remote
Information Security Risk Specialist - Booz Allen Hamilton
Software Engineer
Lead cyber risk assessments for government clients, translate complex threats into actionable mitigation plans, and align security controls with NIST, ISO 27001, and cloud security best practices.
About the role
Key Responsibilities
- Conduct comprehensive risk assessments to identify and prioritize cyber threats for federal agencies.
- Translate technical findings and policy requirements into clear, actionable mitigation strategies.
- Develop and maintain security policies and controls aligned with NIST, ISO 27001, and other relevant frameworks.
- Collaborate with subject‑matter experts to gather technical and personnel data, ensuring accurate risk documentation.
- Provide guidance on vulnerability management and cloud security best practices, including AWS and Azure environments.
Requirements
- 5+ years of experience in information security risk analysis or a related field.
- Strong knowledge of NIST Cybersecurity Framework, ISO 27001, and other federal security standards.
- Hands‑on experience with vulnerability assessment tools and cloud security architectures.
- Excellent communication skills to convey complex technical concepts to non‑technical stakeholders.
- Relevant certifications such as CISSP, CISM, or CRISC preferred.