Information Assurance Specialist
planettechnologies
DC Metro Area - Hybrid
Posted Sep 4, 2026
- Full-time
- Federal Division
Job description
Planet Technologies, the Nation’s leading Microsoft services provider to the public sector, is looking for a highly motivated individual to join our growing team as an Information Assurance Specialist. In this role, you will be supporting impactful projects that make a difference for our country. The Information Assurance Specialist utilizes knowledge of Federal sector security processes, hardening of systems, and is essential to the team in managing projects in Azure DevOps, applying Scrum principles and practices to remove impediments and deliver value and foster a collaborative environment. ### Responsibilities - Security Baseline Implementation: Implement, manage, and enforce robust security baselines and benchmarks such as CIS Benchmarks and Azure Foundations across enterprise endpoints and server infrastructure. - Microsoft Group Policy (GPO): Technical expertise to support and audit Active Directory Group Policy Objects (GPOs) to enforce least privilege, disable insecure legacy protocols, and harden on-premises Windows environments. - Microsoft Intune Policy Management Configuration: Experience translating traditional GPOs into modern cloud management frameworks using Microsoft Intune Settings Catalogs, Administrative Templates, and Endpoint Security configurations. - Compliance Mapping & Governance: Aligning technical configuration baselines directly with overarching Information Assurance (IA) frameworks, ensuring that GPO and Intune policy maps cleanly to auditable compliance controls. - Risk Identification & Assessment: Ability to identify, evaluate, and categorize security risks within organizational systems by analyzing technical configurations against established frameworks (such as NIST SP 800-30 or FedRAMP risk assessments). - Guide stakeholders in determining and integrating baseline security requirements, advise on viability of alternative approaches. - Propose remediation/mitigating controls and recommendations to stakeholders and management to minimize risk. - Lead security team engagements to build and mature processes to produce written Standard Operating Procedures (SOP) with a focus on improvement to FERC’s Information Assurance processes, methodologies, and communication methods. ### Qualifications - Bachelor's degree and 3-5 years of relevant work experience with network engineering and/or system administration background (Unix/Linux/Windows). - **Framework Alignment:** Minimum of 3–5 years of experience aligning infrastructure with NIST SP 800-53 Rev 5 or FedRAMP security control frameworks. - **Infrastructure Hardening:** Proven track record authoring and deploying hardening guidance using CIS Benchmarks including Azure Foundations. - **Policy Management:** Technical proficiency understanding and managing Microsoft Group Policy Objects (GPOs) and Microsoft Intune configuration policies. - **Network & Endpoint Security:** Strong understanding of cloud networking architecture, including NSGs, VNet segmentation, Azure Firewall, WAF, and Private Link. - **Identity & Governance:** Strong understanding of Azure RBAC policies, configuring logging/monitoring solutions, and implementing data protection mechanisms. - Skilled in authoring, testing, and debugging Azure Policy definitions and blueprints to automatically enforce configuration benchmarks (like CIS Azure Foundations) across subscriptions. - Direct experience utilizing Microsoft Defender for Cloud and its Regulatory Compliance dashboard to monitor and report on security posture - Ability to articulate ideas to both technical and non-technical audiences through excellent written and oral communication skills. - Ability to independently collect, review, and evaluate IT product data to identify and characterize security threat sources of concern and provide recommendations to Government leadership. - Experience securing infrastructure within Microsoft Azure or Azure Government environments. - **Must possess a valid baseline security certification (e.g., CompTIA Security+, CISSP, CEH, or DoD equivalent).** - Ability to obtain Public Trust Clearance