A Square Group
Frederick, Maryland
Job Description Job Description Description: Company Description: ASG is a Minority- and Woman-Owned, Physician-Owned small business with over 15 years of experience in federal government contracting. We deliver a wide range of technology services, including software development, mobile apps, AI/ML, analytics, data science, big data, DevSecOps, digital transformation, cloud, and cybersecurity. ASG is CMMI Level 3 certified and holds ISO 9001:2015, 20000-1:2018, and 27001:2022 certifications . Job Description: ASG is seeking an experienced Security Lead to own the Program security posture, compliance artifacts, and coordination with Program Security Oversight leadership. This role shares leadership of the security team with a Co-Lead and directs the work of the Information Security Specialist team, ensuring compliance documentation, vulnerability management, and ATO artifacts are complete, current, and defensible in a complex federal healthcare IT environment. The ideal candidate brings deep federal cybersecurity experience, a track record of leading security teams, and the judgment to represent the program's security posture to executive and government stakeholders. What You Will Do: Own Task 3 security management deliverables, including compliance documentation, risk register maintenance, and coordination with the Program Security Oversight Leader. Direct and coordinate the Information Security Specialist team, including workload distribution and quality oversight of security deliverables, alongside the Sr. Information Security Specialist (Co-Lead). Support Authorization to Operate (ATO) maintenance, continuous Assessment & Authorization (A&A) activities, and FISMA/FedRAMP compliance documentation for Client-managed systems. Author and review security documentation, including System Security Plans (SSPs), Risk Assessments, and Security Impact Analyses (SIA), prior to submission to Program Security Oversight leadership. Oversee vulnerability scanning, remediation tracking, and security findings reporting across enterprise tools; review results and recommended corrective actions from the Information Security Specialist team. Serve as the primary security point of contact with Program Security Oversight Leadership, and maintain collaborative relationships with federal ISSOs, CSPs (e.g., AWS, Azure), system owners, and vendors. Coordinate with the Tools Management team through the combined Security/Tools scrum cadence. Track and maintain the centralized Security Risk Register, map vulnerabilities to POA&Ms, and support FISMA/FedRAMP compliance efforts across the program. Provide guidance and privacy/security insight to Agile teams across projects, and support Privacy and Security Compliance through all stages of the systems development lifecycle (SDLC). Work within Client system repositories such as CFACTS and BOX. Oversee declared game day events, ensuring after-action reports and other required game day artifacts are completed by the security team. Develop and maintain standard operating procedures (SOPs) for repeatable security processes across the team. Perform additional duties as assigned by the Program Security Oversight Leader. Perform additional duties assigned. Requirements: What We Need : Bachelor's degree or higher in Computer Science, Information Technology, Cybersecurity, Systems Engineering, or a related field (or equivalent professional experience). 8+ years of information security experience in a federal or enterprise environment, including team leadership. Experience with FISMA compliance, ATO processes, and continuous Assessment & Authorization (A working understanding of NIST 800-53/37. Experience co-leading or managing a multi-person security team, including workload distribution and quality oversight of deliverables. Working knowledge of vulnerability scanning and compliance/POA&M platforms, Jira, Confluence, and FISMA/ATO documentation standards and processes. Ability to obtain and maintain Program EUA access and required Public Trust clearance. Strong communication skills and ability to coordinate across multi-disciplinary teams and government stakeholders. Even Better: Prior Program or HHS security program experience strongly preferred. Relevant security certification (CISSP, CISM, CEH, CCNA Security, or Security+). Familiarity with federal control tracking systems (e.g., CFACTS and BOX). Working knowledge of cloud environments (AWS, Azure) and associated security controls. Exposure to pen testing, application security, and CDN security services (e.g., Akamai). Experience providing security and privacy input within Agile development environments. Knowledge about emerging industry or technology trends such as Artificial Intelligence (AI) frameworks. Clearance Requirement: Ability to obtain and maintain public trust background investigation/clearance per client requirements. Additional Information: At ASG, we value diversity and always treat all employees and job applicants based on merit, qualifications, competence, and talent. We do not discriminate on the basis of race, color, religion, sex, sexual orientation, gender identity, national origin, age, disability, or status as a protected veteran. Applicants in need of special assistance or accommodation during the interview process or in accessing our website may contact us by sending an email to . We will treat your request as confidentially as possible. In your email, please include your name and preferred method of contact, and we will respond as soon as possible. Perks: At ASG, we want you to be well and thrive. Our benefits package includes: Healthcare Benefits Life Disability Paid Time Off 401k Matching Employee Referral Bonus Education Assistance Learning and Development resources EOE, including Disability/Veterans
Job Description Job Description Description: Company Description: ASG is a Minority- and Woman-Owned, Physician-Owned small business with over 15 years of experience in federal government contracting. We deliver a wide range of technology services, including software development, mobile apps, AI/ML, analytics, data science, big data, DevSecOps, digital transformation, cloud, and cybersecurity. ASG is CMMI Level 3 certified and holds ISO 9001:2015, 20000-1:2018, and 27001:2022 certifications . Job Description: ASG is seeking an experienced Security Lead to own the Program security posture, compliance artifacts, and coordination with Program Security Oversight leadership. This role shares leadership of the security team with a Co-Lead and directs the work of the Information Security Specialist team, ensuring compliance documentation, vulnerability management, and ATO artifacts are complete, current, and defensible in a complex federal healthcare IT environment. The ideal candidate brings deep federal cybersecurity experience, a track record of leading security teams, and the judgment to represent the program's security posture to executive and government stakeholders. What You Will Do: Own Task 3 security management deliverables, including compliance documentation, risk register maintenance, and coordination with the Program Security Oversight Leader. Direct and coordinate the Information Security Specialist team, including workload distribution and quality oversight of security deliverables, alongside the Sr. Information Security Specialist (Co-Lead). Support Authorization to Operate (ATO) maintenance, continuous Assessment & Authorization (A&A) activities, and FISMA/FedRAMP compliance documentation for Client-managed systems. Author and review security documentation, including System Security Plans (SSPs), Risk Assessments, and Security Impact Analyses (SIA), prior to submission to Program Security Oversight leadership. Oversee vulnerability scanning, remediation tracking, and security findings reporting across enterprise tools; review results and recommended corrective actions from the Information Security Specialist team. Serve as the primary security point of contact with Program Security Oversight Leadership, and maintain collaborative relationships with federal ISSOs, CSPs (e.g., AWS, Azure), system owners, and vendors. Coordinate with the Tools Management team through the combined Security/Tools scrum cadence. Track and maintain the centralized Security Risk Register, map vulnerabilities to POA&Ms, and support FISMA/FedRAMP compliance efforts across the program. Provide guidance and privacy/security insight to Agile teams across projects, and support Privacy and Security Compliance through all stages of the systems development lifecycle (SDLC). Work within Client system repositories such as CFACTS and BOX. Oversee declared game day events, ensuring after-action reports and other required game day artifacts are completed by the security team. Develop and maintain standard operating procedures (SOPs) for repeatable security processes across the team. Perform additional duties as assigned by the Program Security Oversight Leader. Perform additional duties assigned. Requirements: What We Need : Bachelor's degree or higher in Computer Science, Information Technology, Cybersecurity, Systems Engineering, or a related field (or equivalent professional experience). 8+ years of information security experience in a federal or enterprise environment, including team leadership. Experience with FISMA compliance, ATO processes, and continuous Assessment & Authorization (A working understanding of NIST 800-53/37. Experience co-leading or managing a multi-person security team, including workload distribution and quality oversight of deliverables. Working knowledge of vulnerability scanning and compliance/POA&M platforms, Jira, Confluence, and FISMA/ATO documentation standards and processes. Ability to obtain and maintain Program EUA access and required Public Trust clearance. Strong communication skills and ability to coordinate across multi-disciplinary teams and government stakeholders. Even Better: Prior Program or HHS security program experience strongly preferred. Relevant security certification (CISSP, CISM, CEH, CCNA Security, or Security+). Familiarity with federal control tracking systems (e.g., CFACTS and BOX). Working knowledge of cloud environments (AWS, Azure) and associated security controls. Exposure to pen testing, application security, and CDN security services (e.g., Akamai). Experience providing security and privacy input within Agile development environments. Knowledge about emerging industry or technology trends such as Artificial Intelligence (AI) frameworks. Clearance Requirement: Ability to obtain and maintain public trust background investigation/clearance per client requirements. Additional Information: At ASG, we value diversity and always treat all employees and job applicants based on merit, qualifications, competence, and talent. We do not discriminate on the basis of race, color, religion, sex, sexual orientation, gender identity, national origin, age, disability, or status as a protected veteran. Applicants in need of special assistance or accommodation during the interview process or in accessing our website may contact us by sending an email to . We will treat your request as confidentially as possible. In your email, please include your name and preferred method of contact, and we will respond as soon as possible. Perks: At ASG, we want you to be well and thrive. Our benefits package includes: Healthcare Benefits Life Disability Paid Time Off 401k Matching Employee Referral Bonus Education Assistance Learning and Development resources EOE, including Disability/Veterans
Powder River Industries, LLC
Washington, Washington DC
Job Description Job Description Description: We are seeking a highly skilled and mission-focused Information Assurance / Security Specialist (ISSO) to support cybersecurity compliance, Assessment & Authorization (A&A) activities, and Authority to Operate (ATO) documentation for designated systems. The ISSO will serve as a key liaison between contractor teams and federal certification authorities, ensuring security requirements are met, risks are communicated, and systems remain compliant with DOE, NNSA, and federal cybersecurity standards. This role requires strong technical acumen, exceptional documentation skills, and the ability to guide and advocate for contractor teams throughout the security lifecycle. Requirements: Key Responsibilities Implement DOE and NNSA cybersecurity policies and procedures for assigned information systems. Lead A&A activities, ensuring systems meet federal and organizational security requirements. Maintain all ATO documentation, including security plans, access control records, and configuration management artifacts. Manage and track POA&M items; assist in completing remediation activities where possible. Conduct risk assessments, identify vulnerabilities, and recommend mitigation strategies. Perform cybersecurity tests and assessments; provide actionable results to the ISSM. Evaluate the security impact of proposed system changes and recommend risk-based solutions. Develop and deliver cybersecurity training based on user roles and responsibilities. Respond to security incidents, document findings, and support incident resolution. Create and maintain security processes, procedures, disaster recovery plans, and incident response plans. Support audits and external reviews; manage findings and drive favorable outcomes. Develop new policies, documentation, and training materials when required, ensuring alignment across contractor and federal stakeholders. Communicate cybersecurity status, risks, and mitigation strategies clearly to leadership and stakeholders. Lead and mentor assigned resources (2 FTEs), ensuring high-quality documentation and successful security outcomes. Required Qualifications Experience supporting A&A/ATO processes within federal environments (DOE/NNSA preferred). Strong understanding of federal cybersecurity frameworks, risk management, and compliance requirements. Ability to create clear, accurate, and technically sound security documentation. Experience supporting audits, external reviews, and POA&M management. Strong communication skills with the ability to brief technical and non-technical stakeholders. Ability to negotiate policy, documentation, and training across diverse stakeholder groups. A notification to prospective applicants that reviews, and tests for the absence of any illegal drug as defined in 10 CFR 707.4, will be conducted by the employer and a background investigation by the Federal government may be required to obtain an access authorization prior to employment, and that subsequent reinvestigations may be required. The position is covered by the Counterintelligence Evaluation Program regulations at 10 CFR part 709, the announcement should also alert applicants that successful completion of a counterintelligence evaluation may include a counterintelligence -scope polygraph examination. As a federal contractor, we are committed to fair and equitable employment practices. We make employment decisions based on job-related qualifications, merit, contract requirements, and legitimate business needs, and prohibit unlawful discrimination in all employment practices As a federal contractor, we comply with Section 503 of the Rehabilitation Act and VEVRAA. No disability-related inquiries will be made prior to a conditional offer of employment, except as permitted by applicable law. Employee Rights Under the National Labor Relations Act (NLRA): As a federal contractor, the Company complies with Executive Order 13496 and informs employees of their rights under the National Labor Relations Act. Information regarding these rights is available at the workplace and from the National Labor Relations Board. This position is covered by the Service Contract Labor Standards (SCLS). Compensation and fringe benefits will be provided in accordance with the applicable U.S. Department of Labor wage determination and any applicable collective bargaining agreement. Medical, dental, vision, and 401k benefits are included with this position.
Job Description Job Description Description: We are seeking a highly skilled and mission-focused Information Assurance / Security Specialist (ISSO) to support cybersecurity compliance, Assessment & Authorization (A&A) activities, and Authority to Operate (ATO) documentation for designated systems. The ISSO will serve as a key liaison between contractor teams and federal certification authorities, ensuring security requirements are met, risks are communicated, and systems remain compliant with DOE, NNSA, and federal cybersecurity standards. This role requires strong technical acumen, exceptional documentation skills, and the ability to guide and advocate for contractor teams throughout the security lifecycle. Requirements: Key Responsibilities Implement DOE and NNSA cybersecurity policies and procedures for assigned information systems. Lead A&A activities, ensuring systems meet federal and organizational security requirements. Maintain all ATO documentation, including security plans, access control records, and configuration management artifacts. Manage and track POA&M items; assist in completing remediation activities where possible. Conduct risk assessments, identify vulnerabilities, and recommend mitigation strategies. Perform cybersecurity tests and assessments; provide actionable results to the ISSM. Evaluate the security impact of proposed system changes and recommend risk-based solutions. Develop and deliver cybersecurity training based on user roles and responsibilities. Respond to security incidents, document findings, and support incident resolution. Create and maintain security processes, procedures, disaster recovery plans, and incident response plans. Support audits and external reviews; manage findings and drive favorable outcomes. Develop new policies, documentation, and training materials when required, ensuring alignment across contractor and federal stakeholders. Communicate cybersecurity status, risks, and mitigation strategies clearly to leadership and stakeholders. Lead and mentor assigned resources (2 FTEs), ensuring high-quality documentation and successful security outcomes. Required Qualifications Experience supporting A&A/ATO processes within federal environments (DOE/NNSA preferred). Strong understanding of federal cybersecurity frameworks, risk management, and compliance requirements. Ability to create clear, accurate, and technically sound security documentation. Experience supporting audits, external reviews, and POA&M management. Strong communication skills with the ability to brief technical and non-technical stakeholders. Ability to negotiate policy, documentation, and training across diverse stakeholder groups. A notification to prospective applicants that reviews, and tests for the absence of any illegal drug as defined in 10 CFR 707.4, will be conducted by the employer and a background investigation by the Federal government may be required to obtain an access authorization prior to employment, and that subsequent reinvestigations may be required. The position is covered by the Counterintelligence Evaluation Program regulations at 10 CFR part 709, the announcement should also alert applicants that successful completion of a counterintelligence evaluation may include a counterintelligence -scope polygraph examination. As a federal contractor, we are committed to fair and equitable employment practices. We make employment decisions based on job-related qualifications, merit, contract requirements, and legitimate business needs, and prohibit unlawful discrimination in all employment practices As a federal contractor, we comply with Section 503 of the Rehabilitation Act and VEVRAA. No disability-related inquiries will be made prior to a conditional offer of employment, except as permitted by applicable law. Employee Rights Under the National Labor Relations Act (NLRA): As a federal contractor, the Company complies with Executive Order 13496 and informs employees of their rights under the National Labor Relations Act. Information regarding these rights is available at the workplace and from the National Labor Relations Board. This position is covered by the Service Contract Labor Standards (SCLS). Compensation and fringe benefits will be provided in accordance with the applicable U.S. Department of Labor wage determination and any applicable collective bargaining agreement. Medical, dental, vision, and 401k benefits are included with this position.