Sr. Control Assessment Analyst

Stellent IT LLC
Washington, DC, United States
15 days ago
Apply on www.careerjet.com
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
3 years minimum
Compensation
$110,000.0 - $137,000.0
Working hours
Regular working hours

Tech stack

Xacta Software System Penetration Testing Cloud Computing Security Cyber Security Security Content Automation Protocol Information Technology Nessus Vulnerability Analysis

Job description

We are seeking FISMA Support Analyst(s) to support the Governance, Risk and Compliance (GRC) team within the IT division at the Board of Governors of the Federal Reserve. This team is responsible for defining, implementing and managing processes that support compliance, policy, outreach, and privacy related work across the organization., Prepare and maintain security authorization packages (System Security Plans, Security Assessment Reports, Plans of Action & Milestones) Conduct continuous monitoring activities and maintain Authority to Operate (ATO) status Ensure compliance with FISMA, NIST 800-53 security controls, and agency-specific policies Risk Management Perform security control assessments and vulnerability analyses Identify, document, and track security weaknesses and deficiencies Develop and maintain Plans of Action & Milestones (POA&Ms) Conduct risk assessments and recommend risk mitigation strategies Support Annual Security Reviews and security authorization updates Documentation & Reporting Develop and maintain System Security Plans (SSPs) Create and update security-related documentation (SOPs, diagrams, inventory) Generate security metrics and reports for management and auditors Maintain system security authorization documentation in compliance repositories Security Operations Support Coordinate security scans and penetration testing activities Review and analyze vulnerability scan results Assist with incident response and security event investigations Support security tool implementation and configuration Stakeholder Coordination Serve as primary liaison between system owners, authorizing officials, and security teams Coordinate with vendors, contractors, and technical teams on security requirements Provide security guidance to development and operations teams, MANTECH seeks a motivated, career and customer-oriented Budget Analyst to join our team in Arlington, VA. This is an onsite position. Responsibilities include, but are not limite…

  • 4 days ago, Control Assessment Analyst/FISMA (Sr.) Washington, DC Pay From: $138,000 per year MUST: Experienced Sr. Control Assessment Analyst Experienced FISMA Support Analyst(s) U.S. …
  • 17 hours ago

Requirements

The candidate shall possess the knowledge and skills set forth in the Technical Services BOA, Section 3.6.2.1 for labor category External Auditor Consultant (FISMA). The candidate shall also demonstrate the below knowledge and experience: Bachelor’s degree in Computer Science, Information Security, or related field 3-5 years of experience in information security or cybersecurity compliance Experience with federal government systems and FISMA compliance Hands-on experience with RMF/ATO processes Security Authorization & Compliance, Strong knowledge of NIST frameworks (800-53, 800-37, 800-171) Familiarity with security assessment tools (Nessus, ACAS, SCAP) Understanding of cloud security (FedRAMP preferred) Experience with compliance management tools (Xacta, or similar) Knowledge of security controls implementation across various platforms.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.careerjet.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

4:11 min

Introduction to cloud-native application developer security

Micah Silverman · World Congress 2022

5:13 min

Audience Q&A on maturity assessments and external consultants

Mathias Tausig · LIVE

3:44 min

Current industry adoption and future security initiatives

Alexander Allmendinger · LIVE

2:07 min

Summarizing critical actions for organizational cybersecurity compliance readiness

Matthew Brady Matthew Brady · World Congress 2026 Europe

1:43 min

Reviewing deterministic security controls and compliance frameworks

Carey Liu Carey Liu · World Congress 2026 Europe

4:27 min

Embracing a new perspective on mobile cyber attacks

Tom Tovar · World Congress 2023

Videos

See all

Related articles

See all