Cybersecurity Analyst
Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
TL;DR
Cybersecurity Analyst (GRC): Leading governance, risk, and compliance activities for federal systems with an accent on NIST Risk Management Framework (RMF) implementation and continuous monitoring. Focus on managing vulnerability assessments via DISA ACAS, maintaining security documentation, and providing senior-level risk reporting to government stakeholders.
Location: Must be based in Alexandria, VA (On-site)
Company
is an SBA certified Service-Disabled Veteran-Owned Small Business providing cybersecurity, IT infrastructure, and professional services to the federal government.
What you will do
- Lead GRC activities ensuring alignment with DoD, DISA, and MC&FP cybersecurity requirements.
- Oversee implementation, assessment, and continuous monitoring of security controls per NIST RMF.
- Manage vulnerability management activities using DISA ACAS, including analysis and remediation tracking.
- Develop and maintain security documentation such as SSPs, POA&Ms, and risk assessments.
- Support cybersecurity audits and inspections by preparing evidence and coordinating corrective actions.
- Provide senior-level risk analysis and compliance reporting to government stakeholders.
Requirements
- Must hold or be able to obtain and maintain a Top Secret clearance.
- BS/BA degree or 14 years of relevant experience.
- 10 years of relevant cybersecurity experience.
- Senior-level cybersecurity and GRC certifications (e.g., CISSP, CAP, CISM) meeting DoD 8570/8140 requirements.
Nice to have
- Master’s Degree.
Culture & Benefits
- Comprehensive medical, dental, and vision insurance plans.
- 401k with competitive matching.
- Paid Time Off and eleven Federal Holidays.
- Parental leave and continuing education assistance.
- Company-paid short-term/long-term disability and life insurance.
- Wellness benefits including Calm Health app and gym subsidies.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →