Cybersecurity Analyst responsible for supporting Government activities in IT security compliance. Requires active TS/SCI clearance and experience with Risk Management Framework at GDIT.
Responsibilities
Acting as an appointed Information System Security Officer (ISSO) for IC cyber systems being developed by the engineering team
Reporting, documenting, and briefing the status of systems under development, while assuring their successful and timely progression through the clients’ Risk Management Framework (RMF) to the satisfaction of the appointed Information System Security Manager (ISSM), and/or Senior Government leadership
Providing clear justification satisfying all applicable security control implementation as specified by the IC, AO, or NIST-800-53, rev 4 rev 5
Authoring System Security Plans (SSP) and System Security Test Plans (SSTP)
Conducting self-assessments of all systems under development
Analyzing security controls and the impacts the changes would have on the environment
Preparing for and assisting with formal risk assessments conducted by the AO’s designated Security Control Assessors (SCA) while acting as a member of the security assessment test team
Ensuring the remediation of any findings assigned to engineering as documented in the Security Assessment Report (SAR) and its Plan of Actions and Milestones (PO&AM)
Documenting and defending reasoning when waivers are sought, or non-standard remediation solutions are requested for specific security controls
Assisting with the transition of systems granted an ATO to the Operations branch and the assignment of an operations ISSO
Researching remediation options for vulnerabilities identified for systems under development or already in production under an ATO
Requirements
Active TS/SCI clearance and ability to obtain and maintain a CI poly
Must meet DoD 8570 IAT Level II requirements including one of the following: Security+ CE, CND, SSCP, GSEC, GICSP, CySA+, or CCNA Security
Bachelor’s Degree in a related technical discipline +6 years’ experience or the equivalent combination of education, technical certification or training, or work/military experience
Minimum of 3-years IC (SCI) RMF Assessment and Authorization (A&A) experience and the ability to describe the differences between collateral and SCI authorization requirements as they apply to DoD and IC instructions and guidelines
Ability to speak to the intent of all NIST 800-53 security controls
Minimum 1-year hands on experience with the Xacta application
Excellent oral and technical writing skills
Ability to work both independently and as a member of a team
Benefits
Comprehensive benefits and wellness packages
401K with company match
Competitive pay and paid time off
Full flex work weeks where possible
Variety of paid time off plans including vacation, sick, personal time, holidays, paid parental, military, bereavement and jury duty leave
Short and long-term disability benefits
Life, accidental death and dismemberment, personal accident, critical illness and business travel and accident insurance
Industrial Security Analyst ensuring compliance with federal security regulations and administering security programs for classified materials. Collaborating with internal and external stakeholders in a high - profile setting.
Staff Cybersecurity Analyst responsible for safeguarding cloud assets and leading security assessments for Southern Glazer’s. Collaborating with teams to develop cloud security policies and addressing cybersecurity incidents.
Senior Threat Intelligence Analyst working with Bupa's cybersecurity team. Focused on threat management and defensive strategies to enhance cyber security posture.
Senior Information Security Analyst at Field Nation leading SOC 2 and ISO 27001 compliance programs. Collaborating with teams to embed security and leverage AI in GRC workflows.
Analista de Ciberseguridad en CRG Solutions responsable de monitorear amenazas y gestionar vulnerabilidades en la organización. Identificación de riesgos y mejora continua de la postura de seguridad.
Compliance & Information Security Analyst at beqom managing GRC and TPRM functions. Overseeing client governance, risk, and compliance requests, and vendor due diligence at a SaaS company.
Senior Technical Expert in Cyber Defense Center at ZEISS analyzing global cyber threats. Collaborating with SOC, CIRT, and ensuring proactive defense strategies.
Information Security Analyst focusing on vulnerability research and data analysis at Flexera. Involves analyzing, verifying vulnerabilities, and maintaining high - quality content standards.
Oversee the testing lifecycle and provide cyber security solutions at Xcel Energy. Engage in various testing techniques and collaborate with teams to enhance quality practices.