Booz Allen Hamilton logo
Booz Allen Hamilton

Booz Allen Hamilton is an award-winning provider of strategic innovation, management consulting, technology, and engineering services. Founded in 1914, the comp

Information Security Risk Specialist

Location

Maryland

Posted

3 days ago

Salary

$61.9K - $141K / year

Seniority

Senior

Bachelor DegreeAmazon IAMAI

Job Description

Information Security Risk Specialist

Booz Allen Hamilton

Information Security Risk Specialist Location: Lexington Park, MD time type Full time job requisition id R0240701 Information Security Risk Specialist The Opportunity: Cyber threats are everywhere, and the constantly evolving nature of these threats can make understanding them seem overwhelming to government agencies. In all of this “cyber noise”, how can these organizations understand their risks and how to mitigate them? The answer is you. We need your knowledge as an information security risk specialist to help break down complex threats into manageable plans of action. As an information security risk specialist on our team, you’ll assist military leaders with discovering their cyber risks, understanding applicable policies, and developing a mitigation plan. You’ll gather technical and personnel details from subject matter experts to help with the assessment of the entire threat landscape. You’ll learn how to guide your client through a plan of action with presentations, whitepapers, and milestones, and help to translate security concepts so they can make the best decisions to secure their critical systems. This is your opportunity to build experience in a strategic information security role while developing skills in cybersecurity. Work with us as we protect our nation's cyber infrastructure. Join us. The world can’t wait. You Have: - 3+ years of experience leading and executing Navy Risk Management Framework (RMF), including full lifecycle implementation across all RMF steps, application of Navy SOPs and cybersecurity directives, and ownership of Plans of Action and Milestones (POA&Ms) - Experience with eMASS and ACAS, including analysis and prioritization of scan results, development and maintenance of hardware and software inventories, and vulnerability management using SCAP, VRAM, and HBSS - Experience reviewing, interpreting, and enforcing Security Technical Implementation Guides (STIGs) using STIG Viewer - Experience developing and supporting Security Assessment Plans (SAPs) and Security Assessment Reports (SARs) in alignment with Navy RMF requirements - Knowledge of Ports, Protocols, and Services Management (PPSM) - Ability to operate in a structured and compliance-driven environment while executing established cybersecurity processes with minimal supervision - Secret clearance - Bachelor's degree in Cybersecurity, IT, CS, Information Systems, Data Science, or Software Engineering - DoD 8140, 752-Cyber Policy and Strategy Planner, Intermediate Certification Nice If You Have: - Master’s degree - IAM or IAT Level III Certification Clearance: Applicants selected will be subject to a security investigation and may need to meet eligibility requirements for access to classified information; Secret clearance is required. Compensation At Booz Allen, we celebrate your contributions, provide you with opportunities and choices, and support your total well-being. Our offerings include health, life, disability, financial, and retirement benefits, as well as paid leave, professional development, tuition assistance, work-life programs, and dependent care. Our recognition awards program acknowledges employees for exceptional performance and superior demonstration of our values. Full-time and part-time employees working at least 20 hours a week on a regular basis are eligible to participate in Booz Allen’s benefit programs. Individuals that do not meet the threshold are only eligible for select offerings, not inclusive of health benefits. We encourage you to learn more about our total benefits by visiting the Resource page on our Careers site and reviewing Our Employee Benefits page. Salary at Booz Allen is determined by various factors, including but not limited to location, the individual’s particular combination of education, knowledge, skills, competencies, and experience, as well as contract-specific affordability and organizational requirements. The projected compensation range for this position is $61,900.00 to $141,000.00 (annualized USD). The estimate displayed represents the typical salary range for this position and is just one component of Booz Allen’s total compensation package for employees. This posting will close within 90 days from the Posting Date. Identity Statement As part of the hiring process, we will ask you to complete an identity verification process that leverages advanced biometrics and artificial intelligence to ensure authenticity and protect against identity fraud. You are expected to be on camera during interviews and assessments. We reserve the right to take your picture to verify your identity and prevent fraud. Candidate AI Usage Policy AI is a part of our daily work at Booz Allen, and we are committed to the responsible and ethical use of AI tools. However, we want to ensure a fair candidate process based on your own skills and knowledge. As part of this commitment, the use of artificial intelligence (AI) or other tools to assist with responses during interviews (whether in-person or virtual) is prohibited unless permission is explicitly provided. Work Model Our people-first culture prioritizes the benefits of collaboration, whether it occurs in person or virtually. To support engagement and effective communication, employees working virtually are generally expected to have their cameras on during meetings. - Remote: If this position is listed as remote, there may still be occasions when you are required to work in person at a Booz Allen or customer facility. - Hybrid: If this position is listed as hybrid, you will be expected to work from a Booz Allen facility frequently, in alignment with leadership expectations and the needs of the role. You may also be required to work from or visit a customer facility. - Onsite: If this position is listed as onsite, work will primarily be performed at a Booz Allen office or customer facility, where employees will collaborate directly with colleagues and customers as required by the role. Commitment to Non-Discrimination All qualified applicants will receive consideration for employment without regard to disability, status as a protected veteran or any other status protected by applicable federal, state, local, or international law.

Related Categories

Related Job Pages

More Security Engineer Jobs

Mercier Consultancy Group logo

French-Speaking Cybersecurity Customer Experts

Mercier Consultancy Group

A fast-growing, operator-led GTM consultancy building AI-powered revenue systems for modern sales teams. The business was founded by experienced CROs who have carried quota, and specializes in engineering end-to-end revenue infrastructure that converts market signals into qualified pipeline — at speed and scale. The company is AI-native and increasingly code-first in its approach, using a sophisticated internal tech stack including custom AI agent orchestration, workflow automation, signal detection and enrichment, multi-channel outreach delivery, and operational intelligence tooling. AI systems are embedded throughout the entire execution layer. They serve growth-stage B2B companies scaling between $1M and $100M+ ARR who need systematic, automation-driven competitive advantages — built on infrastructure, not headcount.

Role Description Mercier Consultancy MD is seeking French-Speaking Cybersecurity Customer Experts to join our team in Athens. This role involves providing dedicated cybersecurity customer support to French-speaking clients, helping them navigate and secure their digital environments. - Provide expert cybersecurity customer support to French-speaking clients through phone, email, and chat channels. - Troubleshoot and resolve security-related customer issues efficiently and professionally. - Guide customers on best practices in cybersecurity and optimal use of security solutions. - Maintain accurate records of all customer interactions and technical issues using CRM tools. - Collaborate with technical teams to escalate and resolve complex cybersecurity challenges. - Stay updated with the latest cybersecurity trends and developments to offer informed support. Qualifications - Fluent in French (both written and spoken); proficiency in English is a plus. - Previous experience in customer support or related roles, preferably within cybersecurity or IT security. - Good knowledge of cybersecurity concepts, threats, and technologies. - Strong communication, analytical, and problem-solving skills focused on customer satisfaction. - Ability to multitask and work effectively under pressure in a fast-paced environment. - Experience with CRM software and customer support platforms. - Passionate about cybersecurity with a willingness to continuously learn and adapt. Benefits - Competitive Monthly Salary - Fully Paid Training - Fully Paid Relocation Package - Monthly Performance Bonus - Health Insurance - 2 Extra Salaries Per Year - And Much More...

Greece
Full TimeRemoteTeam 1,001-5,000H1B Sponsor

• Own the end-to-end vulnerability management lifecycle across Azure and AWS environments, including triage, prioritisation, and tracking through to remediation. • Build and maintain Threat & Vulnerability Management (TVM) dashboards and Azure Data Explorer queries to surface real-time risk posture, remediation trends, and SLA adherence. • Produce and maintain Monthly Security KPI Dashboards covering Microsoft Secure Scores, tooling coverage metrics, and vulnerability remediation performance across all cloud environments. • Partner with Cloud Engineering and SRE teams to drive remediation of critical and high-severity findings within defined SLAs, escalating blockers and tracking progress to closure. • Manage and operationalise External Attack Surface Management (EASM) tooling (e.g. BlackKite) to continuously assess and monitor Intapp’s external threat exposure and digital footprint. • Translate external posture findings into prioritised remediation actions and track outcomes rigorously through to closure, reporting status to security leadership. • Monitor and report on third-party and supply chain risk signals surfaced through external posture tooling, contributing to broader vendor risk management processes. • Design, implement, and maintain policy-based security controls for Kubernetes workloads across Azure (AKS) and AWS (EKS) environments. • Collaborate with DevOps and SRE teams to embed Kubernetes security controls into deployment pipelines and operational runbooks. • Develop and maintain Microsoft Sentinel data connectors and platform integrations to ensure comprehensive security telemetry coverage across Azure and AWS.

Portugal
Mollica IT logo

Cybersecurity Architect – Senior

Mollica IT

Recrutando talentos de tecnologia & conectando histórias

Full TimeRemoteTeam 11-50Since 2013H1B No Sponsor

• Define, govern, and evolve cybersecurity architecture models and standards, aligning global frameworks (NIST, ISO 27001, CIS, COBIT) with the specific needs of operations; • Lead security architecture projects and initiatives for multi-cloud, on-premises, network, application, industrial IoT/IIoT, data, and mobility environments; • Design solutions for threat prevention, detection, containment, and remediation, integrating SIEM, SOAR, EDR, IAM systems, and advanced encryption; • Contribute to defining identity and access policies and controls (IAM, SSO, MFA), network segmentation, endpoint protection, vulnerability management, and governance; • Promote integration between physical security, IT, OT (Operational Technology), and operations teams to create resilient, secure environments; • Develop and validate business continuity, cyber disaster recovery, and incident response strategies; • Evaluate and implement innovative security solutions (Zero Trust, Cloud Security Posture Management, Threat Intelligence, security automation and orchestration); • Ensure compliance with data protection laws and regulations in the countries where the company operates (LGPD, GDPR, PIPEDA); • Produce and maintain technical documentation, security plans, best-practice guides, and training for internal teams; • Participate in technical communities, forums, audits, and global compliance assessments; • Other routine duties of the area.

Brazil
nesto logo

Cloud Security Developer

nesto

The bright side of mortgages

Full TimeRemoteTeam 501-1,000Since 2018H1B No Sponsor

• Implement and maintain robust security controls to protect our cloud infrastructure and applications. • Discover, remediate, and validate security issues across cloud infrastructure. • Perform architectural/design reviews through a security lens and provide timely, actionable requirements and recommendations. • Collaborate with security leadership, compliance, and engineering teams to execute security strategies. • Build, deploy, and manage security tools such as WAF, IDS/IPS, workload protection, GCP Command Center, and Azure Security Center, etc. • Propose and contribute to security and compliance improvements for nesto CI/CD pipelines and deployment processes. • Automate infrastructure provisioning and deployment processes using Infrastructure as Code (IaC) tools like Terraform or Pulumi. • Design and operate scalable processes to provision cloud access and maintain least privilege. • Participate in and support the incident detection and response process by enhancing observability and alerting and assisting the incident response team. • Self-organize and prioritize activities independently. • Support audits and first-party security questionnaires. • Conduct and oversee security assessments and threat modeling exercises. • Implement security controls within Kubernetes. • Build DevSecOps tools/integrations.

Canada