Talent.com
Lead Analyst - Info Sec
Lead Analyst - Info SecMAXIMUS • Columbia, SC, United States
No longer accepting applications
Lead Analyst - Info Sec

Lead Analyst - Info Sec

MAXIMUS • Columbia, SC, United States
1 day ago
Job type
  • Full-time
Job description

Description & Requirements

The Maximus DoD Cloud Information Systems Security Officer (ISSO) will work directly with the Maximus Federal Business Information Security Officer (BISO) to identify and manage implementation of security policies, standards, and procedures that support federal customers with federal requirements to include FISMA, applicable FAR and DFAR Clauses, Executive Orders, and OMB's applicable to IL5 Cloud Environments. The primary role of the ISSO will be the creation, management, and administration of a System Security Plan (SSP) to include all required artifacts needed to obtain a DISA IL5 certification and to maintain compliance with NIST 800-53 and associated NIST 800 series publications. The ISSO will be responsible for all continuous monitoring of the IL5 environment supporting federal customers and will be the SME for control management and the establishment of Inheritance which will be used to support future DoD projects

Essential Duties and Responsibilities :

  • Performs application vulnerability assessments to identify application vulnerabilities.
  • Performs network vulnerability assessments to identify host vulnerabilities.
  • Identifies, analyzes, and prioritizes vulnerability findings.
  • Analyzes system configurations to identify possible security gaps andor compliance violations.
  • Establishes collaborative working relationships with internal resources to provide security assessments, reports, and recommendations.
  • Performs other related duties as assigned.

Additional Duties and Responsibilities :

  • Create and manage System Security Plan and creation and or validation of all associated artifacts required to obtain DISA IL5 certification as well as NIST 800-53 compliance to include but not limited to a System Level Continuous Monitoring (SLCM) Strategy, HW / SW lists, Information Flow Diagrams, System Categorization Forms, System Topologies, Configuration Management Plan, Configuration Control Board (CCB) Charter, System and Services Acquisition Plan, System and Information Integrity Plan, System and Communication Protection Plan, Security Assessment and Authorization Plan, Risk Assessment Plan, Program Management Plan, Security Planning, Physical and Environmental Protection Plan, Personnel Security Plan, Media Protection Plan, Identification and Authentication Plan, Contingency Plan, Audit and Accountability Plan, Security Awareness and Training Plan, Incident Response Plan, Access Control Plan, Risk Assessment Review (RAR) and Plan of Action and Milestone (POA&M).
  • Liaison with Maximus Federal business units, Maximus Corporate business units, and external stakeholders to ensure all legal and contractual requirements pertaining to cybersecurity, physical security, and Information Assurance are being met.
  • Communicate federal requirements to Maximus Information Security Office (ISO) and advise implementation of applicable security controls and hardening standards to governance and technical teams.
  • Assist the BISO and ISO Team in the identification and assignment of control owners throughout the organization and continually review controls on organizationally defined periodicities.
  • Actively collaborate with Maximus Threat and Vulnerability Management (TVM) Team to ensure applicable technologies are compliant with defined remediation timelines and hardening standards via enterprise vulnerability management tools.
  • Minimum Requirements

  • Please refer to the additional information section of the job requisition for this opening to determine clearance eligibility required.
  • Bachelor's Degree
  • 7-10 years of security or technology related experience
  • Professional certifications, such as Security+, CEH, or CISSP, desirable
  • Knowledge of IPv4 network architecture and core services
  • Knowledge of web application development and architecture
  • Knowledge of network security controls
  • Knowledge of vulnerability management
  • Experience with dynamic application security testing (DAST) tools
  • Experience with vulnerability management (VM) tools
  • Familiarity with OWASP Top 10
  • Familiarity with WASC Threat Classification
  • Familiarity with CVE
  • Familiarity with NIST SP 800-53
  • Experience with automated service ticketing systems
  • Excellent analytical, decision-making, and problem-solving skills
  • Ability to communicate technical information in understandable business terms
  • Excellent interpersonal skills, presentation skills, and verbal / written communication skills
  • Strong customer service abilities required.
  • Ability to work collaboratively with a broad range of staff. Skilled in Microsoft Office software including Word, Excel, Visio, MS Project, and PowerPoint
  • Ability to perform comfortably in a fast-paced, deadline-oriented work environment
  • Ability to execute many complex tasks simultaneously, and work as a team member as well as independently
  • Additional Minimal Requirements :

  • Have a DoD secret clearance status or eligible to obtain secret clearance status.
  • DISA IL5 Certification Experience
  • Strong understanding of federal and DoD requirements to include but not limited to applicable Executive Orders, FISMA, FIPS, CMMC, NIST 800-171, NIST 800-60, NIST 800-65, SCRM, FedRAMP, DODI 8500s, 8500.2s, and 8510s.
  • Experience with GRC tools (eMASS, CFACTS, CSAM).
  • Experience developing SSP's and applicable artifacts required for A&A activities.
  • Experience with STIG compliance.
  • Experience with vulnerability management and assessment via Qualys and Tenable.
  • Works on complex issues where analysis of situations or data requires an in depth evaluation of variable
  • Exercises judgement in selecting methods, techniques, and evaluation criteria for obtaining results.
  • Networks with key contacts outside own area of expertise.
  • Develops solutions to a variety of complex problems.
  • Work requires considerable judgment and initiative.
  • EEO Statement

    Maximus is an equal opportunity employer. We evaluate qualified applicants without regard to race, color, religion, sex, age, national origin, disability, veteran status, genetic information and other legally protected characteristics.

    Pay Transparency

    Maximus compensation is based on various factors including but not limited to job location, a candidate's education, training, experience, expected quality and quantity of work, required travel (if any), external market and internal value analysis including seniority and merit systems, as well as internal pay alignment. Annual salary is just one component of Maximus's total compensation package. Other rewards may include short- and long-term incentives as well as program-specific awards. Additionally, Maximus provides a variety of benefits to employees, including health insurance coverage, life and disability insurance, a retirement savings plan, paid holidays and paid time off. Compensation ranges may differ based on contract value but will be commensurate with job duties and relevant work experience. An applicant's salary history will not be used in determining compensation. Maximus will comply with regulatory minimum wage rates and exempt salary thresholds in all instances.

    Accommodations

    Maximus provides reasonable accommodations to individuals requiring assistance during any phase of the employment process due to a disability, medical condition, or physical or mental impairment. If you require assistance at any stage of the employment process-including accessing job postings, completing assessments, or participating in interviews,-please contact People Operations at applicantaccommodations@maximus.com .

    Minimum Salary

    108,375.00

    Maximum Salary

    146,625.00

    Create a job alert for this search

    Analyst • Columbia, SC, United States

    Related jobs
    Security Analyst - Consultant (Hybrid)

    Security Analyst - Consultant (Hybrid)

    Serigor Inc. • Blythewood SC, SC, US
    Full-time
    Quick Apply
    Security Analyst - Consultant (Hybrid) Location : Blythewood SC Duration : 12+ Months Job Description : DAILY DUTIES / RESPONSIBILITIES : Champion DevSecOps through Security Automation : Leverage your f...Show more
    Last updated: 21 days ago
    COBOL Programmer - Consultant

    COBOL Programmer - Consultant

    US Tech Solutions • Blythewood, SC, United States
    Temporary
    Job Title : COBOL Programmer - Consultant.Location : Onsite in Blythewood, SC 29016 (100% onsite through probationary period, then option for Hybrid schedule. Local or regional location SC, GA, NC wil...Show more
    Last updated: 1 day ago • Promoted
    Customs and Border Protection Officer - Experienced (GS9)

    Customs and Border Protection Officer - Experienced (GS9)

    U.S. Customs and Border Protection • Lexington, South Carolina, US
    Permanent
    Customs and Border Protection (CBP) offers those interested in a career in law enforcement an exceptional opportunity to work with an elite team of highly trained professionals whose camaraderie, p...Show more
    Last updated: 30+ days ago • Promoted
    Cyber Operations Specialist

    Cyber Operations Specialist

    United States Army • Columbia, SC, US
    Part-time +1
    Cyber Operations Specialist Now Hiring Full and Part Time Positions You will gain critical skills in conducting both offensive and defensive cyberspace operations to protect networks and systems ag...Show more
    Last updated: 5 days ago • Promoted
    Junior Systems Administrator

    Junior Systems Administrator

    Kintegra Health • Camden, SC, US
    Full-time
    The Junior Systems Administrator plays a critical role in supporting the IT team through routine system maintenance, assisting with troubleshooting, and helping to ensure the reliability and securi...Show more
    Last updated: 9 hours ago • Promoted • New!
    IT Architect

    IT Architect

    Alpek Polyester USA • Gaston, SC, US
    Full-time
    We are seeking a motivated individual to join our Information Technology team based out of our Gaston, SC facility.The ideal candidate for the Alpek Polyester. Cybersecurity and IT Infrastructu...Show more
    Last updated: 30+ days ago • Promoted
    Security National Life Agent (Free Lead Program)

    Security National Life Agent (Free Lead Program)

    Team Nexa Insurance Solutions • Eastover, SC, US
    Full-time
    Candidates must hold a valid Life Insurance Producer's license at the time of application.Pope Insurance Group is an exclusive Security National Life Insurance Company Agency.Security National ...Show more
    Last updated: 30+ days ago • Promoted
    Lead Game Technician

    Lead Game Technician

    Stars and Strikes • Irmo, SC, US
    Full-time
    As a Stars and Strikes Arcade Technician, you will work with the Arcade Manager and Regional Game Technician to ensure that the arcade and games are maintained to the highest standards.Arcade Techn...Show more
    Last updated: 30+ days ago • Promoted
    Access Management Analyst II

    Access Management Analyst II

    Segra • Columbia, South Carolina, US
    Full-time
    Segra is searching for a qualified and experienced Access Management Analyst II to join us in a full-time capacity.Location Requirement : Ideally, this person will be in the Kansas City, MO office....Show more
    Last updated: 8 hours ago • Promoted • New!
    Security Architect - Consultant

    Security Architect - Consultant

    United Global Technologies • Columbia, SC, US
    Full-time
    Interview Process : INITIAL ROUND OF INTERVIEWS ON MICROSOFT TEAMS (ON CAMERA) WITH IN-PERSON INTERVIEWS PREFERRED BEFORE FINAL SELECTION. Duration of the Contract : 12 Months.Possibility for Extensio...Show more
    Last updated: 18 days ago • Promoted
    Engineering Co-Op

    Engineering Co-Op

    Alpek Polyester USA • Gaston, SC, US
    Full-time
    We are seeking motivated students to join our.Co-ops are reportable to their assigned engineering team's manager and work closely with Technical, Business and Engineering personnel to accomplis...Show more
    Last updated: 30+ days ago • Promoted
    Staff Information Security Engineer

    Staff Information Security Engineer

    VirtualVocations • Columbia, South Carolina, United States
    Full-time
    A company is looking for a Staff Information Security and Risk Engineer.Key Responsibilities Develop and maintain an effective Information Security Management System for compliance with ISO 27001...Show more
    Last updated: 30+ days ago • Promoted
    Security Architect 8-11

    Security Architect 8-11

    Focused HR Solutions • Columbia, South Carolina, United States
    Full-time
    Quick Apply
    This job is 100% on-site in Columbia, SC .Our direct client has an opening for a Security Architect 10945-1.This position is up to 6 months, with the option of extension, and is in Columbia, S...Show more
    Last updated: 30+ days ago
    Information Systems Analyst

    Information Systems Analyst

    Kintegra Health • Camden, SC, US
    Full-time
    The Information Systems Analyst is responsible for the maintenance and support of all electronic equipment, including computer hardware, software, networking, and telephony systems.This role encomp...Show more
    Last updated: 9 hours ago • Promoted • New!
    Staff Security Research Engineer

    Staff Security Research Engineer

    Proofpoint • West Columbia, SC, United States
    Full-time
    We are the leader in human-centric cybersecurity.Half a million customers, including 87 of the Fortune 100, rely on Proofpoint to protect their organizations. Were driven by a mission to stay ahead ...Show more
    Last updated: 1 day ago • Promoted
    Cyber Warfare Technician

    Cyber Warfare Technician

    Navy • Gaston, SC, United States
    Full-time
    ABOUT Enlisted Sailors in the Navy Cryptology community analyze encrypted electronic communications, jam enemy radar signals, decipher information in foreign languages, and maintain state-of-the-ar...Show more
    Last updated: 30+ days ago • Promoted
    Operational Excellence Leader

    Operational Excellence Leader

    Pure Power Technologies Inc • Blythewood, SC, US
    Full-time
    The OPEX Leader is responsible for leading the implementation and advancement of the Stanadyne Production System (SPS) at the site level. This role will develop and execute a local lean roadmap to e...Show more
    Last updated: 30+ days ago • Promoted
    Senior Mainframe / COBOL Developer

    Senior Mainframe / COBOL Developer

    InterSources • Blythewood, SC, United States
    Full-time
    Job Title : Senior Mainframe / COBOL Developer.The Client operates a multi-tiered architecture supporting a wide range of business functions. The application tier primarily uses.IIS on Microsoft Window...Show more
    Last updated: 30+ days ago • Promoted