Senior Information Security Analyst DoS CSS
- Discuss this with your agent
- Open in Claude
- Open in ChatGPT
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Role details
Tech stack
+3 more
Job description
Assessments; document results and lessons learned; update CP, ISCP, IRP, and CMP as needed.Perform Security Impact Analyses for hardware, software, patch, and configuration changes; participate in CCB/ECM; contribute to the Quarterly Configuration and Change Impact Summary.Coordinate incident reporting and documentation with the SOC and system owners; reflect outcomes in risk posture and POA&Ms.Direct system-specific security operations contractors to obtain evidence and implement remediation; validate completion before POA&M closure.Support audits and data calls (OIG, GAO, CISA, HVA, BOD, OMB, CDM) and maintain the Audit and Data Call Response Package for assigned systems.Provide day-to-day direction and quality review for Information Assurance Analysts supporting the portfolio.Required QualificationsSeven (7)+ years of information security experience, including four (4)+ years as an ISSO or in an equivalent A&A role for federal information systems.Demonstrated experience authoring SSPs, MANTECH seeks a motivated and mission-driven Senior Cyber Security Analyst to join our team in Springfield, VA. This role supports critical defensive cyber operations through tar…
- 11 days ago
Requirements
POA&Ms, contingency plans, and supporting authorization packages under NIST SP 800-37 / SP 800-53 Rev. 5.One of: CISSP, CISM, CGRC/CAP, or CISA (DoD 8140/8570 IAM Level II or higher).Active, final SECRET security clearance; U.S. citizenship.Experience with an enterprise GRC tool and with interpreting vulnerability scan results.Strong technical writing and stakeholder coordination skills.Preferred QualificationsDepartment of State (DT/CA/CST) experience; ArchAngel and iPost proficiency.Experience with cloud or hybrid authorization boundaries and FedRAMP inheritance.Experience conducting NIST SP 800-34 contingency plan tests and NIST SP 800-63 Digital Identity Risk Assessments.Security+ CE, CySA+, or CCSP in addition to the required certification.Technical SkillsNIST SP 800-37 Rev. 2, 800-53/53A Rev. 5, 800-60, 800-34, 800-61, FIPS 199/200; CISA BODs and KEV.GRC platforms (ArchAngel or equivalent), iPost or equivalent, POA&M lifecycle management.Reading Tenable/Nessus, Wiz, and STIG output; understanding of patch and configuration management.Visio diagramming; advanced Word/Excel; SharePoint/Teams collaboration.Security ClearanceActive, final SECRETEducationBachelor’s degree in Computer Science, Information Technology, Cybersecurity, or a related field, or an additional four (4) years of directly relevant experience in lieu of degree.Remote/Hybrid/On-site and any other relevant work-environment requirementRemote. Duties are performed remotely; the selected candidate must reside within the National Capital Region (NCR). The Government does not furnish equipment; OneZero provides the laptop and collaboration tools. Position requires an OpenNet account, DoS PIV badge, multifactor authentication, and adherence to DoS SBU/CUI handling requirements. Local travel within the National Capital Region; minimal other travel.Contract:U.S. Department of State, Bureau of Diplomatic Technology (DT), Enterprise Applications (EA), Consular Systems and
Benefits & conditions
We are an employee-centric company that truly values our team members and the contributions they make to our customers and the missions they support. We pride ourselves on being forward-leaning thinkers and on building teams that are, and continue to be, technically proficient across a broad range of cyber mission areas. OneZero full-time employees receive a highly competitive benefits package, including health, dental, vision, and life insurance, a 401(k) with company matching, paid time off and holidays, an employee referral program, and educational assistance. Additional details are available on our website: https://www.onezerollc.com/careers/ Position Title: Senior Information Security AnalystLocation: Remote; must reside within the National Capital Region (NCR).Clearance: SecretWork Schedule: Full-time, 40 hours per week. Must be available during Department core hours of 9:00 a.m. - 3:00 p.m. ET, Monday - Friday, and flex working hours as needed to meet CST day-to-day and emergent requirements. No work is performed on Federal holidays or during Government closures.Employment Type: Full-Time, Exempt (W-2), contingent upon Call Order award Position SummaryThe Senior Information Security Analyst serves as ISSO of record for an assigned portfolio of approximately 6-8 Moderate-baseline consular systems. The Senior Analyst owns each system’s authorization package and continuous monitoring cadence end to end, leads the system’s triennial RMF cycle, directs technical remediation by system operations teams, and provides day-to-day direction to Information Assurance Analysts supporting the portfolio.Key ResponsibilitiesServe as ISSO of record and primary cybersecurity point of contact for an assigned portfolio of approximately 6-8 Moderate-baseline systems.Execute RMF Steps 1-3 for assigned systems: categorization with CIA justification, baseline and overlay selection, tailoring rationale, Inherited Controls Matrix, SSP and Security Control Implementation Statements, Evidence
Apply for this position
This job is hosted externally. Click below to view the full posting and apply.
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Good distractions
Talks and stories from around this role — technically off-topic, practically not.
Moments
Explore playlistsVideos
See allRelated articles
See all
9 Ways to Make Money Hacking
The Overflow: Security and Privacy
Walking Into The Era of Supply Chain Risks
Is Software Engineering Over-Saturated?