Talent.com
Information Systems Security Analyst
Information Systems Security AnalystCTAC • Falls Church, VA, United States
No longer accepting applications
Information Systems Security Analyst

Information Systems Security Analyst

CTAC • Falls Church, VA, United States
30+ days ago
Job type
  • Full-time
Job description


Job Title

Information Systems Security Analyst

# of Hires Needed

1

Date Needed By

1/30/2026

Category

Information Technology

Education

Bachelor's Degree

Career Level

Experienced (Non-Manager)

Job Type

Full-time

Location

CTAC HQ - Falls Church, VA 22042 US (Primary)

Travel

0 - 10%

Job Description

CTAC is seeking an experienced Information Systems Security Analyst to support a federal program focused on achieving and sustaining an Authority to Operate (ATO) for a complex, multi-tenant AWS cloud environment. This role is a key member of CTAC's federal delivery team and is responsible for executing Risk Management Framework (RMF) activities across the full NIST lifecycle, with a strong emphasis on control validation, documentation, evidence development, and assessor engagement.

The ideal candidate will bring deep hands-on experience supporting federal ATOs, implementing NIST SP 800-53 controls, managing POA&Ms, and working directly with cloud engineers, architects, and Authorizing Officials to remediate security gaps and maintain continuous authorization readiness. This position requires a balance of technical security expertise, disciplined documentation, and the ability to operate effectively in a fast-paced, sprint-based delivery model.

Key Responsibilities

  • Execute and support the full NIST Risk Management Framework (RMF) lifecycle (Categorize, Select, Implement, Assess, Authorize, Monitor) for ORNL's AWS multi-tenant platform.

  • Perform control-by-control gap analysis against NIST SP 800-53, identifying incomplete, partially implemented, or undocumented controls.

  • Develop, update, and maintain RMF artifacts, including:

    • System Security Plan (SSP)

    • Control implementation narratives

    • POA&M

    • Continuous Monitoring documentation

    • Objective evidence mappings


  • Partner closely with cloud architects and engineers to validate technical control implementations and support remediation activities within AWS.

  • Support assessment and authorization activities, including direct engagement with assessors, auditors, and ORNL security stakeholders.

  • Track, document, and manage risks, findings, and remediation activities in accordance with federal RMF expectations.

  • Ensure security documentation accurately reflects the operational state of the environment and remains audit-ready throughout the engagement.

  • Support the use of governance, risk, and compliance (GRC) tools (e.g., eMASS, Kion, or equivalent) to manage controls, evidence, and reporting.

  • Contribute to sprint planning and execution by aligning RMF activities with engineering and documentation deliverables.

  • Assist in the development or refinement of security policies, procedures, and standards where gaps exist.

  • Provide subject matter expertise on federal security requirements, best practices, and emerging guidance relevant to cloud-hosted systems




Job Requirements
  • Bachelor's degree in Information Security, Cybersecurity, Information Technology, or a related discipline (or equivalent experience).

  • 10+ years of progressive experience in cybersecurity, information assurance, or RMF-focused security roles supporting federal systems.

  • Demonstrated hands-on experience supporting ATO packages for federal cloud or hybrid environments.

  • Deep working knowledge of:

    • NIST SP 800-53

    • NIST SP 800-37

    • FISMA requirements

    • Federal A&A processes



  • Strong experience developing and maintaining SSPs, POA&Ms, and RMF evidence.

  • Experience working with cloud (Amazon Web Services) security environments, including validation of technical control implementations.

  • Ability to clearly document complex technical and compliance concepts for both technical and non-technical audiences.

  • Proven ability to collaborate across engineering, security, and program management teams.

    Strong analytical, organizational, and communication skills.

  • Ability to obtain and maintain a Public Trust (or higher) clearance.


Preferred Qualifications

  • Master's degree in Cybersecurity, Information Systems, or a related field.

  • Active CISSP and/or CISM certification.

  • Experience supporting multi-tenant cloud platforms and control inheritance models.

  • Familiarity with Infrastructure as Code (IaC) concepts and how automation supports compliance.

  • Experience supporting federal research, scientific, or mission-driven environments.

  • Prior experience working in agile or sprint-based delivery models for RMF execution.


CTAC is an equal opportunity employer. Qualified applicants will receive consideration for employment without regard to race, color, religion, sex, age, sexual orientation, gender identity, national origin, disability, or protected veteran status. VEVRAA Federal Contractor

Create a job alert for this search

Information Systems Security Analyst • Falls Church, VA, United States

Similar jobs
Lead Information Security Analyst

Lead Information Security Analyst

Genesis10 • McLean, VA, US
Permanent
Genesis10 is currently seeking a Lead Information Security Analyst for a 6-month On-site position located in McLean, VA or Plano, TX.This is a contract to hire opportunity.This role will lead cutti...Show more
Last updated: 18 days ago • Promoted
Information Systems Security Specialist/Officer

Information Systems Security Specialist/Officer

Yulista • Quantico, VA, United States
Full-time
StraitSys is seeking an Information Systems Security Specialist/Officer to support the FBI in Quantico, Virginia.In this role, you will evaluate, advise, and support the documentation, validation, ...Show more
Last updated: 4 days ago • Promoted
Lead Cybersecurity Engineer / Information Systems Security Engineer (ISSE), TS/SCI

Lead Cybersecurity Engineer / Information Systems Security Engineer (ISSE), TS/SCI

Blue Sky Innovators Inc • Reston, VA, United States
Full-time
Lead Cybersecurity Engineer / Information Systems Security Engineer (ISSE).Cybersecurity Ops Sr Principal.Seeking a Lead Cybersecurity Ops Engr / Information System Security Engineer (ISSE) to serv...Show more
Last updated: 4 days ago • Promoted
Information System Security Engineer (ISSE) - Senior

Information System Security Engineer (ISSE) - Senior

Network Designs • McLean, VA, United States
Full-time
NDi) is a leading Federal contractor that specializes in designing, developing, and delivering information technology and network solutions for government customers.Founded in 1985, NDi's firmly de...Show more
Last updated: 4 days ago • Promoted
Information Security Analyst

Information Security Analyst

Hire Talent • McLean, VA, United States
Full-time
As a Security Consultant, you will be joining a team performing security assessments and providing consulting support to assist clients in meeting FISMA and FedRAMP requirements.The ideal candidate...Show more
Last updated: 4 days ago • Promoted
Information Systems Security Engineer (TS/SCI) & A&A Lead

Information Systems Security Engineer (TS/SCI) & A&A Lead

Pinnacle Government Solutions • McLean, VA, United States
Full-time
A leading government solutions provider in Virginia is seeking an experienced Information Systems Security Engineer.The role involves defining security requirements, overseeing cybersecurity progra...Show more
Last updated: 13 days ago • Promoted
Senior Information Security Architect (AWS)

Senior Information Security Architect (AWS)

CGI Technologies and Solutions, Inc. • Reston, VA, United States
Full-time
Senior Information Security Architect (AWS).United States, Virginia, Reston.Finding purpose at CGI (https://youtu.By playing this video you consent to Google/YouTube processing your data and using ...Show more
Last updated: 4 days ago • Promoted
Information Security Analyst (Third Shift)

Information Security Analyst (Third Shift)

Appian • McLean, VA, United States
Full-time
We set high standards and live up to them, ensuring that everything we do is done with care and quality.We approach every challenge with ambition and commitment, holding ourselves and each other ac...Show more
Last updated: 4 days ago • Promoted
Staff Information Security Analyst

Staff Information Security Analyst

ManTech International Corporation • Chantilly, VA, United States
Full-time
Unlock the secrets of intelligence with MANTECH! Join a dynamic team at the forefront of national security, providing advanced solutions to government intelligence agencies.Since 1968, we’ve been s...Show more
Last updated: 4 days ago • Promoted
Information Security, ISSE FS Poly- Prime contract

Information Security, ISSE FS Poly- Prime contract

stanleyreid.com • Sterling, VA, United States
Full-time
Our client is the prime of a sole source contract.They are seeking an experienced Information Systems Security Officer (ISSE) to provide hands-on proactive ownership of the cybersecurity posture of...Show more
Last updated: 4 days ago • Promoted
Information Systems Security Manager

Information Systems Security Manager

M.C. Dean, Inc. • Vienna, VA, United States
Full-time
We design, build, operate, and maintain cyber-physical solutions for the nation's most mission-critical facilities, secure environments, complex infrastructure, and global enterprises.With over 7,0...Show more
Last updated: 4 days ago • Promoted
Information Security Analyst

Information Security Analyst

Information Technology Strategies LLC • Ashburn, VA, United States
Full-time
Information Technology Strategies, Inc.IT solutions provider servicing commercial and government initiative in various parts of the United States.We are currently seeking an Information Security An...Show more
Last updated: 4 days ago • Promoted
Information Security Analyst 3

Information Security Analyst 3

Veracity • McLean, VA, United States
Full-time
Information Security Analyst 3.Months (Potential to extend or convert).McLean, VA (Tysons Corner) and Chandler, AZ - Hybrid Role (3 days onsite, 2 days remote).Contribute significantly to the devel...Show more
Last updated: 4 days ago • Promoted
Senior Scientist, Information Security Systems Engineer (Herndon, VA)

Senior Scientist, Information Security Systems Engineer (Herndon, VA)

L3Harris • Herndon, VA, United States
Full-time
L3Harris is dedicated to recruiting and developing high-performing talent who are passionate about what they do.Our employees are unified in a shared dedication to our customers' mission and quest ...Show more
Last updated: 4 days ago • Promoted
Information System Security Engineer (ISSE)

Information System Security Engineer (ISSE)

ClearanceJobs • Chantilly, VA, United States
Full-time
Information System Security Engineer (ISSE)s Levels 1 - 3.VTG is looking for an Information System Security Engineer (ISSE)s Levels 1 - 3 in Chantilly VA.These positions are contingent upon contrac...Show more
Last updated: 5 days ago • Promoted
Cloud Security Information Analyst

Cloud Security Information Analyst

General Dynamics • Falls Church, VA, United States
Full-time
Cloud Security Information Analyst.Seize your opportunity to make a personal impact as a Cloud Security Information Analyst supporting the Case Management Modernization (CMM) Program.The CMM progra...Show more
Last updated: 4 days ago • Promoted
Information System Security Engineer (ISSE) Senior Level (Government)

Information System Security Engineer (ISSE) Senior Level (Government)

AT&T • Chantilly, VA, United States
Full-time
AT&T Global Public Sector is a trusted provider of secure, IP enabled, cloud-based, network solutions and professional services to the Federal Government.We are dedicated to recruiting, developing ...Show more
Last updated: 4 days ago • Promoted
Information Systems Security Engineer (ISSE)

Information Systems Security Engineer (ISSE)

VTG Defense • Falls Church, VA, United States
Full-time
Byte Systems, a subsidiary of VTG, is seeking a Information Systems Security Engineer (ISSE).The ISSE will lead and execute security engineering activities across complex, enterprise-scale environm...Show more
Last updated: 4 days ago • Promoted