Security Analyst
- Discuss this with your agent
- Open in Claude
- Open in ChatGPT
Role details
Tech stack
+6 more
Job description
-
Brief Description: The Security Analyst supports Risk Management Framework, cybersecurity compliance, Authority to Operate, and continuous monitoring activities across a complex, mission-critical cloud platform hosted in AWS GovCloud supporting 300+ applications and services. This role performs vulnerability scanning, security documentation management, Plan of Actions and Milestones tracking, audit support, credential and account management, and security posture reporting, ensuring continuous compliance with Federal and VA security requirements across all platform and tenant authorization boundaries., * Conduct ad hoc, prescribed, and recurring vulnerability scans for the platform and all hosted applications using Nessus and approved scanning tools
-
Document and report scan findings in accordance with VA RMF and POA&M processes including uploading results to the appropriate scan repository and maintaining the Continuous Authorization and Monitoring system security posture
-
Create and maintain Plan of Actions and Milestones within SNOWCAM, ensuring proper alignment to NIST security families and Control Correlation Identifiers, with periodic review and updating of milestones and mitigation plan details
-
Draft and maintain POA&M verbiage clearly depicting mitigation strategies and timelines, closing out POA&Ms once mitigated, overcome by events, or no longer relevant
-
Maintain program security documents, diagrams, and RMF artifacts including Privacy Threshold Analysis, Privacy Impact Analysis, Security Impact Analysis, Business Impact Analysis, Data Security Categorization, hardware and software lists, and Ports Protocols and Services Management documents
-
Collaborate with application development teams and platform architects to establish and maintain Interconnection Diagrams, High-Level Diagrams, and security assessment boundary diagrams
-
Support all security audits including Inspector General audits, Security Assessment and Validation Directorate assessments, Cybersecurity Compliance Task Force audits, and assessments by Office of Information Security and external teams
-
Attend assessment closeout meetings and review reported findings to ensure accuracy with assessed platform assets and resources
-
Draft assessment finding mitigation plans including roadmaps and timelines for all prescribed remediations
-
Conduct regular user access audits ensuring inactive accounts are removed and existing accounts contain only access required for assigned duties
-
Enforce role-based access management controls, Zero Trust Architecture, and least-privilege principles in accordance with VA security governance policy
-
Rotate service account credentials in accordance with VA security policy and NIST guidelines
-
Submit and maintain Technical Reference Model requests for licensed software and application usage, drafting justification verbiage and attending TRM approval board meetings
-
Submit and maintain Business Partner Extranet connection requests, managing information gathering, submission, and approval meetings
-
Support development and maintenance of Incident Response Plans and Disaster Recovery Plans including RACI charts and tabletop exercise participation
-
Contribute to monthly RMF, Security, and ATO Reports detailing authorization posture, vulnerability findings, POA&M tracking, and remediation progress
-
Support tenant ATO/ATC package preparation including documentation, training, and guidance for tenant teams
Requirements
-
Demonstrated experience in cybersecurity compliance, vulnerability management, or RMF support for Federal IT programs
-
Experience with vulnerability scanning tools, specifically Nessus Professional or equivalent
-
Hands-on experience with security posture tracking systems (SNOWCAM, eMASS, or equivalent)
-
Experience creating and managing Plan of Actions and Milestones through full maturity cycles
-
Knowledge of NIST SP 800-53 Rev. 5 security controls, NIST SP 800-37 Rev. 2 RMF process, FISMA, and FIPS requirements
-
Experience developing and maintaining RMF security documentation including PTA, PIA, SIA, BIA, ICD, HLD, and boundary diagrams
-
Experience supporting security audits and assessments from multiple oversight organizations
-
Knowledge of credential and account management practices including Zero Trust Architecture and least-privilege principles
-
Familiarity with cloud security in AWS environments including EKS, container security, and cloud-native vulnerability management
-
Experience with TRM submission and governance processes
-
Understanding of HIPAA, Privacy Act, and Federal data protection requirements
-
Experience working in Agile or SAFe environments with sprint-based delivery cadences
-
Security+ or equivalent cybersecurity certification required
-
CISSP, CAP, or equivalent certification preferred
-
Bachelor’s Degree from an accredited academic institution with a minimum of 5 years of experience in cybersecurity compliance, vulnerability management, or RMF support for Federal IT environments
-
OR
-
Associate’s Degree from an accredited academic institution with a minimum of 7 years of experience in cybersecurity compliance, vulnerability management, or RMF support for Federal IT environments
-
Plus:
-
Department of Veterans Affairs (VA) experience
-
Active Personal Identity Verification (PIV) card
-
Experience with VA-specific security governance including VA Handbook 6500, VA Directive 6500, and VA Critical Security Controls
-
Experience with SNOWCAM, ICAMP, and OIS Unified Services Portal
-
Experience supporting ATO for platforms with tiered multi-tenant authorization boundaries
Apply for this position
This job is hosted externally. Click below to view the full posting and apply.
Apply on www.indeed.comGood distractions
Talks and stories from around this role — technically off-topic, practically not.
Moments
Explore playlistsVideos
See allRelated articles
See all
Understanding and Mitigating Common Web Vulnerabilities
Walking Into The Era of Supply Chain Risks
9 Ways to Make Money Hacking
Dev Digest 134 - Where pixels sing?