> Markdown version of [/jobs/ext/3093573-information-security-analyst](https://www.wearedevelopers.com/jobs/ext/3093573-information-security-analyst). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Information Security Analyst - **Company:** OneZero Solutions - **Location:** Washington, DC, United States (Remote available) - **Experience:** Expert - **Salary:** $76,960.0 - **Contract:** Permanent contract - **Skills:** Microsoft Word, Microsoft Excel, Configuration Management, Collaborative Software, Cyber Security, Information Systems, Multi-Factor Authentication, Federal Information Processing Standards (FIPS), Identity and Access Management, Microsoft Visio, Microsoft SharePoint, Information Technology, Nessus, RSA Archer Platform, Plan of Action and Milestones, Vulnerability Analysis - **Published:** September 26, 2026 - **Apply:** https://www.dice.com/job-detail/0155499b-172d-449a-b806-3c6f7ae3f9a0 ## About the Role * Seven (7)+ years of information security experience, including four (4)+ years as an ISSO or in an equivalent A&A role for federal information systems. * Demonstrated experience authoring SSPs, POA&Ms, contingency plans, and supporting authorization packages under NIST SP 800-37 / SP 800-53 Rev. 5. * One of: CISSP, CISM, CGRC/CAP, or CISA (DoD 8140/8570 IAM Level II or higher). * Active, final SECRET security clearance; U.S. citizenship. * Experience with an enterprise GRC tool and with interpreting vulnerability scan results. * Strong technical writing and stakeholder coordination skills., * Department of State (DT/CA/CST) experience; ArchAngel and iPost proficiency. * Experience with cloud or hybrid authorization boundaries and FedRAMP inheritance. * Experience conducting NIST SP 800-34 contingency plan tests and NIST SP 800-63 Digital Identity Risk Assessments. * Security+ CE, CySA+, or CCSP in addition to the required certification. Technical Skills * NIST SP 800-37 Rev. 2, 800-53/53A Rev. 5, 800-60, 800-34, 800-61, FIPS 199/200; CISA BODs and KEV. * GRC platforms (ArchAngel or equivalent), iPost or equivalent, POA&M lifecycle management. * Reading Tenable/Nessus, Wiz, and STIG output; understanding of patch and configuration management. * Visio diagramming; advanced Word/Excel; SharePoint/Teams collaboration. Security Clearance Active, final SECRET Education Bachelor's degree in Computer Science, Information Technology, Cybersecurity, or a related field, or an additional four (4) years of directly relevant experience in lieu of degree. Remote/Hybrid/On-site and any other relevant work-environment requirement Remote. Duties are performed remotely; the selected candidate must reside within the National Capital Region (NCR). The Government does not furnish equipment; OneZero provides the laptop and collaboration tools. Position requires an OpenNet account, DoS PIV badge, multifactor authentication, and adherence to DoS SBU/CUI handling requirements. Local travel within the National Capital Region; minimal other travel. ## Description The Senior Information Security Analyst serves as ISSO of record for an assigned portfolio of approximately 6-8 Moderate-baseline consular systems. The Senior Analyst owns each system's authorization package and continuous monitoring cadence end to end, leads the system's triennial RMF cycle, directs technical remediation by system operations teams, and provides day-to-day direction to Information Assurance Analysts supporting the portfolio., * Serve as ISSO of record and primary cybersecurity point of contact for an assigned portfolio of approximately 6-8 Moderate-baseline systems. * Execute RMF Steps 1-3 for assigned systems: categorization with CIA justification, baseline and overlay selection, tailoring rationale, Inherited Controls Matrix, SSP and Security Control Implementation Statements, Evidence Index, and Implementation Readiness Review. * Develop and maintain PIA, DIRA, ISA/MOU, Security Assessment Plan, POA&M, SIA, system inventory, IRP, CP/ISCP, CP Test report, and CMP for assigned systems; ensure CMPs are delivered into the GRC tool. * Set up and support Security Control Review Meetings and demos, collect and validate artifacts requested by the SCA, attend A&A Findings Meetings, and support remediation validation(RMF Step 4). * Maintain authoritative POA&Ms in theGRC tool (monthlyupdates and within 5 business days of status changes) with realistic milestones, accurate risk levels, and closure evidence attached (RMF Step 6). * Review iPost scores weekly; coordinate remediation with system and application teams; track and report findings open more than 30 days. * Review vulnerability, KEV, CVE, and STIG results within 5 business days; drive critical and high remediation within Department and BOD timelines; document in POA&Ms. * Conduct annual Contingency Plan tests and Annual Control Assessments; document results and lessons learned; update CP, ISCP, IRP, and CMP as needed. * Perform Security Impact Analyses for hardware, software, patch, and configuration changes; participate in CCB/ECM; contribute to the Quarterly Configuration and Change Impact Summary. * Coordinate incident reporting and documentation with the SOC and system owners; reflect outcomes in risk posture and POA&Ms. * Direct system-specific security operations contractors to obtain evidence and implement remediation; validate completion before POA&M closure. * Support audits and data calls (OIG, GAO, CISA, HVA, BOD, OMB, CDM) and maintain the Audit and Data Call Response Package for assigned systems. * Provide day-to-day direction and quality review for Information Assurance Analysts supporting the portfolio. ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Developing the Rich Text Editor for DeepL.com](https://www.wearedevelopers.com/videos/1172-developing-the-rich-text-editor-for-deepl-com) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [What makes Cybersecurity different for critical infrastructure?](https://www.wearedevelopers.com/videos/571-what-makes-cybersecurity-different-for-critical-infrastructure) - [One Pipeline, Three Regulator - SBOM Compliance for the Developer](https://www.wearedevelopers.com/videos/100169-one-pipeline-three-regulator-sbom-compliance-for-the-developer) - [Cyber Security: Small, and Large!](https://www.wearedevelopers.com/videos/259-cyber-security-small-and-large) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again](https://www.wearedevelopers.com/magazine/751-how-we-built-a-worry-free-system-that-runs-for-10-years-and-what-we-d-do-again) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [The Overflow: Security and Privacy](https://www.wearedevelopers.com/magazine/715-the-overflow-security-and-privacy) - [Fully Remote Software Engineer Jobs](https://www.wearedevelopers.com/magazine/447-fully-remote-software-engineer-jobs) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed)