Information Systems Security Analyst (ISSA)

ZANTECH INC.
Reston, VA, United States
3 days ago
Apply on www.indeed.com
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience required
1 year minimum
Working hours
Regular working hours
Job source

Tech stack

Apple IOS Configuration Management Cyber Security Information Systems Firmware Identity and Access Management Software Vulnerability Management Information Technology Plan of Action and Milestones Vulnerability Analysis

Job description

  • Conduct information system security inspections, tests, and reviews of the Risk Management Framework (RMF) Information Assurance Package to ensure ANG DSS maintains an Authority to Operate (ATO). Update artifacts and information within the Enterprise Mission Assurance Support Service (eMASS) to validate Security Controls and Assessments. Develop Plan of Actions and Milestones (POAMs) for non-compliant items.
  • Maintain a formal information system security program, including systems security plans, cyber security policies, security control assessments, contingency plans, configuration management plans, incident response plans, plan of actions and milestones, risk management plans, vulnerability scanning, and/or vulnerability management plans.
  • Ensures software, hardware, and firmware comply with appropriate security configuration guidelines (e.g., security technical implementation guides /security requirement guides).
  • Ensures cybersecurity-related events or configuration changes that impact AF IT authorization or adversely impact the security posture are formally reported to the Authorizing Official (AO) and other affected parties, such as Information Owners (IOs) and stewards and AOs of interconnected IT.
  • Coordinates with the Air National Guard Readiness Center’s Risk Management Framework lead on eMASS related tasks.

Requirements

  • 1+ Years of experience working on ATOs for government systems
  • Ability to manage the Plan of Actions & Milestones (POA&M) documents associated with Information Systems.

  • Demonstrated on-the-job knowledge and experience of the Risk Management Framework (RMF) process and the National Institute of Standards and Technology (NIST) publications (specifically NIST 800-53 and NIST 800-37), including development and maintenance of associated certification and accreditation documentation.

  • Excellent writing, verbal communication, and time-management skills., + Bachelor’s Degree in Information Systems, Information Assurance Management, Computer Science, or related field.
  • (May be substituted for relevant work experience)
  • Certifications Required:

*

  • IAT Level II or IAM Level II DoD approved cybersecurity baseline certification, or higher.

Required Security Clearance:

  • US Citizenship and the ability to obtain and maintain an active Secret or higher clearance, per contract requirements.

Benefits & conditions

Our corporate motto represents our commitment to build long-term relationships with both our clients and our employees by providing the highest quality service in everything we do. We strive for excellence for our clients and for each other. We embrace the opportunity to hire individuals with new talents and fresh perspectives. Zantech offers competitive compensation, strong benefits, and a vacation package, as well as a fast-paced and exciting work environment. Come join our team!

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.indeed.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

1:53 min

Transitioning toward DevSecOps with dynamic scanning and secrets management

Christoph Ruggenthaler · LIVE

2:19 min

Orchestrating over-the-air firmware updates for vehicle modules

Denis Grahovac · World Congress 2021

2:25 min

Testing the AI generated Apple iOS Flashcards application

MIlan Todorović MIlan Todorović · World Congress 2026 Europe

4:11 min

Introduction to cloud-native application developer security

Micah Silverman · World Congress 2022

2:07 min

Summarizing critical actions for organizational cybersecurity compliance readiness

Matthew Brady Matthew Brady · World Congress 2026 Europe

2:20 min

Utilizing custom firmware for variable torque manipulation

Daniel Meilak Daniel Meilak +1 · World Congress 2026 Europe

Videos

See all

Related articles

See all