Jobs and Careers
SE

Information Assurance Officer/ Security Engineer

Serco North America
Washington, United Statesfull_timeVerifiedPosted 15 Jul 2025

About the role

Position Description

Serco is seeking a highly skilled and experienced Information Assurance Officer (IAO) to oversee the day-to-day security operations and compliance of our information systems and IT resources supporting a critical Government contract. The IAO will be instrumental in ensuring that all systems, including facility, training, service delivery, quality assurance, workforce management, and performance monitoring, adhere strictly to Federal IT security policies and standards. This role demands a proactive professional with deep expertise in federal cybersecurity frameworks and a commitment to maintaining a secure and resilient operational environment.

Key Responsibilities:

  • Security Incident Management: Immediately report all security incidents in accordance with GSA policy, including providing preliminary reports within 24 hours and comprehensive executive summaries detailing the event, cause, fix, and prevention plan.

  • System Evolution & Problem Resolution: Collaborate closely with the Program Manager to ensure systems evolve to meet changing program needs. Identify, document, and report technology-related problems to the Government, providing performance improvement plans for resolution and prevention.

  • Compliance & Standards Adherence: Ensure all information systems supporting task requirements meet initial and ongoing security compliance with Federal Information Processing Standards (FIPS) Publication 200 and NIST SP 800-53 security controls, as amended.

  • Documentation & Reporting: Oversee the preparation of all required compliance documentation, including Security Plans, Risk Assessments, Contingency and Contingency Test Plans, Configuration Management Plans, System Test and Evaluation Reports, and Security Certification and Accreditation (C&A) packages.

  • Continuous Monitoring & Reporting: Prepare ongoing responses to reports, data calls, and updates, such as quarterly Plan of Action and Milestones (POA&Ms), monthly vulnerability scans, server/application analysis, and annual Federal Information Security Management Act (FISMA) reporting.

  • Security Integration: Ensure IT security requirements (NIST SP 800-53 controls) are incorporated early in the planning and execution of transition activities and the development of new projects.

  • Risk Management: Conduct comprehensive risk assessments, identify vulnerabilities, and develop mitigation strategies to protect sensitive government data and systems.

  • Security Architecture Guidance: Advise on strategies for complying with Federal IT security requirements and contribute to the development of robust IT security architectures.

Qualifications

  • Bachelor's degree in Computer Science, Information Technology, Cybersecurity, or a related field.

  • Minimum of 7 years of progressive experience in Information Assurance or Cybersecurity, with at least 3 years in a Federal Government IT program.

  • Demonstrated familiarity with NIST IT security publications, including NIST SP 800-37 (Risk Management Framework), 800-53 (Security and Privacy Controls), and related OMB/NIST/GSA policies.

  • Proven experience and expertise in supporting Certification and Accreditations (C&As) for IT systems within the Federal Government, including in-depth knowledge of all controls at the moderate impact level.

  • Expertise in conducting vulnerability scans at the operating system, application, and database levels, performing code reviews, and assessing compliance with Center for Internet Security (CIS) benchmarks.

  • Experience in completing POA&Ms, FISMA Assessments, and other IT security data calls for Federal IT systems.

  • Broad familiarity with processes and security tools to advise on compliance strategies and IT security architecture development, including policies related to HSPD-12 and privacy requirements.

Preferred Skills:

  • Relevant industry certifications such as CISSP, CISM, CompTIA Security+, or equivalent.

  • Experience with IT vendor management, ensuring third-party compliance with security requirements.

  • Strong understanding of contact center architecture, including telephony and IT management aspects.

  • Familiarity with cloud security principles and FedRAMP requirements.

  • Experience with Governance, Risk, and Compliance (GRC) tools.

  • Excellent written and verbal communication skills, with the ability to articulate complex security concepts to diverse audiences.

  • Strong analytical and problem-solv

Apply for this role

Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.

Apply Now →Generate Application Kit

Free account required — sign up in 30s

Company

Serco North America

View company profile →