Senior Security Analyst (A&A)/Assessor - NIST

ITC Federal, Inc.

• $110K — $130K *
Information Technology
5 - 7 years of experience
Job Overview by Ladders

Qualifications

  • 5-8 years of experience implementing NIST 800 Series Special Publications
  • Demonstrable experience conducting IT assessor activities under NIST Risk Management Framework
  • Experience in Security Test and Evaluation and developing Security Assessment Reports
  • Proficiency in handling vulnerability data, writing Assessment Reports, and creating POA&Ms
  • Strong skills in IT security policy formation to ensure system confidentiality and integrity

Responsibilities

  • Conduct A&A activities for NIST systems individually or as a team member
  • Collaborate with NIST staff to provide technical and policy solutions for risk mitigation
  • Support system personnel with remediation plans for A&A findings
  • Provide guidance to Information System Security Officers (ISSO) on documentation
  • Coordinate and conduct vulnerability scans, analyzing results
  • Complete comprehensive Security Assessment Reports
  • Review and update A&A packages based on management feedback

Benefits

  • Health, Dental and Vision insurance
  • 401(k) plan
  • Flexible Spending Account (FSA) options
  • 11 Paid Federal Holidays
  • Paid Time Off (PTO)
  • Education reimbursement
Full Job Description
Overview

JOB TITLE: Senior Security Analyst/A&A SME

GOVERNMENT AGENCY: NIST - National Institute of Standards & Technology

POSITION INFORMATION: Full-Time Position; Government contractor supporting NIST

LOCATION: Fully remote

BENEFITS: Health, Dental and Vision, 401(k), Flexible Spending Account (FSA), 11 Paid Federal Holidays, PTO, education reimbursement

Senior Security Analyst will be focused on Security Assessment & Authorization (A&A) of systems for the National Institute of Standards and Technology (NIST). The Senior Security Analyst is expected to be capable of lending subject matter expertise while performing A&A activities. The Senior Security Analyst will demonstrate a strong knowledge of Security Requirement Analysis, Security Architecture , Enterprise Security Program Assessment, evaluating Vulnerability Assessment results and perform other duties as required.

Responsibilities

RESPONSIBILITIES:
  • Conducting A&A activities for NIST systems working individually or as part of a team.
  • Work with NIST staff to provide technical and policy driven solutions to remediate or mitigate identified risks.
    • Support system personnel with remediation plans for A&A findings.
    • Provide guidance to Information System Security Officers (ISSO) on system documentation.
  • Coordinate/conduct vulnerability scans and analyze results.
  • Complete Security Assessment Reports involving both technical and policy related aspects of the assessment.
  • Review and update A&A packages based on management feedback.


Qualifications

  • 5 - 8 years of experience implementing the NIST 800 Series Special Publications.
  • Demonstrable experience:
    • Conducting IT assessor activities based on the NIST Risk Management Framework, to include the interviewing, examining and testing of related control sets; the review and/or updates of core system documents- System Security Plans, Contingency Plans, Privacy Threshold Assessments, hardware and software inventories, and system diagrams.
    • Performing Security Test and Evaluation and developing Security Assessment Reports for NIST senior management.
    • Delivering risk and vulnerability briefings confidently to management and government customers.
  • Experience working with vulnerability data, writing Assessment Reports, POA&Ms and Risk Acceptance justifications
  • Knowledge of the formation and implementation of IT security policies to ensure confidentiality, integrity and availability of information systems.
  • Strong technical oral, writing and customer service skills as you will regularly interact with NIST colleagues and senior managers.

PREFERRED:
  • Prior federal or GOVCON experience
  • Cloud Experience (AWS or Azure)
  • Active Certified Information Systems Security Professional (CISSP), Certified Information Security Manager (CISM), Certified Information Security Auditor (CISA) or comparable certification
  • Advanced Degree in computer science or related field or related experience
  • Direct experience with NIST or other academic environments.
  • Expertise with COTS based security tools (i.e. RSA Archer, CSAM, Tenable, WebInspect, AppDetective) used to establish security baselines and assess continuing compliance.


SECURITY CLEARANCE REQUIREMENTS:
  • Ability to successfully pass a National Agency Check with Local Agency Check (NACLC)


WORK ENVIRONMENT AND PHYSICAL DEMANDS: Candidate must be able to function in general office environment.

Similar Jobs

More Jobs at ITC Federal, Inc.

More Information Technology Jobs

Find similar Senior Security Analyst (A&A)/Assessor - NIST jobs: