Talent.com
Senior Cybersecurity Risk Management Analyst
Senior Cybersecurity Risk Management AnalystEvolver Federal • Springfield, VA, USA
Senior Cybersecurity Risk Management Analyst

Senior Cybersecurity Risk Management Analyst

Evolver Federal • Springfield, VA, USA
30+ days ago
Job type
  • Full-time
  • Quick Apply
Job description

Evolver Federal is seeking a Senior Cybersecurity Risk Management Analyst to support its Federal client in Springfield, VA in managing a portfolio of systems participating in Ongoing Authorization / Continuous ATO. This role will ensure compliance with established guidance / processes for Ongoing Authorization (OA) including but not limited to : developing and reviewing security documentation in support of the OA process and compiling related security packages for submission, validating control sets for testing, and conducing internal compliance reviews of assigned systems processes, as well as develop various compliance reports relating to all areas of risk and compliance.

The successful candidate will have previous experience managing a Federal Government Ongoing Authorization Program or previous experience as an ISSO with assigned systems participating in Ongoing Authorization / Continuous ATO Program. The candidate will also have experience with FISMA metrics and in reviewing and analyzing data output from scanning tools for the purposes of identifying risks and trends at the enterprise level in support of continuous monitoring and drive remediation efforts.

Responsibilities :

  • Provide security SME-level input to working groups to improve FISMA metrics and continuous monitoring processes.
  • Advise on architectural requirements for system / network security, Active Directory, application integration, and system hierarchy.
  • Analyze data from continuous monitoring, configuration, vulnerability, asset, and software management tool output to identify security trends and risks.
  • Support risk mitigation through performance analysis and anomaly detection.
  • Guide System Team stakeholders on OA processes and ensure compliance with OA Methodology.
  • Perform document reviews for all security documentation in support of initial authorization, reauthorization, and ongoing Security Authorization packages, as well as compile and prepare authorization packages.
  • Conduct monthly reviews and annual assessments of OA systems.
  • Validate system control assessment test plans and ensure control testing is in alignment with OA assessment frequency requirements.
  • Organize and lead monthly Organizational Risk Management Board (ORMB) meetings, including preparing and distributing meeting minutes.
  • Develop, maintain, and make recommendations for enhancing Cybersecurity Policies.
  • Develop, update, and maintain Standard Operating Procedures (SOPs) and make recommendations for new processes and / or SOPs needed to mature and improve Government Programs.
  • Apply knowledge of NIST 800-53 security controls and recommend appropriate allocation to support OA / Continuous ATO.
  • Communicate clearly with system owners, developers, and executive leadership on various cybersecurity, risk and compliance topics, including providing recommendations on system and network security architecture, Active Directory integration, and application security.
  • Coordinate, schedule, develop agendas, and facilitate meetings for large governance groups and working groups comprised of all levels of government and contractor stakeholders.
  • Perform other duties as assigned by the Government.
  • Ability to work efficiently and effectively in a dynamic and fast-paced environment.

Basic Qualifications

  • 8 years of related experience with Bachelor's Degree or 10 years of overall related experience in a relevant field
  • 5 years of experience with NIST 800-37, experience that can span across a subset, or all, of the steps within the Risk Management Framework.
  • 3 years of experience in DHS environment
  • 1 year of experience assessing security controls in accordance with NIST 800-53 in support of the Federal Government to include evaluating and validating security control implementation.
  • Must have a current Active Secret clearance
  • 3 years of experience with NIST SP 800-53, 800-37
  • 3 years of experience with DHS 4300A / B
  • 1 year of experience with FISMA metrics, and security compliance.
  • 3 years of experience executing continuous monitoring activities, including those supporting vulnerability management and configuration management.
  • 3 years of experience with government GRC tools such as Archer, IACS, CSAM, etc.
  • 5 years' experience managing / supporting cybersecurity architecture and governance.
  • Must have previous client-engagement experience.
  • Preferred Qualifications

  • 2 years of experience assessing security controls in accordance with NIST 800-53 in support of the Federal Government to include evaluating and validating security control implementation.
  • 5 years of experience as an Information System Security Office (ISSO) in / in support of the Federal government, developing and maintaining comprehensive security documentation in support of the Risk Management Framework, including, but not limited to : System Security Plans (SSPs) (Sections 1 & 2), Contingency Plans (CPs), Contingency Plan Tests (CPTs), Privacy Impact Assessments (PIAs), and Privacy Threshold Analyses (PIA), and Business Impact Assessments (BIAs).
  • 3 years of experience as an Information System Security Office (ISSO) in / in support of the Federal government, developing and maintaining comprehensive security documentation in support of the Risk Management Framework, including, but not limited to : System Security Plans (SSPs) (Sections 1 & 2), Contingency Plans (CPs), Contingency Plan Tests (CPTs), Privacy Impact Assessments (PIAs), and Privacy Threshold Analyses (PIA), and Business Impact Assessments (BIAs).
  • Ability to schedule and lead meetings, including Working Groups and formal Governance Groups, with a diverse group of government and contractor stakeholders at various levels within the organization, including developing and maintaining agendas, meeting notes, and meeting records, including maintaining a repository of all meeting records.
  • Ability to communicate clearly and effectively via written and verbal communication in both formal and informal situations.
  • Ability to clearly communicate complex technical concepts to Information Technology Project Managers, ISSOs, Application Developers, and Security Compliance Analysts, as well as non-technical POCs such as Branch Chiefs and Business System Owners.
  • Ability to adapt to frequent changes in priorities, follow project schedules, meet established deadlines, and proactively communicate risks and issues to the Contractor PM and / or Federal Leads.
  • Possess good listening skills and the ability to detect explicit and implicit needs and wants of the client.
  • Demonstrated ability to exercise good judgment, prioritize multiple tasks, and problem solve under pressure of deadlines and resource constraints
  • Possess strong analytical and critical thinking skills with the ability to apply them to the client / contract workspace.
  • Excellent organizational skills and attention to detail.
  • Strong analytical, critical thinking, and problem-solving skills.
  • Evolver Federal is an equal opportunity employer and welcomes all job seekers. It is the policy of Evolver Federal not to discriminate based on race, color, ancestry, religion, gender, age, national origin, gender identity or expression, sexual orientation, genetic factors, pregnancy, physical or mental disability, military / veteran status, or any other factor protected by law.

    Actual salary will depend on factors such as skills, qualifications, experience, market and work location. Evolver Federal offers competitive benefits, including health, dental and vision insurance, 401(k), flexible spending account, and paid leave (including PTO and parental leave) in accordance with our applicable plans and policies.

    Job Posted by ApplicantPro

    Create a job alert for this search

    Risk Management Analyst • Springfield, VA, USA

    Related jobs
    Cyber Strategy & Management Manager

    Cyber Strategy & Management Manager

    Grant Thornton • Arlington, VA, United States
    Full-time
    As a Cyber Strategy & Management Manager, you will get the opportunity to grow and contribute to our clients' business needs by applying a collection of information and cybersecurity capabilities, ...Show more
    Last updated: 16 days ago • Promoted
    Cybersecurity Engineer - Senior

    Cybersecurity Engineer - Senior

    Spear AI • Washington, DC, United States
    Full-time
    Spear AI is a growing defense contracting company dedicated to delivering cutting‑edge solutions that support our nation's security. As we expand, we're building a culture where innovation meets mis...Show more
    Last updated: 9 days ago • Promoted
    Senior Cybersecurity Engineer

    Senior Cybersecurity Engineer

    Accenture Federal Services • Washington, DC, United States
    Full-time
    At Accenture Federal Services, nothing matters more than helping the US federal government make the nation stronger and safer and life better for people. Our 13,000+ people are united in a shared pu...Show more
    Last updated: 2 days ago • Promoted
    Senior Cybersecurity Engineer

    Senior Cybersecurity Engineer

    E-Solutions • Washington, DC, United States
    Temporary
    We are currently seeking a highly skilled Senior Cybersecurity Engineer for a 12+ month contract opportunity with our Randstad client in Washington, DC. The ideal candidate will bring in-depth exper...Show more
    Last updated: 2 days ago • Promoted
    Sr. Cybersecurity Expert

    Sr. Cybersecurity Expert

    Marathon TS • Washington, DC, United States
    Full-time
    The Senior Cybersecurity Expert will support the following objectives : .To strengthen capabilities of host government agencies and critical infrastructure operators to identify, protect, detect, res...Show more
    Last updated: 2 days ago • Promoted
    VP Risk Management

    VP Risk Management

    Apple Federal Credit Union • Fairfax, VA, United States
    Full-time
    Join to apply for the VP Risk Management role at Apple Federal Credit Union.At Apple Federal Credit Union, we’re more than a financial institution. we’re a community‑focused organization powered by...Show more
    Last updated: 7 days ago • Promoted
    Cybersecurity Risk Management Analyst

    Cybersecurity Risk Management Analyst

    Evolver Federal • Springfield, VA, USA
    Full-time
    Quick Apply
    Cybersecurity Risk Management Analyst.Federal client in Springfield, VA in managing all aspects of cybersecurity risk and compliance including, but not limited to : maintaining an accurate FISMA Inv...Show more
    Last updated: 30+ days ago
    Senior Cyber Risk & Security Manager

    Senior Cyber Risk & Security Manager

    BTI • Washington, DC, United States
    Full-time
    A leading company in cybersecurity is seeking an Information Systems Security Manager to oversee risk management processes. The successful candidate will lead a team focused on IT security goals and...Show more
    Last updated: 3 days ago • Promoted
    Senior Director, Cybersecurity Programs

    Senior Director, Cybersecurity Programs

    The Aspen Institute • Washington, DC, United States
    Full-time
    The Aspen Institute is a global nonprofit organization committed to realizing a free, just, and equitable society.Since its founding in 1949, the Institute has been driving change through dialogue,...Show more
    Last updated: 19 hours ago • Promoted • New!
    Senior Cybersecurity Engineer

    Senior Cybersecurity Engineer

    Accenture • Washington, DC, United States
    Full-time
    At Accenture Federal Services, nothing matters more than helping the US federal government make the nation stronger and safer and life better for people. Our 13,000+ people are united in a shared pu...Show more
    Last updated: 2 days ago • Promoted
    Senior Cybersecurity Engineer

    Senior Cybersecurity Engineer

    Leidos • Sterling, VA, United States
    Full-time
    Join our dynamic team at Leidos as a Senior Cybersecurity Engineer, where you will play a pivotal role in safeguarding our government contract operations. We seek a proactive professional who excels...Show more
    Last updated: 1 day ago • Promoted
    Sr. Director Global Risk - 1LOD Incident Management

    Sr. Director Global Risk - 1LOD Incident Management

    PayPal • Washington, DC, United States
    Full-time
    Director Global Risk - 1LOD Incident Management.PayPal has been revolutionizing commerce globally for more than 25 years. Creating innovative experiences that make moving money, selling, and shoppin...Show more
    Last updated: 9 days ago • Promoted
    Senior Cybersecurity Engineer - Compliance & Risk Management

    Senior Cybersecurity Engineer - Compliance & Risk Management

    Human Resources Research Organization • Alexandria, VA, United States
    Full-time
    Senior Cybersecurity Engineer - Compliance & Risk Management.The Human Resources Research Organization (HumRRO).We work with federal and state government agencies, private sector organizations, and...Show more
    Last updated: 1 day ago • Promoted
    Senior Cybersecurity Engineer

    Senior Cybersecurity Engineer

    ManTech • Washington, DC, United States
    Full-time
    Responsibilities include but are not limited to : .Reviewing testing and validation to ensure system functionality and compliance with security standards. Developing technical documentation including ...Show more
    Last updated: 30+ days ago • Promoted
    Cybersecurity Lead Manager

    Cybersecurity Lead Manager

    ASRC Federal Holding Company • Alexandria, VA, United States
    Full-time
    ASRC Federal is a leading government contractor furthering missions in space, public health and defense.As an Alaska Native owned corporation, our work helps secure an enduring future for our share...Show more
    Last updated: 16 days ago • Promoted
    Senior Cybersecurity Engineer

    Senior Cybersecurity Engineer

    Maveris • Washington, DC, United States
    Full-time +1
    Senior Cybersecurity Engineer .Qualified candidates must be US citizens and able to obtain a minimum of a Public Trust clearance . Maveris is an IT and cybersecurity services company committed to he...Show more
    Last updated: 2 days ago • Promoted
    Senior Cybersecurity Engineer

    Senior Cybersecurity Engineer

    ManTech International Corporation • Washington, DC, United States
    Full-time
    Shape the future of defense with MANTECH! Join a team dedicated to safeguarding our nation through advanced tech and innovative solutions. Since 1968, we’ve been a trusted partner to the Department ...Show more
    Last updated: 2 days ago • Promoted
    Senior Associate, Risk Management - Governance, Valuations, & Innovation

    Senior Associate, Risk Management - Governance, Valuations, & Innovation

    Veterans Staffing • Falls Church, VA, US
    Full-time +1
    Senior Associate, Risk Management - Governance, Valuations, & Innovation.Capital One's Governance, Valuations, & Innovation (GV&I) Team is a second line of defense function housed within the Credit...Show more
    Last updated: 2 days ago • Promoted