Sign up to access all features of our service.
  • Job search
  • Favorites
  • Create a CV
    New
  • Salaries
  • Subscriptions

Information Security Risk Specialist

$99k - $225k

BOOZ, ALLEN & HAMILTON, INC.

Information Security Risk Specialist
The Opportunity:

Cyber threats are everywhere, and the constantly evolving nature of these threats can make understanding them seem overwhelming to government agencies. In all of this "cyber noise", how can these organizations understand their risks and how to mitigate them? The answer is you. We need your knowledge as an information security risk spe cia list to help break down complex threats into manageable plans of action.


As an information security risk spe cia list on our team, you'll assist military leaders with discovering their cyber risks, understanding applicable policies , and developing a mitigation plan. You'll gather technical and personnel details from subject matter experts to help with the assessment of the entire threat landscape. You'll learn how to guide your client through a plan of action with presentations, whitepapers, and milestones, and help to translate security concepts so they can make the best decisions to secure their critical systems.

This is your opportunity to build experience in a strategic information security role while developing skills in cybersecurity.

Work with us as we protect our nation's cyber infrastructure.

Join us. The world can't wait.

You Have:
  • 5+ years of experience executing Department of Defense (DoD) Risk Management Framework (RMF) activities for DoD information systems, including across the RMF lifecycle, development and maintenance of authorization artifacts, security control implementation and assessment, Plan of Action and Milestone (POA&M) management, and support of system authorization activities
  • 3+ years of experience with Department of the Navy (DON) RMF, including applying Navy specific RMF processes, policies, procedures, SOPs, and cybersecurity requirements in support of Navy information systems and authorization packages
  • Experience supporting DoD system authorization and Authorization to Operate (ATO) activities
  • Experience using eMASS and ACAS within a DoD environment, including analyzing and prioritizing vulnerability scan results, developing and maintaining hardware and software inventories, tracking vulnerabilities, and supporting remediation activities
  • Experience developing and supporting Security Assessment Plans (SAPs), Security Assessment Reports (SARs), RMF artifacts, control assessments, and authorization packages in accordance with DoD RMF requirements
  • Experience with reviewing, interpreting, and enforcing Security Technical Implementation Guides (STIGs) using STIG Viewer
  • Knowledge of Ports, Protocols, and Services Management (PPSM)
  • Ability to operate in a structured and compliance-driven environment while executing established cybersecurity processes with minimal supervision
  • Secret clearance
  • Bachelor's degree in Cybersecurity, Information Technology, Computer Science, Information Systems, Data Science, or Software Engineering
  • DoD 8140, 752- Cyber Policy and Strategy Planner, Intermediate Certification
Nice If You Have:
  • Top Secret clearance
  • Master's degree
Clearance:

Applicants selected will be subject to a security investigation and may need to meet eligibility requirements for access to classified information ; Secret clearance is required.


Compensation

At Booz Allen, we celebrate your contributions, provide you with opportunities and choices, and support your total well-being. Our offerings include health, life, disability, financial, and retirement benefits, as well as paid leave, professional development, tuition assistance, work-life programs, and dependent care. Our recognition awards program acknowledges employees for exceptional performance and superior demonstration of our values. Full-time and part-time employees working at least 20 hours a week on a regular basis are eligible to participate in Booz Allen's benefit programs. Individuals that do not meet the threshold are only eligible for select offerings, not inclusive of health benefits. We encourage you to learn more about our total benefits by visiting the Resource page on our Careers site and reviewing Our Employee Benefits page.

Salary at Booz Allen is determined by various factors, including but not limited to location, the individual's particular combination of education, knowledge, skills, competencies, and experience, as well as contract-specific affordability and organizational requirements. The projected compensation range for this position is $99,000.00 to $225,000.00 (annualized USD). The estimate displayed represents the typical salary range for this position and is just one component of Booz Allen's total compensation package for employees. This posting will close within 90 days from the Posting Date.

Identity Statement

As part of the hiring process, we will ask you to complete an identity verification process that leverages advanced biometrics and artificial intelligence to ensure authenticity and protect against identity fraud. You are expected to be on camera during interviews and assessments. We reserve the right to take your picture to verify your identity and prevent fraud.

Candidate AI Usage Policy

AI is a part of our daily work at Booz Allen, and we are committed to the responsible and ethical use of AI tools. However, we want to ensure a fair candidate process based on your own skills and knowledge. As part of this commitment, the use of artificial intelligence (AI) or other tools to assist with responses during interviews (whether in-person or virtual) is prohibited unless permission is explicitly provided .


Work Model
Our people-first culture prioritizes the benefits of collaboration, whether it occurs in person or virtually. To support engagement and effective communication, employees working virtually are generally expected to have their cameras on during meetings.
  • Remote : If this position is listed as remote, there may still be occasions when you are required to work in person at a Booz Allen or customer facility.
  • Hybrid : If this position is listed as hybrid, you will be expected to work from a Booz Allen facility frequently, in alignment with leadership expectations and the needs of the role. You may also be required to work from or visit a customer facility.
  • Onsite : If this position is listed as onsite, work will primarily be performed at a Booz Allen office or customer facility, where employees will collaborate directly with colleagues and customers as required by the role.
Commitment to Non-Discrimination

All qualified applicants will receive consideration for employment without regard to disability, status as a protected veteran or any other status protected by applicable federal, state, local, or international law.
Vacancy posted 5 days ago
Similar jobs that could be interesting for youBased on the Information Security Risk Specialist in Maryland vacancy
  • $61.9k - $141k

    Information Security Risk SpecialistThe Opportunity: Cyber threats are everywhere, and the constantly evolving nature of these threats can make...  .... We need your knowledge as an information security risk specialist to help break down complex threats into manageable plans of... 
    Suggested
    Full time
    Contract work
    Part time
    Work at office
    Local area
    Remote work

    Booz Allen Hamilton

    Lexington Park, MD
    4 days ago
  •  ...Infosec Risk Specialist Our client is seeking junior to mid-level InfoSec Risk Specialists. As an information security risk specialist on our team, you'll assist military leaders with discovering their cyber risks, understanding applicable policies, and developing a... 
    Suggested
    Contract work

    Sparks Group

    Maryland
    15 hours ago
  •  ...to the United States Government.  We seek an experienced Information System Security Specialist to serve as a part of ACI’s Government Programs team,...  ...work.  Execute and monitor the Enterprise Protection Risk Management Program Participate in the Garrison level... 
    Suggested
    Contract work
    Work at office

    Augustine Consulting Inc.

    Aberdeen, MD
    3 days ago
  •  ...Diverse Systems Group, LLC is seeking an Information Assurance Specialist to support Walter Reed National Military Medical Center (WRNMMC)’s system security authorization processes in compliance...  ...Defense Health Agency (DHA)-specific Risk Management Framework (RMF)-related... 
    Suggested

    Diverse Systems Group LLC

    Bethesda, MD
    3 days ago
  • Job Description Responsible for providing security and risk analysis of engineering solutions, to include technical solution development,...  ...assists in the identification and implementation of appropriate information security functionality. Interfaces with IT and non-IT... 
    Suggested
    Remote work

    The Chronicle of Higher Education

    Bowie, MD
    5 days ago
  • A university in Maryland seeks a Security Analyst to provide security and risk analysis of engineering solutions. Responsibilities include conducting security...  ...requires a minimum of two years of experience in information security and is open to candidates with a Bachelor’s... 
    Remote job

    Bowie State University

    Bowie, MD
    4 days ago
  •  ...Description Job Description Lead Information Assurance (IA)/ Security SpecialistFull Time Ft. Meade,...  ...seeking an experienced Lead IA / Security Specialist to support a program in the Fort...  ...security requirements, and guiding risk management activities across IT programs... 
    Contract work

    Semper Valens Solutions

    Maryland, MD
    3 days ago
  • $125k - $155k

     ...Senior Technical Security Specialist Ocean Bay, a subsidiary of Three Saints Bay, LLC, and a Federal Government Contractor industry leader...  ...technical security services to ensure the security of DOE information. Develop and present technical security related training to... 
    For contractors

    Clearance Jobs

    Germantown, MD
    5 days ago
  • $127.5k - $172.5k

     ...Required: None Job Family: Cyber and IT Risk Management Job Qualifications: Skills: Information Assurance, Information Systems, Information...  ...discovering new ways to apply the latest technologies securely and expertly. By owning your opportunity at GDIT... 
    Full time
    Temporary work
    Immediate start
    Remote work
    Worldwide
    Flexible hours

    General Dynamics Information Technology

    Annapolis Junction, MD
    3 days ago
  • $105k - $130k

     ...learn, and work. CampusGuard, a Nelnet company, provides information security and privacy consulting and compliance services primarily for...  ...scope verification, and incident response. Understanding of risk assessments and targeted risk analyses. Technical understanding... 
    Full time
    Temporary work
    Fixed term contract
    Local area
    Remote work
    Work from home
    Home office

    Nelnet

    Annapolis, MD
    2 days ago
  •  ...Cyber And It Security Risk AnalystLocation: Bethesda, MDContract: 12 MonthsPosition SummaryWe are seeking a Cyber and Information Security Risk Analyst to join our growing professional services team. As a Cyber and IT Security Risk Analyst, you will assist with identifying... 
    For contractors

    InteliX Systems

    Bethesda, MD
    1 day ago
  • The CACI International Inc is seeking a Security Support Assistant to maintain clearance records and process clearance documents for...  ...government contract. You will help protect classified government information and monitor security procedures to ensure compliance across... 
    Contract work

    CACI International Inc

    Annapolis, MD
    5 days ago
  •  ...SOMEONE WHO HAS WORKED WITH THE SERVICENOW GRC APPLICATION Overview: ~ The GRC Analyst supports the administration of Information Security Governance, Risk, and Compliance programs, including policy exception management and enterprise risk register activities using... 
    Long term contract
    Internship

    System One

    Rockville, MD
    3 days ago
  • ASSYST, Inc. is seeking an Information Security Governance, Risk & Compliance (GRC) Analyst to support our client in administering and maintaining an enterprise GRC program. This role focuses on policy exceptions and maintaining the risk register using ServiceNow IRM, under... 

    ASSYST, Inc.

    Rockville, MD
    3 days ago
  • $105.4k - $207.8k

    Position Summary Cisco Network Security Engineer/ Senior Consultant, Strategy, Growth, and TransformationDeloitte’s Cyber business...  ...architectures, integrating Cisco platforms with security information and event management (SIEM) tools and automation solutions, and... 
    Work experience placement
    Local area
    Visa sponsorship

    Deloitte

    Baltimore, MD
    2 days ago
  • $110.5k - $149.5k

     ...Required: MBI (T2) Job Family: Cyber and IT Risk Management Job Qualifications: Skills: IT Security Services, IT Security Support, IT System...  ...our nation for the future. Our work depends on a Information Security Analyst Sr Advisor joining our team to... 
    Full time
    Temporary work
    Immediate start
    Remote work
    Work from home
    Worldwide
    Monday to Friday
    Flexible hours

    General Dynamics Information Technology

    Maryland
    3 days ago
  • $94.49k - $131.16k

     ...is a place you can engage in meaningful work and grow your career. Let’s see what we can achieve. Together.SummaryThe Senior Information Security Analyst is responsible for identifying, investigating, and addressing both internal and external threats. This position... 
    Full time
    Work at office
    Remote work
    Relocation
    Visa sponsorship
    Relocation package

    DLA Piper

    Baltimore, MD
    2 days ago
  • $55 - $60 per hour

    DescriptionPosition Overview The Information Security Analyst II (GRC) provides support for Governance, Risk, and Compliance activities aligned to NIST CSF, NIST SP 800-53, HIPAA Security Rule, and HITRUST CSF, PCI-DSS. The role supports risk assessments, audit readiness... 
    Contract work
    Temporary work

    TEKsystems

    Columbia, MD
    4 days ago
  •  ...VT Group (VTG) is seeking a Senior Information Review and Release Analyst in Fort Meade, MD. The role involves reviewing classified documents, conducting redactions under FOIA and Privacy Act guidelines, and making recommendations for document release. Candidates must... 

    VT Group (VTG)

    Maryland
    5 days ago
  •  ...eSimplicity is seeking an Information Security Analyst to support security controls across systems with varying maturity levels. You will drive ATO readiness, coordinate with product teams and ISSOs, and maintain security artifacts while monitoring posture and responding... 

    eSimplicity Inc

    Maryland
    1 day ago
  • ASSYST is seeking an Information Security Governance, Risk & Compliance (GRC) Analyst to support our client in administering and maintaining an established enterprise Information Security Governance, Risk, and Compliance (GRC) program. This role will focus on managing Information... 
    Work at office
    Local area

    Assyst

    Rockville, MD
    3 days ago
  •  ...to the business. Job Description: Security Operations & Tooling Monitor, tune, and...  ...post-incident reviews Governance, Risk & Compliance (GRC) ~ Support ongoing...  ...QualificationsRequired ~3–5 years of experience in an information security role with exposure to both... 

    Jobiqo

    Annapolis, MD
    3 days ago
  •  ...Create/Update all client security deliverables (SSP, CP, ISRA, CP, PTA/PIA, etc.) Work with team members to ensure security functions are...  ...functional and tabletop testing required) Experience in performing risk assessments. Experience running meetings and holding team... 

    Jobtailor

    Annapolis, MD
    2 days ago
  •  ...Define, develop, and/or implement technology controls and information security policies, programs, and tools Provide specialized expertise and guidance on risk assessment, gap identification, and security solutions Lead and coordinate real-time analysis of cyber incidents... 
    Work at office
    Rotating shift

    Jobtailor

    Laurel, MD
    2 days ago
  •  ...Rct Systems, Inc. is seeking senior-level Information Review and Release Analysts to support an Intelligence Community client at Fort Meade. Analysts perform first-level reviews of classified documents, researching context and content to determine appropriate redactions... 
    Immediate start
    Flexible hours

    RCT Systems

    Maryland
    5 days ago
  • $105k - $115k

     ...or an approved equivalent AI solution. DSA is hiring a Senior Information Security Analyst. This is a full-time position supporting a customer...  ...candidate will serve as a subject matter expert with regards to the Risk Management Framework (RMF) and all associated information... 
    Full time
    Contract work
    Work at office
    Remote work
    Flexible hours

    Data Systems Analysts

    Annapolis, MD
    1 day ago
  • $100k - $121k

     ...significant and complex challenges in science, security and sustainability. Our people apply...  ...access reviews and recertifications. Risk Assessment, Auditing & Monitoring:...  ...Ability to present complex technical information to a non-technical audience. Strong collaboration... 
    Hourly pay
    Contract work
    Local area

    Amentum

    Annapolis, MD
    3 days ago
  •  ...seeking an InfoSec Analyst II, Trust to operate and enhance our security compliance program across SOC 2, ISO 27001, and client reviews....  ...will translate complex compliance data into clear customer responses, maintain records, and support risk assessments, #J-18808-Ljbffr... 

    P2P

    Annapolis, MD
    5 days ago
  • $131.3k - $237.35k

    Leidos is seeking Information Security Professionals for programs in our Intelligence Sector, Cyber & Analytics Business Area (CABA). Our talented...  ...processing classified information and perform vulnerability/risk assessments to support certification and accreditation.... 
    Full time
    Immediate start
    Flexible hours

    Leidos

    Annapolis Junction, MD
    5 days ago
  • Salute is seeking a Data Center Security Officer to safeguard client facilities, patrolling interior and exterior areas, monitoring CCTV and alarms, controlling access, and preparing incident reports for hyperscale environments. The ideal candidate communicates professionally... 
    Shift work

    Salute

    Frederick, MD
    2 days ago

Do you want to receive more vacancies?

Subscribe and receive similar vacancies to Information Security Risk Specialist. Be the first to apply!