Security Analyst (Cloud)*Hybrid (DC Metro*US Citizens Only)

Azzur Group
Herndon, VA, United States
Full-time

PLEASE READ : Our client will not hold your Security Clearance for this role. This person must be a US Citizen.

Role Summary :

This role serves as a hands-on mid-level security analyst who will be responsible for interfacing with the security engineering, operations, architecture and build teams, assisting with the development and / or maintenance of various System Security Plans (SSP) and associated documentation for multiple environments, gathering the security control implementations information for the security controls and documenting their implementation in the SSP, as well as updating associated security document

Security Analyst (Mid-Level)

This role serves as a hands-on mid-level security analyst who will be responsible for interfacing with the security engineering, operations, architecture and build teams, assisting with the development and / or maintenance of various System Security Plans (SSP) and associated documentation for multiple environments, gathering the security control implementations information for the security controls and documenting their implementation in the SSP, as well as updating associated security documentation as needed (i.

e., plans, procedures, processes). Additionally, this role will assist with the security assessments (i.e. IRS specific security control implementation, FedRAMP, FISMA, HIPPA, SOC, PCI, ISO, etc.

to include supporting collection of evidence.

The Security Analyst will be responsible for maintenance of the security documentation for various environments; but concentrating on the SAP HANA Cloud tenants and IRS customer.

This position may include development of the security documentation, use of RegScale, assisting with the IRS, FedRAMP, SOC or FISMA authorization / assessment processes to include prep of the operations team, and documentation summary and update as required.

This role serves as a mid level security analyst who assists with the security documentation and can provide thoughtful recommendations on processes and procedures, as well as implementation of security controls.

This role must communicate between security, architecture, engineering, development and operations teams as required, and be able to interpret and document the results of data gathering.

Key deliverables for success will be participation and / or facilitation of assessments, development and maintenance of security documentation that is current and useful, ensuring processes and procedures are current and up to date, and assists with assurance that all appropriate IRS and other framework security controls are successfully implemented and associated security documentation is developed and implemented.

This position will also assist with various assessments, as a team member, or as a lead. This will include scheduling of the interviews, collection of evidence, working with third party assessors in tracking evidence, update of security documentation in preparation of the assessment, and other duties as assigned.

Customer interaction is also required with clear and concise oral / written responses.

The main customer for this position with be IRS.

GENERAL RESPONSIBILITES :

  • Gather information, architecture diagrams and implementation of the security controls through interfacing with the security engineering, operations and build teams
  • Develop security documentation such as, but not limited to, System Security Plans (SSP), security plans, procedures, and processes
  • Maintain, via review and update, of all security documentation
  • Understand the intent of the IRS and FedRAMP security controls, FISMA security controls and communicate as needed
  • Assist with the FedRAMP, FISMA, PCI, ISO, SOC, etc authorization to include, but not limited to, prep of operations team through training and mock interviews, update documentation as required, and support FedRAMP PMO / Agency / CISO requests

GENERAL QUALIFICATIONS :

  • Bachelor’s Degree in Computer Science / MIS / Information Technology, or equivalent experience in Information Security, Information Technology, or related technical discipline
  • Minimum 7 years Information Technology experience
  • Experience with Cloud technologies, especially AWS, Azure, and / or Goggle Cloud, desirable
  • Experience with FedRAMP and / or other authorization processes and NIST risk management framework
  • Experience in developing, evaluating, and implementing information security architectures, technologies, standards, and practices to secure applications and IT systems, desirable
  • Experience in development of security documentation such as SSP, policies, procedures, etc.
  • Flexible, self-motivated, and able to work independently in a fast paced environment
  • Excellent communication skills and the proven ability to work effectively with all levels of IT and business management.
  • Familiarity with Testing, Development, Staging, and pre-production environment requiring cyber security support.
  • Knowledge of Privacy Act, GDPR, and other data privacy frameworks.
  • Experience in writing or executing system security documentation, authorization to operate packages, POA&Ms, and policies.
  • Experience in reviewing / editing / writing technical documents
  • Skill in preparing and making written and oral presentations of complex technical nature.
  • Demonstrated ability to coordinate multiple tasks
  • U.S. Person

SPECIFIC TECHNICAL SKILLS DESIRED :

  • Professional industry certifications in area of expertise.
  • Knowledge of Best Practice and security guides (ex. NIST 800-53 rev 4, NIST 800-53, FedRAMP)
  • Knowledge of security frameworks to include RMF, ISO, HIPAA, FedRAMP and HIPAA

ISC CISSP or ISACA CISM or equivalent certification

27 days ago
Related jobs
Promoted
AKIMA
Herndon, Virginia

May talk to user to learn steps used and source of error; answering questions, applying knowledge of computer software, hardware, and procedures; determining cause of problem. All applicants will receive consideration for employment, without regard to race, color, religion, creed, national origin, g...

Promoted
Accenture Federal Services
Reston, Virginia

All employment decisions shall be made without regard to age, race, creed, color, religion, sex, national origin, ancestry, disability status, veteran status, sexual orientation, gender identity or expression, genetic information, marital status, citizenship status or any other basis as protected by...

Promoted
AKIMA
Herndon, Virginia

All applicants will receive consideration for employment, without regard to race, color, religion, creed, national origin, gender or gender-identity, age, marital status, sexual orientation, veteran status, disability, pregnancy or parental status, or any other basis prohibited by law. Must possess ...

Promoted
Mastech Digital
Reston, Virginia

Seeking a Personnel Security Officer (PSO) to assist its Industrial Security Team with management and administration of Department of Defense and Intelligence Community (IC) contracts and assist with updating and maintaining the company’s various systems of record. The contractor shall directly comm...

Promoted
Zillion Technologies
Vienna, Virginia

US CITIZENS / Green Card Holders ONLY. Maintain ownership of all technical aspects of the SFDC: analysis, architecture, evaluation, design, build, data migrations/quality, systems integrations, 3rd party applications, AppExchange products, custom development. The position is remote but the candidate...

Mastech Digital
Reston, Virginia

Seeking a Personnel Security Officer (PSO) to assist its Industrial Security Team with management and administration of Department of Defense and Intelligence Community (IC) contracts and assist with updating and maintaining the company’s various systems of record. The contractor shall directly comm...

Amazon Development Center U.S., Inc.
Herndon, Virginia

The AWS Security US-ADC-Security, Industrial Security & Compliance team is responsible for creating, implementing, and overseeing Amazon’s National Industrial Security Program (NISP). AWS Security is looking for an exceptional Program Security Administrator with a strong track record of supporting s...

Transaction Network Services
Herndon, Virginia

The Cloud Security (CS) Analyst is responsible for the secure operation of all Amazon Web Services (AWS) cloud instances (i. Monitor server logs, firewall logs, intrusion detection lDS, and network traffic for unusual or suspicious activity. This includes monitoring system alerts, analyzing IDS aler...

NANA
Herndon, Virginia

Routing, Switching, Virtual Private Cloud (VPC), Virtual Network, NAT Gateways, VPN Gateways, Route53, NDS, Traffic Manager, Network Load Balancer, Application Gateway, Custom Route Tables, User Defined Routes, AWS Direct Connect and AZURE ExpressRoute). Must possess a bachelor’s degree in computer ...

Akima
Herndon, Virginia

Must possess a bachelor’s degree in computer science, Information Systems, Business Administration, Information Technology or equivalent work experience. Must have 5 years’ experience managing hybrid IT environments. Must have 5 years’ experience managing on-premises and cloud infrastructure includi...