Talent.com
System Security Analyst (FedRamp)
System Security Analyst (FedRamp)Flex Staffing Resources • Herndon, VA, US
System Security Analyst (FedRamp)

System Security Analyst (FedRamp)

Flex Staffing Resources • Herndon, VA, US
5 days ago
Job type
  • Full-time
  • Quick Apply
Job description

System Security Analyst (FedRAMP / FISMA)

Location

Employment Type

Work Model

Herndon, VA 20171

Full-Time Employee (FTE) + Benefits

Hybrid (4 Days Remote / 1 Day On-Site)

Citizenship

Experience

Clearance

U.S. Citizenship Required

5+ Years

Public Trust

About the Role

Join the team as a Senior System Security Analyst and play a critical role in securing the future of our cloud offerings. You will be the essential link responsible for driving and achieving FedRAMP and FISMA authorizations for new Cloud Products and Third-Party Applications across various cloud environments (including commercial, FedRAMP, and DOD).

This is a technical, hands-on position where you will bridge the gap between our Security, Engineering, Build, and Operations teams. You will gather critical technical control implementation details and translate them into accurate, high-quality security documentation, including System Security Plans (SSPs) . If you are a self-motivated expert who thrives on ensuring continuous compliance, performing in-depth analysis, and making thoughtful security recommendations, this position offers high impact and autonomy.

What You'll Do (Key Responsibilities)

Authorization & Documentation Leadership

Lead and support all aspects of the FedRAMP and FISMA authorization process, including preparing Engineering, Build, and Operations teams through training and mock interviews.

Serve as the primary liaison for security-related data gathering, working directly with technical teams to accurately document security control implementation in the SSP.

Develop, update, and manage essential security documentation, including System Security Plans (SSPs), policies, procedures, and technical implementation language.

Conduct thorough Security Impact Analyses for changes to the environment and provide expert, actionable recommendations to senior management.

Interpret and communicate the intent of FedRAMP Moderate and FISMA security controls to technical and non-technical stakeholders.

Security Assessment & Monitoring

Configure, execute, and perform in-depth analysis of vulnerability scans using industry tools (e.g., Nessus / Security Center, WebInspect).

Evaluate vulnerability scan data and control implementation to identify risks and suggest robust remediation strategies.

Identify and assess the security posture of cloud systems, including RMF package status, patching compliance, and Cyber Security Vulnerability Assessment (CSVA) mechanisms.

Support ongoing activities and effectively respond to customer / Agency inquiries regarding compliance status.

Technical Analysis & Communication

Interpret and assess complex technical artifacts, including network diagrams (Visio), logical / physical system diagrams, and data flow diagrams.

Utilize tools such as Splunk to execute queries, search, and review data for security impact analysis and continuous monitoring.

Prepare and deliver clear, concise written and oral presentations of complex technical material to all levels of IT and business management.

What You'll Bring (Required Qualifications)

Experience : Minimum 5 years of experience in Information Technology, with a strong focus on Information Security, Security Engineering, or a related technical discipline.

Government Framework Expertise : Proven, hands-on experience with FedRAMP and / or other government authorization processes (e.g., FISMA, DOD), and a deep understanding of the NIST Risk Management Framework (RMF) and NIST 800-53 controls.

Vulnerability Management : Direct experience in the execution and detailed analysis of vulnerability scans using industry-standard tools (e.g., Nessus / Security Center, WebInspect).

Technical Documentation : Demonstrated ability to document information system specifications and security controls.

Communication : Excellent communication skills and the proven ability to work effectively with cross-functional teams (Security, Engineering, and Operations).

Education : Bachelor’s Degree in Computer Science, MIS, Information Technology, or equivalent professional experience.

Bonus Points (Desired Skills & Certifications)

Cloud Technologies : Experience with major Cloud Service Providers, specifically AWS and Azure .

Security Certifications : Professional certifications such as ISC CISSP , ISACA CISM , or equivalent.

Security Architecture : Experience in developing, evaluating, and implementing information security architectures, technologies, and best practices.

Tooling : Familiarity with Splunk for security data analysis.

Create a job alert for this search

Security Analyst • Herndon, VA, US

Related jobs
SOC Analyst

SOC Analyst

VirtualVocations • Rockville, Maryland, United States
Full-time
A company is looking for a SOC Analyst.Key Responsibilities Follow standard operating procedures for real-time security event intake Monitor infrastructure with SIEM to identify security inciden...Show more
Last updated: 30+ days ago • Promoted
Epic HIM Certified Analyst

Epic HIM Certified Analyst

VirtualVocations • Alexandria, Virginia, United States
Full-time
A company is looking for a Systems Management Analyst (EPIC) to work remotely.Key Responsibilities Liaise with stakeholders and vendors to analyze business problems and provide IT solutions Moni...Show more
Last updated: 2 days ago • Promoted
Assessment & Authorization (A&A) Analyst

Assessment & Authorization (A&A) Analyst

Base One Technology • Ashburn, VA, US
Full-time
Our Ashburn, VA client is looking for an Assessment & Authorization (A&A) Analyst.If you Are interested in this opportunity. Please forward a copy of your most update resume in word format to lli@ba...Show more
Last updated: 30+ days ago • Promoted
Senior DFIR Analyst

Senior DFIR Analyst

VirtualVocations • Alexandria, Virginia, United States
Full-time
A company is looking for a Sr Digital Forensics and Incident Response (DFIR) Analyst.Key Responsibilities Protect the organization's IT assets as part of the Cybersecurity Operations Center (CSOC...Show more
Last updated: 2 days ago • Promoted
Senior Information Systems Security Engineer

Senior Information Systems Security Engineer

Leidos Inc • Columbia, MD, United States
Full-time
Senior Information Systems Security Engineer (ISSE).National Security Sector's (NSS) Cyber & Analytics Business Area (CABA). Our talented team is at the forefront in Security Engineering, Computer N...Show more
Last updated: 24 days ago • Promoted
Network Based System Analyst

Network Based System Analyst

Node.Digital • Arlington, VA, US
Full-time
Must have an active Top Secret Security Clearance.Node provides remote and onsite advanced technical assistance, proactive hunting, rapid onsite incident response, and immediate investigation and r...Show more
Last updated: 30+ days ago • Promoted
Information System Security Manager (ISSM)

Information System Security Manager (ISSM)

The Johns Hopkins University Applied Physics Laboratory • Laurel, MD, United States
Full-time
Do you love solving problems while enabling impactful research to operate securely?.Are you passionate about making meaningful contributions to national security cyber missions?.Do you like collabo...Show more
Last updated: 30+ days ago • Promoted
Penetration Testing Analyst

Penetration Testing Analyst

VirtualVocations • Alexandria, Virginia, United States
Full-time
A company is looking for a Security Analyst, Penetration Testing.Key Responsibilities Perform technical testing against various targets, including network and web application penetration testing ...Show more
Last updated: 30+ days ago • Promoted
VM Security Analyst

VM Security Analyst

Powder River Industries, LLC • Washington, DC, US
Full-time
Candidates should have a strong in-depth knowledge of the Windows OS (Windows Workstation and Windows server) as well as a foundational knowledge of LINUX / UNIX OS, networking, databases, and other ...Show more
Last updated: 6 days ago • Promoted
Information System Security Engineer

Information System Security Engineer

Fusion Technology • Washington, DC, United States
Full-time
Fusion Technology is a performance-driven HUBZone Small Business concern residing in the heart of the beautiful mountainsides of West Virginia, steps away from the Federal Bureau of Investigation's...Show more
Last updated: 12 hours ago • Promoted • New!
Senior Information System Security Engineer (ISSE)

Senior Information System Security Engineer (ISSE)

Leidos Inc • Alexandria, VA, United States
Full-time
Join us in transforming how technology serves those who serve.At Leidos, we're not just delivering solutions - we're pioneering the future of defense and intelligence technology.Our diverse teams o...Show more
Last updated: 15 days ago • Promoted
Senior Malware Analyst

Senior Malware Analyst

Leidos Inc • Alexandria, VA, United States
Full-time
Leidos has a current job opportunity for a.DISA GSM-O program in Alexandria, VA.An active Top Secret security clearance and demonstrated advanced technical ability in reverse engineering custom pro...Show more
Last updated: 30+ days ago • Promoted
Security Analyst

Security Analyst

Leidos Inc • Alexandria, VA, United States
Full-time
Leidos is seeking a Security Engineer to support the execution of strategic, operational, and organizational PPSM objectives. This position can be based out of any of our three locations - Alexandri...Show more
Last updated: 30+ days ago • Promoted
Platform Security Analyst - USCIS - Remote

Platform Security Analyst - USCIS - Remote

ITC Federal, Inc • Fairfax, VA, United States
Remote
Full-time
Platform Security Analyst - USCIS - Remote.Department of Homeland Security (DHS) - USCIS OIT Architecture Engineering Support (AES2). Must be able to obtain DHS Suitability security clearance, which...Show more
Last updated: 30+ days ago • Promoted
Cloud Security Analyst

Cloud Security Analyst

VirtualVocations • Alexandria, Virginia, United States
Full-time
A company is looking for a Cloud Security Information Analyst.Key Responsibilities Write documentation required for Authority to Operate (ATO) and gather supporting artifacts Support performance...Show more
Last updated: 30+ days ago • Promoted
Senior Application Security Analyst

Senior Application Security Analyst

VirtualVocations • Alexandria, Virginia, United States
Full-time
A company is looking for a Senior Application Security Analyst (Pentester).Key Responsibilities Perform vulnerability assessments, risk assessments, and penetration tests for various applications...Show more
Last updated: 2 days ago • Promoted
System Analyst- Rockville, MD

System Analyst- Rockville, MD

Creative Information Technology, Inc • Falls Church, Virginia, US
Full-time
Scroll down to find an indepth overview of this job, and what is expected of candidates Make an application by clicking on the Apply button. Rockville, MD About us Creative Information Technology In...Show more
Last updated: 8 days ago • Promoted
Application Security Analyst

Application Security Analyst

VirtualVocations • Alexandria, Virginia, United States
Full-time
A company is looking for an Application Security Analyst (Remote).Key Responsibilities Assist in the support and documentation of DAST, IaC, SAST, and SCA solutions, including operational process...Show more
Last updated: 30+ days ago • Promoted