Назад
Company hidden
3 дня назад

Security Assessment & Authorization (SA&A) Analyst

115 000 - 126 000$
Формат работы
onsite
Тип работы
fulltime
Грейд
middle
Английский
b2
Страна
US
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Security Assessment & Authorization (SA&A) Analyst (RMF/cybersecurity): Developing and maintaining Authority to Operate security packages and authorization documentation across the Risk Management Framework lifecycle with an accent on NIST 800-53 controls, STIG and SCAP compliance, and vulnerability management. Focus on assessing security controls, managing POA&Ms, evaluating configuration changes, and recommending mitigating controls for federal systems.

Location: Bethesda, Maryland, United States

Salary: $115,000–$126,000 yearly

Company

hirify.global delivers health, national security, systems engineering, digital transformation, artificial intelligence, data analytics, cloud enablement, modeling, and simulation solutions for federal programs.

What you will do

  • Develop and maintain Authority to Operate security packages and authorization documentation.
  • Support assigned systems throughout the Risk Management Framework lifecycle.
  • Assess security controls for compliance with NIST SP 800-53 requirements.
  • Develop, manage, and update Plans of Action & Milestones.
  • Analyze STIG and SCAP requirements and track vulnerabilities through remediation, mitigation, or risk acceptance.
  • Evaluate system and environmental changes and recommend mitigating controls and countermeasures.

Requirements

  • At least five years of experience developing and maintaining ATO security packages and supporting the RMF and ATO lifecycle.
  • Experience documenting system configuration, operations, and security controls.
  • Experience with Tenable, Splunk, and GRC JCAM.
  • Working knowledge of federal security guidelines, NIST SP 800-53, and related control frameworks.
  • Bachelor’s degree in information technology, cybersecurity, or a related field.
  • Relevant certification required, such as CGRC (CAP), CISA, CompTIA Security+, or CISSP; must be able to obtain a Public Trust clearance.

Nice to have

  • Cloud security experience with AWS, Azure, or GCP in a large government environment.
  • Experience with FedRAMP-certified environments.

Culture & Benefits

  • Personal time off, medical, dental, vision, life, disability, and flexible spending benefits.
  • 401(k) retirement plan with employer matching.
  • Training, e-learning, professional and technical certification preparation, and education assistance.
  • Performance incentives and program-specific awards may be available.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →