Information Security Analyst 3

Chags Health Information Technology LLC
Columbia, MD, United States
about 2 months ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Experienced
Experience required
3 years minimum
Working hours
Regular working hours
Job source

Tech stack

Microsoft Word Microsoft Excel Agile Methodology Amazon Web Services Software System Penetration Testing Microsoft Outlook Cloud Computing Cyber Security Information Systems Computer Networks Dynamic Host Configuration Protocol DevOps
+13 more
Domain Name System (DNS) Virtual Private Networks (VPN) Microsoft Office Routing Microsoft PowerPoint SAP (Applications) SonarQube Virtual Local Area Networks Web Applications Information Security Management System Devsecops Static Application Security Testing Dynamic Application Security Testing

Job description

Job Description: The Information Security Officer (ISO) will work closely with Project and Technical management to plan, design and implement Dynamic Application Security Testing (DAST) and/or Static Application Security Testing (SAST) security methodologies into the technical solution of a program within the Centers for Medicare and Medicaid Services (CMS). The ISO will be responsible for assuring all CMS security and privacy considerations and requirements are assessed, addressed and documented for the given application, designing the solution so that it passes the required Annual Security Assessment Testing (within CMS referred to ACT or Adaptive Capabilities Testing) and maintains the system Authority to Operate (ATO).

The primary responsibilities of the position include but are not limited to:

  • Promote a professional work ethic with the ability to meet commitments, scheduled timelines and take ownership of problems.
  • Lead, support and document all security incident response activities.
  • Perform annual security assessment audits (such as ACT, PenTest, etc.).
  • Perform Web Application Penetration and Continuous Diagnostic Monitoring (CDM) testing.
  • Mitigate and/or address the security specific vulnerabilities and document via Plan of Action and Milestones (POA&M).
  • Support ad hoc security requests from the customer and program management.
  • Conduct security impact assessments for new or existing architecture changes.

Requirements

Do you have experience in Vendor communication?, * 3+ years of experience with NIST and Federal security documentation.

  • Active CISSP or equivalent security related certification.
  • Capable of obtaining Level Five: Public Trust security clearance.
  • Proven experience with FISCAM and FedRAMP requirements.
  • Experience writing and maintaining security related documents, including the System Security Plan (SSP), Contingency Plan and Test (CP), Information System Risk Assessment (ISRA), Security Assessment Plan/Report (SAP/SAR) and the Privacy Impact Assessment (PIA).
  • Ability to resolve complex support issues by leveraging user forums, support forums, or opening support cases with vendors and following them to closure. Strong ability to find mitigation and alternative approaches.
  • Knowledge of current as well as emerging security threats.
  • Understanding of and experience with Agile Development and DevSecOps/DevOps.
  • Proven experience with Cloud Technologies (AWS)
  • Proven experience with Microsoft Office Tools (Outlook, Word, Excel, PowerPoint).

Desired Skills and Certifications:

  • Working experience within CMS including with CMS Information Systems Security and Privacy Policy (IS2P2), NIST 800-53, NIST 800-63, CMS Acceptable Risk Safeguards (ARS), CMS Risk Management Handbook (RMH) and CMS Federal Information Security Management Act (FISMA) Controls Tracking System (CFACTS).
  • Proven experience with Security tools such as Burp, SonarQube, AWS Security Tools
  • Proven experience with networking concepts, such as, DHCP, DNS, VLANs, Routing and VPNs

Benefits & conditions

Pulled from the full job description

  • Health insurance
  • 401(k) matching
  • Paid time off
  • Health savings account
  • Flexible spending account
  • Life insurance
  • Employee assistance program, * The actual salary offer will carefully consider a wide range of factors, including your skills, qualifications, experience, and location.
  • C-HIT offers Healthcare Benefits, Remote Working Options, Paid Time Off, PTO cash-out, Training/Certification opportunities, Healthcare Savings Account & Flexible Savings Account, Paid Life Insurance, Short-term & Long-term Disability, 401K Match, Employee Assistance Program, Paid Holidays, and much more perks and Voluntary benefits!
  • Employees of C-HIT shall, as an enduring obligation throughout their term of employment, adhere to all information security requirements as documented in company policies and procedures.

C-HIT, a CMMI Maturity Level 5 company, focuses on delivering information technology and professional services to Federal and State agencies.

“C-HIT is an EOE, including disability and veterans”

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on indeed.com

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

1:45 min

Transitioning from software development to security roles

Stefania Chaplin · WWC 2022

2:17 min

Mapping the maturity roadmap for scaled devops adoption

Dominik Krichbaum Dominik Krichbaum · WWC Europe 2026

2:04 min

Enhancing network privacy with routing fees and onion routing

Andreas M Antonopoulos · LIVE

1:15 min

Key lessons learned from implementing automated mobile DevSecOps

Moataz Nabil Moataz Nabil · LIVE

5:25 min

Shifting left and creating internal security champion programs

Vandana Verma Sehgal · LIVE

3:18 min

Scaling global network engineering through DevOps culture

Stuart Clark · LIVE

Videos

See all

Related articles

See all