Назад
Company hidden
3 дня назад

Security Assessment & Authorization Analyst (Cybersecurity)

102 000 - 115 000$
Формат работы
onsite
Тип работы
fulltime
Грейд
middle
Английский
b2
Страна
US
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Security Assessment & Authorization Analyst (Cybersecurity): Developing and maintaining ATO security packages and authorization documentation across the RMF lifecycle with an accent on NIST 800-53 controls, STIG and SCAP compliance, and vulnerability management. Focus on assessing security controls, managing POA&Ms, evaluating configuration changes, and recommending mitigating controls for government systems.

Location: Bethesda, Maryland, United States

Salary: $102,000–$115,000 yearly

Company

hirify.global delivers health, national security, research, systems engineering, and digital transformation solutions for civilian and military federal programs.

What you will do

  • Develop and maintain Authority to Operate security packages and authorization documentation.
  • Support assigned systems across the Risk Management Framework lifecycle.
  • Assess security controls for compliance with NIST 800-53 requirements.
  • Develop, manage, and update Plans of Action & Milestones.
  • Analyze STIG and SCAP requirements and track vulnerabilities through remediation, mitigation, or risk acceptance.
  • Evaluate configuration and environmental changes, recommend mitigating controls, and coordinate with diverse stakeholders.

Requirements

  • Bachelor’s degree in information technology, cybersecurity, or a related field.
  • At least three years of experience developing and maintaining ATO packages and supporting the RMF and ATO lifecycle.
  • Experience documenting system configurations, operations, and security controls.
  • Working knowledge of federal security guidelines and frameworks, including NIST SP 800-53.
  • Experience with security tools such as Tenable, Splunk, and GRC JCAM.
  • Relevant certification required, such as CGRC/CAP, CISA, CompTIA Security+, or CISSP; must be able to obtain a Public Trust clearance.

Nice to have

  • Cloud security experience with AWS, Azure, or GCP in a large FedRAMP-certified government environment.

Culture & Benefits

  • Personal time off, medical, dental, vision, life, disability, and flexible spending benefits.
  • 401(k) retirement plan with employer matching.
  • Training, e-learning, certification preparation, and education assistance.
  • Performance incentives and program-specific awards may be available.

Hiring process

  • hirify.global maintains a fair and authentic interview process.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →