> Markdown version of [/jobs/ext/1217671-senior-information-security-analyst-cybersecurity-specialist](https://www.wearedevelopers.com/jobs/ext/1217671-senior-information-security-analyst-cybersecurity-specialist). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Senior Information Security Analyst / Cybersecurity Specialist - **Company:** Makpar Corporation - **Location:** Washington, DC, United States - **Experience:** Expert - **Contract:** Permanent contract - **Skills:** Cyber Security, Databases, System Configuration, Federal Information Processing Standards (FIPS), Networking Hardware, Mainframes, Comptia Pentest+ CE, Security Content Automation Protocol, SQL Server Reporting Services, Virtualization Technology, Software Vulnerability Management, Cloud Platform System, Nessus, CIS Benchmarks, Plan of Action and Milestones - **Published:** July 9, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=ea2d0908dd29b3d5 ## About the Role * High school diploma or higher. * Demonstrated experience identifying and applying information security or cybersecurity requirements. * Demonstrated experience ensuring cybersecurity requirements are addressed through development, implementation, and configuration. * Demonstrated experience implementing security controls, configuration changes, software/hardware updates, vulnerability remediation, and secure configurations. * At least one of the required PWS-listed certifications, including CCNA Security, CySA+, GICSP, GSEC, Security+ CE, CND, SSCP, CASP+ CE, CCNP Security, CISA, CISSP or Associate, GCED, GCIH, CCSP, CAP, CISM, GSLC, CCISO, HCISPP, CEH, GSNA, CFR, or PenTest+. A minimum two-year IT/cybersecurity program may substitute for certification. * Ability to complete IRS suitability / staff-like access requirements., * Experience securing configurations within Government organizations. * Prior IRS, Treasury, Safeguards, Publication 1075, FTI, or federal compliance experience. * Experience with Nessus audit files, SCAP/XCCDF, SCSEMs, CAP/POA&M closure, SSR/system security plans, and technical inquiry responses. * Experience assessing cloud environments, mainframes, network devices, databases, virtualization, and operating systems. * Strong technical writing and customer-facing communication skills. ## Description Our Mission: We solve complex problems for the Federal government to accelerate access to citizen services. When it comes to excellence, we deliver. Learn more about our employer brand at makpar.com/careers. The Senior Information Security Analyst will perform the core cybersecurity assessment and compliance work for IRS Safeguards. The role supports computer security reviews of partner agencies that receive FTI, evaluates agency submissions, performs manual and automated checks, documents findings, and helps assess whether systems meet Publication 1075, NIST, CIS, STIG, and IRS requirements., * Conduct computer security reviews of partner agency systems that process, store, transmit, or protect FTI. * Execute system configuration checks and review technical artifacts, policies, procedures, and administrator evidence. * Support Nessus scans, manual testing, SCSEM completion, and automated evaluation file use. * Validate in-scope technologies, versions, support status, shared systems, responsible entities, applicable checklists, and FTI system interactions. * Prepare scope memos, status updates, preliminary findings, technology matrices, AARs, and SRR Section H packages. * Review CAPs / POA&Ms, SSRs, notifications, and technical inquiries. * Provide written cybersecurity guidance to partner agencies. * Apply NIST, IRS Publication 1075, CIS Benchmarks, DISA STIGs, FIPS, OMB A-130, and RMF guidance. ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Cloud as the new mainframe: why the cloud hype does not reflect the dev reality](https://www.wearedevelopers.com/videos/797-cloud-as-the-new-mainframe-why-the-cloud-hype-does-not-reflect-the-dev-reality) - [Kubernetes and Microservices with Multi-Model Databases](https://www.wearedevelopers.com/videos/382-kubernetes-and-microservices-with-multi-model-databases) - [".Net is too slow" was not an option](https://www.wearedevelopers.com/videos/100176-net-is-too-slow-was-not-an-option) - [Fault Tolerance and Consistency at Scale: Harnessing the Power of Distributed SQL Databases](https://www.wearedevelopers.com/videos/1146-fault-tolerance-and-consistency-at-scale-harnessing-the-power-of-distributed-sql-databases) - [What makes Cybersecurity different for critical infrastructure?](https://www.wearedevelopers.com/videos/571-what-makes-cybersecurity-different-for-critical-infrastructure) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Best Paying Jobs in Technology](https://www.wearedevelopers.com/magazine/256-best-paying-jobs-in-technology) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [7 Important Tips That Every Software Developer Should Know](https://www.wearedevelopers.com/magazine/101-7-important-tips-that-every-software-developer-should-know) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed)