System Technical Security Analyst

4 months ago


Herndon, United States FSR Inc Full time
Company Description

Entrusted by companies with challenging Cyber Security and IT data management recruiting needs, Flex Staffing Resources identifies exceptional talent and cutting edge companies and brings them together.

Job Description

System Technical Security Analyst

Location of Services: Herndon, VA 20171 (Remote)

Employment Type: FTE + Benefits

Client is supporting the FedRAMP and FISMA authorization(s) of new Cloud Products and 3rd Party Applications into our various cloud environments. This effort requires security testing/assessment support, the knowledge/development of the appropriate security documentation (i.e., System Security Plan (SSP), plans and procedures), and ongoing continuous monitoring activities. This position is majority remote (post-pandemic).

This role serves as a "hands-on" senior-level technical security analyst responsible for interfacing with the build, operations and security engineering teams on security issues and information gathering; creating and managing the Plan of Action and Milestones (POAM) for multiple environments, configuration/execution/analysis of vulnerability scans, gathering the security control implementations information for the technical controls and documenting their implementation in the SSP.

Additionally, this role will assist with the security assessments, and continuous monitoring evidence for any of the CLIENT environments (corporate, commercial regulated, FedRAMP, DOD and International).

The Technical Security Analyst will be responsible for maintenance of the commercial and corporate environment POAM and analysis of the corresponding vulnerability scans; development of the metrics / trends of vulnerabilities, assisting with the FedRAMP or FISMA authorization processes to include prep of the operations and build teams, and technical documentation summary and update as required. This role serves as a senior level technical security analyst who has the knowledge to create policies and execute vulnerability scans as needed, evaluates the vulnerability scan data and control implementation and who can provide thoughtful recommendations, as well as conduct security impact analysis of changes to the environments. This role must communicate between security, engineering, build/development and operations teams daily, and be able to interpret and document the results of data gathering.

GENERAL RESPONSIBILITES:
  • Configuration, Execution and Analysis of vulnerability scans
  • Ability to interpret and assess network diagrams and drawings using Visio.
  • Identify and assess Cloud System state, including vulnerabilities, RMF package status/accreditation model, PPS compliance, and patching, Cyber Security Vulnerability Assessments (CSVA) mechanisms.
  • Demonstrate familiarity with current FedRAMP, DOD and NIST Security controls and technologies, including vulnerability management capabilities.
  • Understand enterprise operating environments, including security posture, application environment, and associated security controls
  • Understand/document information system specifications and security controls, including logical and physical diagrams, connectivity, communication, and data flow diagrams, both internal and external to the system.
  • Gather information, architecture diagrams and implementation of the security controls through interfacing with the security engineering, operations and build teams
  • Develop security documentation input of technical control implementation
  • Understand the intent of the FedRAMP moderate security controls, FISMA security controls and communicate as needed
  • Assist with the FedRAMP or FISMA authorization to include, but not limited to, prep of security engineering, build and operations teams through training and mock interviews, update implementation language in the security documentation and develop processes as required, and support FedRAMP PMO/ Agency / CISO requests
  • Maintain and update a monthly Plan of Actions and Milestones (POAM), inventory and other continuous monitoring deliverables as appropriate
  • Ability to respond effectively to customer's concerns regarding ConMon activities
Qualifications
  • Bachelor's Degree in Computer Science / MIS / Information Technology, or equivalent experience in Information Security, Information Technology, or related technical discipline
  • Minimum 5 years Information Technology experience
  • Experience with Cloud technologies, especially AWS and Azure, desirable
  • Experience with FedRAMP and/or other authorization processes and NIST risk management framework
  • Execution and Analysis of vulnerability scans; such as but not limited to: Nessus/Security Center, WebInspect, etc.
  • Familiarity with Splunk to execute queries, search/review data for impact.
  • Experience in developing, evaluating, and implementing information security architectures, technologies, standards, and practices to secure applications and IT systems, desirable
  • Flexible, self-motivated, and able to work independently in a fast paced environment
  • Excellent communication skills and the proven ability to work effectively with all levels of IT and business management.
  • Skill in preparing and making written and oral presentations of complex technical nature.
  • Demonstrated ability to coordinate multiple tasks
  • U.S. Citizenship
SPECIFIC TECHNICAL SKILLS DESIRED:
  • Professional industry certifications in area of expertise.
  • Knowledge of Best Practice and security guides (ex. NIST 800-53 rev 4, NIST 800-53, FedRAMP)
  • ISC CISSP or ISACA CISM or equivalent certification


Additional Information

Qualified applicants will receive consideration for employment without regard to race, color, religion, sex, national origin, sexual orientation, gender identity, disability or protected veteran status.

  • Herndon, Virginia, United States Mantis Security Corporation Full time

    About the Role:Mantis Security Corporation seeks a skilled Information Systems Security Engineer to join our team of experts. As an ISSE, you will be responsible for defining information security requirements and integrating them into information systems and technology components through purposeful security design.Key Responsibilities:Develops and implements...


  • Herndon, United States Integrated Security Technologies Full time

    Come join our team! At Unlimited Technology, we are committed to our company's core values of Passion, Collaboration, Innovation and Adaptability. With offices throughout the United States, we are a premier cyber and physical security specialty contractor, and we are growing at a rapid pace. We have a wide range of talented and experienced individuals that...


  • Herndon, United States ManTech Full time

    Become an integral part of a diverse team while working at an Industry Leading Organization, where our employees come first. At ManTech International, you’ll help protect our national security while working on innovative projects that offer opportunities for advancement. We are seeking a highly skilled and motivated Cyber Security Forensics Analyst to...


  • Herndon, United States FSR Inc Full time

    Company Description Entrusted by companies with challenging Cybersecurity and IT data management recruiting needs, Flex Staffing Resources identifies exceptional talent and cutting edge companies and brings them together. Job DescriptionLocation of Services: Herndon, VA 20171 (1 day a week)Employment Type: FTE + BenefitsRemote: 80% (4 days a week) Supports...


  • Herndon, United States FSR Inc Full time

    Company Description Entrusted by companies with challenging Cybersecurity and IT data management recruiting needs, Flex Staffing Resources identifies exceptional talent and cutting edge companies and brings them together. Job DescriptionLocation of Services: Herndon, VA 20171 (1 day a week)Employment Type: FTE + BenefitsRemote: 80% (4 days a week) Client...


  • Herndon, United States DigiCert Full time

    Who we are We're a leading, global security authority that's disrupting our own category. Our encryption is trusted by the major ecommerce brands, the world's largest companies, the major cloud providers, entire country financial systems, entire internets of things and even down to the little things like surgically embedded pacemakers. We help companies put...


  • Herndon, United States DigiCert Full time

    Who we are We're a leading, global security authority that's disrupting our own category. Our encryption is trusted by the major ecommerce brands, the world's largest companies, the major cloud providers, entire country financial systems, entire internets of things and even down to the little things like surgically embedded pacemakers. We help companies put...


  • Herndon, Virginia, United States FSR Inc Full time

    Job Description:We are seeking an experienced Cybersecurity Systems Analyst to join our team at FSR Inc. as a Cloud Security Expert. This role involves working closely with operations and security engineering teams to ensure the secure implementation of cloud environments.Key Responsibilities:Cloud Environment Security: Interface with operations and security...


  • Herndon, United States Insight Global Full time

    Title: Information Security Analyst/Cloud Security Analyst - ISSOLocation: FULLY REMOTE - must work EST hoursDuration: 1 year contractCompensation: $50/hr to $62/hr.Required Skills and Experience *- 8+ years of Security Analyst experience- 2+ years working in a Cloud environment and FedRAMP protocols- Expert in FIPS 199 process- Expert with FISMA, risk...


  • Herndon, United States TCI Technology Consulting Inc Full time

    TCI has an immediate need for a SOC Analyst in Herndon, VA. This is a long-term contract opportunity with the possibility of hire.SUMMARYThe SOC Analyst will be responsible for analyzing and/or administering security controls for information systems.RESPONSIBILITIESSafeguard the network against unauthorized infiltration, modification, destruction or...


  • Herndon, Virginia, United States Mantis Security Corporation Full time

    About Mantis Security CorporationMantis Security Corporation is a leading specialty firm of high-caliber talent specializing in Cyber Operations, Cyber Defense, Information Assurance, Software Development, DevSecOps, Security Engineering, and Cloud Engineering. We empower and protect our nation's most critical IT assets by investing in the long-term career...


  • Herndon, Virginia, United States Mantis Security Corporation Full time

    Job OverviewMantis Security Corporation is a leading specialty firm of high-caliber talent that specializes in Cyber Operations, Cyber Defense, Information Assurance, Software Development, DevSecOps, Security Engineering, and Cloud Engineering. We enable and protect our nation's most important IT assets and invest in the long-term career development of every...


  • Herndon, Virginia, United States Mantis Security Corporation Full time

    Mantis Security Corporation is a leading specialty firm of high caliber talent that specializes in Cyber Operations, Cyber Defense, Information Assurance, Software Development, DevSecOps, Security Engineering, and Cloud Engineering.We are currently looking for an experienced IT Systems Operations Manager to join our team of experts. In this role, you will be...


  • Herndon, Virginia, United States Crimson Phoenix Full time

    Technical Systems ArchitectCrimson Phoenix is seeking a highly skilled Technical Systems Architect to join our team. As a key member of our infrastructure team, you will be responsible for designing, implementing, and maintaining our cloud-based infrastructure.Key Responsibilities:Design and implement cloud-based infrastructure solutions using Amazon Web...


  • Herndon, Virginia, United States iQuasar Full time

    Business Analyst Job DescriptionJob SummaryWe are seeking a skilled Business Analyst to join our team at iQuasar, LLC. As a Business Analyst, you will be responsible for owning and managing the product backlog of user stories, communicating requirements to the team, and working with stakeholders to define technical solutions to solve business...


  • Herndon, United States System One Full time

    Cloud Security Engineer 100% Remote US Citizenship is Required per government contract Ability to pass enhanced background screen (criminal, financial, drug) for Public Trust clearance ALTA IT Services is seeking a Cloud Security Engineer in support of our clients Bank Data Integration Service program. Our client serves as a valued partner to essential...


  • Herndon, Virginia, United States IT Partners,Inc Full time

    Job OverviewIT Partners Inc is seeking experienced Business Systems Analysts to join our Federal Consulting practice.Candidates should have a strong understanding of full lifecycle development, including requirements gathering, design, build, testing, and deployment.US Citizenship is required due to potential clearance/background checks on many of our...


  • Herndon, Virginia, United States cyDaptiv Solutions Full time

    Job OverviewCyDaptiv Solutions, a firm specializing in Systems Engineering and Cybersecurity Solutions Integration, is seeking a seasoned Cyber Security Analyst to support Federal projects. With a strong background in IT and cybersecurity, this professional will play a crucial role in ensuring the security of our clients' systems.About the RoleThis exciting...


  • Herndon, Virginia, United States Amazon, Inc. Full time

    Job OverviewAmazon Web Services (AWS) is seeking a skilled Cloud Technical Advisor to support our National Security customers. As a member of our team, you will be responsible for providing strategic technical guidance and advocacy to help plan and build solutions using best practices.About the RoleWe are looking for a highly motivated individual with 2+...


  • Herndon, United States QVine Full time

    DESCRIPTION : QVine is seeking a candidate with Network Engineering experience and skills. The analyst will support the customer's overall threat analysis efforts by performing technical assessments on IT infrastructure components, malicious code, and Advance Persistent Threat capabilities as they relate to computer networking. The candidate will be...