hatch I.T. is partnering with Expression to find a Senior Information Assurance Engineer. See details below:
About The Role:
Expression is looking for an experienced Senior Information Assurance (IA) Engineer to lead cybersecurity and Risk Management Framework (RMF) activities supporting the Defense Information Systems Agency (DISA) Global Force Management (GFM) Program Management Office (PMO) for the Joint Planning and Execution Services (JPES) and Joint Capabilities Requirements Manager (JCRM) Sustainment Program.
The Senior Information Assurance Engineer serves as the cybersecurity lead for the program, ensuring the confidentiality, integrity, availability, and compliance of mission-critical systems operating in classified and unclassified environments. This position provides technical leadership for RMF implementation, security compliance, vulnerability management, continuous monitoring, and cybersecurity documentation while partnering closely with Government Information System Security Managers (ISSMs), Security Control Assessors (SCAs), system engineers, and DevSecOps teams.
Clearance: Secret Clearance required
Location: DISA Headquarters, 6910 Cooper Ave, Fort Meade, MD
About the Company:
Founded in 1997 and headquartered in Washington DC, Expression provides data fusion, data analytics, software engineering, information technology, and electromagnetic spectrum management solutions to the U.S. Department of Defense, Department of State, and national security community. Expression’s “Perpetual Innovation” culture focuses on creating immediate and sustainable value for their clients via agile delivery of tailored solutions built through constant engagement with their clients. Expression was ranked #1 on the Washington Technology 2018's Fast 50 list of fastest growing small business Government contractors and a Top 20 Big Data Solutions Provider by CIO Review.
Responsibilities:
- Lead execution of the DoD Risk Management Framework (RMF) throughout the system lifecycle in accordance with DoD, DISA, and NIST guidance.
- Maintain and update cybersecurity documentation, security controls, and authorization artifacts within eMASS to support Authority to Operate (ATO) requirements.
- Develop and maintain cybersecurity documentation, including Self-Assessment Plans, Self-Assessment Reports, Plans of Action and Milestones (POA&Ms), and other required RMF deliverables.
- Conduct security control assessments, vulnerability assessments, STIG compliance reviews, and continuous monitoring activities to ensure ongoing system compliance.
- Create, manage, and track POA&Ms, recommend risk mitigation strategies, and coordinate remediation efforts with engineering and system administration teams.
- Support implementation of security controls aligned with NIST SP 800-37, NIST SP 800-53, DoD RMF, DISA STIGs, and applicable cybersecurity policies.
- Collaborate with software development, DevSecOps, cloud infrastructure, and system administration teams to integrate cybersecurity requirements throughout the software development lifecycle.
- Evaluate security impacts of software releases, infrastructure changes, patches, and technology refresh activities to ensure continued compliance.
- Monitor emerging cybersecurity vulnerabilities, DoD taskings, and security advisories, providing recommendations to maintain secure system operations.
- Support Government cybersecurity reviews, security inspections, audits, and authorization activities while serving as the primary cybersecurity interface with Government stakeholders.
- Provide technical guidance on secure system architecture, vulnerability remediation, configuration management, and continuous improvement of cybersecurity processes.
- Ensure compliance with classified network security requirements supporting NIPRNet, SIPRNet, and Microsoft Azure IL6 environments.
Qualifications:
- Bachelor's degree in Information Technology, Computer Science, Cybersecurity, Information Assurance, or a related technical discipline. Four additional years of relevant experience may substitute for the degree.
- Minimum 4 years of experience supporting Information Assurance, Cybersecurity, or Risk Management Framework (RMF) activities within Federal Government or DoD environments.
- Security+, CISSP, CAP, CASP+, or equivalent DoD 8570/8140 cybersecurity certification.
- Demonstrated experience implementing and maintaining DoD RMF in accordance with NIST SP 800-37 and NIST SP 800-53.
- Experience administering and maintaining RMF documentation within eMASS.
- Experience performing vulnerability assessments, STIG compliance reviews, POA&M management, and continuous monitoring.
- Experience supporting Authority to Operate (ATO) packages and cybersecurity accreditation activities.
- Working knowledge of DoD cybersecurity policies, DISA Security Technical Implementation Guides (STIGs), and cybersecurity compliance requirements.
- Strong understanding of Windows and Linux operating systems, network security principles, cloud environments, and secure system administration.
- Excellent written and verbal communication skills with experience preparing technical reports and briefing Government stakeholders.
- Active Secret security clearance with the ability to maintain eligibility for access to classified DoD systems.
Preferred Qualifications:
- Experience supporting DISA, Global Force Management (GFM), or other DoD enterprise systems.
- Experience with Microsoft Azure IL6 cloud environments and DevSecOps security practices.
- Experience supporting classified NIPRNet and SIPRNet environments.
- Familiarity with vulnerability management tools, SCAP, ACAS, HBSS/ESS, and DISA cybersecurity toolsets.
- Experience supporting Agile software development environments and secure software delivery practices.
Benefits:
Expression offers competitive salaries and benefits, such as:
- 401k matching
- PPO and HDHP medical/dental/vision insurance
- Education reimbursement up to $10,000/yr
- Complimentary life insurance
- Generous PTO and 11 days of holiday leave
- Onsite gym facility and trainer
- Commuter Benefits Plan
- In-office Cold Brew Coffee
Skills Required
- Bachelor's degree in IT, Computer Science, Cybersecurity, Information Assurance, or related technical discipline (or four additional years of relevant experience)
- Minimum 4 years' experience supporting Information Assurance, Cybersecurity, or RMF activities within Federal Government or DoD environments
- DoD 8570/8140 certification such as Security+, CISSP, CAP, or CASP+ (or equivalent)
- Demonstrated experience implementing and maintaining DoD RMF per NIST SP 800-37 and NIST SP 800-53
- Experience administering and maintaining RMF documentation within eMASS
- Experience performing vulnerability assessments, STIG compliance reviews, POA&M management, and continuous monitoring
- Experience supporting Authority to Operate (ATO) packages and cybersecurity accreditation activities
- Working knowledge of DoD cybersecurity policies, DISA STIGs, and compliance requirements
- Strong understanding of Windows and Linux operating systems, network security principles, cloud environments, and secure system administration
- Excellent written and verbal communication skills; experience preparing technical reports and briefing Government stakeholders
- Active Secret security clearance with ability to maintain eligibility for access to classified DoD systems
- Experience supporting DISA, Global Force Management, or other DoD enterprise systems
- Experience with Microsoft Azure IL6 cloud environments and DevSecOps security practices
- Experience supporting classified NIPRNet and SIPRNet environments
- Familiarity with vulnerability management tools, SCAP, ACAS, HBSS/ESS, and DISA cybersecurity toolsets
- Experience supporting Agile software development environments and secure software delivery practices
What We Do
Get behind the scenes insights from startup tech teams: https://www.myhatchpad.com/newsletter/ hatch I.T. is a specialized technology consulting firm connecting software, product, and data engineers with tech startups in emerging tech markets. We offer customized models that transform the way early-stage and high-growth startups scale. Our flagship programs include: - Scale – technical consulting and recruiting services for high-growth startups - Stride – technical strategy and consulting for early-stage startups - hatchpad – an online community platform connecting startup technologists to network, learn, and advance in their careers In true startup fashion, our roots can be traced to a garage in Leesburg, VA in 2013. While working with local startups, our Founder & CEO, Tim Winkler, realized that traditional staffing models didn’t align with the growth needs of startups. Working with those firms felt transactional and the costs were way outside a startup's budget. There was a need for a solution that was relational, community driven, and flexibly priced. With this in mind, hatch I.T. was formed, along with customized models that transform the way early-stage and high-growth startups scale. Fast forward 8 years and 15 employees later, hatch has developed a platform that provides a roadmap to guide startups from MVP through all stages of growth. After proving this model with dozens of startups across DC, Maryland, & Virginia, we realized it was needed in all emerging startup markets. If you’re a startup looking to grow your startup team, or an engineer looking for a career at an innovative tech company, connect with hatch I.T. today.








