Talent.com
Information Security Analyst, Information Assurance / RMF
Information Security Analyst, Information Assurance / RMFNationwide IT Services • Alexandria, VA, US
Information Security Analyst, Information Assurance / RMF

Information Security Analyst, Information Assurance / RMF

Nationwide IT Services • Alexandria, VA, US
Hace más de 30 días
Tipo de contrato
  • A tiempo completo
Descripción del trabajo

Job Description

Job Description
Information Security Analyst, Information Assurance/RMF
Active Secret Required
Hybrid schedule
CISSP, CAP, or CISM certification required

Nationwide IT Services, NIS, is seeking an Information Security Analyst/Information Assurance/RMF for the following potential opportunity.

Core Responsibilities:
  • Support the execution of the full cybersecurity and RMF lifecycle for DoD and Federal systems, with emphasis on security control implementation, assessment, authorization, and continuous monitoring activities.
  • Perform vulnerability scanning and compliance validation, including, but not limited to, ACAS scanning, STIG assessments, SCAP validation, and configuration compliance checks.
  • Analyze vulnerability scan results, identify false positives, assess risk severity, and support remediation planning in coordination with engineering and operations teams.
  • Track, document, and manage remediation activities and Plans of Action and Milestones (POA&Ms) through closure, ensuring alignment with mandated timelines and risk tolerance.
  • Support RMF authorization activities, including initial ATOs, ATO renewals, significant change packages, and continuous authorization (cATO) efforts.
  • Support and execute Information Security Continuous Monitoring (ISCM) activities, including vulnerability trend analysis, control effectiveness validation, configuration drift monitoring, and security posture reporting.
  • Support the implementation and monitoring of Zero Trust security principles at a system level, including identity awareness, least privilege access, and continuous validation of users, devices, and workloads.
  • Prepare, review, and maintain cybersecurity and authorization artifacts in eMASS, including, but not limited to:
    • System Security Plans (SSPs)
    • Security Assessment Reports (SARs)
    • Plans of Action and Milestones (POA&Ms)
    • Control implementation narratives and supporting evidence packages
  • Conduct security control assessments and support independent verification and validation activities.
  • Assist with the implementation and maintenance of security controls aligned with NIST SP 800-53 and DoD cybersecurity requirements.
  • Coordinate with system owners, cybersecurity engineers, and program leadership to communicate security findings, risks, and remediation status.
  • Support cybersecurity audits, inspections, and Cyber Operational Readiness Assessments (CORA), ensuring accurate documentation and evidence traceability.
  • Assist in maintaining compliance with applicable cybersecurity policies, including FISMA, DoD RMF, DoD Zero Trust guidance, and the DoD Cloud Computing Security Requirements Guide (CC SRG).
Qualifications:
  • Active Secret clearance required.
  • Five or more years of experience in information security, information assurance, or cybersecurity operations, with experience supporting RMF-based programs.
  • Hands-on experience performing vulnerability scanning and compliance assessments using tools such as ACAS, STIG Viewer, and SCAP Compliance Checker.
  • Experience supporting RMF documentation and authorization packages, including SSPs, SARs, and POA&Ms.
  • Working knowledge of NIST SP 800-53, NIST RMF, and DoD cybersecurity policies.
  • Experience using eMASS to support RMF lifecycle activities and track authorization artifacts.
  • Familiarity with cloud security concepts and environments such as AWS GovCloud or Microsoft Azure Government.
  • One or more cybersecurity certifications required, including CISSP, CCSP, CISM, and CASP+ ( Renamed SecurityX)
Preferred Qualification:
  • Bachelor’s degree in Cybersecurity, Information Systems, Computer Science, or a related field.

About Nationwide IT Services
NIS is an IT and Management consulting company that is a CVE-verified Service-Disabled Veteran- Owned Small Business. Our mission is to deliver value-added services to our customers, leveraging technology, people, and industry best practices to implement innovative solutions through our trusted employees and team members.

Our benefits package includes medical, dental, and vision insurance, life and disability insurance, 401(k) plan with employer match, paid holidays, PTO (sick/vacation), commuter benefits, employee assistance program (EAP), and educational reimbursement, along with Pet Insurance.

Nationwide IT Services, Inc. provides equal employment opportunities (EEO) to all qualified applicants regardless of race, color, religion, sex, national origin, sexual orientation, gender identity, genetics, disability, or protected veteran status. for the following potential opportunity.

Core Responsibilities:
  • Support the execution of the full cybersecurity and RMF lifecycle for DoD and Federal systems, with emphasis on security control implementation, assessment, authorization, and continuous monitoring activities.
  • Perform vulnerability scanning and compliance validation, including, but not limited to, ACAS scanning, STIG assessments, SCAP validation, and configuration compliance checks.
  • Analyze vulnerability scan results, identify false positives, assess risk severity, and support remediation planning in coordination with engineering and operations teams.
  • Track, document, and manage remediation activities and Plans of Action and Milestones (POA&Ms) through closure, ensuring alignment with mandated timelines and risk tolerance.
  • Support RMF authorization activities, including initial ATOs, ATO renewals, significant change packages, and continuous authorization (cATO) efforts.
  • Support and execute Information Security Continuous Monitoring (ISCM) activities, including vulnerability trend analysis, control effectiveness validation, configuration drift monitoring, and security posture reporting.
  • Support the implementation and monitoring of Zero Trust security principles at a system level, including identity awareness, least privilege access, and continuous validation of users, devices, and workloads.
  • Prepare, review, and maintain cybersecurity and authorization artifacts in eMASS, including, but not limited to:
    • System Security Plans (SSPs)
    • Security Assessment Reports (SARs)
    • Plans of Action and Milestones (POA&Ms)
    • Control implementation narratives and supporting evidence packages
  • Conduct security control assessments and support independent verification and validation activities.
  • Assist with the implementation and maintenance of security controls aligned with NIST SP 800-53 and DoD cybersecurity requirements.
  • Coordinate with system owners, cybersecurity engineers, and program leadership to communicate security findings, risks, and remediation status.
  • Support cybersecurity audits, inspections, and Cyber Operational Readiness Assessments (CORA), ensuring accurate documentation and evidence traceability.
  • Assist in maintaining compliance with applicable cybersecurity policies, including FISMA, DoD RMF, DoD Zero Trust guidance, and the DoD Cloud Computing Security Requirements Guide (CC SRG).
Qualifications:
  • Active Secret clearance required.
  • Bachelor’s degree in Cybersecurity, Information Systems, Computer Science, or a related field.
  • Five or more years of experience in information security, information assurance, or cybersecurity operations, with experience supporting RMF-based programs.
  • Hands-on experience performing vulnerability scanning and compliance assessments using tools such as ACAS, STIG Viewer, and SCAP Compliance Checker.
  • Experience supporting RMF documentation and authorization packages, including SSPs, SARs, and POA&Ms.
  • Working knowledge of NIST SP 800-53, NIST RMF, and DoD cybersecurity policies.
  • Experience using eMASS to support RMF lifecycle activities and track authorization artifacts.
  • Familiarity with cloud security concepts and environments such as AWS GovCloud or Microsoft Azure Government.
  • One or more cybersecurity certifications required, including CISSP, CCSP, CISM, and CASP+ ( Renamed SecurityX)

About Nationwide IT Services
NIS is an IT and Management consulting company that is a CVE-verified Service-Disabled Veteran- Owned Small Business. Our mission is to deliver value-added services to our customers, leveraging technology, people, and industry best practices to implement innovative solutions through our trusted employees and team members.

Our benefits package includes medical, dental, and vision insurance, life and disability insurance, 401(k) plan with employer match, paid holidays, PTO (sick/vacation), commuter benefits, employee assistance program (EAP), and educational reimbursement, along with Pet Insurance.

Nationwide IT Services, Inc. provides equal employment opportunities (EEO) to all qualified applicants regardless of race, color, religion, sex, national origin, sexual orientation, gender identity, genetics, disability, or protected veteran status.

Powered by JazzHR

c0K0qYsyDv

Crear una alerta de empleo para esta búsqueda

Information Security Analyst Information Assurance RMF • Alexandria, VA, US

Ofertas similares
Remote Information Security Engineer

Remote Information Security Engineer

International Legal Technology Association • Washington, DC, United States
Teletrabajo
A tiempo completo
A prominent law firm is seeking an Information Security Engineer in Washington, DC, with the potential for remote work.The candidate will be responsible for supporting security operations, engineer...Mostrar más
Última actualización: hace más de 30 días • Oferta promocionada
Information Assurance Specialist

Information Assurance Specialist

AnaVation LLC • Bethesda, MD, United States
A tiempo completo
Information Assurance Specialist.Information Assurance Specialist.Be Challenged and Make a Difference.In a world of technology, people make the difference.At AnaVation, we provide unmatched value t...Mostrar más
Última actualización: hace 14 días • Oferta promocionada
Specialist, Information Systems Security-Mid

Specialist, Information Systems Security-Mid

Orbis Corporation • Washington, DC, United States
A tiempo completo
SEA 21, NAVSEA's Director of Surface Ship Maintenance, Modernization, and Sustainment is seeking professional support services (PSS) to support the Government's existing organization, personnel, kn...Mostrar más
Última actualización: hace 4 horas • Oferta promocionada • Nueva oferta
Remote Information Security Engineer

Remote Information Security Engineer

ARMA International • Washington, DC, United States
Teletrabajo
A tiempo completo
A global legal firm is seeking an Information Security Engineer to enhance security posture across its IT infrastructure.This position allows for 100% remote work within a firm-approved U.Candidate...Mostrar más
Última actualización: hace más de 30 días • Oferta promocionada
Senior Manager Information Security

Senior Manager Information Security

Children's National Hospital • Silver Spring, MD, United States
A tiempo completo
Your north star: build and oversee a team of information security experts dedicated to protecting Children's National and our patients, families, and staff.The Senior Manager Information Security s...Mostrar más
Última actualización: hace 20 días • Oferta promocionada
Information Systems Security Engineer

Information Systems Security Engineer

MANTECH • Washington, DC, United States
A tiempo completo
Joint Base Anacostia-Bolling (JBAB), DC.As an Information Systems Security Engineer (ISSE) IV, you will serve as the lead technical authority for ensuring the cybersecurity of project information s...Mostrar más
Última actualización: hace 12 días • Oferta promocionada
Systems Analyst / Information Security Specialist - Subject Matter Expert (SME)

Systems Analyst / Information Security Specialist - Subject Matter Expert (SME)

LinTech Global, Inc. • Washington, DC, United States
A tiempo completo
Systems Analyst / Information Security Specialist - Subject Matter Expert (SME) - Level II.LinTech Global is seeking a Subject Matter Expert (SME) to provide high-impact technical advisory support ...Mostrar más
Última actualización: hace 14 días • Oferta promocionada
Information Assurance/Security Controls Assessor (15.34)

Information Assurance/Security Controls Assessor (15.34)

OCT CONSULTING LLC • Washington, DC, United States
A tiempo completo
OCT Consulting is a business management and technology consulting firm that supports Federal Government clients.We provide consulting services in the areas of Strategy, Process Improvement, Change ...Mostrar más
Última actualización: hace 4 horas • Oferta promocionada • Nueva oferta
Senior Information Security Leader, Consumer Tech

Senior Information Security Leader, Consumer Tech

Bank of America • Washington, DC, United States
A tiempo completo
A major financial institution is seeking a Senior Business Information Security Officer to support the organization’s information security initiatives.This role requires 10+ years of experience wit...Mostrar más
Última actualización: hace 14 días • Oferta promocionada
16 Yrs Information Assurance and Security Specialist

16 Yrs Information Assurance and Security Specialist

AHU Technologies Inc • Washington, DC, United States
A tiempo completo
Role : Information Assurance and Security Specialist – Master.Identify network problems, and recommend improvements to ensure optional performance;.Ability to monitor and analyze data traffic patte...Mostrar más
Última actualización: hace 14 días • Oferta promocionada
Information Assurance/Security Engineer, Manager (15.34)

Information Assurance/Security Engineer, Manager (15.34)

OCT Consulting LLC • Washington, DC, United States
A tiempo completo
Information Assurance/Security Engineer, Manager (15.Be among the first 25 applicants.This range is provided by OCT Consulting LLC.Your actual pay will be based on your skills and experience — talk...Mostrar más
Última actualización: hace más de 30 días • Oferta promocionada
Information Security Analyst

Information Security Analyst

TradeJobsWorkforce • Arlington, VA, United States
A tiempo completo
Monitor their organizations networks for security breaches and investigate a violation when one occurs.Install and use software, such as firewalls and data encryption programs, to protect sensitive...Mostrar más
Última actualización: hace 7 días • Oferta promocionada
Information Security Analyst

Information Security Analyst

TradeJobsWorkForce • 22219 Arlington, VA, US
A tiempo completo
Monitor their organization’s networks for security breaches and investigate a violation when one occurs Install and use software, such as firewalls and data encryption programs, to protect sensitiv...Mostrar más
Última actualización: hace más de 30 días • Oferta promocionada
Global ISSO: Information Assurance Lead (TS/SCI)

Global ISSO: Information Assurance Lead (TS/SCI)

CACI International • Washington, DC, United States
A tiempo completo
A defense contracting firm in Washington, DC seeks an Information Systems Security Officer (ISSO).Citizen with a TS/SCI clearance and a strong background in information assurance.Key responsibiliti...Mostrar más
Última actualización: hace 14 días • Oferta promocionada
Senior Information Security Engineer (ISSE) – RMF/IA Expert

Senior Information Security Engineer (ISSE) – RMF/IA Expert

General Dynamics Information Technology • Washington, DC, United States
A tiempo completo
A global technology provider is seeking an Information System Security Engineer (ISSE) in Washington, DC.The successful candidate will ensure compliance with various U.Government security requireme...Mostrar más
Última actualización: hace 14 días • Oferta promocionada
Senior Manager Information Security

Senior Manager Information Security

Children's National Medical Center • Silver Spring, MD, United States
A tiempo completo
Job Description - Senior Manager Information Security (250003HY).Senior Manager Information Security - (250003HY).Your north star: build and oversee a team of information security experts dedicated...Mostrar más
Última actualización: hace 14 días • Oferta promocionada
Information Assurance (IA) Specialist SCI/SAP

Information Assurance (IA) Specialist SCI/SAP

ADVANCED DECISION VECTORS, LLC • Washington, DC, United States
A tiempo completo
Information Assurance Specialist.Advanced Decision Vectors, LLC (ADV), established in 2009, provides superior program management, program support, strategic planning, and systems engineering to the...Mostrar más
Última actualización: hace 3 días • Oferta promocionada
Senior Information Security Officer – Federal CSAM/NIST Expert

Senior Information Security Officer – Federal CSAM/NIST Expert

SBC Innovations • Washington, DC, United States
A tiempo completo
A technology solutions company is searching for a Cyber Security Advisor in Washington, DC, to enhance their enterprise-level IT security.The role involves ensuring compliance with NIST standards, ...Mostrar más
Última actualización: hace 14 días • Oferta promocionada