Haystack
← Back to Jobs
Remote
Administrative
SI

Security Specialist

Stellar IT SolutionUnited States🇺🇸United StatesPosted 25 Aug 2026

Quick Overview

Seniority
Mid Senior
Work mode
Remote
Location
United States
Posted
23 hours ago
Jira

Job Description

Our Fortune 500 client is looking for a Security Specialist on their project based in  the US. 

Job Title: Security Specialist

Remote Role

Duration: Long-term

Job Description:

  • Cybersecurity Operations & Compliance:
  • Responsibility:
  • Operations Security (OPSEC)
  • SDLC Security
  • Incident & Issue Response
  • Government Information Protection
  • Data Protection
  • Incident & Issue Response

Specific Tasks:

  • Identifies vulnerability and coordination regarding cybersecurity findings and sensitive security artifacts as responsibilities of the Security Specialist role. Specifically addresses STIG findings, ACAS/Nessus results, POA&Ms, IAVA/IAVM information, Evaluate-STIG materials, .cklb files, vulnerability information, and related security evidence
  • Support lifecycle engineering, security updates, and cyber compliance sustainment.
  • Coordinate with ISSM/ISSO and resolve cybersecurity findings and issues.
  • The Contractor shall not divulge any information about files, data, programs, people, processing activities or functions, user IDs, passwords, access codes or other information to anyone not authorized access to such information.
  • The Contractor shall protect identified critical information, sensitive unclassified information and activities
  • All instances of loss, compromise and electronic spillage of classified or controlled unclassified information shall be reported to the COR and Government Security Office within 24 hours of the incident occurring

Continuous Monitoring &  Vulnerability Remediation:

Responsibility:

  • Security Scanning
  • Vulnerability Analysis
  • Vulnerability Management
  • Core Platform Security
  • Application Security Testing
  • User Acceptance Testing (Security)

Specific Tasks:

  • Perform and provide ACAS/Nessus scans for Training, Test, and Production environments
  • Perform vulnerability analysis and generate PMO-acceptable evidence. HAF/A4SC requires the Contractor to determine the exploitation potential and potential risk mitigations for delivered vulnerabilities. Vulnerability analysis should include the use of information concerning impact, environment of operations, known or assumed threats, and acceptable risk levels, and produce evidence that meet PMO acceptance criteria.
  • Establish cradle-to-grave tracking of CAT I, II, and III vulnerabilities to provide support to the ISSM/ISSO throughout the Risk Management Framework process. Confirm the applicable product, benchmark, vulnerability ID, rule, Check Text, and Fix Text before making recommendations. Distinguish between product-specific requirements and recognize technology or benchmark mismatches; Review and incorporate existing ticket history and system-specific technical context before recommending remediation. Maintain clear traceability between source findings, Jira tickets, supporting artifacts, remediation activity, and validation evidence
  • Review scan results and apply core Case Management Platform patches, upgrades, and security fixes. (Preferred) System-specific translation of security requirements that benefits from platform knowledge.
  • Resolve all CAT I and CAT II code vulnerabilities prior to production
  • Conduct Fortify, DISA STIG, CWE/SANS Top 25, Audit Workbench, and AS&D STIG assessments
  • Support cyber-compliance testing and validation of upgrades/releases

Artifact:

  • Security Scans per envionrment
  • Analyze discovered vulnerability and report evidence to PMO. Define appropriate format for reporting to PMO.
  • Leverage process for using JIRA to capture, track, resolve and report on vulnerabilities.
  • ACAS/Nessus Scan Results Deployment Plan,  Deployment Acceptance, Re-scans.
  • Provide Sprint update that shows planned vulnerability remediation of CAT I and CAT II code vulnerabilities passed re-scan.
  • Assessment Reports
  • Provide Sprint update that shows overall report of security issue after rescans.

Risk Management & Security Engineering:

Responsibility:

  • Threat Modeling
  • Security Architecture
  • Security Controls Design
  • Secure Integrations
  •  

Specific Tasks:

  • Support threat identification and threat modeling activities
  • Develop security architecture and design specifications aligned with enterprise architecture
  • Define security functionality and allocate controls across system components
  • Ensure secure communication and integrations with external systems

Plans, Designs, Reports and Artifacts:

Artifact:

  • Operations Security Plan (OPSEC)
  • Design Documents
  • ACAS/Nessus Scan Results
  • Fortify and STIG Reports
  • Problem Notification

Security Relevance:

  • Program security and protection of sensitive information
  • Security architecture and control allocation
  • Vulnerability management evidence. Server and network level scanning.
  • Secure code compliance evidence. Application level Dynamic Application Security Testing (DAST) scanning.
  • Security incidents/problems affecting performance

Key Security Performance Standards:

Standard:

  • Patch Deployment
  • CAT I / CAT II Findings
  • Security Scans
  • Incident & Issue Response
  • Problem Notification
  • Government Inquiry Response
  • Quality Control Plan

Requirement:

  • Within 72 hours of release (or 5 business days for existing delinquent patches) or upon AFJIS PM scheduled approval
  • Resolved before production release
  • Monthly ACAS/Nessus scans or as requested by the ISSM/ISSO
  • All instances of loss, compromise and electronic spillage of classified or controlled unclassified information shall be reported to the COR and Government Security Office within 24 hours of the incident occurring
  • Within 24 hours of identification of a problem that impacts the Contractor’s ability to perform any aspect of the PWS
  • Within 1 business day
  • Follow process for identifying quality deficiencies, determining root cause, taking corrective action, and preventing recurrence when work products, tickets, responses, records, or services do not meet applicable requirements, accepted quality criteria, or approved procedures. Specifically addresses vulnerability tracking, STIG/Fortify artifact review, ACAS/Nessus coordination, cybersecurity POA&M support, validation, and escalation. It also makes clear that subcontractor outputs are subject to the same quality-control, review, deficiency-tracking, corrective-action, and escalation processes.

 

 Please send your updated Word-format resume along with your best contact details to  or call me at .                               

Stellar IT Solutions is a Global IT Solution provider headquartered in Rockville, MD, with operations in the US and India. Stellar IT Solutions has over 15 years of IT and consulting experience to give cost-effective solutions to many Fortune 500 companies.  

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

Similar jobs