Security Assessment and Continuous Monitoring Analyst

A-TEK Inc.

$110K — $120K *
Education, Government & Non-Profit
Less than 5 years of experience
Job Overview by Ladders

Qualifications

  • 5-7 years of experience in Federal Risk Management Framework (RMF), authorizations, and security assessments.
  • In-depth knowledge of NIST guidelines including SP 800-37, SP 800-53, and FISMA compliance.
  • Skilled in gathering and evaluating security control evidence effectively.
  • Experience in maintaining System Security Plans (SSPs), Security Assessment Reports (SARs), and Plans of Action and Milestones (POA&Ms).
  • Understanding of vulnerabilities, configurations, and security impact analysis processes.
  • Strong analytical, documentation, and stakeholder communication abilities.
  • Experience managing multiple priorities with strict deadlines.

Responsibilities

  • Support security control assessments across multiple authorization boundaries.
  • Collect, organize, and validate evidence for assessments and control documentation.
  • Coordinate logistics for assessments, including schedules and communications with assessors.
  • Monitor and track findings through the remediation process.
  • Update and maintain the status of POA&Ms in the designated Governance, Risk, and Compliance (GRC) platform.
  • Conduct continuous monitoring activities and maintain relevant documentation.
  • Assist with onboarding, decommissioning, audits, and security reporting.

Benefits

  • Health, dental, and vision insurance.
  • 401(k) with employer match.
  • Paid time off.
  • Opportunities for professional development.
Full Job Description
The Security Assessment and Continuous Monitoring Analyst supports annual security assessments, continuous monitoring, POA&M management, cybersecurity documentation, vulnerability and risk tracking, GRC platform updates, and authorization sustainment for an HHS-affiliated agency. This individual collects and validates evidence, maintains accurate records, tracks findings, and keeps authorization packages ready for Government and independent assessor review. Must be able to support hybrid work requirements in the Washington, DC metropolitan area or Research Triangle area.

Responsibilities
  • Support security control assessments for three primary authorization boundaries.
  • Collect, organize, validate, and maintain assessment evidence and control implementation documentation.
  • Coordinate assessment schedules, interviews, demonstrations, evidence requests, and assessor communications.
  • Track findings from identification through remediation, validation, closure, or POA&M acceptance.
  • Update POA&M status in the designated GRC platform within five business days of a status change.
  • Perform continuous monitoring activities and maintain supporting documentation and evidence.
  • Reconcile GRC records against system inventories, authorization artifacts, and operational information.
  • Support the annual review cycle for system documentation and authorization artifacts.
  • Monitor vulnerabilities, configuration changes, control status, and risk indicators.
  • Support security impact analyses within 10 business days after identification of a change request.
  • Prepare risk reports within 10 business days after assessments, major changes, or other triggering events.
  • Support cloud and FedRAMP artifact reviews, control inheritance analysis, and continuous monitoring.
  • Assist with system onboarding, decommissioning, data calls, audits, and cybersecurity reporting.
  • Apply quality checks that promote accurate documentation and 98 percent GRC data accuracy.

Required Experience and Qualifications
  • Demonstrated experience supporting Federal RMF, A&A, security assessments, and continuous monitoring.
  • Knowledge of NIST SP 800-37, NIST SP 800-53, NIST SP 800-53A, FISMA, and POA&M requirements.
  • Experience collecting and evaluating security control evidence.
  • Experience maintaining SSPs, SARs, POA&Ms, risk records, and related cybersecurity artifacts.
  • Understanding of vulnerability management, configuration management, and security impact analysis.
  • Strong analytical, documentation, and stakeholder communication skills.
  • Ability to manage concurrent priorities and meet time sensitive assessment and reporting deadlines.
  • Ability to support hybrid work requirements in the Washington, DC metropolitan area or Research Triangle area.
  • Education and experience that satisfy the proposed GSA labor category.

Preferred Experience and Qualifications
  • Experience supporting HHS or another Federal health agency.
  • Experience using JCAM or a comparable Federal GRC platform.
  • Experience with cloud and FedRAMP artifacts, control inheritance, and shared responsibility models.
  • Experience supporting independent assessors and addressing assessment findings.
  • Experience in maintaining accurate system inventory and authorization data.
  • CAP/CGRC, Security+, CISSP, CISM, or an applicable cloud security certification.

Compensation

Salary Range: $110,000 - $120,000 annually (commensurate with experience)
Benefits: Health, dental, and vision insurance; 401(k) with employer match; paid time off; professional development opportunities.

This is an opportunity to make a direct impact on healthcare data processes that support critical regulatory functions. You will collaborate with dedicated professionals, work on meaningful projects, and contribute to improvements in public health systems.

Candidates may use tools (including AI) for proofreading or formatting; however, using any tool to fabricate, exaggerate, or misrepresent qualifications, experience, or work product is not permitted. We may assess application materials for job-related technical depth, internal consistency, and demonstrated hands-on experience, including through follow-up questions, skills assessments, or reference checks. Verification of education may be requested before or during the hiring process.

For security and identity verification purposes, participants may be asked to temporarily disable virtual backgrounds during portions of the call.

Misrepresentation or falsification may result in removal from further consideration. Candidates who need a reasonable accommodation in the application or interview process may request one.

Similar Jobs

More Jobs at A-TEK Inc.

More Education, Government & Non-Profit Jobs

Find similar Security Assessment and Continuous Monitoring Analyst jobs: