Information Security Analyst IV

4 weeks ago


Annapolis Junction, United States eSimplicity Full time
Job DescriptionJob DescriptionDescription:

About Us

eSimplicity is a modern digital services company that delivers innovative federal and commercial IT solutions designed to improve the health and lives of millions of Americans while defending our national interests. Our solutions and services improve healthcare for millions of Americans, protect our borders, and defend our country on the battlefield by supporting the Air Force, Space Force, and Navy.


eSimplicity's people-centric approach aims to transform the American healthcare experience through innovative technologies. Our team’s experience spans various federal civilian customers on diverse projects across its core competencies. Our priority is safeguarding our community by leading the government’s cloud migration, developing artificial intelligence models to identify fraudulent Medicare claims, and accelerating access to data and insights.


Purpose of Scope:

We’re seeking an Information Security Analyst who is responsible for providing security support services while meeting security control compliance requirements for a portfolio of systems at various states of maturity and modernization. This role will provide support for continuously monitoring the cybersecurity posture of systems to secure against cyber threats. The primary responsibility is to facilitate security tool implementation, security tool usage, ensuring tools remain compliant and configured properly, all the while ensuring a successful program Authorization to Operate (ATO). Additionally, the expectation is to take ownership of communication and visualization of security issues especially where coordination between product teams, information owners, engineering and infrastructure staff is necessary for remediation. Owns coordination and response to the agency’s security related inquiries, compliance with agency policy, security controls, maintenance of security documentation and artifacts. Act as the primary liaison to provide timely and accurate responses to security related data calls (System Security & Compliance Status, Vulnerability and Compliance scanning issues). Provide subject matter expertise throughout all phases of the system development lifecycle. Interface with multiple stakeholders through multiple touchpoints weekly.


Responsibilities:

  • Work closely with the Product Owners, ISSOs, engineering and infrastructure staff to provide guidance on implementation if security policies, standards, and procedures
  • Analyze new or updated security requirements, collaborate with stakeholders, and develop responses that are clear and accurate.
  • Support the review and update of ATO artifacts such as System Security Plans, Information System Contingency Plans, Configuration and Change Management Plans, Incident Response Plans, Privacy Impact Analysis, and more.
  • Interpret security risk assessment, review security scan results, assess security vulnerabilities and support the development and remediation of vulnerability and compliance issues via Plan of Action and Milestones (POA&Ms).
  • Support the development of implementation and design documentation relating to security feature implementation.
  • Work with engineering and infrastructure personnel to document remediation for vulnerabilities and non-compliance issues.
  • Analyze and interpret agency security requirements and provide governance communication to non-security personnel.
  • Collaborate with product teams, ISSOs and other stakeholders in support of continuous monitoring and ATO efforts.
  • Conducts vulnerability assessments and monitors systems, networks, databases and Web-based assets for potential system breaches. Recommends and takes the lead on implementing changes to enhance security systems, prevent unauthorized access, and help mitigate security vulnerabilities.
  • Responds to alerts from information security tools. Reports, investigates, and resolves higher level security incidents.
  • Responds to security tool outages, degradations in service, tune security rules and alerts, and setup/maintain security tool dashboards and reporting.
  • Research security trends, new methods, and techniques used in unauthorized access of data to preemptively eliminate the possibility of system breach. Ensures compliance with regulations and privacy laws. Conducts research to identify new attack vectors.
  • Educates and communicates security requirements and procedures to all users and new employees.
  • Recommend process improvements to the information system for risk mitigation.
  • Applies iterative security automation to all program aspects increasing overall security posture iteratively and never accepts the status quo.
  • Provide audit log review in Splunk, present any findings to ISSO, and plan for any investigation or remediation activities.
  • Periodic user and privileged access reviews.


Requirements:

Required Qualifications:

  • Minimum of 7+ years related experience.
  • A bachelor's degree in computer science, Information Systems, Engineering, Business, or other related scientific or technical discipline. With six years of general information technology experience and at least four years of specialized experience, a degree is not required.
  • Familiarity with Agile Methodologies.
  • Working knowledge of AWS Security tools, their functionality, and purpose
  • Assist customer with defining appropriate change management processes (Responsible for documenting application criticality, privacy, and security impact analysis).
  • Knowledge of hardening standards (DISA STIG, CIS).
  • Understanding of NIST Risk Management Framework and NIST 800-53 rev5
  • Experience with CI/CD, defining security decision gates and DevSecOps
  • Know the difference between SAST, DAST, IAST, OAST tools and their functions, benefits, and weaknesses within CI/CD.
  • Understanding of business security practices and procedures; knowledge of current security tools available; hardware/software security implementation; different communication protocols; encryption techniques/tools; familiarity with commercial products; and current Internet technology.
  • Understands continuous automated security practices applied to data and application engineering teams.
  • Prior experience managing systems in AWS cloud environments, familiarity with AWS Tools and Services.
  • Experience with designing security “baked-in” to any architecture: Cloud and IaC, Applications, Web application, Data Processing, Data Centric Applications, AI/ML, CICD Pipelines; seeks automation driven designs.
  • Demonstrated work experience with the following: computer networking, cryptography, security engineering and architecture, vulnerability assessments, or operating systems required.
  • Broad experience using cloud services, Linux systems, and Development/Data engineering core tools Github, GitHub Actions, Security Tools, etc.
  • Demonstrated working knowledge of vulnerability and compliance scanning tools.
  • Understands how to assess vulnerabilities and provide recommendations regardless of first-hand knowledge of the application or system.
  • Proven ability to work effectively both independently and/or in a team setting.
  • Must possess strong analytical and problem-solving abilities; and strong critical-thinking skills in complex communication environments.
  • Strong attention to detail. Required to manage/follow-through of multiple independent tasks, dependencies across intra/inter-project teams.
  • Excellent organizational and time-management skills in a fast-paced environment.
  • Excellent customer service skills with the ability to deal tactfully, confidently, and ethically with both internal and external customers.
  • Experience with Government Agency Security Assessment Process in support of maintaining and/or establishing an ATO and the appropriate security boundary.
  • Experience with Atlassian Jira & Confluence.
  • Excellent command of written and spoken English.
  • Possess secret clearance.

Desired Qualifications:

  • Federal Government contracting work experience.
  • Experience as an ISSO for DoD.
  • Highly preferred industry certification such as the CISSP, CEH, GIAC, etc.
  • Experience with Security Information and Event Management (SIEM) systems (i.e Splunk).

Location:
Onsite - Fort Meade, MD. Expected hours are 9:00 AM to 5:00 PM Eastern unless otherwise directed by your manager.

Occasional travel for training and project meetings. It is estimated to be less than 5% per year.


Benefits:

We offer a highly competitive salary, full healthcare benefits, performance bonus, and a flexible leave policy.


Equal Employment Opportunity:

eSimplicity is an equal opportunity employer. All qualified applicants will receive consideration for employment without regard to race, religion, color, national origin, gender, age, status as a protected veteran, sexual orientation, gender identity, or status as a qualified individual with a disability.




  • Annapolis, Maryland, United States OPS Consulting, LLC Full time

    OPS Consulting, LLC is in search of a seasoned Senior Information Security Analyst to provide expertise in safeguarding significant federal information systems/applications.Position Overview:The Senior Information Security Analyst will be responsible for proposing, coordinating, implementing, and enforcing security policies, standards, and methodologies for...


  • Annapolis Junction, Maryland, United States EMTAK LLC Full time

    Position OverviewThe Level 2 Cybersecurity Systems Officer is responsible for ensuring the integrity and security of information systems. This role involves a variety of critical tasks aimed at safeguarding assets from both intentional and unintentional threats.Key ResponsibilitiesExecute necessary protocols to maintain the security of information systems...


  • Annapolis, Maryland, United States ARSIEM Corporation Full time

    About ARSIEM Corporation: At ARSIEM Corporation, we are dedicated to fostering a dependable partnership with our governmental clients. We provide assistance to various agencies within the United States Government. Our team is composed of seasoned professionals committed to delivering exceptional support. As the demand for our services increases, we remain...


  • Annapolis, United States Marriott Full time

    Job Number 24150916 Job Category Information Technology Location Marriott International HQ, 7750 Wisconsin Avenue, Bethesda, Maryland, United States Schedule Full-Time Located Remotely? Y Relocation? N Position Type Management JOB SUMMARY The Application Security Analyst will assist in monitoring and assessing the security of web applications under the...


  • Annapolis Junction, United States IMG Information Management Group, Inc. Full time

    Opportunity: IMG is seeking an experienced Information Systems Security Engineeer (ISSE) to support our mission-vital customer in Annapolis Junction, MD. As a Information Systems Security Engineer/ISSE, you will leverage your technical expertise by reviewing technical security assessments of cloud-based and physical computing environments to identify points...

  • Program Analyst

    2 months ago


    Annapolis Junction, Maryland, United States Transportation Security Administration Full time

    This Program Analyst position is located Operations Support (SO), Enrollment Services and Vetting Program (ESVP), Vetting Programs Branch, Transportation Security Administration, Department of Homeland Security (DHS).Duties include but are not limited to:Applies a variety of quantitative and qualitative analytical and evaluative methods to assess program...


  • Annapolis, United States iNovex Information Systems Full time

    We're searching for talented individuals who provide intelligence, engineering, and mission management expertise for the Government. This program will maximize the effectiveness and efficiency of our country's most important missions both at home and abroad. If you are ready to support a high-performing team that truly makes a difference, then come join...


  • Annapolis, United States Quantum Strides LLC Full time

    About the job Information Security Platform Administrator Job Description: Scope of Work: 1. The purpose of this position is to serve at the primary technical support lead that actively participates in the planning and design, installation, administration, operations, and day-to-day daily activities of multiple SAAS platforms as noted in the offeror &...

  • Exploitation Analyst

    2 months ago


    Annapolis Junction, United States BlueHalo Full time

    At BlueHalo our analysts provide actionable intelligence. We quickly convert customer requirements into real hardware, software, firmware, and mechanical solutions in weeks, not years. With an organizational structure and design processes tailored to quick reaction, our process identifies risks that would prevent delivery and implements mitigation strategies...


  • Annapolis Junction, United States EverWatch Full time

    Overview EverWatch is a government solutions company providing advanced defense, intelligence, and deployed support to our country’s most critical missions. We are a full-service government solutions company. Harnessing the most advanced technology and solutions, we strengthen defenses and control environments to preserve continuity and ensure...


  • Annapolis Junction, Maryland, United States BAE Systems Full time

    Job Description Provides support for a program, organization, system, or enclave's information assurance program. Provides support for proposing, coordinating, implementing, and enforcing information systems security policies, standards, and methodologies. Maintains operational security posture for an information system or program to ensure information...


  • Annapolis Junction, United States Omega Enterprise Solutions, LLC Full time

    Job DescriptionJob DescriptionInformation System Security Engineer (ISSE)Omega Enterprise Solutions is a Maryland-based, Service-Disabled Veteran-Owned Small Business (SDVOSB) with a special focus on the U.S. Department of Defense (DoD) and Intelligence Community (IC) mission and enabling technologies. We are building a team with shared values and a passion...


  • Annapolis Junction, United States Omega Enterprise Solutions, LLC Full time

    Job DescriptionJob DescriptionInformation System Security Engineer (ISSE)Omega Enterprise Solutions is a Maryland-based, Service-Disabled Veteran-Owned Small Business (SDVOSB) with a special focus on the U.S. Department of Defense (DoD) and Intelligence Community (IC) mission and enabling technologies. We are building a team with shared values and a passion...


  • Annapolis Junction, United States Independent Software Full time

    Job DescriptionJob DescriptionWhat you will be doing!As an Information System Security Officer, you will provide support for a program, organization, system, or enclave’s information assurance program. Provides support for proposing, coordinating, implementing, and enforcing information systems security policies, standards, and methodologies. Maintains...


  • Annapolis Junction, Maryland, United States ManTech Full time

    Secure Our Nation, Ignite Your FutureManTech is seeking a highly motivated and customer-oriented Information Systems Security Specialist to join our team. This is an onsite position in the Annapolis Junction, MD area.Key Responsibilities:Participate as a security engineer representative on teams for the design, development, implementation, and integration of...


  • Annapolis Junction, Maryland, United States M.C. Dean Full time

    Information Systems Security OfficerCore Responsibilities:Support the information assurance initiatives of the organization.Establish and uphold security policies and standards for information systems.Ensure the operational security integrity of information systems.Assist in the assessment of security solutions for classified data handling.Oversee the...


  • Annapolis Junction, Maryland, United States Lockheed Martin Full time

    Position Overview:This role may qualify for a sign-on incentive for external candidates.Company Mission: At Lockheed Martin Rotary and Mission Systems, we prioritize innovation and ethical practices. We are committed to upholding the highest standards of integrity, believing that with the right approach, we can achieve remarkable outcomes. Lockheed Martin...


  • Annapolis Junction, Maryland, United States BAE Systems Full time

    Job Description The Information Systems Security Engineer (ISSE) shall perform, or review, technical security assessments of computing environments to identify points of vulnerability, non-compliance with established Information Assurance (IA) standards and regulations, and recommend mitigation strategies.Validates and verifies system security requirements...


  • Annapolis Junction, United States Peterson Technologies Full time

    Job DescriptionJob DescriptionPeterson Technologies has been the premier resource for mission-critical solutions through detailed analysis, strategic insight, extensive operational experience, and technical expertise. Today, we provide leading-edge data, network security software, and expert guidance to reduce exposure to information theft and augment...


  • Annapolis Junction, Maryland, United States Peraton Full time

    Position Title: Senior Information Systems Security Engineer (ISSE)Key Responsibilities:- Act as a Senior ISSE on the NiFi initiative, extending beyond standard ISSO responsibilities.- Integrate Information Assurance principles into systems utilized in operational settings.- Assist in the formulation of security architectures and foster trusted relationships...