> Markdown version of [/jobs/ext/1906993-information-security-analyst](https://www.wearedevelopers.com/jobs/ext/1906993-information-security-analyst). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Information Security Analyst - **Company:** NextGen Staffing - **Location:** Washington, DC, United States - **Experience:** Expert - **Contract:** Permanent contract - **Skills:** Microsoft Word, Microsoft Excel, Microsoft Outlook, Cyber Security, Federal Information Processing Standards (FIPS), Microsoft Office, Microsoft PowerPoint, Microsoft SharePoint, Information Security Management System, Operational Systems, Plan of Action and Milestones - **Published:** August 3, 2026 - **Apply:** https://www.dice.com/job-detail/2181f696-7ffa-49bd-a33c-e3546ec5a7e5 ## About the Role * Significant ISSO experience required, in lieu of degree. (2 years) * A minimum of 7 years of experience in the following: * Developing System Security Plan * Managing and tracking POAMs * Continuing monitoring activities * Developing Standard Operating Procedures (SOP) * Understanding of NIST 800-Series * Proficiency with Microsoft Office software, including Word, Excel, PowerPoint, Outlook, and SharePoint. * Positive adjudication from a CBP Background Investigation. ## Description NextGen Federal Systems is seeking an Information Security Analyst to join our work supporting our DHS customer in Washington, DC. The ISA will report to the ISSM and provide security and compliance duties to assigned systems stakeholders. Duties include but are not limited to: * Track and manage POAMs throughout the remediation cycle from creation to closure. * Review and approve Technical Requirement Model (TRM) for software products * Lead Authority to Operate efforts for assigned Air and Marine Operations systems * Ensure technical team is adhering to laid down policy and procedures to meet DHS and CBP compliance requirements. * Ensuring audit logs are reviewed periodically in accordance with departmental policy and the Security Authorization documentation (e.g. weekly or daily) * Develop, analyze and update System Security Plan (SSP), Risk Assessment (RA), Privacy Threshold Analysis (PTA), Privacy Impact Assessment (PIA), System Security test and Evaluation (ST&E) and the Plan of Actions and Milestones (POA&M) * Document risks and appropriate compensation controls for the Authorizing Official to make a risk-based decision on identified vulnerabilities. * Designate systems and categorize its C.I.A using FIPS 199 and NIST SP 800-60 * Create update Standard Operating Procedure (SOP) for process flows and quality enhancements * Develop Information Security Continuous Monitoring Strategy to help maintain an ongoing awareness of information security (Ensure continued effectiveness of all security controls), vulnerabilities, and threats to support organizational risk management decisions * Create security impact analysis document to accompany required changes for Change Control Board approval before changes are made to assigned systems ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [In-depth .NET Azure Functions: Isolated mode, performance and durable AI agents](https://www.wearedevelopers.com/videos/100207-in-depth-net-azure-functions-isolated-mode-performance-and-durable-ai-agents) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [Developing the Rich Text Editor for DeepL.com](https://www.wearedevelopers.com/videos/1172-developing-the-rich-text-editor-for-deepl-com) - [DevSecOps culture](https://www.wearedevelopers.com/videos/783-devsecops-culture) - [From Syntax to Singularity: AI’s Impact on Developer Roles](https://www.wearedevelopers.com/videos/900-from-syntax-to-singularity-ai-s-impact-on-developer-roles) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Best Paying Jobs in Technology](https://www.wearedevelopers.com/magazine/256-best-paying-jobs-in-technology) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities)