Information Security Risk Specialist

Booz Allen Hamilton

Confirmed live 2 days ago High trust

Quick summary

Work type
On-site
Location
Fort Belvoir, VAMcLean, VA
Salary
$99,000–$225,000 / yr
Posted
2 days ago
Freshness
Confirmed live 2 days ago

Market check

Salary context

Competitive pay

How this pay compares to similar roles

Similar $160k
This role $162k
$84k most similar roles pay here $240k

This role pays more than 56% of similar roles. Most pay $127,550–$193,000 — the shaded band above. At the midpoint, this role pays about $162k versus about $160k for comparable roles.

Based on 238 similar postings.

Employer

About Booz Allen Hamilton

Booz Allen Hamilton is a management and technology consulting firm that provides analytics, digital, engineering, and cybersecurity solutions primarily to U.S. government agencies and commercial clients. Industry: Management & Technology Consulting

Booz Allen Hamilton currently has 802 open roles on FindRole.

Listed pay typically runs $86,800–$198,000 across 783 roles with salary data.

Most-posted roles

View all roles at Booz Allen Hamilton

At a glance

TL;DR · Information Security Risk Specialist

As an Information Security Risk Specialist, you will join the team to collaborate with contractor and DoD government system owners, administrators, and developers to identify cyber risks and develop mitigation strategies. You will evaluate technical infrastructure and personnel dynamics to assess the threat landscape while guiding clients through actionable remediation plans via white papers and presentations. The role involves managing risk for critical DoD systems by translating complex security concepts into clear decisions. Key responsibilities include performing assessment and authorization, RMF processes, and security control assessments in cloud-native and containerized environments. You will utilize tools such as ACAS, SCAP, STIGs, eMASS, or Xacta while working with NIST SP 800-53 and CNSSI 1253 standards. Required expertise includes AWS, Azure, DevSecOps pipelines, Red Hat Enterprise Linux, Windows Server, and container orchestration technologies like Kubernetes and Rancher.

What you'll do

  • Identify cyber risks and analyze applicable policies for DoD government systems.
  • Develop comprehensive mitigation strategies based on technical infrastructure and personnel dynamics.
  • Guide clients through actionable remediation plans using white papers and formal presentations.
  • Perform risk assessments and security control evaluations for cloud-native and containerized environments.
  • Manage Authorization to Operate (ATO) packages and RMF processes for federal systems.
  • Align DevSecOps pipelines with established cybersecurity policies and requirements.
  • Conduct compliance testing using tools such as ACAS, SCAP, STIGs, or eMASS.
  • Translate complex security concepts into actionable decisions for stakeholders to secure critical infrastructure.

What we're looking for

  • TS/SCI clearance is required.
  • DoD 8570 Level II Security+ Certification is required.
  • High school diploma or GED is required.
  • 5+ years of experience in a professional IT environment.
  • 3+ years of experience in cybersecurity and Assessment and Authorization (A&A) supporting DoD environments.
  • Experience performing RMF, risk assessments, and security control assessments for federal systems in AWS, Azure, or hybrid cloud environments.
  • Experience with NIST SP 800-53, CNSSI 1253, SSPs, POA&Ms, and compliance tools like ACAS, SCAP, STIGs, eMASS, or Xacta.
  • Bachelor's degree in IT or Cybersecurity (preferred).

More like this

Similar roles

Information Security Specialist

The Federal Reserve

New York, NY 45 days ago
DevSecOps CI/CD Application Security Testing NIST 800-53 SaaS Gen AI Agile Risk Management Vulnerability Remediation Information Systems Risk Management IoT ICS

Information Security Risk Analyst

Lam Research

Tualatin, OR 68 days ago
SIEM Microsoft Sentinel Splunk KQL SPL SQL Python PowerShell MITRE ATT&CK UEBA Azure AWS Cloud Platform Entra ID Logic Apps STIX/TAXII MISP Threat Hunting Incident Response
Hybrid

Information Security Risk Analyst

Lam Research

Tualatin, OR 67 days ago
SIEM KQL SPL SQL Python PowerShell Microsoft Sentinel Splunk Exabeam Securonix Microsoft Defender XDR Entra ID Azure AWS Cloud Platform MITRE ATT&CK UEBA STIX/TAXII MISP Logic Apps

Information Security Risk Analyst

Lam Research

Tualatin, OR 58 days ago
SIEM Microsoft Sentinel Splunk KQL SPL SQL Python PowerShell MITRE ATT&CK UEBA Azure AWS Cloud Platform Entra ID Logic Apps MISP STIX/TAXII Threat Hunting Incident Response

Security Risk Management Specialist II

Affirm

Remote 24 days ago $130,000$180,000
Python Cursor Claude Agentic Coding Platforms AWS GCP Azure Low-code Platforms NIST ISO 27001 SOC 2 PCI DSS GRC Third Party Risk Management Security Governance Automation
3+ yrs exp Remote

Cyber Security Risk Analyst

The Federal Reserve

Chicago, IL 136 days ago
DevSecOps CI/CD NIST 800-53 Application Security Testing SaaS Gen AI Agile Risk Management Information Security IoT ICS