Sign up to access all features of our service.
  • Job search
  • Favorites
  • Create a CV
    New
  • Salaries
  • Subscriptions

Information Security Risk Specialist

$99k - $225k

BOOZ, ALLEN & HAMILTON, INC.

Information Security Risk Specialist
The Opportunity:

Cyber threats are everywhere, and the constantly evolving nature of these threats can make understanding them seem overwhelming to government agencies. In all of this "cyber noise," how can these organizations understand their risks and how to mitigate them? The answer is you. We need your knowledge as an information security risk specialist to help break down complex threats into manageable plans of action.


As an information security risk specialist on our team, you'll assist military leaders with discovering their cyber risks, understanding applicable policies, and developing a mitigation plan. You'll gather technical and personnel details from subject matter experts to help with the assessment of the entire threat landscape. You'll learn how to guide your client through a plan of action with presentations, white papers, and milestones, and help to translate security concepts so they can make the best decisions to secure their critical systems.

This is your opportunity to build experience in a strategic information security role while developing skills in cybersecurity.

Work with us as we protect our nation's cyber infrastructure.

Join us. The world can't wait.

You Have:
  • 7+ years of experience leading and executing Navy Risk Management Framework (RMF), including full lifecycle implementation across all RMF steps, application of Navy SOPs and cybersecurity directives, and ownership of Plans of Action and Milestones (POA&Ms)
  • Experience with eMASS and ACAS, including analysis and prioritization of scan results, development and maintenance of hardware and software inventories, and vulnerability management using SCAP, VRAM and HBSS
  • Experience reviewing, interpreting, and enforcing Security Technical Implementation Guides (STIGs) using STIG Viewer, and a strong understanding of Ports, Protocols, and Services Management (PPSM)
  • Experience developing and supporting Security Assessment Plans (SAPs) and Security Assessment Reports (SARs) in alignment with Navy RMF requirements
  • Ability to operate in a structured and compliance-driven environment while executing established cybersecurity processes with minimal supervision
  • Secret clearance
  • Bachelor's degree
  • Current DoD 8140, 752- Cyber Policy and Strategy Planner, Advance, Certification
Nice If You Have:
  • Top Secret clearance
  • Master's degree
Clearance:

Applicants selected will be subject to a security investigation and may need to meet eligibility requirements for access to classified information; Secret clearance is required.

Compensation

At Booz Allen, we celebrate your contributions, provide you with opportunities and choices, and support your total well-being. Our offerings include health, life, disability, financial, and retirement benefits, as well as paid leave, professional development, tuition assistance, work-life programs, and dependent care. Our recognition awards program acknowledges employees for exceptional performance and superior demonstration of our values. Full-time and part-time employees working at least 20 hours a week on a regular basis are eligible to participate in Booz Allen's benefit programs. Individuals that do not meet the threshold are only eligible for select offerings, not inclusive of health benefits. We encourage you to learn more about our total benefits by visiting the Resource page on our Careers site and reviewing Our Employee Benefits page.

Salary at Booz Allen is determined by various factors, including but not limited to location, the individual's particular combination of education, knowledge, skills, competencies, and experience, as well as contract-specific affordability and organizational requirements. The projected compensation range for this position is $99,000.00 to $225,000.00 (annualized USD). The estimate displayed represents the typical salary range for this position and is just one component of Booz Allen's total compensation package for employees. This posting will close within 90 days from the Posting Date.

Identity Statement

As part of the hiring process, we will ask you to complete an identity verification process that leverages advanced biometrics and artificial intelligence to ensure authenticity and protect against identity fraud. You are expected to be on camera during interviews and assessments. We reserve the right to take your picture to verify your identity and prevent fraud.

Candidate AI Usage Policy

AI is a part of our daily work at Booz Allen, and we are committed to the responsible and ethical use of AI tools. However, we want to ensure a fair candidate process based on your own skills and knowledge. As part of this commitment, the use of artificial intelligence (AI) or other tools to assist with responses during interviews (whether in-person or virtual) is prohibited unless permission is explicitly provided .


Work Model
Our people-first culture prioritizes the benefits of collaboration, whether it occurs in person or virtually. To support engagement and effective communication, employees working virtually are generally expected to have their cameras on during meetings.
  • Remote : If this position is listed as remote, there may still be occasions when you are required to work in person at a Booz Allen or customer facility.
  • Hybrid : If this position is listed as hybrid, you will be expected to work from a Booz Allen facility frequently, in alignment with leadership expectations and the needs of the role. You may also be required to work from or visit a customer facility.
  • Onsite : If this position is listed as onsite, work will primarily be performed at a Booz Allen office or customer facility, where employees will collaborate directly with colleagues and customers as required by the role.
Commitment to Non-Discrimination

All qualified applicants will receive consideration for employment without regard to disability, status as a protected veteran or any other status protected by applicable federal, state, local, or international law.
Vacancy posted 4 days ago
Similar jobs that could be interesting for youBased on the Information Security Risk Specialist in Maryland vacancy
  • $99k - $225k

    Information Security Risk Specialist page is loaded## Information Security Risk Specialistlocations: St Inigoes, MDtime type: Full timeposted on: Posted Todaytime left to apply: End Date: July 8, 2026 (30+ days left to apply)job requisition id: R0237489Information Security... 
    Suggested
    Full time
    Contract work
    Part time
    Work at office
    Local area
    Remote work

    Booz Allen Hamilton

    Annapolis, MD
    3 days ago
  •  ...Information Systems Security Specialist (contingent 034) Job Category: Operations Requisition Number: INFOR001845 Posted: March 31, 2026 Full-...  ...work. Execute and monitor the Enterprise Protection Risk Management Program Recommend modification(s) to existing... 
    Suggested
    Full time
    Work experience placement
    Work at office
    Local area

    SPS Commerce

    Aberdeen Proving Ground, MD
    3 days ago
  •  ...Senior Information System Security Specialist TriTech Enterprise Systems (TriTech) is seeking a Senior Information System Security Specialist to support...  ...testing reports, including executive summaries, risk ratings, proof-of-concept evidence, and actionable remediation... 
    Suggested
    Contract work
    Flexible hours

    TriTech Enterprise

    Baltimore, MD
    4 days ago
  •  ...Summary Arlo Solutions (Arlo) is an information technology consulting services company...  ...Description: The Information Security Specialist III supports the National Oceanic and...  ...Atmospheric Administration (NOAA) Internal Risk Management Program (IRMP), providing advanced... 
    Suggested
    Contract work
    For contractors
    Work at office

    Arlo Solutions

    Silver Spring, MD
    8 hours ago
  •  ...Information System Security Specialist - Level II ACI is a professional services provider of engineering and technical services to the United States...  ...work. Execute and monitor the Enterprise Protection Risk Management Program Participate in the Garrison level... 
    Suggested
    Contract work
    Work experience placement
    Work at office
    Local area

    Augustine Consulting

    Baltimore, MD
    2 days ago
  • Job Description Responsible for providing security and risk analysis of engineering solutions, to include technical solution development,...  ...assists in the identification and implementation of appropriate information security functionality. Interfaces with IT and non-IT... 
    Remote work

    The Chronicle Of Higher Education, Inc.

    Bowie, MD
    4 days ago
  • $91k - $125k

     ...Information Security, Risk, and Compliance Consultant California, US residents click here. The job details are as follows: We are the first publicly-traded biotech or pharmaceutical company to take the form of a public benefit corporation. Our public benefit purpose... 
    Temporary work
    Work experience placement
    2 days per week

    IVIVA Medical

    Silver Spring, MD
    1 day ago
  • Inside Higher Ed is seeking an Information Assurance (IA) Security Specialist for Bowie State University. The role involves performing security assessments, implementing policies, and coordinating with data stewards. Candidates should have at least two years of experience... 
    Remote job

    Inside Higher Ed

    Bowie, MD
    5 days ago
  • A leading cyber technology firm is seeking an Information Security Risk Specialist in Maryland. The ideal candidate will possess at least 7 years of experience in executing Navy Risk Management Framework (RMF). You will assist military leaders in assessing cyber risks,... 

    Booz Allen Hamilton

    Annapolis, MD
    3 days ago
  • A university in Maryland seeks a Security Analyst to provide security and risk analysis of engineering solutions. Responsibilities include conducting security...  ...requires a minimum of two years of experience in information security and is open to candidates with a Bachelor’s... 
    Remote job

    Bowie State University

    Bowie, MD
    3 days ago
  •  ...Systems Plus today. Position Details Position Title Information Assurance/Security Specialist - Level II-Charleston Position Type Full Time, Onsite...  ...and system administrators to address vulnerabilities and risks. Develop and maintain system security plans, security... 
    Full time
    Contract work
    For contractors
    Worldwide

    Systems Plus, Inc.

    Rockville, MD
    1 day ago
  •  ...Lead Information Assurance (IA)/ Security Specialist Full Time Ft. Meade, MD Secret clearance **This position is contingent upon contract award**...  ...and organizational security requirements, and guiding risk management activities across IT programs. Key Responsibilities... 
    Full time
    Contract work

    Semper Valens Solutions

    Maryland
    3 days ago
  • Tactibit Technologies provides innovative information technology, cybersecurity, and cloud...  ...we do. About the Information Security Compliance Specialist position We are looking for a talented...  ...and maintain effective security and risk management programs on complex government... 
    Flexible hours

    Tactibit Technologies LLC

    Suitland, MD
    3 days ago
  •  ...Cyber And It Security Risk Analyst Location: Bethesda, MD Contract: 12 Months Position Summary We are seeking a Cyber and Information Security Risk Analyst to join our growing professional services team. As a Cyber and IT Security Risk Analyst, you will assist... 
    Contract work
    For contractors

    InteliX Systems

    Bethesda, MD
    3 days ago
  •  ...Information Systems Security Expert (ISSE) (Mid to Senior Level) Location: Suitland, Maryland Clearance: TS/SCI Salary: Highly Competitive...  .... Assesses and mitigates system security threats/risks throughout the program life cycle. Contributes to the security... 

    Fullscope

    Suitland, MD
    3 days ago
  • Peraton, located in Maryland, is seeking an Information Systems Security Officer (ISSO) to join our cybersecurity team. The ISSO will oversee operational...  ...security measures, manage security compliance, and perform risk assessments. Candidates must possess a Bachelor’s degree... 

    Peraton

    Annapolis, MD
    5 days ago
  • $110k - $125k

     ...live, learn, and work. CampusGuard, a Nelnet company, provides information security and privacy consulting and compliance services primarily for...  ...scope verification, and incident response. Understanding of risk assessments and targeted risk analyses. Technical... 
    Temporary work
    Fixed term contract
    Local area
    Remote work
    Work from home
    Home office

    Nelnet

    Annapolis, MD
    5 days ago
  • The Maryland Department of Information Technology is seeking an analyst for its Third-Party Risk Management program. This role involves developing vendor assessments and ensuring compliance with state security standards. Qualified candidates will have four years of experience... 

    Maryland Department of Information Technology

    Crownsville, MD
    3 days ago
  •  ...DatamanUSA is looking for a Cyber Risk & Compliance Analyst for our direct client...  ...Abilities: *) Hands-on experience of cyber security and privacy industry, including the...  ...integrity and availability of sensitive information. *) Hands-on experience working knowledge... 
    Work experience placement

    Dataman Ltd

    Rockville, MD
    1 day ago
  •  ...new ways to apply the latest technologies securely and expertly. By owning your opportunity...  ...may include: Acting as an appointed Information System Security Officer (ISSO) for IC cyber...  ...timely progression through the clients’ Risk Management Framework (RMF) to the... 

    General Dynamics Information Technology

    Annapolis, MD
    5 days ago
  • As the state’s IT leader, DoIT manages information technology and telecommunications services...  ..., ensuring the State of Maryland is more secure, productive, and accessible. Main Purpose...  ...Information Technology’s (DoIT) Third-Party Risk Management (TPRM) program while providing... 
    Contract work
    For contractors
    Work experience placement
    Work at office
    Local area

    Maryland Department of Information Technology

    Crownsville, MD
    3 days ago
  • GAMA-1 is seeking a remote Cloud Security Specialist IV focused on AWS security operations, IAM,...  ...Provide subject matter expertise on information security architecture and systems engineering...  ...effective access governance Assess risks and vulnerabilities and implement... 
    Local area
    Remote work

    GAMA-1 Technologies

    Greenbelt, MD
    1 day ago
  • $70k - $125k

     ...The cornerstone of Morgan Stanley's risk management philosophy is the execution of risk-adjusted returns through prudent risk-...  ...Function and Legal Entity. The NFR Cyber, Technology and Information Security (CTIS) Department is focused specifically on managing cyber,... 
    Temporary work
    Local area

    Morgan Stanley

    Baltimore, MD
    2 days ago
  • Sr IT Security/Vulnerability Management Specialist AAC is seeking Senior Security Analyst focusing on Vulnerability...  ..., you will work closely with the Information Systems Security Officer (ISSO)...  ...agency infrastructure and communicate risk posture and remediation progress... 
    Work experience placement
    3 days per week

    AAC

    Bethesda, MD
    5 days ago
  •  ...Subject Matter Expert (SME) – Cybersecurity & Risk Assessment The Subject Matter Expert...  ..., integrity, and effectiveness of security-related initiatives. The SME works cross...  ...Support the development and implementation of information security policies, standards, and... 

    Private Label Staff

    Baltimore, MD
    4 days ago
  • Overview As the state’s IT leader, DoIT manages information technology and telecommunications...  ..., ensuring the State of Maryland is more secure, productive, and accessible. Position Main...  ...Information Technology’s (DoIT) Third-Party Risk Management (TPRM) program while providing... 
    Contract work
    For contractors
    Work experience placement
    Work at office
    Local area

    State of Maryland

    Annapolis, MD
    2 days ago
  • $90k - $110k

     ...Management, Acquisition/Procurement, and Information Technology. OCT currently has an opening for a Cloud Security & Compliance Specialist to support a federal client. The...  ...management. Experience with Governance, Risk, and Compliance (GRC) platforms such as Archer... 
    Contract work
    Temporary work
    For contractors
    Work experience placement
    Remote work

    OCT Consulting, LLC

    Hyattsville, MD
    10 days ago
  • $30 per hour

     ...professional development in fields such as information technology, technical/systems consulting...  ...Federal Sales Teams. The Information Security Compliance Analyst is expected to work with...  ...Knowledge and expertise in projects of risk, information security and environment... 
    Hourly pay
    Temporary work
    Internship
    Flexible hours

    Oracle

    Annapolis, MD
    3 days ago
  •  ...commercial markets. Summary DataPath, Inc. is seeking an Information Security Analyst that will Plan, implement, upgrade, or monitor...  ...and information. Assess system vulnerabilities for security risks and propose and implement risk mitigation strategies. May ensure... 
    Remote work

    DataPath

    Aberdeen Proving Ground, MD
    3 days ago
  •  ...Information Security Analyst - SME Zantech is looking for a talented Information Security Analyst - SME to provide specialized cybersecurity expertise supporting risk management operations, conduct security assessments, implement continuous monitoring solutions, and... 
    Contract work

    Zantech

    Suitland, MD
    3 days ago

Do you want to receive more vacancies?

Subscribe and receive similar vacancies to Information Security Risk Specialist. Be the first to apply!