Information Security Assurance Lead
Job description
About the role
The is a pivotal senior position responsible for steering the information assurance and cybersecurity compliance posture within demanding Federal technology environments. This role owns the end-to-end strategy, execution, and governance of enterprise security programs, ensuring rigorous adherence to Federal regulations, risk management standards, and mission-critical objectives. The successful Lead provides expert technical and managerial direction for complex Assessment and Authorization (A&A) initiatives, Risk Management Framework (RMF) implementations, FISMA compliance verification, and FISCAM audit readiness activities. Success in this position requires hands-on leadership in developing, implementing, and sustaining robust security programs designed to safeguard critical Federal information systems and infrastructure. The Lead acts as the primary subject matter expert, bridging technical security controls with executive and programmatic oversight to ensure organizational resilience. This position demands a proactive and disciplined approach to identifying, assessing, and mitigating cybersecurity risks across the enterprise landscape. The role is integral to enabling secure system development, deployment, and authorization, ensuring that security is embedded throughout the entire system lifecycle.
Location and Engagement
This position is based in Indianapolis, Indiana, and operates as a full-time engagement. The compensation for this role is set at 183,000 USD annually.
What you'll do
- Orchestrate the development and implementation of standardized security intake procedures that capture security requirements and relevant policy documents before any system design activities commence, ensuring security needs are identified early and addressed systematically.
- Design, build, and coordinate the integration of security controls, configurations, and supporting documentation directly into secure infrastructure and applications, embedding security architecture throughout the entire system lifecycle.
- Conduct structured, in-depth review cycles to validate strict compliance with FISMA mandates, Risk Management Framework processes, and Assessment and Authorization standards, verifying that security implementations meet established objectives and rigorous regulatory expectations.
- Coordinate all system shipping, deployment, and change activities to rigorously ensure that systems retain their Authority to Operate and Authority to Connect both during and after any modifications or updates.
- Establish and actively manage strategic partnership workflows that align internal security teams with infrastructure, program management, and audit stakeholders to ensure clear communication, shared accountability, and cohesive security outcomes.
- Champion robust Assessment and Authorization practices that meticulously verify security controls are correctly implemented, comprehensively tested, and precisely matched to stated objectives and federal requirements.
- Implement and oversee risk management strategies that systematically track, categorize, analyze, and proactively address vulnerabilities across the enterprise information systems and technology infrastructure.
- Guide and lead complex FISCAM audit preparations by meticulously organizing evidence, clearly clarifying findings, and diligently tracking remediation status to ensure timely resolution and audit readiness.
- Supervise Information Assurance personnel, providing strategic direction, technical mentorship, performance feedback, and professional development to ensure high team effectiveness and program success.
- Communicate regularly and proactively with internal and external stakeholders to provide detailed status updates, clarify intricate requirements, manage evolving expectations, and facilitate informed decision-making.
- Sustain unwavering Authority to Operate and Authority to Connect through vigilant, continuous oversight, timely corrective action, and comprehensive monitoring of security controls and compliance postures.
- Drive continuous improvement initiatives for information assurance processes, ensuring that security programs evolve in alignment with emerging threats, Federal regulations, and best practices.
- Serve as the principal technical and management authority for Information Assurance, representing the organization's security interests at executive levels and during cross-functional engagements.
- Ensure all security activities, documentation, and controls are meticulously maintained, auditable, and aligned with Federal oversight requirements and reporting standards.
- Lead incident response readiness and coordination efforts related to security assurance, contributing to rapid identification, assessment, and remediation of potential security impacts.
Requirements
- Must hold active experience overseeing Information Assurance programs within Federal contexts, a background that is critical for navigating complex regulatory environments and ensuring compliance.
- Requires proven ability directing Assessment and Authorization activities and Risk Management Framework implementations, demonstrating successful delivery of compliant security outcomes in real-world Federal engagements.
- Should demonstrate extensive hands-on experience developing, maintaining, and governing enterprise security programs through direct involvement in security architecture and control implementation.
- Requires deep technical understanding of security controls, compliance processes, and Federal regulations, including FISMA, NIST frameworks, and related statutory and regulatory requirements.
- Must possess the capacity to supervise personnel effectively, communicate clearly and persuasively with diverse stakeholders, and sustain rigorous Authority to Operate and Authority to Connect throughout the system lifecycle.
- Needs strong analytical and problem-solving skills to interpret complex security requirements, assess risk implications, and develop practical mitigation strategies.
- Requires demonstrated ability to manage multiple priorities and deadlines in a fast-paced Federal technology environment while maintaining attention to detail and accuracy.
- Must be capable of reading, interpreting, and applying Federal security policies, directives, and guidance documents to ensure full program compliance and auditability.
Nice to have
No optional or nice-to-have qualifications are specified for this role at this time.
Practical notes
- Engagement is full-time based in Indianapolis, Indiana.
- Compensation is fixed at 183,000 USD annually.
- No travel, visa, or deadline information is provided in the source material.