Talent.com
Security Analyst

Security Analyst

SynergyReston, VA, US
job_description.job_card.variable_hours_ago
serp_jobs.job_preview.job_type
  • serp_jobs.job_card.full_time
job_description.job_card.job_description

Synergy Business Innovation & Solutions is a premier implementer of cutting-edge software solutions. Synergy brings the experience and expertise necessary to deliver capability that provides tangible ROI to our customers. Synergy's core areas of expertise are in the fields of Digital Transformation, Cloud Solutions, SaaS and Low-Code / No-Code solutions, Emerging Technologies, Data analytics and Visualization, Information Assurance, and Business Process Re-Engineering.

Synergy offers its employees a generous portfolio of core and voluntary benefits including : group medical, dental, and vision insurance, company paid life, short-term, and long-term disability insurance; HSA, FSA; 401(k) with immediately vested company match; PTO / Sick Leave, 11 paid federal holidays, parental leave; tuition and training reimbursement; a referral bonus program; and life management programs.

At Synergy, you'll be challenged and given the opportunity to grow in your career path. In fact, growth is such a big deal to us that you will have dedicated career coaches available for every employee, company-funded certification opportunities, education reimbursement, and a general open-door policy so that you have support when you need it. Our team is eager to learn, fast-paced, and quality-driven-if that sounds like you, Synergy has a position for you!

Overview

  • We are seeking a mid-level Security Analyst. The candidate will work for the engineering division that supports developing and managing a suite of enterprise services and applications. The candidate should have a strong Dev / Sec / Ops background that will focus embedding security practices into the automated software development lifecycle, ensuring systems meet federal government compliance standards. The candidate will work closely with our DevOps, Support, and administrative teams in an agile environment to maintain the security posture of systems.

Responsibilities

  • Execution of Risk Management Framework (RMF)
  • Perform Security Impact Assessment for all application and environment updates
  • Counsel to ensure auditing, testing, preventive and reactive measures are being adequately implemented for systems with an active Authorization to Operate (ATO).
  • Practical knowledge and skills in working with cloud computing platforms, while adhering to the strict security standards set by the Federal Risk and Authorization Management Program (FedRAMP)
  • Develop an in-depth understanding of customer requirements to quantify security and application risks, and perform impact assessments
  • Maintaining ongoing vigilance to ensure adherence to regulatory requirements through continuous monitoring of critical processes
  • Oversight, expertise, technical security strategy, standards, and best practices for security categorizations (low, moderate and high).
  • Reviews, testing and implementation of security requirements within project plan timelines.
  • Research and tracking of Agency security standards, policies, and procedures.
  • Support for multiple project assignments with strong and effective communication, time management and collaboration skills.
  • Skills, Qualifications and Certifications of Best Candidates

  • Documented experience executing Risk Management Framework (RMF, NIST-800-53)
  • Experience with agile software development
  • General knowledge of security best practices and compliance requirements
  • Excellent organizational and communication skills are mandatory for various stakeholder audiences
  • Experience collaboratively establishing secure configuration baselines for technologies
  • Knowledge or experience with conducting Assessment and Authorization (A&A) and Continuous Monitoring following NIST guidelines
  • Knowledge or experience developing security documentation and conducting reviews for A&A packages
  • Maintain, track, and communicate detailed project tasks
  • Manage initial and reauthorization System Assessment and Authorization (SAA) / Security Controls Assessment (SCA) task and milestone, task dependencies for low, moderate, and high security systems
  • Identify and visually demonstrate system boundaries, select security controls, and ensure implemented controls are adequate for COTS or proprietary web applications. Provide recommendations as necessary to meet or improve controls
  • Ensure security policies are developed, maintained and updated to meet IT security best business practices and standards, including Federal Info Security Management Act (FISMA), and National Institute of Standards and Technology (NIST) 800-53 - IPS federal info processing standard
  • Be able to review security scans, advise on triaging vulnerabilities, and be able to provide recommendations on mitigating security risks
  • Assists with documenting and managing artifacts in Atlassian Suite (JIRA, Confluence) and CSAM security repositories, including but not limited to writing implementation statements
  • Assists Information Systems Security Managers (ISSMs) in generating ATO packages
  • Conduct continuous monitoring and reporting of security control implementations
  • Must evaluate business strategies and requirements to develop security strategies, assess risk, research standards, and determine security requirements as necessary
  • Track and coordinate POA&M remediation activity with different functional teams across multiple systems
  • Experience with security tools such as Splunk, Nessus, SonarQube, SIEMs and Static Code Analyzers
  • Other duties as assigned
  • Preferred Qualifications

  • 7+ years' experience in an enterprise security role preferred
  • Experience in Dev / Sec / Ops
  • Experience in CSAM
  • Proficient in the Atlassian suite of agile tools : Confluence and Jira
  • Experience with Java and other programming languages
  • Experience with Federal Government systems
  • Federal Government Secret Clearance
  • Certifications & Technical Stack

  • Must have a Security+ certification
  • Citizenship or Work Authorization Required

  • US citizen
  • Ability to obtain and maintain Federal Government Position of Trust
  • Must pass a background investigation.
  • Compensation for roles at Synergy varies depending on a wide variety of factors including but not limited to the requirements of the role; education and certifications; knowledge, training, skills and abilities; level of experience; geographic location; and alignment with market data, law, and other business and organizational needs. As required by local law, the posted pay range represents the lowest to the highest pay that Synergy believes in good faith it might pay for this particular job, depending on the circumstances. The disclosed range estimate has not been adjusted for the applicable geographic differential associated with the location at which the position may be filled. It is not typical for an individual to be hired at or near the top of the range for their role and compensation decisions are dependent on the facts and circumstances of each case.

    A reasonable estimate of the current pay range is : $70,000.00- $95,000.00.

    Essential Job Function Physical Requirements : The physical requirements of this position are critical in evaluating the qualifications and abilities of an applicant or employee. The physical efforts needed to perform the essential duties of this job 90% of the time are repetitive motions, grasping, holding, and finger dexterity of the hands, reading, writing, eye-hand coordination, color distinction, and full visual abilities, hearing, talking, sitting, and use of IT equipment, phones, and office machines.

    To a reduced degree,

    Synergy is an equal opportunity employer, and does not discriminate against applicants for employment or its employees on the basis of age, race, creed, color, religion, religious creed, ancestry, national origin, ethnic origin, sexual orientation, gender identity or expression, military or veteran status, sex, medical condition, pregnancy, physical or mental disability, personal appearance, organ donation and hair length associated with race, genetic information or characteristics, family responsibilities, familial status, marital status, citizenship or immigration status, status as a victim of domestic violence, a sexual offense, or stalking, political affiliation, arrest records and criminal convictions, credit information, matriculation, homeless status, or any other characteristic protected by federal, state and local law. Discrimination or harassment based upon these protected categories is expressly prohibited. This policy applies to all aspects of employment, including job selection, assignment, promotion, compensation, benefits, training, discipline and termination.

    LI-Remote

    J-18808-Ljbffr

    serp_jobs.job_alerts.create_a_job

    Security Analyst • Reston, VA, US

    Job_description.internal_linking.related_jobs
    • serp_jobs.job_card.promoted
    Senior Security Assurance Analyst

    Senior Security Assurance Analyst

    VirtualVocationsRockville, Maryland, United States
    serp_jobs.job_card.full_time
    Security Assurance Analyst to lead the design, implementation, and optimization of enterprise information security controls and compliance programs. Key Responsibilities Lead and maintain SOC 2 an...serp_jobs.internal_linking.show_moreserp_jobs.last_updated.last_updated_1_day
    • serp_jobs.job_card.promoted
    Security Analyst - Cybersecurity Training

    Security Analyst - Cybersecurity Training

    VirtualVocationsAlexandria, Virginia, United States
    serp_jobs.job_card.full_time
    A company is looking for a Security Analyst - Cybersecurity Awareness and Training.Key Responsibilities Design and execute monthly phishing campaigns for users and targeted groups Assist in plan...serp_jobs.internal_linking.show_moreserp_jobs.last_updated.last_updated_variable_days
    • serp_jobs.job_card.promoted
    Security Operations Analyst

    Security Operations Analyst

    VirtualVocationsAlexandria, Virginia, United States
    serp_jobs.job_card.full_time
    A company is looking for a Security Operations Analyst.Key Responsibilities Monitor security tools and alerts to identify suspicious activity Investigate security incidents and coordinate respon...serp_jobs.internal_linking.show_moreserp_jobs.last_updated.last_updated_30
    • serp_jobs.job_card.promoted
    IAM Security Analyst

    IAM Security Analyst

    VirtualVocationsFairfax, Virginia, United States
    serp_jobs.job_card.full_time
    A company is looking for an IAM Security Analyst.Key Responsibilities Execute user access certifications for compliance and collaborate with audit teams Enhance IAM controls and participate in d...serp_jobs.internal_linking.show_moreserp_jobs.last_updated.last_updated_variable_days
    • serp_jobs.job_card.promoted
    Senior Security Compliance Analyst

    Senior Security Compliance Analyst

    VirtualVocationsFairfax, Virginia, United States
    serp_jobs.job_card.full_time
    Security Compliance Analyst to monitor, assess, and improve its compliance program.Key Responsibilities Evaluate organizational policies and standards to ensure compliance with internal and exter...serp_jobs.internal_linking.show_moreserp_jobs.last_updated.last_updated_30
    • serp_jobs.job_card.promoted
    • serp_jobs.job_card.new
    SOC Analyst Level 1

    SOC Analyst Level 1

    VirtualVocationsAlexandria, Virginia, United States
    serp_jobs.job_card.full_time
    A company is looking for a SOC Analyst (L1).Key Responsibilities Monitor and analyze security alerts to detect potential threats and optimize detection rules Execute incident response activities...serp_jobs.internal_linking.show_moreserp_jobs.last_updated.last_updated_variable_hours
    • serp_jobs.job_card.promoted
    Cybersecurity Event Analyst

    Cybersecurity Event Analyst

    VirtualVocationsAlexandria, Virginia, United States
    serp_jobs.job_card.full_time
    A company is looking for a Cybersecurity Event Analyst.Key Responsibilities Develop and mentor SOC L1 / L2 Information Security Analysts, ensuring adherence to processes and driving new detections ...serp_jobs.internal_linking.show_moreserp_jobs.last_updated.last_updated_30
    • serp_jobs.job_card.promoted
    Security Engineer - Application Security

    Security Engineer - Application Security

    VirtualVocationsAlexandria, Virginia, United States
    serp_jobs.job_card.full_time
    A company is looking for a Security Engineer - Application & AI Security (REMOTE).Key Responsibilities Build and deploy security controls across web applications, data pipelines, and AI systems; ...serp_jobs.internal_linking.show_moreserp_jobs.last_updated.last_updated_1_day
    • serp_jobs.job_card.promoted
    Senior Security Analyst

    Senior Security Analyst

    VirtualVocationsWashington, District of Columbia, United States
    serp_jobs.job_card.full_time
    A company is looking for a Senior Security Analyst to monitor and respond to cybersecurity threats.Key Responsibilities Monitor and triage security alerts from various sources and lead incident r...serp_jobs.internal_linking.show_moreserp_jobs.last_updated.last_updated_30
    • serp_jobs.job_card.promoted
    Senior Detection Analyst

    Senior Detection Analyst

    VirtualVocationsArlington, Virginia, United States
    serp_jobs.job_card.full_time
    A company is looking for a Detection & Response Analyst.Key Responsibilities Act as the point of escalation for security incidents and lead the Incident Detection team Triage security incidents ...serp_jobs.internal_linking.show_moreserp_jobs.last_updated.last_updated_variable_days
    • serp_jobs.job_card.promoted
    Threat Intelligence Analyst

    Threat Intelligence Analyst

    VirtualVocationsAlexandria, Virginia, United States
    serp_jobs.job_card.full_time
    A company is looking for a Threat Intelligence Reporting Analyst.Key Responsibilities Produce actionable intelligence reports for defenders and counter abuse teams Report on threats to enable fi...serp_jobs.internal_linking.show_moreserp_jobs.last_updated.last_updated_30
    • serp_jobs.job_card.promoted
    Oracle Cloud Security Analyst

    Oracle Cloud Security Analyst

    VirtualVocationsArlington, Virginia, United States
    serp_jobs.job_card.full_time
    A company is looking for an Oracle Cloud Application Security Analyst.Key Responsibilities Develop and implement security policies and procedures for the Oracle Financial Applications system Def...serp_jobs.internal_linking.show_moreserp_jobs.last_updated.last_updated_variable_days
    • serp_jobs.job_card.promoted
    • serp_jobs.job_card.new
    SOC Analyst Level 2

    SOC Analyst Level 2

    VirtualVocationsAlexandria, Virginia, United States
    serp_jobs.job_card.full_time
    A company is looking for a SOC Analyst (L2) to maintain its cybersecurity posture through monitoring, detection, and incident response. Key Responsibilities Monitor and analyze security alerts to ...serp_jobs.internal_linking.show_moreserp_jobs.last_updated.last_updated_variable_hours
    • serp_jobs.job_card.promoted
    Cyber Package Analyst

    Cyber Package Analyst

    VirtualVocationsAlexandria, Virginia, United States
    serp_jobs.job_card.full_time
    A company is looking for a Cyber Package Analyst to support the review and augmentation of current security packages.Key Responsibilities Review and supplement security documentation as part of a...serp_jobs.internal_linking.show_moreserp_jobs.last_updated.last_updated_variable_days
    • serp_jobs.job_card.promoted
    Cloud Security Analyst - USCIS - Remote

    Cloud Security Analyst - USCIS - Remote

    ITC Federal, IncFairfax, VA, United States
    serp_jobs.filters.remote
    serp_jobs.job_card.full_time
    Cloud Security Analyst - USCIS - Remote.Department of Homeland Security (DHS) - USCIS OIT Architecture Engineering Support (AES2). Must be able to obtain DHS Suitability security clearance, which ty...serp_jobs.internal_linking.show_moreserp_jobs.last_updated.last_updated_30
    • serp_jobs.job_card.promoted
    Cyber Security Data Analyst

    Cyber Security Data Analyst

    VirtualVocationsAlexandria, Virginia, United States
    serp_jobs.job_card.full_time
    A company is looking for a Principal Cyber Security Data Analyst, Remote.Key Responsibilities Participate in incident investigations following data events Secure and document incidents to preser...serp_jobs.internal_linking.show_moreserp_jobs.last_updated.last_updated_1_day
    • serp_jobs.job_card.promoted
    Platform Security Analyst - USCIS - Remote

    Platform Security Analyst - USCIS - Remote

    ITC Federal, IncFairfax, VA, United States
    serp_jobs.filters.remote
    serp_jobs.job_card.full_time
    Platform Security Analyst - USCIS - Remote.Department of Homeland Security (DHS) - USCIS OIT Architecture Engineering Support (AES2). Must be able to obtain DHS Suitability security clearance, which...serp_jobs.internal_linking.show_moreserp_jobs.last_updated.last_updated_30
    • serp_jobs.job_card.promoted
    South Carolina Licensed Information Security Analyst

    South Carolina Licensed Information Security Analyst

    VirtualVocationsAlexandria, Virginia, United States
    serp_jobs.job_card.full_time
    A company is looking for an Information Security GRC Analyst II.Key Responsibilities Develop and maintain information security policies and procedures in alignment with regulatory requirements C...serp_jobs.internal_linking.show_moreserp_jobs.last_updated.last_updated_1_day
    • serp_jobs.job_card.promoted
    Application Security Analyst

    Application Security Analyst

    VirtualVocationsAlexandria, Virginia, United States
    serp_jobs.job_card.full_time
    A company is looking for an Application Security Analyst to protect its digital ecosystem.Key Responsibilities Analyze and refine security findings from various security tools Reduce false posit...serp_jobs.internal_linking.show_moreserp_jobs.last_updated.last_updated_variable_days
    • serp_jobs.job_card.promoted
    Security Analyst - Data Protection

    Security Analyst - Data Protection

    VirtualVocationsRockville, Maryland, United States
    serp_jobs.job_card.full_time
    A company is looking for a Security Analyst, Data Protection.Key Responsibilities Execute security and data protection requirements to enhance data security and privacy protections Expand capabi...serp_jobs.internal_linking.show_moreserp_jobs.last_updated.last_updated_variable_days