About the job
Senior System Technical Security Analyst
Location of Services: Herndon, VA 20171 (Remote)
Employment Type: Full-time with Benefits
Our client is dedicated to facilitating the FedRAMP and FISMA authorizations for new Cloud Products and third-party applications across various cloud environments. This initiative necessitates comprehensive security testing and assessment support, along with the creation and maintenance of essential security documentation, such as the System Security Plan (SSP), plans, and procedures, along with continuous monitoring activities. This position primarily offers remote work post-pandemic.
In this senior-level role, you will act as a hands-on technical security analyst, collaborating closely with build, operations, and security engineering teams to address security issues and enhance information gathering. You will be responsible for developing and managing the Plan of Action and Milestones (POAM) for multiple environments, executing vulnerability scans, analyzing results, and documenting security control implementations within the SSP.
Your responsibilities will extend to assisting with security assessments and continuous monitoring for various CLIENT environments, including corporate, commercial regulated, FedRAMP, DOD, and international sectors.
The Technical Security Analyst will maintain the POAM for both commercial and corporate environments, analyze vulnerability scans, develop metrics and trends regarding vulnerabilities, and support the FedRAMP or FISMA authorization processes, including preparation for operations and build teams, along with updating technical documentation as needed. This role requires a deep understanding of security policies, execution of vulnerability scans, evaluation of scan data, and control implementations, leading to informed recommendations and conducting security impact analyses for environmental changes. Daily communication with security, engineering, build/development, and operations teams is essential, as is the ability to interpret and document data gathering results.
Key Responsibilities:
- Configuration, execution, and analysis of vulnerability scans
- Ability to interpret and assess network diagrams and drawings using Visio
- Identify and assess the Cloud System state, including vulnerabilities, RMF package status/accreditation model, PPS compliance, and patching, along with Cyber Security Vulnerability Assessments (CSVA) mechanisms
- Familiarity with current FedRAMP, DOD, and NIST Security controls and technologies, particularly around vulnerability management capabilities
- Understanding of enterprise operating environments, including security posture, application environments, and associated security compliance measures

