Info Security Analyst IV

Location: Vienna, VA
Date Posted: 03-15-2018
6 - 12 months contract - 1099 or w2
looking for hires that are interested in 
conversion after contract
Rate is DOE per hour
Ability to obtain Public Trust is Required

This role with perform assessment and authorization (A&A) efforts under the NIST Risk Management Framework (RMF) on behalf of a federal civilian agency as a contractor. The role will conduct cybersecurity analysis in preparation for A&A reviewing and validation of all associated cybersecurity documentation and technical controls.
The position will assist with the development of the System Security Plan (SSP), Contingency Plan, Business Impact Analysis, POA&Ms, SAR (Security Assessment Report), and SAP (Security Assessment Plan).
This position covers all cybersecurity aspects including, but not limited to, identifying risks, validating the mitigation of plans of action, analyzing system designs, and assisting with A&A issues that may prevent a system from receiving authorization. It supports the implementation of RMF by developing documentation and updating policies, procedures, and processes as assigned.
Responsibilities and Duties:
• Identify key stakeholders in A&A efforts and ensure system documentation reflects current system security configurations to include hardware and software components, data flow, interconnections, and ports, protocols, and services, etc.
• Identify potential risks associated with system configurations and advise on mitigation strategies
• Participate in A&A status meetings and facilitate moving systems toward a successful A&A effort
• Assist to estimate Level of Effort (LOE) involved in performing A&A activities
• Assist to develop and implement detailed test plans and review findings from self-assessments to determine readiness for independent validation and verification (IV&V) assessment
• Assist customer program offices in interpreting and applying mitigation strategies
• Conduct IV&V assessments and analyze test results for accuracy, compliance, and adherence to Federal cybersecurity requirements
• Conduct thorough reviews of all vulnerabilities, architecture, and defense in depth strategies and report findings in a plan of action and milestones (POA&M) document
• Document residual risks and provide the cybersecurity risk analysis and mitigation determination results
• Produce risk assessment artifacts describing initial risks during system development and residual risks identified during IV&V
• Maintain cybersecurity policy and processes as assigned
• Able to analyze, interpret, and apply Federal cybersecurity guidance to customer needs
• Communicate the security posture of systems through designated reporting mechanism
• Collaborate with other team members in cybersecurity
Required Skills:
• Familiar with NIST publications, specifically RMF and NIST controls
• Familiar with dealing with defense-in-depth, and other information security and assurance principles and associated supporting technologies
• Excellent customer service and organization skills
• Excellent oral and written communication skills
• Must demonstrate proficiency in the following areas: multi-tasking, critical thinking; and the ability to work quickly, efficiently and accurately in a dynamic and fluid environment
• Ability to work both independently and as a member of a team
Desired Skills:
• Experience working with Security engineering to review Nessus Vulnerability / Tripwire compliance scans
• Experience performing on-site cybersecurity assessments using Standards such as CIS Benchmarks, DISA STIGS, etc.
• Broad technical experience related to IT operations, networks, OS's, and system administration
Education and Experience:
• Bachelor's Degree in IT, Cyber Security, Computer Science, or related field preferred and 5+ years of experience 
• 3 - 5 years of experience in the following areas: Cybersecurity policy, procedures, and processes, including RMF and NIST 800-53 and A&A's
• Experience using MS office tools such as Excel, Word and Visio
• One or more of the following certifications preferred (Security+, CAP, CISSP, CISM, GSEC, GCIH, or GSLC)
 US Citizenship Required
Must have the ability to obtain a Public Trust Clearance prior to starting work
this job portal is powered by CATS