CybersecurityJobs.io
← Back to all jobs

Job Description

Data Systems Analysts, Inc. is seeking a Senior Information Security Analyst to support the Environmental Protection Agency (EPA) Office of Information Security and Privacy (OISP) in the DC Metro area on a hybrid schedule. In this role, you will function as a Risk Management Framework (RMF) subject matter expert, helping develop and mature an enterprise-wide information security program while advising senior stakeholders across governance, risk, and compliance activities.

Based in Aberdeen Proving Ground, MD, this position provides a salary range of USD 105,000 to 115,000 per year and requires 8 years of relevant experience. The work includes supporting authorization and continuous improvement efforts through Independent Validation and Verification (IV&V), coordinating government reporting, and using GRC tooling to track findings to resolution.

Responsibilities

  • Advise senior-level stakeholders on InfoSec initiatives covering compliance, awareness and training, and security operations.
  • Lead Independent Validation and Verification (IV&V) activities for security authorization/ATO packages to confirm alignment with agency requirements.
  • Use the existing Governance, Risk, and Compliance (GRC) tool such as Telos Xacta (or alternate tools like CSAM or RSA Archer) to reconcile and track findings from assessments, audits, and vulnerability scans.
  • Coordinate government data calls (including FISMA, FMFIA, BDR, etc.) and support monthly reporting.
  • Evaluate the effectiveness of the InfoSec and privacy training program and collect, analyze, and present enterprise-level InfoSec performance metrics.
  • Manage InfoSec Program POA&Ms, including guidance on remediation planning and execution.
  • Partner with senior agency security officials, system owners, information system security officers (ISSOs), and other stakeholders to advise on and implement security solutions.
  • Identify opportunities for process efficiencies and innovative approaches across program activities.
  • Participate in team problem solving and contribute ideas to address client needs.
  • Conduct relevant research, perform data analysis, and produce reports and documentation.
  • Assist with development of policy and procedures, and implement processes to monitor risk across programs and projects.
  • Prepare executive briefings to debrief the results of studies, analyses, and plans.
  • Support client leadership in reviewing monthly project progress, documenting issues, and monitoring resolution.

Requirements

  • Ability to obtain a Public Trust.
  • Bachelor's degree in information technology or a related field and 8 years of relevant IA experience. Security certification (e.g., CISSP) may substitute for 2 years of experience.
  • 3+ years in a leadership role.
  • Strong data analysis skills.
  • Excellent written and verbal communication skills.
  • In-depth knowledge applying, selecting, and testing NIST 800-53 Rev 4 security controls.
  • In-depth knowledge of NIST 800-37 Risk Management Framework.
  • Experience using a GRC tool such as Telos Xacta, RSA Archer, CSAM, or eMASS.
  • Excellent attention to detail.
  • Ability to handle and prioritize multiple tasks and deadlines.

Technologies

  • Microsoft Copilot
  • Telos Xacta
  • CSAM
  • RSA Archer
  • eMASS
  • NIST 800-53 Rev 4
  • NIST 800-37 Risk Management Framework
  • Risk Management Framework (RMF)
  • Governance, Risk, and Compliance (GRC) tool
  • FISMA
  • FMFIA
  • BDR
  • Independent Validation and Verification (IV&V)
  • Security authorization/ATO packages
  • POA&Ms

Similar Jobs