Information Assurance Support Analyst

Astrion$80K — $110K *
Information Technology
5 - 7 years of experience
Job Overview by Ladders

Qualifications

  • BA/BS degree or equivalent experience (5 years)
  • 6 years IT experience with 4 years in Information Assurance
  • Active Secret Clearance with eligibility for NRC Clearance
  • At least one certification from a long list including CompTIA Security+ and CISSP

Responsibilities

  • Collaborate with personnel, including system admins and ISSOs, on Security Assessment & Authorization (SA&A)
  • Evaluate information security impact levels for systems to determine FIPS 199 categorization
  • Develop security documentation across all phases of the NIST Risk Management Framework (RMF)
  • Analyze risks from security assessments and provide remediation recommendations
  • Conduct vulnerability scans and compliance checks against established standards
  • Document and assess customer responsibilities in FedRAMP security packages
  • Review continuous monitoring deliverables from Cloud Service Providers

Benefits

  • Occasional domestic travel opportunities
  • Support for a critical civilian contract
  • Exposure to a variety of security frameworks
  • Collaboration with a diverse team of security professionals
Full Job Description

Overview

 

Information Assurance Support Analyst

LOCATION: Rockville, MD     

CLEARANCE: NRC Clearance

JOB STATUS: Full-Time

TRAVEL: 10% Occasional Domestic Travel

 

Astrion has an exciting opportunity for a Information Assurance Support Analyst for the NRC-CPSS Contract, supporting the Civilian Division.

 

REQUIRED QUALIFICATIONS / SKILLS

  • BA/BS or 5 years additional equivalent experience
  • 6 years IT experience, with 4 years specialized in Information Assurance
  • Secret Clearance; the ability to obtain an NRC Security Clearance; US citizenship required
  • Must hold at least one of the following certifications: CompTIA Security+, CISSP, ISACA CISA, GIAC GSEC, GIAC GSNA, GIAC GPEN, CEH, CAP, CASP+, CRISC, or CCSK

PREFERRED QUALIFICATIONS / SKILLS

  • A strong understanding of FISMA and NIST Special Publications, especially NIST SP 800-37 and NIST SP 800-53
  • Excellent written and oral communication skills; attention to detail is a must
  • Experience with vulnerability scanning tools, such as Tenable Security Center
  • Working knowledge of DISA STIGs, SCAP content/ audit files, and CIS Benchmarks
  • Understanding of cloud service models (SaaS, PaaS, IaaS) and protections as described in FedRAMP security documentation
  • Experience reviewing FedRAMP authorization packages and understanding how to ensure customer responsibilities are addressed in accordance with the shared responsibility model
  • Experience with performing technical architecture reviews of complex systems with a strong understanding of a system's authorization
  • Knowledge of major cloud platforms (Azure/ Amazon Web Services [AWS]), virtualization, networking devices (e.g., routers and switches), web services (e.g., IIS, Apache Tomcat), network security appliances (e.g., firewalls, VPNs), databases (e.g., Microsoft SQL), and intrusion prevention/ anti-malware software
  • Knowledge of system and application security threats and vulnerabilities
  • Proficiency with Microsoft Office applications
  • Ability to prioritize and complete tasks efficiently and effectively
  • Comfortable working individually and as part of a team
  • Scripting ability (e.g., PowerShell, VBA) is a plus
  • Familiarity with the use of artificial intelligence (AI) tools such as chat technologies to enhance personal productivity

 

RESPONSIBILITIES

 

  • Work closely with all levels of personnel, including system administrators, Information System Security Officers (ISSOs), and Authorizing Official (AO), to support FISMA systems through the Security Assessment & Authorization (SA&A)
  • Assess the confidentiality, integrity, and availability impact levels of information stored, possessed, and transmitted by systems to determine the FIPS 199 security categorization
  • Develop and maintain system security documentation throughout all phases of the NIST Risk Management Framework (RMF). This includes security categorizations, digital identity risk assessments, system security plans, system policy and procedures, privacy impact assessments, contingency plans, configuration management plans, incident response plans, vulnerability assessment reports, deviation requests, and any other documents necessary to support systems' authorization and continuous monitoring
  • Analyze risks identified during security control assessments and continuous monitoring activities in accordance with NIST SP 800-30. This includes making a determination regarding the likelihood and impact of the risk being exploited, along with a supporting rationale, and providing recommendations for mitigation/remediation
  • Perform and document the results of vulnerability scans and configuration compliance checks against configuration standards such as DISA STIGs and CIS Benchmarks
  • Analyze FedRAMP security packages to document and assess customer responsibility for cloud-based
  • Assist in the review of monthly continuous monitoring deliverables produced by Cloud Service Providers (CSPs) and annual assessments (produced by third party assessors [3PAOs]) in support of FedRAMP requirements to ensure that cloud services maintain an appropriate risk
  • Create, track, and manage system Plans of Action and Milestones (POA&Ms)
  • Attend project meetings and collaborate with stakeholders to ensure security is addressed throughout the entire system lifecycle

 

#CJ

About Astrion

Astrion Careers

Joining Astrion presents an unparalleled opportunity to become part of a leading team of professionals dedicated to pioneering innovation and digital transformation. Astrion, a beacon in the tech industry, offers a variety of job opportunities that cater to ambitious individuals eager to drive change and lead industries forward.

Work That Matters

At Astrion, every position is a chance to collaborate with some of the brightest minds in technology and business. The company helps the world’s most renowned companies navigate their digital transformation journeys, leveraging a unique blend of industry expertise and technological innovation.

Explore Job Opportunities and Internships

Astrion is constantly seeking passionate, curious, and creative individuals to join its team. Whether looking for full-time employment or an internship, Astrion provides a platform to develop professional skills, engage in meaningful networking, and contribute to impactful projects. Explore the myriad of positions available and find where your skills can help shape the future of technology.

Innovative Work Environment

Astrion fosters a culture of innovation where team members from diverse backgrounds come together to solve complex challenges. The company is committed to diversity training and leadership development, ensuring that all team members have the opportunity for personal and professional growth.

Benefits and Growth

Astrion is dedicated to the growth of its team members, offering substantial benefits and resources to support career advancement. This includes comprehensive health benefits, leadership training programs, and opportunities for professional development. Astrion’s commitment to career growth ensures that every team member has the resources to reach their full potential.

Join the Astrion Team

Astrion is hiring! Search open positions that match your skills and interests. The company looks for driven, solution-oriented team players. Prepare your resume, refine your interview skills, and get ready to join a team that values leadership and professional growth.

Stay Connected with Astrion Careers

Keep up to date with career tips, insider perspectives, and industry-leading insights—all from the professionals who are part of Astrion. Personalize your subscription to receive job alerts, latest news, and insider tips tailored to your preferences. Discover the exciting and rewarding career opportunities that await at Astrion.

Networking and Professional Development

Astrion values the power of networking and encourages its team to engage in events and activities that foster professional connections. This commitment to networking is integral to maintaining a vibrant, innovative, and inclusive workplace.

Empower Your Career with Astrion

Embark on a journey of professional discovery and innovation at Astrion. Whether you are starting your career or looking to enhance it, Astrion offers a dynamic environment where your ambitions can take flight.
Learn more about Astrion

Similar Jobs

More Jobs at Astrion

More Information Technology Jobs

Find similar Information Assurance Support Analyst jobs: