> Markdown version of [/jobs/ext/2292550-cybersecurity-analyst-information-system-secu](https://www.wearedevelopers.com/jobs/ext/2292550-cybersecurity-analyst-information-system-secu). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Cybersecurity Analyst/Information System Secu - **Company:** SHR CONSULTING GROUP, LLC - **Location:** Alexandria, VA, United States - **Experience:** Expert - **Contract:** Permanent contract - **Skills:** Agile Methodology, Amazon Web Services, Microsoft Azure, Cloud Computing Security, Configuration Management, CompTIA Security+, Cyber Security, Information Systems, Zero Trust Network Access, Security Information and Event Management, Software Vulnerability Management, Privacy Controls, SARS Software Products, Cloud Platform System, Information Technology, Nessus, Devsecops, Plan of Action and Milestones, Vulnerability Analysis - **Published:** August 29, 2026 - **Apply:** https://www.clearancejobs.com/jobs/9124476/cybersecurity-analystinformation-system-secu ## About the Role * Bachelor's degree in Cybersecurity, Information Technology, Computer Science, Information Systems, or a related discipline; relevant experience may be considered in lieu of a degree. * 5+ years of cybersecurity or information assurance experience, preferably supporting federal government environments. * Demonstrated experience supporting RMF, A&A, security control implementation, continuous monitoring, vulnerability management, and POA&M management. * Working knowledge of NIST SP 800-53, NIST SP 800-37, FISMA, FedRAMP, and federal cybersecurity requirements. * Experience developing and maintaining cybersecurity authorization and compliance documentation. * Familiarity with enterprise and cloud environments, including AWS and/or Microsoft Azure. * Strong written and verbal communication skills with the ability to work effectively with technical and non-technical stakeholders. Preferred Qualifications * Previous experience supporting FEMA, DHS, or another federal civilian agency. * Experience securing AWS GovCloud and/or Azure Government environments. * Experience with vulnerability management, SIEM, endpoint security, and continuous monitoring technologies. * Experience working with Agile and DevSecOps engineering teams. * Familiarity with Zero Trust architecture and federal cloud security requirements. * One or more relevant certifications, such as CISSP, CAP/CGRC, Security+, CISM, CCSP, or equivalent cybersecurity certification., * Strong attention to detail and ability to maintain accurate, audit-ready security documentation. * Ability to manage multiple systems, security requirements, findings, and deadlines simultaneously. * Proactive approach to identifying and resolving cybersecurity risks. * Ability to translate federal cybersecurity requirements into actionable requirements for engineering and operations teams. * Strong collaboration skills and ability to work across cybersecurity, engineering, program management, and Government stakeholder organizations. Clearance Requirements * U.S. Citizenship. * Ability to obtain and maintain required DHS/FEMA suitability and security clearance/access requirements. Priority will be given to FEMA Public Trust Clearance or DHS Public Trust within the last 3 years, or to active/current Public Trust. ## Description * Support implementation and ongoing execution of the NIST Risk Management Framework (RMF) and DHS/FEMA security policies and procedures. * Develop, maintain, and update system security documentation, including System Security Plans (SSPs), Security Assessment Reports (SARs), Plans of Action and Milestones (POA&Ms), Contingency Plans, Configuration Management Plans, and related authorization artifacts. * Support Assessment and Authorization (A&A) activities for FEMA systems, applications, and cloud environments. * Maintain security documentation and evidence within applicable DHS/FEMA governance, risk, and compliance (GRC) systems. * Conduct and document security control assessments and support implementation and validation of NIST SP 800-53 security and privacy controls. * Track cybersecurity findings, vulnerabilities, POA&Ms, remediation activities, and risk acceptance through closure. * Review vulnerability scanning and security monitoring results from tools such as Tenable/Nessus, CrowdStrike, Elastic, and other DHS/FEMA-approved security platforms. * Coordinate with system administrators, cloud engineers, DevSecOps teams, application teams, and system owners to remediate vulnerabilities and configuration deficiencies. * Support continuous monitoring, including recurring security control reviews, vulnerability management, configuration compliance, and required reporting. * Review proposed system and infrastructure changes to identify cybersecurity impacts and ensure security requirements are incorporated throughout the system lifecycle. * Support compliance with applicable DHS security directives, FEMA policies, FISMA, FedRAMP, NIST guidance, and federal cybersecurity requirements. * Assist with incident response activities, security investigations, audit requests, and cybersecurity reporting as required. * Participate in security reviews, technical meetings, change management activities, and coordination with FEMA cybersecurity stakeholders. * Identify cybersecurity risks and provide practical recommendations for mitigation, remediation, or risk management. * Maintain audit-ready security documentation and supporting evidence. ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [DevSecOps: Injecting Security into Mobile CI/CD Pipelines](https://www.wearedevelopers.com/videos/273-devsecops-injecting-security-into-mobile-ci-cd-pipelines) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [DevSecOps culture](https://www.wearedevelopers.com/videos/783-devsecops-culture) - [What makes Cybersecurity different for critical infrastructure?](https://www.wearedevelopers.com/videos/571-what-makes-cybersecurity-different-for-critical-infrastructure) - [DevSecOps: Security in DevOps](https://www.wearedevelopers.com/videos/36-devsecops-security-in-devops) ## Related Articles - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing)