Description
The Office of the Chief Information Officer (OCIO) advances the Department of Energy’s (DOE) mission by establishing enterprise-wide policy, standards, and services that ensure secure, reliable, and innovative information technology (IT) delivery across the Department. The OCIO is committed to strengthening DOE’s cybersecurity posture, improving IT service performance, and ensuring the protection of the Department’s systems, networks, and data while maintaining responsible stewardship of taxpayer resources. To join our team of outstanding professionals, apply today!
The Cyber Security Analyst III supports this mission by supporting cybersecurity measures, assessing security controls, evaluating system risks, and responding to cybersecurity data calls, research, and analysis as required. This role combines hands‑on operational cybersecurity functions with mid‑level Assessment & Authorization (A&A) responsibilities to ensure DOE systems remain compliant, secure, and resilient.
Responsibilities
- Conduct assessments of implemented security and privacy controls to determine effectiveness and alignment with DOE requirements.
- Review control implementations for accuracy, operating effectiveness, and alignment with security and privacy outcomes.
- Document findings, deficiencies, and recommended corrective actions in formal assessment reports and deliver results to Team Leaders.
- Conduct initial remediation actions and reassess remediated controls to verify successful implementation.
- Assess system-specific and inherited controls in accordance with DOE’s continuous monitoring strategy.
- Contribute to cybersecurity performance metrics, deliverables, and reporting requirements.
Cybersecurity Analyst Duties:
- Perform assessments of existing and new NIST and FISMA systems, including subsystems within respective system boundaries, communicate results, articulate potential implications of identified control weaknesses, and work to document through artifacts and documentation.
- Support assessments within Cloud environments such as SaaS, PaaS, and IaaS, and systems and platforms within an on-prem environment.
- Review, analyze, and create Assessment & Authorization (A&A) packages to include Assessment Readiness Workbooks (ARW), Security Assessment Plans (SAP), Security Assessment Reports (SARs), and Risk Assessments for completeness, accuracy, and effectiveness of controls.
- Review, analyze, and create findings packages outlining identified findings, weaknesses, remediation, and provide an overview during findings meeting reviews.
- Participate in the review of significant system change requests, deviation requests, and provide input and feedback on potential system or system security impacts.
- Review and analyze vulnerability scan reports, test reports, and Plan of Action & Milestones (POA&Ms), Hardware/Software lists, Network Diagrams, Data Flows, System Change Requests/Proposal, for completeness, accuracy, effectiveness of controls, and plans and procedures implementation.
- Document and provide findings and recommendations that are concise, grammatically correct, system- and platform-specific, and actionable and executable.
- Respond to security-and system-related data calls for internal and external audits such as FISMA and data calls as requested.
Qualifications
- Bachelor’s Degree or four (4) years of equivalent work experience.
- 5–7 years of experience in cybersecurity operations, security control assessments, or related technical security functions.
- Experience in assessing and determining control applicability, such as inheritance, hybrid, independent (standalone).
- Experience performing detailed reviews of controls, technical security control testing for each of the component types, including development of security and privacy assessment plans.
- Experience with the RMF process and understanding each phase of the RMF process and possess a strong understanding of the NIST Special Publication 800-53 security and privacy controls, the NIST Cybersecurity Framework, and other information security and privacy laws and regulations.
- Ability to analyze information system configurations and technical specifications against NIST SP 800-53 and other overlays.
- Experience conducting security assessments within federal cybersecurity frameworks (such as NIST RMF, NIST SP 800‑53).
- Ability to analyze and document risks, incidents, and vulnerabilities clearly and accurately, and provide results of analysis and recommendations as required.
- Ability to work independently with minimal supervision, manage complex issues, and elevate issues as necessary to leads and managers.
- Strong written communication skills, including preparation of security documentation and assessment reports.
- Ability to complete a DOE background investigation and obtain federal government clearance for access to federal systems.
- Ability to obtain DOE Q clearance.
Benefits InformationRegular - The company offers a comprehensive benefits program, including medical, dental, vision, life insurance, 401(k) and a range of other voluntary benefits. Paid Time Off (PTO) is offered to regular full-time and part-time employees.
Pay Range$130,000 - $150,000
Job ID2026-25983
Work TypeRemote