System Security Analyst

Flex Staffing Resources
Herndon, VA, US
Full-time
Quick Apply

System Security Analyst (FedRAMP)

Location of Services : Herndon, VA 20171 (1 day a week)

Employment Type : FTE + Benefits

Remote : 4 days a week

Client is supporting the FedRAMP and FISMA authorization(s) of new Cloud Products and 3rd Party Applications into various cloud environments.

This effort requires security assessment support, the knowledge / development of the appropriate security documentation (i.

e., System Security Plan (SSP), plans and procedures), and ongoing continuous monitoring activities. This position is majority remote (post-pandemic).

This role serves as a technical security analyst responsible for interfacing with the build, operations and security engineering teams on security issues and information gathering;

gathering the security control implementations for the technical controls and documenting their implementation in the SSP.

Additionally, this role will assist with the security assessments, and continuous monitoring evidence for any of the client environments (corporate, commercial regulated, FedRAMP, DOD and International).

The Security Analyst will be responsible for assisting with the FedRAMP or FISMA authorization processes to include prep of the operations and build teams, and technical documentation summary and update as required.

This role serves as a senior level technical security analyst who has the knowledge to create policies and execute vulnerability scans as needed, evaluates the vulnerability scan data and control implementation and who can provide thoughtful recommendations, as well as conduct security impact analysis of changes to the environments.

This role must communicate between security, engineering, build / development and operations teams daily, and be able to interpret and document the results of data gathering.

GENERAL RESPONSIBILITES :

  • Configuration, Execution and Analysis of vulnerability scans
  • Ability to interpret and assess network diagrams and drawings using Visio.
  • Identify and assess Cloud System state, including vulnerabilities, RMF package status / accreditation model, PPS compliance , and patching, Cyber Security Vulnerability Assessments (CSVA) mechanisms.
  • Demonstrate familiarity with current FedRAMP, DOD and NIST Security controls and technologies, including vulnerability management capabilities.
  • Understand enterprise operating environments, including security posture, application environment, and associated security controls
  • Understand / document information system specifications and security controls, including logical and physical diagrams, connectivity, communication, and data flow diagrams, both internal and external to the system.
  • Gather information , architecture diagrams and implementation of the security controls through interfacing with the security engineering, operations and build teams
  • Develop security documentation input of technical control implementation
  • Understand the intent of the FedRAMP moderate security controls, FISMA security controls and communicate as needed
  • Assist with the FedRAMP or FISMA authorization to include, but not limited to, prep of security engineering, build and operations teams through training and mock interviews, update implementation language in the security documentation and develop processes as required, and support FedRAMP PMO / Agency / CISO requests
  • Ability to respond effectively to customer’s concerns regarding ConMon activities

GENERAL QUALIFICATIONS :

  • Bachelor’s Degree in Computer Science / MIS / Information Technology, or equivalent experience in Information Security, Information Technology, or related technical discipline
  • Minimum 5 years Information Technology experience
  • Experience with Cloud technologies , especially AWS and Azure, desirable
  • Experience with FedRAMP and / or other authorization processes and NIST risk management framework
  • Execution and Analysis of vulnerability scans; such as but not limited to : Nessus / Security Center, WebInspect, etc.
  • Familiarity with Splunk to execute queries, search / review data for impact.
  • Experience in developing, evaluating, and implementing information security architectures, technologies, standards, and practices to secure applications and IT systems, desirable
  • Flexible, self-motivated, and able to work independently in a fast paced environment
  • Excellent communication skills and the proven ability to work effectively with all levels of IT and business management.
  • Skill in preparing and making written and oral presentations of complex technical nature.
  • Demonstrated ability to coordinate multiple tasks
  • U.S. Citizenship

SPECIFIC TECHNICAL SKILLS DESIRED :

  • Professional industry certifications in area of expertise.
  • Knowledge of Best Practice and security guides (ex. NIST 800-53 rev 4, NIST 800-53, FedRAMP)
  • ISC CISSP or ISACA CISM or equivalent certification
  • 20 days ago
Related jobs
Promoted
The Aerospace Corporation
Westfield, Virginia

Imagery Programs Division’s (IPD) Reconnaissance Systems (RS) Office is looking for an RF System Analyst (Senior Project Engineer) to support manufacturing, unit test, subsystem integration, and SV-level test activities for a spacecraft communication subsystem and other auxiliary RF hardware in supp...

Promoted
The Boeing Company
Herndon, Virginia

The Boeing Defense, Space & Security (BDS) organization, Space and Launch Division is seeking a Experienced Systems Security Analyst to join our team in Herndon, VA. The Experienced Systems Security Analyst will be a part of a high-performing team that is immersed in high intensity development proje...

Promoted
COGNITIVE MEDICAL SYSTEMS INC
Vienna, Virginia
Remote

Cognitive Medical Systems is seeking a talented and motivated Security Analyst to join our team and play a key role in safeguarding our systems, data, and infrastructure against potential threats. As a Security Analyst at Cognitive Medical Systems, you will be responsible for assessing, monitoring, ...

AttainIT Technologies
McLean, Virginia

AttainIT is seeking a motivated, career and customer-oriented Information System Security Engineer to join our team. You will perform, or review, technical security assessments of computing environments to identify points of vulnerability, non-compliance with established cybersecurity standards and ...

Procession Systems
Herndon, Virginia

This role will support the Program in working with the customer’s security team towards completing the information security assurance activities that are required to obtain and maintain the Authorization to Operate (ATO) for multiple systems, with particular focus on understanding and documenting se...

Boeing
Herndon, Virginia

The Boeing Defense, Space & Security (BDS) organization, Space and Launch Division is seeking a Experienced Systems Security Analyst to join our team in Herndon, VA. The Experienced Systems Security Analyst will be a part of a high-performing team that is immersed in high intensity development proje...

Parsons Corporation
Centreville, Virginia

Parsons is looking for an amazingly talented Junior Cyber Security Systems Engineer/Analyst to join our team!Are you ready to be part of a cutting-edge cybersecurity project that will make a huge impact? If you’re interested in leveraging and honing your systems engineering and cyber security skills...

Procession Systems
Chantilly, Virginia

We are seeking a Systems Security Analyst to provide support to the  Client's Cross Domain Support Office (CDSO) integrating and implementing Cross-Domain  Solutions (CDS) in a secure environment and implement security measures to resolve  vulnerabilities, mitigate risks, and recommend security chan...

Procession Systems
Reston, Virginia

As our Information Security Analyst, you will perform various Vulnerability Management duties including the tracking and dissemination of vulnerability assessments, participate in red/blue team events, and the identification and reporting of network and system vulnerabilities, security events, and a...

Procession Systems
Herndon, Virginia

Information System Security: Work with Sponsor to maintain and implement a strategy for appropriately securing sensitive application, administrative and Sponsor data. Demonstrated experience providing information security guidance to the organization throughout the system lifecycle. Desired Certific...