Cybersecurity Analyst (ISSO)
Job Description
ActioNet is hiring a Cybersecurity Analyst (ISSO) to support Information Assurance (IA) and Cyber Security (CS) activities within the NIST RMF Assessment & Authorization (A&A) process for a hybrid role in Washington, DC.
Responsibilities
- Conduct security assessments of system security plans to help ensure documented controls meet stated security requirements.
- Assess the management, operational, and technical security controls within or inherited by an information system to evaluate overall control effectiveness.
- Verify security configuration compliance for IT systems and support clear implementation and enforcement processes for system security configurations.
- Support the risk management process by:
- Assisting with determination and assignment of risk impact ratings in line with Information Assurance standards guidelines and methodologies.
- Contributing to development and maintenance of Plans of Action and Milestones (POA&Ms) for systems in the RMF process.
- Supporting annual security assessments of IT systems.
- Evaluate severity of weaknesses or deficiencies in the system and its operating environment; recommend corrective actions for identified vulnerabilities.
- Prepare security assessment reports with results and findings from system security assessments.
Requirements
- Demonstrated knowledge and experience in IA / INFOSEC concepts and requirements, including:
- Firewall Policy
- Ports & Protocols
- Cybersecurity
- Cybersafe
- Familiarity with Tenable and BigFix (preferred).
- Experience with CSAM or eMASS.
- Knowledge of the A&A process and standards for NIST RMF.
- System and network vulnerability analysis.
- Risk assessment and risk mitigation analysis.
- Contingency planning.
- Knowledge and experience implementing and complying with Defense Information Systems Agency (DISA) published Security Technical Information Guidance (STIG).
- Knowledge of virtualization, networking, Windows and Linux operating systems, and storage and backup.
- Strong oral and technical writing skills.
- Extensive knowledge of US Government Information Assurance security processes.
- IAT Level II or one of the following: CISSP, CCSP, CISM, SecurityX.
Technologies
- NIST Risk Management Framework (RMF)
- Assessment & Authorization (A&A)
- Authority to Operate (ATO)
- Information Assurance (IA)
- Information Assurance standards
- Plans of Action and Milestones (POA&Ms)
- Tenable
- BigFix
- CSAM
- eMASS
- Defense Information Systems Agency published Security Technical Information Guidance (STIG)
- Windows
- Linux
- Virtualization
- Storage and backup
- ITIL v4
- Tenable Certified Nessus Auditor
- Qualys Certified Specialist
- Rapid7 InsightVM Certification
- ACAS Administrator
- SCAP Compliance Checker Training
- CISSP
- CCSP
- CISM
- SecurityX
- IAT Level II
Public Trust Clearance
- Requires a Public Trust clearance.
Work Location
- Hybrid role with on-site time 1-2 days a week.
- Washington, DC (hybrid); noted support location: Silver Spring, MD.
Compensation
- Salary up to USD 140,000 per year.
Minimum Qualifications
- 4+ years of minimum relevant experience.
- Education: Bachelor's degree or AA/AS in Information Assurance or InfoSec field.
Preferred Certifications
- ITIL v4
- Tenable Certified Nessus Auditor
- Qualys Certified Specialist
- Rapid7 InsightVM Certification
- ACAS Administrator
- SCAP Compliance Checker Training