Назад
Company hidden
3 дня назад

Security Assessment & Authorization Analyst, Senior (Cybersecurity)

135 000 - 150 000$
Формат работы
onsite
Тип работы
fulltime
Грейд
senior
Английский
b2
Страна
US
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Security Assessment & Authorization Analyst, Senior (Cybersecurity) (RMF/NIST): Developing and maintaining Authority to Operate security packages and authorization documentation for federal systems with an accent on NIST 800-53 controls, STIG and SCAP compliance, vulnerability remediation, and POA&M management. Focus on assessing security controls, evaluating configuration changes, recommending mitigating controls, and guiding systems through the Risk Management Framework authorization lifecycle.

Location: Bethesda, Maryland, United States

Salary: $135,000–$150,000 yearly

Company

hirify.global delivers health, national security readiness, science research and development, systems engineering, integration, and digital transformation solutions for federal civilian and military customers.

What you will do

  • Develop and maintain Authority to Operate security packages and authorization documentation.
  • Assess security controls against NIST SP 800-53 requirements and support systems through the Risk Management Framework lifecycle.
  • Develop, manage, and update Plans of Action and Milestones.
  • Analyze STIG and SCAP requirements and track vulnerabilities through remediation, mitigation, or risk acceptance.
  • Evaluate environmental and configuration changes for their impact on system security posture.
  • Recommend mitigating controls and countermeasures while coordinating with customers, cross-functional teams, and third parties.

Requirements

  • At least eight years of experience developing and maintaining ATO security packages.
  • Experience documenting system configuration, operations, and security controls.
  • Experience with Tenable, Splunk, and GRC JCAM.
  • Strong knowledge of federal security guidelines, NIST SP 800-53, security standards, and best practices.
  • Bachelor’s degree in information technology, cybersecurity, or a related field.
  • Relevant certification such as CGRC/CAP, CISA, CompTIA Security+, or CISSP; must be able to obtain a Public Trust clearance.

Nice to have

  • Cloud security experience with AWS, Azure, or GCP in a large government environment.
  • Experience with FedRAMP-certified environments.

Culture & Benefits

  • Personal time off, medical, dental, vision, life, disability, and flexible spending benefits.
  • 401(k) retirement plan with employer matching.
  • Training, e-learning, professional and technical certification preparation, and education assistance.
  • Performance incentives and program-specific awards may be available.

Hiring process

  • hirify.global maintains a fair and authentic interview process.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →