> Markdown version of [/jobs/ext/3129119-senior-information-security-analyst-dos-css](https://www.wearedevelopers.com/jobs/ext/3129119-senior-information-security-analyst-dos-css). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Senior Information Security Analyst DoS CSS - **Company:** OneZero Solutions - **Location:** Washington, DC, United States - **Experience:** Expert - **Salary:** $107,900.0 - $195,050.0 - **Contract:** Permanent contract - **Skills:** Microsoft Word, Microsoft Excel, Cascading Style Sheets (CSS), Collaborative Software, Cyber Security, Multi-Factor Authentication, Federal Information Processing Standards (FIPS), Identity and Access Management, Microsoft SharePoint, Enterprise Software Applications, Information Technology, Nessus, Cyber Warfare, Plan of Action and Milestones, Vulnerability Analysis - **Published:** September 28, 2026 - **Apply:** https://www.careerjet.com/jobad/usdc05bedad954ec00d68da76b121521b3 ## About the Role POA&Ms, contingency plans, and supporting authorization packages under NIST SP 800-37 / SP 800-53 Rev. 5.One of: CISSP, CISM, CGRC/CAP, or CISA (DoD 8140/8570 IAM Level II or higher).Active, final SECRET security clearance; U.S. citizenship.Experience with an enterprise GRC tool and with interpreting vulnerability scan results.Strong technical writing and stakeholder coordination skills.Preferred QualificationsDepartment of State (DT/CA/CST) experience; ArchAngel and iPost proficiency.Experience with cloud or hybrid authorization boundaries and FedRAMP inheritance.Experience conducting NIST SP 800-34 contingency plan tests and NIST SP 800-63 Digital Identity Risk Assessments.Security+ CE, CySA+, or CCSP in addition to the required certification.Technical SkillsNIST SP 800-37 Rev. 2, 800-53/53A Rev. 5, 800-60, 800-34, 800-61, FIPS 199/200; CISA BODs and KEV.GRC platforms (ArchAngel or equivalent), iPost or equivalent, POA&M lifecycle management.Reading Tenable/Nessus, Wiz, and STIG output; understanding of patch and configuration management.Visio diagramming; advanced Word/Excel; SharePoint/Teams collaboration.Security ClearanceActive, final SECRETEducationBachelor's degree in Computer Science, Information Technology, Cybersecurity, or a related field, or an additional four (4) years of directly relevant experience in lieu of degree.Remote/Hybrid/On-site and any other relevant work-environment requirementRemote. Duties are performed remotely; the selected candidate must reside within the National Capital Region (NCR). The Government does not furnish equipment; OneZero provides the laptop and collaboration tools. Position requires an OpenNet account, DoS PIV badge, multifactor authentication, and adherence to DoS SBU/CUI handling requirements. Local travel within the National Capital Region; minimal other travel.Contract:U.S. Department of State, Bureau of Diplomatic Technology (DT), Enterprise Applications (EA), Consular Systems and ## Description Assessments; document results and lessons learned; update CP, ISCP, IRP, and CMP as needed.Perform Security Impact Analyses for hardware, software, patch, and configuration changes; participate in CCB/ECM; contribute to the Quarterly Configuration and Change Impact Summary.Coordinate incident reporting and documentation with the SOC and system owners; reflect outcomes in risk posture and POA&Ms.Direct system-specific security operations contractors to obtain evidence and implement remediation; validate completion before POA&M closure.Support audits and data calls (OIG, GAO, CISA, HVA, BOD, OMB, CDM) and maintain the Audit and Data Call Response Package for assigned systems.Provide day-to-day direction and quality review for Information Assurance Analysts supporting the portfolio.Required QualificationsSeven (7)+ years of information security experience, including four (4)+ years as an ISSO or in an equivalent A&A role for federal information systems.Demonstrated experience authoring SSPs, MANTECH seeks a motivated and mission-driven Senior Cyber Security Analyst to join our team in Springfield, VA. This role supports critical defensive cyber operations through tar… + 11 days ago ## Related Videos - [Developing the Rich Text Editor for DeepL.com](https://www.wearedevelopers.com/videos/1172-developing-the-rich-text-editor-for-deepl-com) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [What makes Cybersecurity different for critical infrastructure?](https://www.wearedevelopers.com/videos/571-what-makes-cybersecurity-different-for-critical-infrastructure) - [DevSecOps culture](https://www.wearedevelopers.com/videos/783-devsecops-culture) ## Related Articles - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [The Overflow: Security and Privacy](https://www.wearedevelopers.com/magazine/715-the-overflow-security-and-privacy) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks) - [Is Software Engineering Over-Saturated?](https://www.wearedevelopers.com/magazine/418-is-software-engineering-over-saturated) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities)