Security Analyst

CAP, CISSP, Cyber security, FISMA, IT security, Information security, NIST, National Institute of Standards and Technology, RMF, Risk management framework, Security, Security analysis, Security controls, System security
Full Time
$100,000 - $120,000
Travel not required

Job Description

The Security Analyst supports the performance of tasks associated with the National Institute of Standards and Technology (NIST) Risk Management Framework (RMF). This individual supports the preparation of system and security documentation in accordance with Federal Information Security Modernization Act (FISMA) requirements throughout the various stages of the RMF. The Security Analyst works in a team environment and performs assigned tasks with minimal supervision and support. The Security Analyst works closely with system stakeholders to document system information, consult on system/authorization boundary topics, and ensure that applicable security controls are identified and documented appropriately. In addition, the Security Analyst provides support during the assessments of systems to which he/she is assigned by assisting with the tracking and gathering of evidentiary artifacts. After authorization of the system, the Security Analyst supports continuous monitoring by assisting with the scheduling of monitoring activities, maintaining system component inventories, tracking Plan of Action and Milestones (POA&M) entries, and performing user account compliance reviews.

Key Responsibilities:

  • Gather and organize technical information about information systems.
  • Perform boundary scoping exercises and architecture reviews.
  • Develop deliverables associated with a FISMA security package including, but not limited to: System Security Plan, Information System Contingency Plan, Incident Response Plan, Continuous Monitoring Plan.
  • Support the performance of security assessments.
  • Gather and organize artifacts in preparation for security assessments.
  • Maintain information system component inventories.
  • Track and update POA&M entries.
  • Support scheduling of assessments and continuous monitoring activities.

Minimum Requirements:

  • At least 3 years of relevant industry experience in performing RMF-related tasks.
  • At least 3 years of experience with FISMA consulting and/or assessment projects.
  • Thorough understanding of FISMA requirements and NIST guidance.
  • Must be able to work both independently and in a team environment.
  • Must have strong written, verbal, and presentation communication skills.
  • At least one (1) IT Security-related professional certification (e.g., CISSP, CAP).
  • Must be able to obtain Public Trust.

Preferred Qualifications (Not all of these are mandatory but are considered a plus):

  • Bachelor’s degree in Cyber Security, Computer Science, or related discipline.
  • Experience performing FISMA security assessments.
  • Experience developing ALL documents associated with a FISMA security package.
Dice Id : 10486463A
Position Id : 5974659
Originally Posted : 1 year ago
Have a Job? Post it