Назад
Company hidden
9 дней назад

Information Assurance Support Analyst (Cybersecurity)

Формат работы
onsite
Тип работы
fulltime
Грейд
senior
Английский
b2
Страна
US
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Information Assurance Support Analyst (Cybersecurity): Supporting FISMA systems through Security Assessment and Authorization and the NIST Risk Management Framework with an accent on security categorization, authorization documentation, vulnerability assessment, and continuous monitoring. Focus on analyzing security risks, assessing FedRAMP packages, documenting compliance against DISA STIGs and CIS Benchmarks, and managing POA&Ms.

Location: Rockville, Maryland, United States; 10% occasional domestic travel

Company

hirify.global provides technical support for the NRC-CPSS Contract and its Civilian Division.

What you will do

  • Support FISMA systems through Security Assessment and Authorization across the NIST Risk Management Framework.
  • Assess confidentiality, integrity, and availability impacts and determine FIPS 199 security categorizations.
  • Develop and maintain security documentation, including system security plans, risk assessments, contingency plans, incident response plans, and vulnerability assessment reports.
  • Analyze risks from security control assessments and continuous monitoring, then recommend mitigation and remediation actions.
  • Perform vulnerability scans and configuration compliance checks against DISA STIGs and CIS Benchmarks.
  • Review FedRAMP packages and continuous monitoring deliverables, and create and manage Plans of Action and Milestones.

Requirements

  • US citizenship required.
  • Secret Clearance and ability to obtain an NRC Security Clearance required.
  • Bachelor’s degree or five additional years of equivalent experience.
  • Six years of IT experience, including four years specializing in information assurance.
  • At least one relevant certification required: CompTIA Security+, CISSP, CISA, GIAC GSEC, GIAC GSNA, GIAC GPEN, CEH, CAP, CASP+, CRISC, or CCSK.
  • Strong communication, attention to detail, prioritization, and collaboration skills.

Nice to have

  • Experience with Tenable Security Center, FedRAMP authorization packages, cloud security, technical architecture reviews, and shared responsibility models.
  • Knowledge of Azure, AWS, virtualization, networking, web services, firewalls, VPNs, databases, intrusion prevention, and anti-malware tools.
  • Familiarity with PowerShell, VBA, and AI chat tools for productivity.

Culture & Benefits

  • Full-time position with collaboration across system administrators, ISSOs, Authorizing Officials, cloud service providers, and other stakeholders.
  • Occasional domestic travel of approximately 10%.
  • Work includes individual responsibilities as well as project and stakeholder meetings.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →