> Markdown version of [/jobs/ext/209310-sr-federal-security-governance-analyst](https://www.wearedevelopers.com/jobs/ext/209310-sr-federal-security-governance-analyst). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Sr. Federal Security Governance Analyst - **Company:** Maximus, Inc. - **Location:** Davenport, IA, United States - **Experience:** Expert - **Salary:** $80,000.0 - $100,000.0 - **Contract:** Permanent contract - **Skills:** Microsoft Word, Microsoft Excel, Cyber Security, Information Systems, Federal Information Processing Standards (FIPS), Microsoft Office, Microsoft PowerPoint, Smartsuite, Smartsheet, Information Technology - **Published:** May 15, 2026 - **Apply:** https://www.careerjet.com/jobad/usd51067173a28b3117a4af8a194e1be30 ## About the Role Please refer to the additional information section of the job requisition for this opening to determine clearance eligibility required. - Bachelor's Degree in related field. - 5-7 years of relevant professional experience required. - Equivalent combination of education and experience considered in lieu of degree. Additional Minimum Requirements: - 7+ of security governance development and management for a corporate organization supporting Federal and DoD customers. - Experience supporting security governance for organizations using FedRAMP CSO's as it pertains to system-specific and hybrid controls. - RMF and A&A experience desired - Demonstrated experience in cybersecurity governance programs in highly regulated federal environments, including implementation and oversight of NIST-based security controls - Strong understanding of Federal requirements to include but not limited to applicable Executive Orders, FISMA, FIPS, CMMC, NIST 800-171, NIST 800-53, NIST 800-60, and NIST 800-65. - Experience with Federal and DoD GRC tools. (CFACTS, CSAM, eMASS, etc.) - Experience mapping and cross walking policies, standards, and procedures to multiple security frameworks. - Exercise judgement in selecting methods, techniques, and evaluation criteria for obtaining results. - Network with key contacts outside own area of expertise. - Develop solutions to a variety of complex problems. - Work requires considerable judgment and initiative. - Ability to communicate Federal language (NIST verbiage) in understandable business terms. - Excellent interpersonal skills, presentation skills, and oral / written communication skills. - Strong customer service abilities required. - Ability to work collaboratively with a broad range of staff. - Skilled in Microsoft Office software including Word, Excel, and PowerPoint; Smartsheet; and Lucid. - Ability to perform comfortably in a fast-paced, deadline-oriented work environment. - Ability to execute many complex tasks simultaneously and work as a team member as well as independently. Preferred Qualifications: - Bachelor's degree in cybersecurity, computer science, information assurance, or related field - Certifications like CISSP, CISM, CISA, or GRC / audit or risk certifications desired. ## Description Perform complex risk analyses and risk assessment. - Establish and satisfy Information Assurance (IA) and security requirements based upon the analysis of user, policy, regulatory, and resource demands. - Support customers in the development and implementation of doctrine and policies. - Advise information system owners on client/project security policies and requirements for systems. - Keep abreast of emerging security technologies and make appropriate recommendations regarding the enhancement of the security posture of systems and their implementation. - Collaborate with the Enterprise (Shared Services) ISSO to ensure proper alignment of organizational governance with Federal and DoD customers. - Collaborate with project ISSO's (existing contracts) and Business Development and Capture Teams to ensure proper alignment of organizational governance with existing and prospective Federal and DoD customers. - Assist the Enterprise (Shared Services) ISSO with application of security policies to shared services supporting Federal and DoD customers. - Recommend enhancements that align governance with Federal and DoD customers. - Support the enhancement and on-going management of governance activities from a Federal perspective, including vendor assessments, annual enterprise risk assessments, enterprise risk registers, security awareness and training, and maintenance of a GRC ## Related Videos - [Developing the Rich Text Editor for DeepL.com](https://www.wearedevelopers.com/videos/1172-developing-the-rich-text-editor-for-deepl-com) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [What makes Cybersecurity different for critical infrastructure?](https://www.wearedevelopers.com/videos/571-what-makes-cybersecurity-different-for-critical-infrastructure) - [Checkmate: 5 Real Incidents That Can End a Software Company](https://www.wearedevelopers.com/videos/100126-checkmate-5-real-incidents-that-can-end-a-software-company) ## Related Articles - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Best Paying Jobs in Technology](https://www.wearedevelopers.com/magazine/256-best-paying-jobs-in-technology) - [What’s the Difference between a Junior, Mid, and Senior Developer?](https://www.wearedevelopers.com/magazine/238-what-s-the-difference-between-a-junior-mid-and-senior-developer)