Information Assurance Analyst
- Discuss this with your agent
- Open in Claude
- Open in ChatGPT
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Role details
Tech stack
Job description
InfoReliance is seeking an Information Assurance (IA) specialist with DIACAP and RMF experience, who has deep expertise in security assessment documentation to support USMC and Navy systems and their Authorizations to Operate (ATO). The scope of this position includes full life-cycle ATO management, security engineering, security assessment and testing, and information system security oversight activities that support several systems from the perspective of DIACAP and RMF requirements. This position is located at the client site in Webster Field, St. Inigoes, MD.
- In this role, you will use your expertise in technical documentation and management to work across several projects as part of a team to maintain all IA requirements.
-
This position requires a Secret clearance. Candidates should have a Secret clearance to be considered. RESPONSIBILITIES INCLUDE:
- Documenting, maintaining, reviewing, evaluating, and updating all system IA, DIACAP, and RMF documentation for assigned systems within the portfolio.
- Assist the team in convert 6 or so systems from DIACAP to RMF over the course of 3 years.
- Apply federal and organizational directives to manage system security operations.
- Manage the application of STIGs, reviewing and reporting of IAVMs, and POA&Ms
- Conduct Annual Security Reviews (ASR), FISMA compliance, and Continuity and Incident Response planning and exercises.
- The types of documentation you will be supported will include, but are not limited to accreditation overview documents, including:
- Concept of Operations (CONOPs) documents,
- System Security Plans (SSP)
- Incident Reponses Plans (IRP) Manage the application of STIGs, reviewing and reporting of IAVMs, and POA&Ms Conduct Annual Security Reviews (ASR), FISMA compliance, and Continuity and Incident Response planning and testing.
- Continuity of Operations, Contingency Plan, Disaster Recovery Plans (COOP, CP, DRP)
- IA system diagram overlays
- POA&Ms, mitigations, remediation, and comments
- Standard Operating Procedures (SOP) documents for performing assessments/security activities.
- System configurations for devices and software performing security-relevant functions
- Vulnerability test results
- Perform Security Impact Analysis (SIA) research and assess the impacts of system modifications, technological advances, etc
- Review system security documentation in order to identify potential security weaknesses, recommend improvements to amend vulnerabilities, implement changes and document security relevant changes
Requirements
IN ORDER TO BE SUCCESSFUL IN THIS ROLE, WE EXPECT THAT QUALIFIED CANDIDATES WILL HAVE THE FOLLOWING KNOWLEDGE, SKILLS, CREDENTIALS, AND EXPERIENCE:
- A Minimum of 3 years’ experience as an ISSO or similar role in which your technical experience can easily be translated into IA, including generating security documentation for requirements, assessment, compliance, Standard Operating Procedures, test results, etc.
- Professional Certification such as Security +ce.
- Experience with vulnerability scanning and assessment tools.
- Strong desktop publishing skills utilizing Microsoft Word and Excel.
- Experience with industry writing style such as grammar, sentence form, and structure.
- Strong initiative, detail orientation, organizational skills, aptitude for analytical thinking.
- Ability to multi-task in a deadline oriented environment across several projects and teams.
- Demonstrated ability to work well independently and as a part of a team.
- Excellent work ethic and a high commitment to quality.
Apply for this position
This job is hosted externally. Click below to view the full posting and apply.
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Good distractions
Talks and stories from around this role — technically off-topic, practically not.
Moments
Explore playlistsVideos
See allRelated articles
See all
Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.
Walking Into The Era of Supply Chain Risks
9 Ways to Make Money Hacking
What Are The Top Skills Required For Azure Developers?