Talent.com
Information Security Analyst, Information Assurance / RMF
Information Security Analyst, Information Assurance / RMFNationwide IT Services • Alexandria, VA, US
Information Security Analyst, Information Assurance / RMF

Information Security Analyst, Information Assurance / RMF

Nationwide IT Services • Alexandria, VA, US
30+ days ago
Job type
  • Full-time
Job description

Job Description

Job Description
Information Security Analyst, Information Assurance/RMF
Active Secret Required
Hybrid schedule
CISSP, CAP, or CISM certification required

Nationwide IT Services, NIS, is seeking an Information Security Analyst/Information Assurance/RMF for the following potential opportunity.

Core Responsibilities:
  • Support the execution of the full cybersecurity and RMF lifecycle for DoD and Federal systems, with emphasis on security control implementation, assessment, authorization, and continuous monitoring activities.
  • Perform vulnerability scanning and compliance validation, including, but not limited to, ACAS scanning, STIG assessments, SCAP validation, and configuration compliance checks.
  • Analyze vulnerability scan results, identify false positives, assess risk severity, and support remediation planning in coordination with engineering and operations teams.
  • Track, document, and manage remediation activities and Plans of Action and Milestones (POA&Ms) through closure, ensuring alignment with mandated timelines and risk tolerance.
  • Support RMF authorization activities, including initial ATOs, ATO renewals, significant change packages, and continuous authorization (cATO) efforts.
  • Support and execute Information Security Continuous Monitoring (ISCM) activities, including vulnerability trend analysis, control effectiveness validation, configuration drift monitoring, and security posture reporting.
  • Support the implementation and monitoring of Zero Trust security principles at a system level, including identity awareness, least privilege access, and continuous validation of users, devices, and workloads.
  • Prepare, review, and maintain cybersecurity and authorization artifacts in eMASS, including, but not limited to:
    • System Security Plans (SSPs)
    • Security Assessment Reports (SARs)
    • Plans of Action and Milestones (POA&Ms)
    • Control implementation narratives and supporting evidence packages
  • Conduct security control assessments and support independent verification and validation activities.
  • Assist with the implementation and maintenance of security controls aligned with NIST SP 800-53 and DoD cybersecurity requirements.
  • Coordinate with system owners, cybersecurity engineers, and program leadership to communicate security findings, risks, and remediation status.
  • Support cybersecurity audits, inspections, and Cyber Operational Readiness Assessments (CORA), ensuring accurate documentation and evidence traceability.
  • Assist in maintaining compliance with applicable cybersecurity policies, including FISMA, DoD RMF, DoD Zero Trust guidance, and the DoD Cloud Computing Security Requirements Guide (CC SRG).
Qualifications:
  • Active Secret clearance required.
  • Five or more years of experience in information security, information assurance, or cybersecurity operations, with experience supporting RMF-based programs.
  • Hands-on experience performing vulnerability scanning and compliance assessments using tools such as ACAS, STIG Viewer, and SCAP Compliance Checker.
  • Experience supporting RMF documentation and authorization packages, including SSPs, SARs, and POA&Ms.
  • Working knowledge of NIST SP 800-53, NIST RMF, and DoD cybersecurity policies.
  • Experience using eMASS to support RMF lifecycle activities and track authorization artifacts.
  • Familiarity with cloud security concepts and environments such as AWS GovCloud or Microsoft Azure Government.
  • One or more cybersecurity certifications required, including CISSP, CCSP, CISM, and CASP+ ( Renamed SecurityX)
Preferred Qualification:
  • Bachelor’s degree in Cybersecurity, Information Systems, Computer Science, or a related field.

About Nationwide IT Services
NIS is an IT and Management consulting company that is a CVE-verified Service-Disabled Veteran- Owned Small Business. Our mission is to deliver value-added services to our customers, leveraging technology, people, and industry best practices to implement innovative solutions through our trusted employees and team members.

Our benefits package includes medical, dental, and vision insurance, life and disability insurance, 401(k) plan with employer match, paid holidays, PTO (sick/vacation), commuter benefits, employee assistance program (EAP), and educational reimbursement, along with Pet Insurance.

Nationwide IT Services, Inc. provides equal employment opportunities (EEO) to all qualified applicants regardless of race, color, religion, sex, national origin, sexual orientation, gender identity, genetics, disability, or protected veteran status. for the following potential opportunity.

Core Responsibilities:
  • Support the execution of the full cybersecurity and RMF lifecycle for DoD and Federal systems, with emphasis on security control implementation, assessment, authorization, and continuous monitoring activities.
  • Perform vulnerability scanning and compliance validation, including, but not limited to, ACAS scanning, STIG assessments, SCAP validation, and configuration compliance checks.
  • Analyze vulnerability scan results, identify false positives, assess risk severity, and support remediation planning in coordination with engineering and operations teams.
  • Track, document, and manage remediation activities and Plans of Action and Milestones (POA&Ms) through closure, ensuring alignment with mandated timelines and risk tolerance.
  • Support RMF authorization activities, including initial ATOs, ATO renewals, significant change packages, and continuous authorization (cATO) efforts.
  • Support and execute Information Security Continuous Monitoring (ISCM) activities, including vulnerability trend analysis, control effectiveness validation, configuration drift monitoring, and security posture reporting.
  • Support the implementation and monitoring of Zero Trust security principles at a system level, including identity awareness, least privilege access, and continuous validation of users, devices, and workloads.
  • Prepare, review, and maintain cybersecurity and authorization artifacts in eMASS, including, but not limited to:
    • System Security Plans (SSPs)
    • Security Assessment Reports (SARs)
    • Plans of Action and Milestones (POA&Ms)
    • Control implementation narratives and supporting evidence packages
  • Conduct security control assessments and support independent verification and validation activities.
  • Assist with the implementation and maintenance of security controls aligned with NIST SP 800-53 and DoD cybersecurity requirements.
  • Coordinate with system owners, cybersecurity engineers, and program leadership to communicate security findings, risks, and remediation status.
  • Support cybersecurity audits, inspections, and Cyber Operational Readiness Assessments (CORA), ensuring accurate documentation and evidence traceability.
  • Assist in maintaining compliance with applicable cybersecurity policies, including FISMA, DoD RMF, DoD Zero Trust guidance, and the DoD Cloud Computing Security Requirements Guide (CC SRG).
Qualifications:
  • Active Secret clearance required.
  • Bachelor’s degree in Cybersecurity, Information Systems, Computer Science, or a related field.
  • Five or more years of experience in information security, information assurance, or cybersecurity operations, with experience supporting RMF-based programs.
  • Hands-on experience performing vulnerability scanning and compliance assessments using tools such as ACAS, STIG Viewer, and SCAP Compliance Checker.
  • Experience supporting RMF documentation and authorization packages, including SSPs, SARs, and POA&Ms.
  • Working knowledge of NIST SP 800-53, NIST RMF, and DoD cybersecurity policies.
  • Experience using eMASS to support RMF lifecycle activities and track authorization artifacts.
  • Familiarity with cloud security concepts and environments such as AWS GovCloud or Microsoft Azure Government.
  • One or more cybersecurity certifications required, including CISSP, CCSP, CISM, and CASP+ ( Renamed SecurityX)

About Nationwide IT Services
NIS is an IT and Management consulting company that is a CVE-verified Service-Disabled Veteran- Owned Small Business. Our mission is to deliver value-added services to our customers, leveraging technology, people, and industry best practices to implement innovative solutions through our trusted employees and team members.

Our benefits package includes medical, dental, and vision insurance, life and disability insurance, 401(k) plan with employer match, paid holidays, PTO (sick/vacation), commuter benefits, employee assistance program (EAP), and educational reimbursement, along with Pet Insurance.

Nationwide IT Services, Inc. provides equal employment opportunities (EEO) to all qualified applicants regardless of race, color, religion, sex, national origin, sexual orientation, gender identity, genetics, disability, or protected veteran status.

Powered by JazzHR

c0K0qYsyDv

Create a job alert for this search

Information Security Analyst Information Assurance RMF • Alexandria, VA, US

Similar jobs
CISO: Strategic Information Security Leader

CISO: Strategic Information Security Leader

SHI • Washington, DC, United States
Full-time
A leading global IT solutions provider in Washington, D.Chief Information Security Officer to develop and implement an information security strategy.Responsibilities include overseeing security pol...Show more
Last updated: 6 days ago • Promoted
Remote Information Security Engineer

Remote Information Security Engineer

International Legal Technology Association • Washington, DC, United States
Remote
Full-time
A prominent law firm is seeking an Information Security Engineer in Washington, DC, with the potential for remote work.The candidate will be responsible for supporting security operations, engineer...Show more
Last updated: 30+ days ago • Promoted
Information Assurance Specialist

Information Assurance Specialist

AnaVation LLC • Bethesda, MD, United States
Full-time
Information Assurance Specialist.Information Assurance Specialist.Be Challenged and Make a Difference.In a world of technology, people make the difference.At AnaVation, we provide unmatched value t...Show more
Last updated: 9 days ago • Promoted
Information Systems Security Officer (ISSO) - Active TS/SCI required

Information Systems Security Officer (ISSO) - Active TS/SCI required

ADVANCED DECISION VECTORS, LLC • Washington, DC, United States
Full-time
Advanced Decision Vectors, LLC (ADV),.Federal and Commercial sectors.Located in Alexandria, Virginia, ADV is a Small Disadvantaged Business (SDB) contractor that has roots established in the Depart...Show more
Last updated: 2 days ago • Promoted
Senior Information Systems Security Officer (ISSO-S)

Senior Information Systems Security Officer (ISSO-S)

HonorVet Technologies • Washington, DC, United States
Full-time
Clearance Required: Top Secret/SCI with Polygraph.Employment Type: Full-Time immediate.The client is seeking a highly experienced Senior ISSO-S.The ISSO-S is responsible for leading the development...Show more
Last updated: 2 days ago • Promoted
Information Security Analyst

Information Security Analyst

TradeJobsWorkForce • 22210 Arlington, VA, US
Full-time
Monitor their organization’s networks for security breaches and investigate a violation when one occurs Install and use software, such as firewalls and data encryption programs, to protect sensitiv...Show more
Last updated: 30+ days ago • Promoted
Senior Information Security Manager

Senior Information Security Manager

Virtual Vocations Inc • Alexandria, VA, United States
Full-time
A company is looking for a Senior Manager, Information Security.Key Responsibilities Lead execution of the enterprise information security program and maintain security policies for a healthcare Sa...Show more
Last updated: 14 hours ago • Promoted • New!
Information Systems Security Engineer

Information Systems Security Engineer

MANTECH • Washington, DC, United States
Full-time
Joint Base Anacostia-Bolling (JBAB), DC.As an Information Systems Security Engineer (ISSE) IV, you will serve as the lead technical authority for ensuring the cybersecurity of project information s...Show more
Last updated: 8 days ago • Promoted
Systems Analyst / Information Security Specialist - Subject Matter Expert (SME)

Systems Analyst / Information Security Specialist - Subject Matter Expert (SME)

LinTech Global, Inc. • Washington, DC, United States
Full-time
Systems Analyst / Information Security Specialist - Subject Matter Expert (SME) - Level II.LinTech Global is seeking a Subject Matter Expert (SME) to provide high-impact technical advisory support ...Show more
Last updated: 9 days ago • Promoted
Senior Information Security Leader, Consumer Tech

Senior Information Security Leader, Consumer Tech

Bank of America • Washington, DC, United States
Full-time
A major financial institution is seeking a Senior Business Information Security Officer to support the organization’s information security initiatives.This role requires 10+ years of experience wit...Show more
Last updated: 9 days ago • Promoted
Information Systems Security Officer (ISSO) - Senior

Information Systems Security Officer (ISSO) - Senior

CGI • Arlington, VA, United States
Full-time
Information Systems Security Officer (ISSO) - Senior.Main location: United States, Virginia, Arlington.CGI Federal has an exciting opportunity for an ISSO within our Intel sector advancing the nati...Show more
Last updated: 2 days ago • Promoted
Information System Security Officer Alternate

Information System Security Officer Alternate

Cayuse Holdings • Arlington, VA, United States
Full-time
Join our dynamic team as the Information System Security Officer Alternate (AISSO), where you will play a crucial role in supporting our senior Information System Security Officers (ISSO) in enforc...Show more
Last updated: 2 days ago • Promoted
Information System Security Manager (ISSM)

Information System Security Manager (ISSM)

The Johns Hopkins University Applied Physics Laboratory • Laurel, Maryland, United States
Full-time
Do you love solving problems while enabling impactful research to operate securely?.Are you passionate about making meaningful contributions to national security cyber missions?.Do you like collabo...Show more
Last updated: 23 days ago • Promoted
Information Assurance/Security Engineer, Manager (15.34)

Information Assurance/Security Engineer, Manager (15.34)

OCT Consulting LLC • Washington, DC, United States
Full-time
Information Assurance/Security Engineer, Manager (15.Be among the first 25 applicants.This range is provided by OCT Consulting LLC.Your actual pay will be based on your skills and experience — talk...Show more
Last updated: 30+ days ago • Promoted
Information Assurance Specialist

Information Assurance Specialist

VTG Defense • Bethesda, MD, United States
Full-time
Exciting opening for an Information Assurance Specialist to support a large customer organization in the fast-growing National Security Group.This position is located in Bethesda; MD.Candidates mus...Show more
Last updated: 9 days ago • Promoted
Information Security Compliance Manager (INDG)

Information Security Compliance Manager (INDG)

Bloomberg Industry Group • Arlington, Virginia, United States
Full-time
As a Manager of Information Security Compliance, you will support Bloomberg Industry Group's Governance, Risk, and Compliance (GRC) programs.You will be part of a team that delivers customer trust,...Show more
Last updated: 8 days ago • Promoted
Senior Information Security Engineer (ISSE) – RMF/IA Expert

Senior Information Security Engineer (ISSE) – RMF/IA Expert

General Dynamics Information Technology • Washington, DC, United States
Full-time
A global technology provider is seeking an Information System Security Engineer (ISSE) in Washington, DC.The successful candidate will ensure compliance with various U.Government security requireme...Show more
Last updated: 9 days ago • Promoted
Senior Manager Information Security

Senior Manager Information Security

Children's National Medical Center • Silver Spring, MD, United States
Full-time
Job Description - Senior Manager Information Security (250003HY).Senior Manager Information Security - (250003HY).Your north star: build and oversee a team of information security experts dedicated...Show more
Last updated: 9 days ago • Promoted