Bachelor's degree in Computer Science, MIS/IT, Engineering, Information Security/Assurance, or a related field
Minimum five years of information security experience
Experience in technical security control testing and assessment planning
Knowledge of RMF Steps 1-6
Strong grasp of NIST SP 800-53 controls and the NIST Cybersecurity Framework
Ability to analyze system configurations against NIST standards
Excellent written and verbal communication skills with adaptiveness to audience
Active Secret clearance with eligibility for Top Secret clearance
Responsibilities
Lead development and implementation of cybersecurity processes and workflows
Document cybersecurity processes and standard operating procedures
Elicit, analyze, and document business requirements into functional specifications
Conduct data analysis, process modeling, and workflow analysis for improvements
Develop and present business cases and strategic recommendations to leadership
Act as a liaison between business units and IT teams
Mentor junior business analysts on best practices and continuous learning
Oversee user acceptance testing and quality assurance activities
Provide governance support over common control projects
Benefits
Hybrid work environment in Washington, DC
Opportunity to work on national security systems
Engagement in a culture of continuous learning
Mentorship opportunities for growth and development
Involvement in cutting-edge cybersecurity processes and federal regulations
Full Job Description
ECS is seeking a Senior Business Analyst to work in our Washington, DC (hybrid) office. Please Note: This position is contingent upon contract award.
Job Responsibilities
Lead the development and implementation of cybersecurity processes and security assessment workflows for information systems, including national security systems, that are managed in a governance, risk management, compliance (GRC) application, and that are governed by federal laws and Department of State policies and standards.
Document cybersecurity processes and standard operating procedures as needed and manage the same in SharePoint and a GRC.
Elicit, analyze, and document business requirements, translating high-level needs into detailed functional specifications and use cases.
Conduct in-depth data analysis, process modeling, and workflow analysis to identify areas for improvement and propose innovative solutions.
Develop and present compelling business cases, cost/benefit analyses, and strategic recommendations to senior leadership and key stakeholders.
Act as a liaison between business units and IT teams, facilitating effective communication and collaboration throughout the project lifecycle.
Lead or mentor less experienced business analysts, providing guidance on best practices and fostering a culture of continuous learning.
Oversee and participate in user acceptance testing (UAT) and quality assurance activities, ensuring solutions meet business requirements and are delivered on time and within budget.
May also be responsible for tasks like vendor management and system administration, depending on the specific role requirements.
Provide governance support over common control projects and cloud service provider on-boarding
Salary Range: $130,000-$147,000
General Description of Benefit
Bachelor's degree in Computer Science, MIS/IT, Engineering, Information Security/Assurance, or a related field
Minimum five (5) years of information security experience
Demonstrated experience conducting full-scope technical security control testing across component types, including development of security and privacy assessment plans
Working knowledge of RMF Steps 1-6
Strong understanding of NIST SP 800-53 controls, the NIST Cybersecurity Framework, and applicable information security/privacy laws and regulations
Ability to analyze information system configurations and technical specifications against NIST SP 800-53 and related overlays
Experience developing risk-based documentation
Excellent written and verbal communication skills, with the ability to present control requirements and deficiencies clearly to both technical and non-technical audiences
Active Secret clearance required with eligibility to get Top Secret clearance
About ECS
ECS is a leading provider of digital solutions and services to the federal government. The company was founded in 2001 by Roy Kapani and has since grown to become a trusted partner to a wide range of government agencies. ECS offers a broad range of services, including cloud computing, cybersecurity, and artificial intelligence. The company has been recognized for its innovative solutions and has won numerous awards, including the AWS Public Sector Partner of the Year award.