Junior Information Security Analyst assisting federal clients at OCT Consulting with NIST security assessments and risk analyses. Responsible for executing hands-on security control assessments and recommending process improvements.
Responsibilities
Execute the hands-on manual technical NIST SP 800-53 security control assessments including any overlays (e.g. high value asset, artificial intelligence, critical software, FedRAMP, etc.)
Assess the impacts of new laws, regulations, policies, and guidance on client Security Assessment requirement initiatives and advise on recommended process changes. Additionally review current client policies, guidance, manuals, and supporting tools to recommend updates and improvements, and assist with the implementation of any new guidelines
Recommend process improvements and automated approaches to support testing methodologies, establishing streamlined/agile approaches for Security Controls Assessments
Maintain key assessment package templates to ensure compliance with current/emerging federal guidance and lessons learned
Execute security controls assessments and provide training to ensure Government staff understand and can perform security control assessments
Provide subject matter expertise to incorporate threat modeling and hunting into the security control assessment process, improving the Government’s ability to proactively identify and mitigate risks
Identify, develop, and implement automation solutions that enhance the efficiency, accuracy, and timeliness of program operations. Evaluate current business processes, workflows, and system interactions to determine opportunities where automation—such as robotic process automation (RPA), workflow orchestration, data transformation tools, or other intelligent automation technologies—can reduce manual workload, eliminate redundancies, and improve mission outcomes
Requirements
Must be a U.S. Citizen
Bachelor’s degree in Cybersecurity, Information Systems, Computer Science, or related technical field
An associate degree plus 2 additional years of hands-on experience may substitute for a bachelor’s degree
1 to 3 years of relevant professional experience in information security, cyber risk management, network defense, or IT system administration with a security focus. Experience may include internships, co-op positions, or hands-on cybersecurity training
programs that demonstrate applied understanding of security principles.
CompTIA Security+ CE certification (or equivalent) required
Network+, CEH, or CAP certifications preferred
Excellent presentation and verbal communication skills
Ability to create accurate written work products by following Job Aids and document templates
Ability to work under pressure and tight timelines for multiple projects with positive attitude and flexibility
Knowledge of FISMA, NIST Special Publications, OMB, Risk Management Framework (RMF), and ISCM Plan development.
IT security knowledge with desired Professional Certifications from the International Information System Security Certification Consortium (ISC)2, the International Society for Automation (ISA), the Project Management Institute (PMI), CompTIA, or the SANS
Institute
Knowledge and experience with technology risk assessments covering Webservices, network appliances and software
Knowledge and experience of the IRS Enterprise Lifecycle and OneSDLC
Knowledge of System Interconnections to include virtual private network (VPN) and other encryption technologies
Knowledge and experience with cloud systems, CSPs, and FedRAMP requirements
Project management experience, experience in monitoring and overseeing multiple tasks concurrently
Knowledge/experience with Qmulos Q-Compliance, SharePoint, scanning tools, ServiceNow GRC, SPLUNK is preferred
Ability to pass a federal government background investigation; the investigation will involve a credit, fingerprint, and law enforcement agency check
Benefits
Medical, Dental, and Vision insurance
Retirement savings 401K plan provided by an industry leading provider with 3% employer contributions of the employee’s gross salary
Paid Time Off and Standard Government Holidays
Life Insurance, Short- and Long-Term disability benefits
Join is seeking a Senior Cybersecurity Analyst for a hybrid quality - focused squad. Responsible for incident response and digital forensics in cybersecurity.
Information Security Analyst developing documentation, managing security incidents, and maintaining information security practices. Engaging with internal teams and external suppliers while working in a hybrid environment.
Cybersecurity Analyst monitoring and responding to security threats in hybrid work environment. Collaborating across teams to enhance security and ensure compliance with standards.
Security Analyst at Aviso joining a cybersecurity team to mitigate threats across IT and Cloud. Responsible for investigations, implementing controls, and enhancing security posture.
IT Security Analyst responsible for monitoring and responding to security incidents. Collaborating with teams and ensuring effective incident response to maintain business continuity.
SOC Analyst Principal impacting national security in cyber at GDIT. Bring your cyber expertise and drive for innovation to a veteran - friendly workplace.
Information Security Analyst engaging in cyber security and governance risk compliance for Grupo BAUMINAS. Collaborating on security operations, incident response, and risk management processes.
Pleno Security Analyst protecting information assets by monitoring, incident management, and vulnerability oversight. Collaborating on compliance with internal policies and regulatory requirements.
Network and Security Analyst in Logicalis, aiding companies in digital transformation. Responsible for network monitoring and incident resolution, ensuring connectivity and security.