Summary
GAMA-1 Technologies provides information assurance, information security, and enterprise technology solutions to the Federal Government. The IT Security Specialist II supports security assessments for High and Moderate systems under the Risk Management Framework in a remote environment. The role assesses vulnerabilities, evaluates security controls, maintains compliance documentation and CSAM records, supports POA&M remediation, and collaborates with system teams and federal stakeholders.
Responsibilities
- Operate and maintain security scanning and monitoring tools to identify vulnerabilities and monitor system security
- Collect, organize, and maintain security artifacts for compliance and audit purposes
- Update and maintain IT security policies, procedures, SOPs, templates, and checklists for security operations and assessments
- Document and maintain CSAM entries to reflect current system compliance status
- Assist with POA&M updates, including tracking remediation progress and retesting evidence to verify resolution of findings
- Support vulnerability management and remediation activities, ensuring compliance with STIGs, NIST standards, and federal cybersecurity policies
- Review all relevant system and core security documentation for assessments
- Document computer security and emergency measures policies, procedures, and tests
- Perform security risk assessments and evaluate system security controls to ensure effective security measures and compliance
- Collaborate with program managers, developers, and infrastructure teams to embed security throughout the system lifecycle
- Train and mentor junior staff in cybersecurity best practices and federal compliance requirements
- Perform other duties and responsibilities as assigned
Skills
- Bachelor's degree in Engineering, Information Technology, Business, or a related field (or equivalent work experience)
- 2-4 years of experience in IT security, with at least 3 years supporting federal government systems
- Experience with Security Repository Tools, such as Cyber Security Assessment and Management (CSAM)
- Experience with NIST SP 800-37, NIST 800-53, FISMA A&A, and federal IT security policies and standards
- Proficiency in applying IT security concepts, methodologies, principles, procedures and using industry-standard IT security tools
- Proficiency with enterprise architecture methodologies, concepts, procedures, principles, and tool
- Familiarity with scanning and monitoring tools and conducting security assessments in cloud environments
- Proficiency in Microsoft Office suite (Word, Excel, PowerPoint, Visio and Project)
- Strong verbal and written communication skills, and ability to adapt to changing environments while working with federal clients and system teams
- Ability to obtain security clearance
- This work will be completed in a remote environment
- Prolonged periods of sitting at a desk and working on a computer
- Travel required:** No
- Relevant professional certifications: CISSP, CEH, CISM, CCSP, CISA, CompTIA Security+
- Additional industry certifications (e.g., AWS Certified Security – Specialty, Microsoft Certified: Azure Security Engineer Associate)•
- Experience with network, endpoint, cloud, and identity/access security, including penetration testing
- Experience developing and maintaining IT security documentation, including authorization packages, policies, SOPs, and templates
- Maintain awareness of evolving cybersecurity threats, standards, and best practices
Qualifications
Must Haves
- Bachelor's degree in Engineering, Information Technology, Business, or a related field (or equivalent work experience)
- 2-4 years of experience in IT security, with at least 3 years supporting federal government systems
- Experience with Security Repository Tools, such as Cyber Security Assessment and Management (CSAM)
- Experience with NIST SP 800-37, NIST 800-53, FISMA A&A, and federal IT security policies and standards
- Proficiency in applying IT security concepts, methodologies, principles, procedures and using industry-standard IT security tools
- Proficiency with enterprise architecture methodologies, concepts, procedures, principles, and tool
- Familiarity with scanning and monitoring tools and conducting security assessments in cloud environments
- Proficiency in Microsoft Office suite (Word, Excel, PowerPoint, Visio and Project)
- Strong verbal and written communication skills, and ability to adapt to changing environments while working with federal clients and system teams
- Ability to obtain security clearance
- This work will be completed in a remote environment
- Prolonged periods of sitting at a desk and working on a computer
- Travel required:** No
Nice to Haves
- Relevant professional certifications: CISSP, CEH, CISM, CCSP, CISA, CompTIA Security+
- Additional industry certifications (e.g., AWS Certified Security – Specialty, Microsoft Certified: Azure Security Engineer Associate)•
- Experience with network, endpoint, cloud, and identity/access security, including penetration testing
- Experience developing and maintaining IT security documentation, including authorization packages, policies, SOPs, and templates
- Maintain awareness of evolving cybersecurity threats, standards, and best practices
Benefits
- Remote work environment
- Health insurance coverage
- Life and disability insurance
- 401(k) savings plan
- Training and career development opportunities
- Paid holidays
- Paid time off (PTO) to cover vacation, illness or disability, appointments, emergencies or other situations that require time off from work
- Opportunities for career advancement throughout employment