> Markdown version of [/jobs/ext/3144281-information-security-analyst-lead](https://www.wearedevelopers.com/jobs/ext/3144281-information-security-analyst-lead). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Information Security Analyst Lead - **Company:** ESimplicity, Inc. - **Location:** Fort Meade, MD, United States (Remote available) - **Experience:** Expert - **Contract:** Permanent contract - **Skills:** Agile Methodology, Artificial Intelligence, Amazon Web Services, Audit Trail, Microsoft Azure, Cloud Computing, Cloud Computing Security, Cyber Security, Information Systems, Databases, Database Applications, Information Systems Security Architecture Professional, Systems Development Life Cycle, Security Support Provider Interface, Security Information and Event Management, Web Applications, Data Processing, Information Technology, Cybercrime, Splunk, Devsecops, Plan of Action and Milestones, Vulnerability Analysis - **Published:** September 29, 2026 - **Apply:** https://www.juju.com/job/16_5efc08e71 ## About the Role * Minimum of eight years of experience in cybersecurity architecture, cloud security, DevSecOps, security engineering, or a related technical field. Bachelor's degree in Computer Science, Information Systems, Engineering, or a related field preferred but not required. * Must hold a current Security+ certification. * Experience designing security "baked-in" to architectures including Cloud and IaC, applications, web applications, data processing, data-centric applications, AI/ML, and CI/CD pipelines. * A proven track record * Familiarity with Agile methodologies. * Working knowledge of AWS or Azure security tools, their functionality, and their purpose. * Ability to assist customers with defining appropriate management processes (responsible for documenting application criticality, privacy, and security impact analysis). * Knowledge of hardening standards (DISA STIG, CIS). * Experience with the NIST Risk Management Framework, NIST 800-53 rev5, and NIST 800-171. * Active secret clearance. Desired Qualifications: * Federal Government contracting work experience. * Experience as an ISSO for the DoD. * Highly preferred industry certifications such as CISSP, CEH, GIAC, etc. * Experience with Security Information and Event Management (SIEM) systems (e.g., Splunk). ## Description We are seeking an Information Security Analyst who is responsible for providing security support services while meeting security control compliance requirements for a portfolio of systems at various states of maturity and modernization. This role will provide support for continuously monitoring the cybersecurity posture of systems to secure against cyber threats. The primary responsibility is to facilitate security tool and control implementation, security tool usage, and ensure tools and controls remain compliant and configured properly, all the while ensuring a successful program Authorization to Operate (ATO). Additionally, the expectation is to take ownership of communication and visualization of security issues, especially where coordination between product teams, information owners, engineering, and infrastructure staff is necessary for remediation. The candidate will own coordination and response to the agency's security-related inquiries, compliance with agency policy, security controls, and the maintenance of security documentation and artifacts. You will function as the primary liaison to provide timely and accurate responses to security-related data calls (System Security & Compliance Status, Vulnerability, and Compliance scanning issues) and provide security guidance throughout the system development lifecycle. This role requires interfacing with multiple stakeholders through multiple touchpoints weekly., * Work closely with the Product Owners, ISSOs, engineering and infrastructure staff to provide guidance on implementation if security policies, standards, and procedures * Analyze new or updated security requirements, collaborate with stakeholders, and develop responses that are clear and accurate. * Support the review and update of ATO artifacts such as System Security Plans, Information System Contingency Plans, Configuration and Change Management Plans, Incident Response Plans, Privacy Impact Analysis, and more. * Interpret security risk assessment, review security scan results, assess security vulnerabilities and support the development and remediation of vulnerability and compliance issues via Plan of Action and Milestones (POA&Ms). * Support the development of implementation and design documentation relating to security feature implementation. * Work with engineering and infrastructure personnel to document remediation for vulnerabilities and non-compliance issues. * Analyze and interpret agency security requirements and provide governance communication to non-security personnel. * Collaborate with product teams, ISSOs and other stakeholders in support of continuous monitoring and ATO efforts. * Conducts vulnerability assessments and monitors systems, networks, databases and Web-based assets for potential system breaches. Recommends and takes the lead on implementing changes to enhance security systems, prevent unauthorized access, and help mitigate security vulnerabilities. * Responds to alerts from information security tools. Reports, investigates, and resolves higher level security incidents. * Responds to security tool outages, degradations in service, tune security rules and alerts, and setup/maintain security tool dashboards and reporting. * Research security trends, new methods, and techniques used in unauthorized access of data to preemptively eliminate the possibility of system breach. Ensures compliance with regulations and privacy laws. Conducts research to identify new attack vectors. * Educates and communicates security requirements and procedures to all users and new employees. * Recommend process improvements to the information system for risk mitigation. * Applies iterative security automation to all program aspects increasing overall security posture iteratively and never accepts the status quo. * Provide audit log review in Splunk, present any findings to ISSO, and plan for any investigation or remediation activities. * Periodic user and privileged access reviews. ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [DevSecOps: Injecting Security into Mobile CI/CD Pipelines](https://www.wearedevelopers.com/videos/273-devsecops-injecting-security-into-mobile-ci-cd-pipelines) - [Our journey with Spring Boot in a microservice architecture](https://www.wearedevelopers.com/videos/511-our-journey-with-spring-boot-in-a-microservice-architecture) - [Kubernetes and Microservices with Multi-Model Databases](https://www.wearedevelopers.com/videos/382-kubernetes-and-microservices-with-multi-model-databases) - [Organizational Change Through The Power Of Why - DevSecOps Enablement](https://www.wearedevelopers.com/videos/478-organizational-change-through-the-power-of-why-devsecops-enablement) - [DevSecOps culture](https://www.wearedevelopers.com/videos/783-devsecops-culture) ## Related Articles - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again](https://www.wearedevelopers.com/magazine/751-how-we-built-a-worry-free-system-that-runs-for-10-years-and-what-we-d-do-again)