Information Security Analyst Lead
Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
TL;DR
Information Security Analyst Lead (Security Compliance/ATO): Provide security support services and continuously monitor cybersecurity posture across a portfolio of systems with an accent on security tool/control implementation, compliance configuration, and successful program Authorization to Operate (ATO). Focus on analyzing security risks and scan results, leading vulnerability remediation via POA&Ms, and coordinating security communications and incident/alert response across product, engineering, and infrastructure stakeholders.
Location: Primarily remote; must be able to report on-site to Fort Meade, MD when requested.
Salary: $112,800 - $150,000
Company
is a digital services company partnering with clients to improve security and outcomes for Americans.
What you will do
- Facilitate security tool and control implementation, ensure tools/controls remain compliant and properly configured, and support successful ATO.
- Continuously monitor cybersecurity posture; respond to alerts and investigate higher-level security incidents.
- Review and update ATO artifacts (e.g., System Security Plans, Contingency Plans, Configuration/Change Management Plans, Incident Response Plans, Privacy Impact Analysis).
- Analyze security risk assessments and scan results; assess vulnerabilities and support remediation through POA&Ms.
- Maintain security documentation and artifacts; act as primary liaison for security-related data calls and security guidance across the system development lifecycle.
- Review audit logs in Splunk, tune security rules/alerts, maintain security dashboards/reporting, and run periodic user/privileged access reviews.
Requirements
- Minimum 8 years of experience in cybersecurity architecture, cloud security, DevSecOps, security engineering, or related technical field.
- Current Security+ certification.
- Experience designing security “baked-in” to architectures including Cloud and IaC, applications/web applications, data processing, AI/ML, and CI/CD pipelines.
- Working knowledge of AWS or Azure security tools.
- Knowledge of hardening standards (DISA STIG, CIS) and NIST frameworks (NIST Risk Management Framework, NIST 800-53 rev5, NIST 800-171).
- Active secret clearance.
Nice to have
- Federal Government contracting work experience.
- Experience as an ISSO for the DoD.
- Certifications such as CISSP, CEH, or GIAC.
- Experience with SIEM systems (e.g., Splunk).
Culture & Benefits
- Comprehensive benefits package: medical, dental, vision, 401(k), paid time off, paid holidays, life and disability insurance.
- Occasional travel for training and project meetings (estimated <5% per year).
- Hybrid setup: primarily remote with on-site reporting to Fort Meade, MD when requested.
- Reasonable accommodations available during application and hiring.
Hiring process
- Interviews and evaluation of security/ATO and compliance experience.
- Assessment of fit for security tool/control implementation, monitoring, and incident/vulnerability response responsibilities.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →