Cloud Service Provider Common Control Analyst

Washington, DC, US • Posted 3 hours ago • Updated 3 hours ago
Full Time
On-site
USD $145,000.00 - 160,000.00 per year
Fitment

Dice Job Match Score™

📊 Calculating match score...

Job Details

Skills

  • DOS
  • FISMA
  • System Security
  • SSP
  • Standard Operating Procedure
  • SOP
  • Incident Management
  • Configuration Management
  • Computer Hardware
  • Data Flow
  • Vulnerability Scanning
  • Test Cases
  • Security QA
  • Web Applications
  • Financial Software
  • Database
  • Operating Systems
  • Network
  • Laptop
  • Security Analysis
  • FedRAMP
  • Presentations
  • Testing
  • Specification Gathering
  • NIST SP 800 Series
  • NIST 800-53
  • Cyber Security
  • Privacy
  • Writing
  • Documentation
  • Communication
  • Computer Science
  • Management Information Systems
  • Information Security
  • Information Architecture
  • Impact Analysis
  • Information Assurance
  • Security Clearance
  • Evaluation
  • Regulatory Compliance
  • Risk Management Framework
  • RMF
  • Risk Assessment
  • Security Controls
  • SCA
  • Authorization
  • Information Technology
  • IT Security Assessment
  • Cloud Computing
  • Amazon Web Services
  • Microsoft Azure
  • Management
  • Budget
  • OMB
  • SAP BASIS
  • Law
  • FOCUS

Summary

Job Description

ECS is seeking a Cloud Service Provider Common Control Analyst to work in our Washington, DC office.

ECS is seeking a Cloud Service Provider Common Control Analyst to support the Department of State (DOS), Bureau of Diplomatic Technology (DT). This role is part of the Common Control team, responsible for ensuring high-value and mission-critical systems comply with federal cybersecurity policies. The ideal candidate will serve as a Cloud Service Provider Common Control Analyst, executing the full range common control tasks spread throughout the Risk Management Framework (RMF).

  • Review and update existing information security policy, standards, and procedures based on federal and departmental regulations.
  • Perform independent security and privacy control assessments in support of Security Assessment & Authorization (SA&A).
  • Conduct assessments of existing and new FISMA systems, including subsystems in the respective system boundary, and communicate the results and potential implications of identified control weaknesses.
  • Reviews and analyze, Assessment & Authorization (A&A) packages to include System Security Plans (SSP), Risk Assessments, Information System Contingency Plans (ISCP), Back-up Standard Operating Procedures (SOP), Incident Response Plans (IRP), Configuration Management Plans, (CMP), Hardware/Software lists, Network Diagrams, Data Flows, System Change Requests/Proposals, Vulnerability scan reports, test reports, and Plan of Actions & Milestones (POA&Ms) for completeness, accuracy, and document effectiveness of controls, plans and procedures implementation.
  • Create and maintain test cases for security assessment testing and perform security testing at the control-requirement level for each unique component of each system (e.g., application, web application server, financial systems, database server/instance, operating systems, specialized appliances, network and infrastructure devices, and end-user devices (e.g., mobile phones, laptops, etc.).
  • Develop and execute a security and privacy assessment plan in accordance with NIST SP 800-53A, as amended, requirements, for each security assessment project. SA&A activities shall include support for RMF steps 4-6
  • Document and provide findings and recommendations that are concise, system-specific, and actionable.
  • Analyze security tool reports and determine residual risk or false positives from technical reports and artifacts before assigning findings.

Salary Range: $145,000 - $160,000

General Description of Benefits

Required Skills

  • Ten (10+) years experience in the cybersecurity field.
  • Three (3+) years plus experience performing security control assessments in FedRAMP cloud environment.
  • Experience in planning assessments and be a senior member in a team of security control assessors
  • Experience in presenting control requirements and deficiencies to both technical and non-technical audiences.
  • Experience performing detailed, full-scope technical security control testing for each of the component types, including development of security and privacy assessment plans is required.
  • Ability to analyze information system configurations and technical specifications against NIST SP 800-53 and other overlays
  • Possesses a strong understanding of the NIST Special Publication 800-53 security and privacy controls, the NIST Cybersecurity Framework and other information security and privacy laws and regulations.
  • Experience with development and writing of risk-based documentation.
  • Experience with Step 4 of RMF process- Assessing Security Controls
  • Strong written and verbal communication skills.
  • Strong communication ability across all levels of management.
  • Bachelor's degree or higher in Computer Science's, MIS/IT, Engineering, Information Security/IA, or related discipline to work requirement
  • ACTIVE Secret Clearance


Desired Skills

  • Five (5+) years experience directly related to security control evaluation and compliance with Federal RMF requirements.
  • Two (2+) years of experience with the use of eGRC tools in Federal environment
  • Experience performing Assessment and Authorization (A&A) activities, including risk assessments, Security Plans, Security Controls Assessments (SCA), Authorization document development and/or review.
  • Knowledge of current industry methods for evaluating, implementing, and disseminating information technology (IT) security assessment, monitoring, detection, and remediation tools and procedures utilizing standards-based concepts and capabilities.
  • Experience with cloud technology offerings from AWS and Azure and assessing systems hosted within those environments
  • Experience performing assessment in accordance with the policies, procedures, and standards of the Office of Management and Budget (OMB), the National Institute of Standards and Technology (NIST), and the Department of State.
#ECS1

ECS is an equal opportunity employer and does not discriminate or allow discrimination on the basis any characteristic protected by law. All qualified applicants will receive consideration for employment without regard to disability, status as a protected veteran or any other status protected by applicable federal, state, or local jurisdiction law.

ECS is a leading mid-sized provider of technology services to the United States Federal Government. We are focused on people, values and purpose. Every day, our 3200+ employees focus on providing their technical talent to support the Federal Agencies and Departments of the US Government to serve, protect and defend the American People.
Employers have access to artificial intelligence language tools (“AI”) that help generate and enhance job descriptions and AI may have been used to create this description. The position description has been reviewed for accuracy and Dice believes it to correctly reflect the job opportunity.
  • Dice Id: 10112MAN
  • Position Id: 3360
  • Posted 3 hours ago
Create job alert
Set job alertNever miss an opportunity! Create an alert based on the job you applied for.

Similar Jobs

Washington, District of Columbia

Today

Full-time

Washington, District of Columbia

Yesterday

Full-time

USD 60,000.00 per year

Arlington, Virginia

Today

Easy Apply

Full-time

$130000 - $155000

Washington, District of Columbia

Today

Easy Apply

Full-time

Search all similar jobs