution
  • Regular team and company social events including our annual party, happy hours, fitness challenges, and more  
  • A focus on community engagement including company wide support activities, employer match for donations, and time off for volunteer efforts
  • To learn more about working at Dev Technology, visit Working At Dev Technology Group

 

Equal Opportunity Employer / Individuals with Disabilities / Protected Veterans

 

 

 

 

Dev Technology Group operates in the following states: AL, AR, AZ, CO, DC, FL, GA, ID, IL, IN, MD, MA, ME, MI, MN, MO, MS, NC, NJ, OH, OR, PA, SC, TN, TX, VA, WV.

Create a Job Alert

Interested in building your career at Dev Technology? Get future opportunities sent straight to your email.

Apply for this job

*

indicates a required field

Phone
Resume/CV*

Accepted file types: pdf, doc, docx, txt, rtf

Cover Letter

Accepted file types: pdf, doc, docx, txt, rtf


Education

Select...
Select...
Select...

Select...
Select...
If you currently hold a clearance, please indicate which security clearance you currently hold: *
Select...
Select...
Select...
Select...
Select...
Select...
Select...
Select...
Select...
Select...
Select...
Select...
Select...
Select...
Select...
Select...

Message and data rates may apply, depending on your mobile phone service plan. At any time you can get more help by replying HELP to these texts, or you can opt out completely by replying STOP.

Candidate Privacy Policy & Terms of Service

 

Select...

Voluntary Self-Identification

For government reporting purposes, we ask candidates to respond to the below self-identification survey. Completion of the form is entirely voluntary. Whatever your decision, it will not be considered in the hiring process or thereafter. Any information that you do provide will be recorded and maintained in a confidential file.

As set forth in Dev Technology’s Equal Employment Opportunity policy, we do not discriminate on the basis of any protected group status under any applicable law.

If you believe you belong to any of the categories of protected veterans listed below, please indicate by making the appropriate selection. As a government contractor subject to the Vietnam Era Veterans Readjustment Assistance Act (VEVRAA), we request this information in order to measure the effectiveness of the outreach and positive recruitment efforts we undertake pursuant to VEVRAA. Classification of protected categories is as follows:

A "disabled veteran" is one of the following: a veteran of the U.S. military, ground, naval or air service who is entitled to compensation (or who but for the receipt of military retired pay would be entitled to compensation) under laws administered by the Secretary of Veterans Affairs; or a person who was discharged or released from active duty because of a service-connected disability.

A "recently separated veteran" means any veteran during the three-year period beginning on the date of such veteran's discharge or release from active duty in the U.S. military, ground, naval, or air service.

An "active duty wartime or campaign badge veteran" means a veteran who served on active duty in the U.S. military, ground, naval or air service during a war, or in a campaign or expedition for which a campaign badge has been authorized under the laws administered by the Department of Defense.

An "Armed forces service medal veteran" means a veteran who, while serving on active duty in the U.S. military, ground, naval or air service, participated in a United States military operation for which an Armed Forces service medal was awarded pursuant to Executive Order 12985.

Select...

Voluntary Self-Identification of Disability

Form CC-305
Page 1 of 1
OMB Control Number 1250-0005
Expires 07/31/2029

Why are you being asked to complete this form?

We are a federal contractor or subcontractor. The law requires us to provide equal employment opportunity to qualified people with disabilities. We have a goal of having at least 7% of our workers as people with disabilities. The law says we must measure our progress towards this goal. To do this, we must ask applicants and employees if they have a disability or have ever had one. People can become disabled, so we need to ask this question at least every five years.

Completing this form is voluntary, and we hope that you will choose to do so. Your answer is confidential. No one who makes hiring decisions will see it. Your decision to complete the form and your answer will not harm you in any way. If you want to learn more about the law or this form, visit the U.S. Department of Labor’s Office of Federal Contract Compliance Programs (OFCCP) website at www.dol.gov/ofccp.

How do you know if you have a disability?

A disability is a condition that substantially limits one or more of your “major life activities.” If you have or have ever had such a condition, you are a person with a disability. Disabilities include, but are not limited to:

  • Alcohol or other substance use disorder (not currently using drugs illegally)
  • Autoimmune disorder, for example, lupus, fibromyalgia, rheumatoid arthritis, HIV/AIDS
  • Blind or low vision
  • Cancer (past or present)
  • Cardiovascular or heart disease
  • Celiac disease
  • Cerebral palsy
  • Deaf or serious difficulty hearing
  • Diabetes
  • Disfigurement, for example, disfigurement caused by burns, wounds, accidents, or congenital disorders
  • Epilepsy or other seizure disorder
  • Gastrointestinal disorders, for example, Crohn's Disease, irritable bowel syndrome
  • Intellectual or developmental disability
  • Mental health conditions, for example, depression, bipolar disorder, anxiety disorder, schizophrenia, PTSD
  • Missing limbs or partially missing limbs
  • Mobility impairment, benefiting from the use of a wheelchair, scooter, walker, leg brace(s) and/or other supports
  • Nervous system condition, for example, migraine headaches, Parkinson’s disease, multiple sclerosis (MS)
  • Neurodivergence, for example, attention-deficit/hyperactivity disorder (ADHD), autism spectrum disorder, dyslexia, dyspraxia, other learning disabilities
  • Partial or complete paralysis (any cause)
  • Pulmonary or respiratory conditions, for example, tuberculosis, asthma, emphysema
  • Short stature (dwarfism)
  • Traumatic brain injury
Select...

PUBLIC BURDEN STATEMENT: According to the Paperwork Reduction Act of 1995 no persons are required to respond to a collection of information unless such collection displays a valid OMB control number. This survey should take about 5 minutes to complete.


We use Greenhouse’s AI-powered Talent Matching tool to compare your application against our job requirements. We do NOT use AI to make final applicant determinations regarding candidacy. Talent Matching does not replace our application/resume review process.

Learn more