Jobs and Careers
PE

Senior Information Security Specialist

PEMCCO
Washington, United Statesfull_timeVerifiedPosted 23 Jul 2026
💰 $168,000/yr($102,000/yr$168,000/yr)

About the role

Pay: $50.64 - $83.55 hourly, depending on experience

Benefits: Medical, Dental, Vision, Paid Time Off, Paid Holidays, Employee Assistance Program, and other company-sponsored benefits
Security Clearance: Ability to obtain and maintain a government security clearance if required

Are you an experienced cybersecurity professional who thrives on protecting mission-critical systems, managing risk, and ensuring compliance in complex environments?

PEMCCO is seeking an Senior Information Security Specialist to lead security, compliance, risk management, and authorization activities supporting government information systems and networks. This role is ideal for a cybersecurity leader who enjoys guiding security initiatives, managing Risk Management Framework (RMF) efforts, assessing risk, and helping organizations maintain strong and compliant security postures.

This opportunity is a strong fit for candidates with experience in information assurance, cybersecurity, information security, RMF, Assessment & Authorization (A&A), compliance management, vulnerability management, continuous monitoring, or system security engineering.

About PEMCCO

PEMCCO supports complex technical and operational programs by providing skilled professionals who help customers achieve mission success. We offer opportunities to work on impactful projects, collaborate with experienced teams, and contribute to innovative solutions that support critical government operations.

Job Overview

As a Senior Information Security Specialist, you will serve as a senior cybersecurity professional responsible for supporting the security and compliance of mission-critical information systems. You will work closely with program leadership, engineers, system administrators, developers, and government stakeholders to ensure cybersecurity requirements are implemented and maintained throughout the system lifecycle.

This position offers the opportunity to lead cybersecurity initiatives, influence risk management decisions, support authorization activities, and play a critical role in protecting systems that support important government missions.

What You'll Do

  • Lead information system security activities throughout the system lifecycle
  • Manage and support Risk Management Framework (RMF) and Assessment & Authorization (A&A) processes
  • Develop, review, and maintain System Security Plans (SSPs), Security Assessment Reports (SARs), Plans of Action & Milestones (POA&Ms), and related cybersecurity documentation
  • Conduct security assessments, compliance reviews, vulnerability analyses, and risk assessments
  • Evaluate implemented security controls and recommend corrective actions and improvements
  • Identify, document, track, and support remediation of security vulnerabilities and compliance deficiencies
  • Support continuous monitoring activities and maintain awareness of system security posture
  • Coordinate with system owners, engineers, developers, administrators, and stakeholders to ensure security requirements are integrated throughout the system lifecycle
  • Advise leadership on cybersecurity risks, compliance requirements, and security strategies
  • Support incident response activities, security investigations, and remediation efforts
  • Ensure compliance with cybersecurity policies, regulations, standards, and contractual requirements
  • Support cybersecurity audits, inspections, and authorization reviews
  • Prepare security reports, briefings, risk assessments, and recommendations for leadership and customers
  • Provide technical guidance and mentorship to cybersecurity personnel

What You Bring

Required Qualifications

  • Bachelor's degree in Cybersecurity, Information Assurance, Information Systems, Information Technology, Computer Science, Engineering, or a related field
  • Ten (10) years of experience in information assurance, information security, cybersecurity, system security, RMF, compliance, or a related field
  • Advanced knowledge of information assurance and cybersecurity principles
  • Advanced knowledge of Risk Management Framework (RMF) processes and security authorization requirements
  • Knowledge of NIST, DoD, and federal cybersecurity policies, standards, and regulations
  • Knowledge of security controls, vulnerability management, risk assessment, and compliance methodologies
  • Ability to identify, assess, and mitigate cybersecurity risks and vulnerabilities
  • Ability to interpret and apply security policies, standards, and procedures
  • Strong analytical, organizational, and pr

Apply for this role

Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.

Apply Now →Generate Application Kit

Free account required — sign up in 30s

Company

PEMCCO

View company profile →