Quick Overview
Job Description
Overview
We are currently looking for an Information Assurance Specialist to support a federal customer in the Washington DC area. The Information Assurance Specialist manages security compliance, architectural safeguards, and systems hardening across our enterprise environments. In this role, you will analyze NIST SP 800-53 Rev 5 and FedRAMP basic categorizations to manage the split of shared security responsibilities between the organization and external providers. The ideal candidate will drive technical hardening initiatives by developing and implementing security baselines rooted in CIS Benchmarks. You will have deep technical proficiency in deploying security policies across both on-premises and modern environments using Microsoft Group Policy Objects (GPOs) and Microsoft Intune. You will oversee key governance and security safeguards—such as access policies (RBAC), data protection, network segmentation, and monitoring—to ensure continuous audit readiness.
*Due to the nature of the work and contract - ship is required.
*This position requires 1 to 2 days/week onsite - candidates not local to the DC area and/or not willing to go onsite 1 to 2 days per week will not be considered.
Responsibilities
- Security Baseline Implementation: Implement, manage, and enforce robust security baselines and benchmarks such as CIS Benchmarks and Azure Foundations across enterprise endpoints and server infrastructure.
- Microsoft Group Policy (GPO): Technical expertise to support and audit Active Directory Group Policy Objects (GPOs) to enforce least privilege, disable insecure legacy protocols, and harden on-premises Windows environments.
- Microsoft Intune Policy Management Configuration: Experience translating traditional GPOs into modern cloud management frameworks using Microsoft Intune Settings Catalogs, Administrative Templates, and Endpoint Security configurations.
- Compliance Mapping & Governance: Aligning technical configuration baselines directly with overarching Information Assurance (IA) frameworks, ensuring that GPO and Intune policy maps cleanly to auditable compliance controls.
- Risk Identification & Assessment: Ability to identify, evaluate, and categorize security risks within organizational systems by analyzing technical configurations against established frameworks (such as NIST SP 800-30 or FedRAMP risk assessments).
- Guide stakeholders in determining and integrating baseline security requirements, advise on viability of alternative approaches.
- Propose remediation/mitigating controls and recommendations to stakeholders and management to minimize risk.
- Lead security team engagements to build and mature processes to produce written Standard Operating Procedures (SOP) with a focus on improvement to FERC’s Information Assurance processes, methodologies, and communication methods.
- Other duties as assigned.
Qualifications
- Bachelor’s degree or equivalent work experience in related field.
- Framework Alignment: Minimum of 3–5 years of experience aligning infrastructure with NIST SP 800-53 Rev 5 or FedRAMP security control frameworks.
- Infrastructure Hardening: Proven track record authoring and deploying hardening guidance using CIS Benchmarks including Azure Foundations.
- Policy Management: Technical proficiency understanding and managing Microsoft Group Policy Objects (GPOs) and Microsoft Intune configuration policies.
- Network & Endpoint Security: Strong understanding of cloud networking architecture, including NSGs, VNet segmentation, Azure Firewall, WAF, and Private Link.
- Identity & Governance: Strong understanding of Azure RBAC policies, configuring logging/monitoring solutions, and implementing data protection mechanisms.
- Ability to articulate ideas to both technical and non-technical audiences through excellent written and oral communication skills.
- Ability to independently collect, review, and evaluate IT product data to identify and characterize security threat sources of concern and provide recommendations to Government leadership.
- Experience securing infrastructure within Microsoft Azure or Azure Government environments.
- Must possess a valid baseline security certification (e.g., CompTIA Security+, CISSP, CEH, or DoD equivalent). Or obtain an approved certification within 90 days of hire.
Preferred Qualifications:
- 3-5 years of relevant work experience with network engineering and/or system administration background (Unix/Linux/Windows).
- The ability to establish effective relationships with internal partners and teams.
- Skilled in authoring, testing, and debugging Azure Policy definitions and blueprints to automatically enforce configuration benchmarks (like CIS Azure Foundations) across subscriptions.
- Direct experience utilizing Microsoft Defender for Cloud and its Regulatory Compliance dashboard to monitor and report on security postures.
Similar jobs
- EG
Senior Cybersecurity Engineer
NewEliassen Group
Cary, NC🇺🇸On-site23 hours agoAWSAnsibleAzure+5Technology - EG
Identity Security Engineer
NewEliassen Group
Cary, NC🇺🇸Hybrid23 hours agoMFAOAuthSAML+7Technology - UT
Senior Cybersecurity Engineer
NewUnicorn Technologies LLC
Atlanta, GA🇺🇸Hybrid23 hours agoAWSEncryptionAzure+1Technology - HA
Intern, Mission Networks Enterprise SOC Analyst
Harris Corporation
Melbourne, FL🇺🇸Hybrid5 weeks agoDockerMicroservicesGit+1Technology - IA
Cyber Security Engineer
NewIO Associates
Tampa, FL🇺🇸Hybrid23 hours agoAWSEncryptionMFA+6Technology - UC
Security Engineer with HashiCorp Vault Enterprise edition Exp
NewUniplus Consultants Inc
Culpeper, VA🇺🇸Hybrid23 hours agoSwiftAnsibleGit+4Technology