Senior Information Security Specialist - Lead
Fully Remote
Job Type
Full-time
Description

Company Description:


ASG is a Minority- and Woman-Owned, Physician-Owned small business with over 15 years of experience in federal government contracting. We deliver a wide range of technology services, including software development, mobile apps, AI/ML, analytics, data science, big data, DevSecOps, digital transformation, cloud, and cybersecurity. ASG is CMMI Level 3 certified and holds ISO 9001:2015, 20000-1:2018, and 27001:2022 certifications.

Job Description:


ASG is seeking an experienced Security Lead to own the Program security posture, compliance artifacts, and coordination with Program Security Oversight leadership. This role shares leadership of the security team with a Co-Lead and directs the work of the Information Security Specialist team, ensuring compliance documentation, vulnerability management, and ATO artifacts are complete, current, and defensible in a complex federal healthcare IT environment. The ideal candidate brings deep federal cybersecurity experience, a track record of leading security teams, and the judgment to represent the program's security posture to executive and government stakeholders.  


What You Will Do: 

  • Own Task 3 security management deliverables, including compliance documentation, risk register maintenance, and coordination with the Program Security Oversight Leader. 
  • Direct and coordinate the Information Security Specialist team, including workload distribution and quality oversight of security deliverables, alongside the Sr. Information Security Specialist (Co-Lead). 
  • Support Authorization to Operate (ATO) maintenance, continuous Assessment & Authorization (A&A) activities, and FISMA/FedRAMP compliance documentation for Client-managed systems. 
  • Author and review security documentation, including System Security Plans (SSPs), Risk Assessments, and Security Impact Analyses (SIA), prior to submission to Program Security Oversight leadership. 
  • Oversee vulnerability scanning, remediation tracking, and security findings reporting across enterprise tools; review results and recommended corrective actions from the Information Security Specialist team. 
  • Serve as the primary security point of contact with Program Security Oversight Leadership, and maintain collaborative relationships with federal ISSOs, CSPs (e.g., AWS, Azure), system owners, and vendors. 
  • Coordinate with the Tools Management team through the combined Security/Tools scrum cadence. 
  • Track and maintain the centralized Security Risk Register, map vulnerabilities to POA&Ms, and support FISMA/FedRAMP compliance efforts across the program. 
  • Provide guidance and privacy/security insight to Agile teams across projects, and support Privacy and Security Compliance through all stages of the systems development lifecycle (SDLC). 
  • Work within Client system repositories such as CFACTS and BOX. 
  • Oversee declared game day events, ensuring after-action reports and other required game day artifacts are completed by the security team. 
  • Develop and maintain standard operating procedures (SOPs) for repeatable security processes across the team. 
  • Perform additional duties as assigned by the Program Security Oversight Leader. 
  • Perform additional duties assigned.
Requirements

What We Need: 

  • Bachelor's degree or higher in Computer Science, Information Technology, Cybersecurity, Systems Engineering, or a related field (or equivalent professional experience). 
  • 8+ years of information security experience in a federal or enterprise environment, including team leadership. 
  • Experience with FISMA compliance, ATO processes, and continuous Assessment & Authorization (A&A); working understanding of NIST 800-53/37. 
  • Experience co-leading or managing a multi-person security team, including workload distribution and quality oversight of deliverables. 
  • Working knowledge of vulnerability scanning and compliance/POA&M platforms, Jira, Confluence, and FISMA/ATO documentation standards and processes. 
  • Ability to obtain and maintain Program EUA access and required Public Trust clearance. 
  • Strong communication skills and ability to coordinate across multi-disciplinary teams and government stakeholders. 

Even Better: 

  • Prior Program or HHS security program experience strongly preferred. 
  • Relevant security certification (CISSP, CISM, CEH, CCNA Security, or Security+). 
  • Familiarity with federal control tracking systems (e.g., CFACTS and BOX). 
  • Working knowledge of cloud environments (AWS, Azure) and associated security controls. 
  • Exposure to pen testing, application security, and CDN security services (e.g., Akamai). 
  • Experience providing security and privacy input within Agile development environments. 
  • Knowledge about emerging industry or technology trends such as Artificial Intelligence (AI) frameworks. 

Clearance Requirement:

  • Ability to obtain and maintain public trust background investigation/clearance per client requirements.

Additional Information:


At ASG, we value diversity and always treat all employees and job applicants based on merit, qualifications, competence, and talent. We do not discriminate on the basis of race, color, religion, sex, sexual orientation, gender identity, national origin, age, disability, or status as a protected veteran.

Applicants in need of special assistance or accommodation during the interview process or in accessing our website may contact us by sending an email to careers@a2-g.com. We will treat your request as confidentially as possible. In your email, please include your name and preferred method of contact, and we will respond as soon as possible.


Perks:

At ASG, we want you to be well and thrive. Our benefits package includes:

  • Healthcare Benefits
  • Life
  • Disability
  • Paid Time Off
  • 401k Matching
  • Employee Referral Bonus
  • Education Assistance
  • Learning and Development resources
  • EOE, including Disability/Veterans