信息保障专员 - 需要安全许可
Information Assurance Specialist - Clearance Required
LMI正在寻找一名信息保障专家,以支持陆军采购、培训和准备(AT&R)部门对陆军合同编写系统(ACWS)的持续维护和增强。ACWS基于Appian平台构建。该职位将支持网络安全、合规性、风险管理及系统授权活动,以确保ACWS符合相关的陆军和国防部安全要求。
LMI是一家新型的数字解决方案提供商,致力于通过创新和速度加速政府影响。LMI提前投资于技术和原型开发,在需求出现之前就为联邦机构提供商用级平台和任务就绪的人工智能,实现商业速度。
凭借我们任务就绪的技术和解决方案、在联邦部署方面的丰富经验以及战略关系,我们高效且有效地提升政府成果。LMI专注于敏捷性和协作,服务于国防、太空、医疗保健和能源领域,帮助机构应对复杂性并超越变化。LMI总部位于弗吉尼亚州泰森斯,致力于交付能够加强任务并推动持久价值的影响结果。
职责
信息保障专家将与系统管理员、工程师、开发人员、DevSecOps人员、项目经理和安全相关方密切合作,以在关键任务的企业应用环境中保持强大的安全态势。
- 支持ACWS及其相关企业环境的信息保障和网络安全活动。
- 协助根据NIST、RMF、STIG和适用的国防部要求实施和维护安全控制措施。
- 支持系统安全授权、评估、认证和运营授权(ATO)活动。
- 进行安全评估、漏洞审查、合规性评估和安全控制审查。
- 监控安全发现,并与系统、应用、基础设施和DevSecOps团队协调修复活动。
- 编写和维护安全文档,包括系统安全计划(SSPs)、POA&Ms、政策、程序、评估资料和持续监控文档。
- 协助持续监控活动、安全指标、状态报告和网络安全报告要求。
- 支持安全审计、检查、客户评估以及对发现的问题作出响应。
- 评估系统和应用程序的安全性,提出改进建议。
查看英文原文
Overview
LMI is seeking an Information Assurance Specialist to support Army Acquisition, Training, and Readiness (AT&R) in the sustainment and enhancement of the Army Contract Writing System (ACWS). ACWS is built on the Appian Platform. This role will support cybersecurity, compliance, risk management, and system authorization activities to help ensure ACWS meets applicable Army and DoD security requirements.
LMI is a new breed of digital solutions provider dedicated to accelerating government impact with innovation and speed. Investing in technology and prototypes ahead of need, LMI brings commercial-grade platforms and mission-ready AI to federal agencies at commercial speed.
Leveraging our mission-ready technology and solutions, proven expertise in federal deployment, and strategic relationships, we enhance outcomes for the government, efficiently and effectively. With a focus on agility and collaboration, LMI serves the defense, space, healthcare, and energy sectors—helping agencies navigate complexity and outpace change. Headquartered in Tysons, Virginia, LMI is committed to delivering impactful results that strengthen missions and drive lasting value.
Responsibilities
The Information Assurance Specialist will work closely with system administrators, engineers, developers, DevSecOps personnel, program managers, and security stakeholders to maintain a strong security posture across a mission-critical enterprise application environment.
- Support information assurance and cybersecurity activities for ACWS and associated enterprise environments.
- Assist with implementation and maintenance of security controls in accordance with NIST, RMF, STIG, and applicable DoD requirements.
- Support system security authorization, assessment, accreditation, and Authority to Operate (ATO) activities.
- Conduct security assessments, vulnerability reviews, compliance evaluations, and security control reviews.
- Monitor security findings and coordinate remediation activities with system, application, infrastructure, and DevSecOps teams.
- Develop and maintain security documentation including System Security Plans (SSPs), POA&Ms, policies, procedures, assessment artifacts, and continuous monitoring documentation.
- Assist with continuous monitoring activities, security metrics, status reporting, and cybersecurity reporting requirements.
- Support security audits, inspections, customer assessments, and responses to identified findings.
- Evaluate system and application changes to ensure continued compliance with established security requirements.
- Work with stakeholders to identify cybersecurity risks and support development of practical mitigation strategies.
- Support incident response and security investigations as needed and participate in root cause and remediation activities.
- Stay current on evolving cybersecurity threats, regulations, security controls, and federal best practices relevant to ACWS.
Qualifications
MINIMUM QUALIFICATIONS:
- Bachelor's degree in Cybersecurity, Information Technology, Computer Science, Information Systems, Engineering, or related field; equivalent experience may be considered.
- 5-10+ years of experience supporting Information Assurance, cybersecurity, information security, or cyber risk management programs.
- Knowledge of NIST cybersecurity frameworks and Risk Management Framework (RMF) processes.
- Experience developing and maintaining security documentation and compliance artifacts.
- Experience supporting vulnerability management, security assessments, and compliance activities.
- Understanding of security controls, risk management, secure configuration, and cybersecurity best practices.
- Strong analytical, organizational, writing, and communication skills.
- Active Secret clearance or ability to obtain and maintain one.
- U.S. citizenship required.
DESIRED SKILLS
- Active Secret security clearance.
- Active DoD 8140-aligned cybersecurity certification such as CISSP, CISM, or Security+.
- Security certifications such as Security+, CISSP, CAP, CISM, or CASP+.
- Experience supporting Army or DoD programs and security requirements.
- Demonstrated experience leading or coordinating cybersecurity, RMF, ATO, or compliance activities for federal or DoD systems.
- Experience with eMASS, ACAS, SCAP, STIGs, or related cybersecurity tools.
- Practical experience with NIST 800-53, NIST 800-171, CMMC, FedRAMP, or comparable federal security requirements.
- Experience working in Agile or DevSecOps environments and integrating security tasks into delivery processes.
- Experience supporting cloud security initiatives within AWS, Azure, or similar environments.
- Experience with Appian-based applications or Appian Cloud security and configuration practices preferred.
- SAFe certification such as SAFe Practitioner, Architect, or DevOps.
- Experience supporting enterprise platform teams and shared services across multiple delivery teams.
The target salary range for this position goes up to $165,000.
The salary range displayed represents the typical salary range for this position and is not a guarantee of compensation. Individual salaries are determined by various factors including, but not limited to location, internal equity, business considerations, client contract requirements, and candidate qualifications, such as education, experience, skills, and security clearances.
Job Locations
US-RemoteOriginally posted on Himalayas