3 дня назад
Security Assessment & Authorization Analyst, Senior (Cybersecurity)
135 000 - 150 000$
Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
Текст:
TL;DR
Security Assessment & Authorization Analyst, Senior (Cybersecurity) (RMF/NIST): Developing and maintaining Authority to Operate security packages and authorization documentation for federal systems with an accent on NIST 800-53 controls, STIG and SCAP compliance, vulnerability remediation, and POA&M management. Focus on assessing security controls, evaluating configuration changes, recommending mitigating controls, and guiding systems through the Risk Management Framework authorization lifecycle.
Location: Bethesda, Maryland, United States
Salary: $135,000–$150,000 yearly
Company
delivers health, national security readiness, science research and development, systems engineering, integration, and digital transformation solutions for federal civilian and military customers.
What you will do
- Develop and maintain Authority to Operate security packages and authorization documentation.
- Assess security controls against NIST SP 800-53 requirements and support systems through the Risk Management Framework lifecycle.
- Develop, manage, and update Plans of Action and Milestones.
- Analyze STIG and SCAP requirements and track vulnerabilities through remediation, mitigation, or risk acceptance.
- Evaluate environmental and configuration changes for their impact on system security posture.
- Recommend mitigating controls and countermeasures while coordinating with customers, cross-functional teams, and third parties.
Requirements
- At least eight years of experience developing and maintaining ATO security packages.
- Experience documenting system configuration, operations, and security controls.
- Experience with Tenable, Splunk, and GRC JCAM.
- Strong knowledge of federal security guidelines, NIST SP 800-53, security standards, and best practices.
- Bachelor’s degree in information technology, cybersecurity, or a related field.
- Relevant certification such as CGRC/CAP, CISA, CompTIA Security+, or CISSP; must be able to obtain a Public Trust clearance.
Nice to have
- Cloud security experience with AWS, Azure, or GCP in a large government environment.
- Experience with FedRAMP-certified environments.
Culture & Benefits
- Personal time off, medical, dental, vision, life, disability, and flexible spending benefits.
- 401(k) retirement plan with employer matching.
- Training, e-learning, professional and technical certification preparation, and education assistance.
- Performance incentives and program-specific awards may be available.
Hiring process
- maintains a fair and authentic interview process.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →
Похожие вакансии
9 дней назад
Cyber Systems Engineer Technical Specialist - DAO-Rep (Cybersecurity)
133 901 - 232 828$
4 дня назад
Senior Information Systems Security Officer (Cybersecurity)
135 000 - 165 000$
4 дня назад
Information Security Risk Specialist (Cybersecurity)
62 000 - 141 000$
10 дней назад
Senior Systems Engineer (LCAP Governance Assistant)
106 000 - 136 000$
4 дня назад
GRC Cybersecurity Controls Analyst (Cybersecurity)
98 800 - 196 000$
9 дней назад
Security Control Assessor II (Cybersecurity)
142 792 - 181 010$