Cybersecurity Analyst/Information System Secu
SHR CONSULTING GROUP, LLC
Alexandria, VA, United States
7 days ago
- Discuss this with your agent
- Open in Claude
- Open in ChatGPT
Apply on www.clearancejobs.com
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Role details
Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
5 years minimum
Working hours
Regular working hours
Job source
Tech stack
Agile Methodology
Amazon Web Services
Microsoft Azure
Cloud Computing Security
Configuration Management
CompTIA Security+
Cyber Security
Information Systems
Zero Trust Network Access
Security Information and Event Management
Software Vulnerability Management
Privacy Controls
+7 more
SARS Software Products
Cloud Platform System
Information Technology
Nessus
Devsecops
Plan of Action and Milestones
Vulnerability Analysis
Job description
- Support implementation and ongoing execution of the NIST Risk Management Framework (RMF) and DHS/FEMA security policies and procedures.
- Develop, maintain, and update system security documentation, including System Security Plans (SSPs), Security Assessment Reports (SARs), Plans of Action and Milestones (POA&Ms), Contingency Plans, Configuration Management Plans, and related authorization artifacts.
- Support Assessment and Authorization (A&A) activities for FEMA systems, applications, and cloud environments.
- Maintain security documentation and evidence within applicable DHS/FEMA governance, risk, and compliance (GRC) systems.
- Conduct and document security control assessments and support implementation and validation of NIST SP 800-53 security and privacy controls.
- Track cybersecurity findings, vulnerabilities, POA&Ms, remediation activities, and risk acceptance through closure.
- Review vulnerability scanning and security monitoring results from tools such as Tenable/Nessus, CrowdStrike, Elastic, and other DHS/FEMA-approved security platforms.
- Coordinate with system administrators, cloud engineers, DevSecOps teams, application teams, and system owners to remediate vulnerabilities and configuration deficiencies.
- Support continuous monitoring, including recurring security control reviews, vulnerability management, configuration compliance, and required reporting.
- Review proposed system and infrastructure changes to identify cybersecurity impacts and ensure security requirements are incorporated throughout the system lifecycle.
- Support compliance with applicable DHS security directives, FEMA policies, FISMA, FedRAMP, NIST guidance, and federal cybersecurity requirements.
- Assist with incident response activities, security investigations, audit requests, and cybersecurity reporting as required.
- Participate in security reviews, technical meetings, change management activities, and coordination with FEMA cybersecurity stakeholders.
- Identify cybersecurity risks and provide practical recommendations for mitigation, remediation, or risk management.
- Maintain audit-ready security documentation and supporting evidence.
Requirements
- Bachelor’s degree in Cybersecurity, Information Technology, Computer Science, Information Systems, or a related discipline; relevant experience may be considered in lieu of a degree.
- 5+ years of cybersecurity or information assurance experience, preferably supporting federal government environments.
- Demonstrated experience supporting RMF, A&A, security control implementation, continuous monitoring, vulnerability management, and POA&M management.
- Working knowledge of NIST SP 800-53, NIST SP 800-37, FISMA, FedRAMP, and federal cybersecurity requirements.
- Experience developing and maintaining cybersecurity authorization and compliance documentation.
- Familiarity with enterprise and cloud environments, including AWS and/or Microsoft Azure.
- Strong written and verbal communication skills with the ability to work effectively with technical and non-technical stakeholders.
Preferred Qualifications
- Previous experience supporting FEMA, DHS, or another federal civilian agency.
- Experience securing AWS GovCloud and/or Azure Government environments.
- Experience with vulnerability management, SIEM, endpoint security, and continuous monitoring technologies.
- Experience working with Agile and DevSecOps engineering teams.
- Familiarity with Zero Trust architecture and federal cloud security requirements.
- One or more relevant certifications, such as CISSP, CAP/CGRC, Security+, CISM, CCSP, or equivalent cybersecurity certification., * Strong attention to detail and ability to maintain accurate, audit-ready security documentation.
- Ability to manage multiple systems, security requirements, findings, and deadlines simultaneously.
- Proactive approach to identifying and resolving cybersecurity risks.
- Ability to translate federal cybersecurity requirements into actionable requirements for engineering and operations teams.
- Strong collaboration skills and ability to work across cybersecurity, engineering, program management, and Government stakeholder organizations.
Clearance Requirements
- U.S. Citizenship.
- Ability to obtain and maintain required DHS/FEMA suitability and security clearance/access requirements. Priority will be given to FEMA Public Trust Clearance or DHS Public Trust within the last 3 years, or to active/current Public Trust.
Benefits & conditions
- Competitive salary commensurate with experience and clearance level
- Comprehensive medical, dental, and vision coverage.
- 401(k) with company contribution.
- Paid time off and eleven federal holidays.
- Certification reimbursement and training
- Life and disability insurance.
About the company
SHR Consulting Group, LLC is a small business delivering enterprise IT, cybersecurity, and program management services to the Department of Defense and federal civilian agencies. We support mission-critical infrastructure at the Pentagon and across the National Capital Region, and we invest in our people through competitive compensation, professional certification support, and long-term career growth on stable, multi-year programs.
Apply for this position
This job is hosted externally. Click below to view the full posting and apply.
Apply on www.clearancejobs.com
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Good distractions
Talks and stories from around this role — technically off-topic, practically not.
Moments
Explore playlistsVideos
See allRelated articles
See all
AJ
Austin Joy
over 4 years ago
LM
Luis Minvielle
9 Ways to Make Money Hacking
over 2 years ago
DC
Daniel Cranney
Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.
7 months ago
DC
Daniel Cranney
Understanding and Mitigating Common Web Vulnerabilities
over 1 year ago
BB
Benedikt Bischof
Walking Into The Era of Supply Chain Risks
about 4 years ago
CH
Chris Heilmann
Dev Digest 134 - Where pixels sing?
almost 2 years ago