Now Hiring at AMERICAN SYSTEMS
Epsilon, Inc. has joined AMERICAN SYSTEMS! As one organization, we offer expanded resources, streamlined operations, and increased opportunities for growth and development.
Join us to be part of a dynamic, collaborative environment dedicated to innovation and customer success.
ResponsibilitiesAn Average Day: As the Information Assurance Specialist I you will support cybersecurity and compliance activities by ensuring information systems meet federal security requirements, maintain operational authorizations, and comply with standards such as the Risk Management Framework. You will work closely with system owners, administrators, and security stakeholders to:
- Audit systems, SOPs, and security checklists.
- Review and analyze audit logs for compliance with STIGs and IAVAs.
- Support Authorization to Operate (ATO) requirements through ongoing compliance monitoring.
- Manage system configuration baselines and documentation.
- Ensure compliance with RMF requirements, including media sanitization, contingency planning, incident response, insider threat policies, and ISAs/SLAs.
- Monitor cloud provider security controls, including FedRAMP-authorized environments.
- Create and modify required artifacts for RMF Steps 1-5.
- Conduct independent reviews, testing, and assessment of all information, artifacts, and other relevant data pertaining to systems progressing through RMF.
- Load artifacts into eMASS.
- Select and tailor controls in eMASS.
- Develop Plan of Actions and Milestones (POA&Ms) / Risk Assessment Reports (RARs), and automated scan reviews.
- Responsible for Certification Test and Evaluation (CT&E) system's compliance with all applicable Information Assurance Controls (IACs) for an assigned system, including developing the appropriate test procedures, executing the test procedures, and accurately documenting the results of security testing.
- Review CT&E test plans and procedures to ensure the test plan addresses level of effort and validates all IA requirements.
- As a requirement of this position, all candidates must be a U.S. Citizen in accordance with 8 U.S.C. 1324b(a)(2)(C).
- Must hold an active DoW Secret Clearance.
- Associate degree or higher in IT, Cybersecurity, Information Assurance, or related field; or 1–2 years of relevant professional experience
- DoD 8570.01-M, IAM Level II certification required.
- Two (2) or more years of experience in the cybersecurity field.
- Experience with assessment and authorization (A&A).
- Experience with assessing and validating RMF, National Institute of Standards and Technology (NIST), and Committee on National Security Systems Instruction (CNSSI) security controls.
- Hands-on experience with eMASS.
- Visio diagram creation and modification.
- RMF Documentation creation and modification (SSP, CCB, COOP, etc.).
- Familiarity with NIST 800-53 controls.
- Ability to provide security assessment reports that cover risks that the client should be aware of and mitigate risk with residual remaining risks.
Skills Required
- U.S. citizenship
- Active DoD Secret clearance
- Associate degree or higher in IT, Cybersecurity, Information Assurance, or a related field, or 1–2 years of relevant professional experience
- DoD 8570.01-M IAM Level II certification
- Two or more years of cybersecurity experience
- Experience with assessment and authorization (A&A)
- Experience assessing and validating RMF, NIST, and CNSSI security controls
- Hands-on experience with eMASS
- Experience creating and modifying Visio diagrams
- Experience creating and modifying RMF documentation, including SSP, CCB, and COOP documents
- Familiarity with NIST 800-53 controls
- Ability to provide security assessment reports covering client risks and residual risk mitigation
What We Do
AMERICAN SYSTEMS is an employee-owned government services contractor that delivers professional, technical, information technology, engineering, analysis, testing, evaluation, and training solutions for complex national-priority programs. Based in McLean, Virginia, the company supports federal customers—particularly defense and other Department of Defense missions—with mission-essential and information engineering, digital engineering, systems integration, cybersecurity, cloud, data, and lifecycle IT services across critical public-sector environments.






