IT Security Analyst

• Posted 14 hours ago • Updated 2 hours ago
Full Time
On-site
Fitment

Dice Job Match Score™

🔢 Crunching numbers...

Job Details

Skills

  • IT Security
  • Impact Analysis
  • Communication
  • Data-flow Diagrams
  • Risk Management
  • FISMA
  • Policies and Procedures
  • NIST SP 800 Series
  • DFAR
  • PPS
  • Vulnerability Management
  • Cloud Computing
  • Security Controls
  • Python
  • Bash
  • Java
  • Windows PowerShell
  • Scripting
  • Continuous Integration
  • Continuous Delivery
  • Amazon ECR
  • Mirroring
  • SAP
  • Regulatory Compliance
  • DoD
  • Risk Assessment
  • FedRAMP
  • RMF
  • STIG
  • Risk Management Framework
  • Writing
  • System Security
  • Documentation
  • Authorization
  • Computer Networking
  • Network
  • Microsoft Visio
  • Testing
  • Cyber Security
  • Privacy
  • Presentations
  • Public Speaking
  • Electronic Warfare

Summary

Herndon, VA - Hybrid (Tue / Wed / Thu Onsite)
No Dual Citizenship

FedRAMP / RMF DoD / NIST

The Security Analyst will work as a member of our client's cyber team, assisting with the creation, update, and maintenance of FedRAMP-required security documentation, associated artifacts, and Continuous Compliance Monitoring (CCM) requirements such as the Plan of Action and Milestones (POA&M). The role also supports the Cloud Operations team with identification and corrective actions associated with known vulnerabilities, and provides advisement to stakeholders on changing regulatory, government, and Cloud/FedRAMP policies - including risk assessment, business impact analysis, system categorization, security authorization and accreditation/certification activities (A&A), security control inheritance, and other artifacts needed to validate control compliance.

? Critical Requirements

Required Skills

Compliance & Governance
  • Understand and document information system specifications and security controls, including logical and physical diagrams, connectivity, communication, and data flow diagrams - both internal and external to the system
  • Advise stakeholders on multiple courses of action in environments with changing or unconfirmed policy (e.g., NIST RMF, DISA SRG)
  • Document courses of action and identify risk mitigation recommendations in accordance with FedRAMP requirements, client policy, and best practices - including associated benefits and drawbacks
  • Apply enterprise security frameworks (FISMA, NIST SP 800, etc.) to existing cloud environment initiatives
  • Develop and update policies and procedures to implement FedRAMP compliance, NIST 800-171 security requirements, and other DFAR clauses
  • Demonstrate familiarity with current FedRAMP, DoD, and NIST security controls and technologies, including vulnerability management capabilities
  • Identify and assess cloud system state including vulnerabilities, RMF package status, accreditation model, PPS compliance, and patching/CSVA mechanisms


Vulnerability Management
  • Knowledge of Risk-Based Vulnerability Framework and how to prioritize, assess, and remediate exploitable vulnerabilities
  • Ability to create automation scripts to minimize manual workload behind identifying and analyzing vulnerabilities across various scanning tools
  • Ability to analyze container vulnerabilities in secure cloud environments and identify remediation paths at the OS and application level
  • Understand enterprise operating environments including security posture, application environment, and associated security controls


Required Technical Experience

Technical Skills

Python, Bash, Java & PowerShell Scripting

Container Scanning Tools

CI/CD Pipelines & AWS ECR

Container Image Mirroring

Attack Vector Analysis

Network Diagrams & Visio

SAP Products

Testing / Dev / Staging Environments

RMF & Compliance Experience
  • Demonstrated knowledge and ability to analyze systems for cybersecurity compliance
  • Knowledge of Federal and DoD policies and risk assessment methodologies including FedRAMP, NIST SPs, and RMF overlays
  • Hands-on experience with DISA STIG requirements and SRGs, CNSSI, and NIST Risk Management Framework
  • Experience writing or executing system security documentation, Authorization to Operate (ATO) packages, POA&Ms, and policies
  • Knowledge and understanding of systems and networking technologies and concepts
  • Ability to interpret and assess network diagrams using Visio
  • Familiarity with Testing, Development, Staging, and pre-production environments requiring cybersecurity support
  • Knowledge of the Privacy Act
  • Presentation and public speaking skills required
  • Ability to work in a fast-paced, team-oriented environment


#LI-EW1
Employers have access to artificial intelligence language tools (“AI”) that help generate and enhance job descriptions and AI may have been used to create this description. The position description has been reviewed for accuracy and Dice believes it to correctly reflect the job opportunity.
  • Dice Id: sharpdec
  • Position Id: 53248
  • Posted 14 hours ago
Create job alert
Set job alertNever miss an opportunity! Create an alert based on the job you applied for.

Similar Jobs

Hybrid in Bethesda, Maryland

Yesterday

Easy Apply

Full-time

$130000

San Diego, California

Today

Full-time

USD 131,300.00 - 237,350.00 per year

Dallas, Texas

Today

Full-time

USD 98,234.50 - 123,765.49 per year

No location provided

Today

Full-time

USD 103,100.00 per year

Search all similar jobs