> Markdown version of [/jobs/ext/2153547-fisma-support-analyst](https://www.wearedevelopers.com/jobs/ext/2153547-fisma-support-analyst). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # FISMA Support Analyst - **Company:** Edgewater Federal Solutions - **Location:** Washington, DC, United States - **Experience:** Experienced - **Salary:** $133,099.0 - **Contract:** Temporary contract - **Skills:** Xacta, Cloud Computing Security, Cyber Security, Information Systems, Security Content Automation Protocol, Information Technology, Nessus, Vulnerability Analysis - **Published:** August 20, 2026 - **Apply:** https://diversityjobs.com/main/sendform/8/8/28176/1/18012180?backUrl=%2Fcareer%2F18012180%2FFisma-Support-Analyst-D-C-Washington ## About the Role * U.S. Citizenship * Bachelor's degree in Computer Science, Information Security, or a related field * Three to five years of experience in information security or cybersecurity compliance * Experience with federal government systems and FISMA compliance Technical Skills * Strong knowledge of NIST frameworks, including SP 800-53, SP 800-37, and SP 800-171 * Familiarity with security assessment tools such as Nessus, ACAS, and SCAP * Understanding of cloud security; FedRAMP experience is preferred * Experience with compliance management tools such as Xacta or similar platforms * Knowledge of security control implementation across various platforms * Hands-on experience with Risk Management Framework (RMF) and Authority to Operate (ATO) processes ## Description We are seeking FISMA Support Analyst(s) to support the Governance, Risk and Compliance (GRC) team within the IT division at the Board of Governors of the Federal Reserve. This team is responsible for defining, implementing, and managing processes that support compliance, policy, outreach, and privacy-related work across the organization. Only candidates that currently reside within a 50 mile radius of DC will be considered., Security Authorization & Compliance Manage the security authorization lifecycle for information systems under NIST RMF (SP 800-37) * Prepare and maintain security authorization packages, including System Security Plans, Security Assessment Reports, and Plans of Action and Milestones * Conduct continuous monitoring activities and maintain Authority to Operate status * Ensure compliance with FISMA, NIST SP 800-53 security controls, and agency-specific policies Risk Management * Perform security control assessments and vulnerability analyses * Identify, document, and track security weaknesses and deficiencies * Develop and maintain Plans of Action and Milestones (POA&Ms) * Conduct risk assessments and recommend risk-mitigation strategies * Support annual security reviews and security authorization updates Documentation & Reporting * Develop and maintain System Security Plans (SSPs) * Create and update security-related documentation, including standard operating procedures, diagrams, and inventories * Generate security metrics and reports for management and auditors * Maintain system security authorization documentation in compliance repositories Security Operations Support * Coordinate security scans and penetration-testing activities * Review and analyze vulnerability scan results * Assist with incident response and security event investigations * Support security tool implementation and configuration Stakeholder Coordination * Serve as the primary liaison among system owners, authorizing officials, and security teams * Coordinate with vendors, contractors, and technical teams on security requirements * Provide security guidance to development and operations teams ## Related Videos - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [What makes Cybersecurity different for critical infrastructure?](https://www.wearedevelopers.com/videos/571-what-makes-cybersecurity-different-for-critical-infrastructure) - [Cyber Security: Small, and Large!](https://www.wearedevelopers.com/videos/259-cyber-security-small-and-large) - [Maturity assessment for technicians or how I learned to love OWASP SAMM](https://www.wearedevelopers.com/videos/351-maturity-assessment-for-technicians-or-how-i-learned-to-love-owasp-samm) - [Less Is More: How Lagom and Agile Can Create Harmonious Workflows](https://www.wearedevelopers.com/videos/1993-less-is-more-how-lagom-and-agile-can-create-harmonious-workflows) ## Related Articles - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks) - [Best Paying Jobs in Technology](https://www.wearedevelopers.com/magazine/256-best-paying-jobs-in-technology) - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [The Overflow: Security and Privacy](https://www.wearedevelopers.com/magazine/715-the-overflow-security-and-privacy)