Apply

Ready to go for it?

AI Apply speeds things up—apply directly if you prefer.

FREE ACCESS
5,000–10,000 jobs/day
Scoutfield Logo

See all jobs on Scoutfield

Search thousands of fresh jobs every day.

Discover
  • Fresh listings
  • Fast filters
  • No subscription required
Create a free account and start exploring right away.
Sherpa

Information Security Specialist

Sherpa

. Maintain the security posture of the organization’s internal information systems .

Posted 9/25/2026full-timeSpringfield • Virginia • United StatesMid-LevelSenior💰 $105,000 - $125,000 per yearWebsite

Tech Stack

Tools & technologies
CloudCyber SecurityLinuxMacOS

About the role

Key responsibilities & impact
  • Maintain the security posture of the organization’s internal information systems
  • Ensure compliance with applicable cybersecurity frameworks
  • Collaborate with Security, IT, leadership, and compliance stakeholders
  • Manage system vulnerabilities through scanning, prioritization, and remediation
  • Support patching and configuration enforcement through endpoint management solutions
  • Continuously monitor information systems and identify and mitigate anomalous activity
  • Collect, review, analyze, and correlate logs from endpoints, servers, identity systems, and cloud services
  • Configure and tune alerting and automated response capabilities for security events
  • Perform incident response and reporting for malware, phishing, unauthorized access, and data exfiltration
  • Maintain Plans of Action & Milestones (POA&M) and track remediation to closure
  • Keep security documentation, including SSPs, baselines, policies, and procedures, current and audit-ready
  • Assist in developing and maintaining security policies, standards, and technical controls
  • Review and assess security impacts of system changes during change control processes
  • Recommend and implement security configurations across Microsoft 365, endpoint, and identity platforms
  • Conduct user activity monitoring and support potential insider-threat or policy-violation investigations
  • Run security awareness initiatives, phishing simulations, and training activities
  • Prepare reports on vulnerabilities, incidents, and overall security posture

Requirements

What you’ll need
  • U.S. citizenship required
  • Must be able to obtain and maintain Secret clearance
  • Bachelor's degree in Computer Science, Information Technology, Cybersecurity, or related field
  • 3–5 years of experience in information security or cybersecurity operations
  • Experience with Microsoft Defender, Microsoft Intune, and Microsoft Purview
  • In-depth understanding of software and system vulnerability management
  • Experience with log aggregation, SIEM tools, or advanced threat detection
  • Experience managing Windows and Linux systems in an enterprise environment
  • Experience implementing and maintaining STIGs or CIS Benchmarks
  • Successful completion of a background screening/check/investigation may be required as a condition of hire
  • Preferred: Security+, CISSP, or equivalent certification
  • Preferred: Experience supporting CMMC/NIST 800-171 or NIST 800-53/RMF
  • Preferred: Familiarity with endpoint management and configuration baselines across enterprise systems
  • Preferred: Experience in a regulated environment handling Controlled Unclassified Information (CUI)
  • Preferred: Experience managing macOS systems in an enterprise environment
  • Preferred: Experience maintaining security controls and working on a change control board
  • Preferred: Experience leveraging AI tools in an enterprise setting
  • Preferred: Experience as a COMSEC custodian

Benefits

Comp & perks
  • Medical coverage for employee and family
  • Dental benefits
  • Vision benefits
  • Health and wellness benefits
  • Generous retirement savings plan
  • Generous PTO policy
  • Reasonable accommodations in compliance with the Americans with Disabilities Act