Talent.com
Senior Cybersecurity Risk Management Analyst

Senior Cybersecurity Risk Management Analyst

Evolver FederalSpringfield, VA, USA
job_description.job_card.30_days_ago
serp_jobs.job_preview.job_type
  • serp_jobs.job_card.full_time
  • serp_jobs.filters_job_card.quick_apply
job_description.job_card.job_description

Evolver Federal is seeking a Senior Cybersecurity Risk Management Analyst to support its Federal client in Springfield, VA in managing a portfolio of systems participating in Ongoing Authorization / Continuous ATO. This role will ensure compliance with established guidance / processes for Ongoing Authorization (OA) including but not limited to : developing and reviewing security documentation in support of the OA process and compiling related security packages for submission, validating control sets for testing, and conducing internal compliance reviews of assigned systems processes, as well as develop various compliance reports relating to all areas of risk and compliance.

The successful candidate will have previous experience managing a Federal Government Ongoing Authorization Program or previous experience as an ISSO with assigned systems participating in Ongoing Authorization / Continuous ATO Program. The candidate will also have experience with FISMA metrics and in reviewing and analyzing data output from scanning tools for the purposes of identifying risks and trends at the enterprise level in support of continuous monitoring and drive remediation efforts.

Responsibilities :

  • Provide security SME-level input to working groups to improve FISMA metrics and continuous monitoring processes.
  • Advise on architectural requirements for system / network security, Active Directory, application integration, and system hierarchy.
  • Analyze data from continuous monitoring, configuration, vulnerability, asset, and software management tool output to identify security trends and risks.
  • Support risk mitigation through performance analysis and anomaly detection.
  • Guide System Team stakeholders on OA processes and ensure compliance with OA Methodology.
  • Perform document reviews for all security documentation in support of initial authorization, reauthorization, and ongoing Security Authorization packages, as well as compile and prepare authorization packages.
  • Conduct monthly reviews and annual assessments of OA systems.
  • Validate system control assessment test plans and ensure control testing is in alignment with OA assessment frequency requirements.
  • Organize and lead monthly Organizational Risk Management Board (ORMB) meetings, including preparing and distributing meeting minutes.
  • Develop, maintain, and make recommendations for enhancing Cybersecurity Policies.
  • Develop, update, and maintain Standard Operating Procedures (SOPs) and make recommendations for new processes and / or SOPs needed to mature and improve Government Programs.
  • Apply knowledge of NIST 800-53 security controls and recommend appropriate allocation to support OA / Continuous ATO.
  • Communicate clearly with system owners, developers, and executive leadership on various cybersecurity, risk and compliance topics, including providing recommendations on system and network security architecture, Active Directory integration, and application security.
  • Coordinate, schedule, develop agendas, and facilitate meetings for large governance groups and working groups comprised of all levels of government and contractor stakeholders.
  • Perform other duties as assigned by the Government.
  • Ability to work efficiently and effectively in a dynamic and fast-paced environment.

Basic Qualifications

  • 8 years of related experience with Bachelor's Degree or 10 years of overall related experience in a relevant field
  • 5 years of experience with NIST 800-37, experience that can span across a subset, or all, of the steps within the Risk Management Framework.
  • 3 years of experience in DHS environment
  • 1 year of experience assessing security controls in accordance with NIST 800-53 in support of the Federal Government to include evaluating and validating security control implementation.
  • Must have a current Active Secret clearance
  • 3 years of experience with NIST SP 800-53, 800-37
  • 3 years of experience with DHS 4300A / B
  • 1 year of experience with FISMA metrics, and security compliance.
  • 3 years of experience executing continuous monitoring activities, including those supporting vulnerability management and configuration management.
  • 3 years of experience with government GRC tools such as Archer, IACS, CSAM, etc.
  • 5 years' experience managing / supporting cybersecurity architecture and governance.
  • Must have previous client-engagement experience.
  • Preferred Qualifications

  • 2 years of experience assessing security controls in accordance with NIST 800-53 in support of the Federal Government to include evaluating and validating security control implementation.
  • 5 years of experience as an Information System Security Office (ISSO) in / in support of the Federal government, developing and maintaining comprehensive security documentation in support of the Risk Management Framework, including, but not limited to : System Security Plans (SSPs) (Sections 1 & 2), Contingency Plans (CPs), Contingency Plan Tests (CPTs), Privacy Impact Assessments (PIAs), and Privacy Threshold Analyses (PIA), and Business Impact Assessments (BIAs).
  • 3 years of experience as an Information System Security Office (ISSO) in / in support of the Federal government, developing and maintaining comprehensive security documentation in support of the Risk Management Framework, including, but not limited to : System Security Plans (SSPs) (Sections 1 & 2), Contingency Plans (CPs), Contingency Plan Tests (CPTs), Privacy Impact Assessments (PIAs), and Privacy Threshold Analyses (PIA), and Business Impact Assessments (BIAs).
  • Ability to schedule and lead meetings, including Working Groups and formal Governance Groups, with a diverse group of government and contractor stakeholders at various levels within the organization, including developing and maintaining agendas, meeting notes, and meeting records, including maintaining a repository of all meeting records.
  • Ability to communicate clearly and effectively via written and verbal communication in both formal and informal situations.
  • Ability to clearly communicate complex technical concepts to Information Technology Project Managers, ISSOs, Application Developers, and Security Compliance Analysts, as well as non-technical POCs such as Branch Chiefs and Business System Owners.
  • Ability to adapt to frequent changes in priorities, follow project schedules, meet established deadlines, and proactively communicate risks and issues to the Contractor PM and / or Federal Leads.
  • Possess good listening skills and the ability to detect explicit and implicit needs and wants of the client.
  • Demonstrated ability to exercise good judgment, prioritize multiple tasks, and problem solve under pressure of deadlines and resource constraints
  • Possess strong analytical and critical thinking skills with the ability to apply them to the client / contract workspace.
  • Excellent organizational skills and attention to detail.
  • Strong analytical, critical thinking, and problem-solving skills.
  • Evolver Federal is an equal opportunity employer and welcomes all job seekers. It is the policy of Evolver Federal not to discriminate based on race, color, ancestry, religion, gender, age, national origin, gender identity or expression, sexual orientation, genetic factors, pregnancy, physical or mental disability, military / veteran status, or any other factor protected by law.

    Actual salary will depend on factors such as skills, qualifications, experience, market and work location. Evolver Federal offers competitive benefits, including health, dental and vision insurance, 401(k), flexible spending account, and paid leave (including PTO and parental leave) in accordance with our applicable plans and policies.

    Job Posted by ApplicantPro

    serp_jobs.job_alerts.create_a_job

    Senior Cybersecurity Analyst • Springfield, VA, USA

    Job_description.internal_linking.related_jobs
    Senior Cybersecurity Engineer - Compliance & Risk Management

    Senior Cybersecurity Engineer - Compliance & Risk Management

    Human Resources Research OrganizationAlexandria, VA, USA
    serp_jobs.job_card.full_time
    serp_jobs.filters_job_card.quick_apply
    Senior Cybersecurity Engineer - Compliance & Risk Management.The Human Resources Research Organization (HumRRO).We work with federal and state government agencies, private sector organizations,...serp_jobs.internal_linking.show_moreserp_jobs.last_updated.last_updated_30
    • serp_jobs.job_card.promoted
    Principal Risk Management Analyst

    Principal Risk Management Analyst

    Clearance JobsFalls Church, VA, US
    serp_jobs.job_card.full_time
    At Northrop Grumman, our employees have incredible opportunities to work on revolutionary systems that impact people's lives around the world today, and for generations to come.Our pioneering and i...serp_jobs.internal_linking.show_moreserp_jobs.last_updated.last_updated_30
    • serp_jobs.job_card.promoted
    Cybersecurity Compliance Analyst

    Cybersecurity Compliance Analyst

    Ginas Tech JobsWashington, DC, US
    serp_jobs.job_card.full_time
    Cybersecurity Compliance Analyst.We are currently looking for a Cybersecurity Compliance Analyst for a great opportunity in Washington, DC. This position is primarily on-site but may allow for hybri...serp_jobs.internal_linking.show_moreserp_jobs.last_updated.last_updated_variable_days
    • serp_jobs.job_card.promoted
    Senior Director of Product Management, Cybersecurity

    Senior Director of Product Management, Cybersecurity

    CodeHunterMcLean, VA, US
    serp_jobs.job_card.full_time
    CodeHunter is a fast-growing, innovative company that provides cutting-edge cloud-based solutions for malware identification and analysis. Our mission is to help businesses stay ahead of cyber threa...serp_jobs.internal_linking.show_moreserp_jobs.last_updated.last_updated_variable_days
    • serp_jobs.job_card.promoted
    Senior Cybersecurity Engineer - Compliance & Risk Management

    Senior Cybersecurity Engineer - Compliance & Risk Management

    Human Resources Research OrganizationAlexandria, VA, US
    serp_jobs.job_card.full_time
    Senior Cybersecurity Engineer - Compliance & Risk Management.The Human Resources Research Organization (HumRRO).We work with federal and state government agencies, private sector organizations,...serp_jobs.internal_linking.show_moreserp_jobs.last_updated.last_updated_30
    • serp_jobs.job_card.promoted
    Risk Manager

    Risk Manager

    Customer Value PartnersRockville, MD, US
    serp_jobs.job_card.full_time
    CVP is seeking an Cybersecurity Risk Manager for a large government agency enterprise-level cybersecurity program.The Cybersecurity Risk Manager will work directly with the Cybersecurity Program Ma...serp_jobs.internal_linking.show_moreserp_jobs.last_updated.last_updated_variable_days
    • serp_jobs.job_card.promoted
    Senior Manager, Technology Risk

    Senior Manager, Technology Risk

    Veterans StaffingWashington, DC, US
    serp_jobs.job_card.full_time
    Senior Manager for Technology Risk.Ready to be pushed beyond what you think you're capable of? At Coinbase, our mission is to increase economic freedom in the world. It's a massive, ambitious opport...serp_jobs.internal_linking.show_moreserp_jobs.last_updated.last_updated_variable_days
    • serp_jobs.job_card.promoted
    Senior Cybersecurity Specialist

    Senior Cybersecurity Specialist

    BarbaricumFort Belvoir, VA, US
    serp_jobs.job_card.full_time
    Barbaricum is a rapidly growing government contractor providing leading-edge support to federal customers, with a particular focus on Defense and National Security mission sets.We leverage more tha...serp_jobs.internal_linking.show_moreserp_jobs.last_updated.last_updated_30
    • serp_jobs.job_card.promoted
    Cybersecurity Compliance Analyst

    Cybersecurity Compliance Analyst

    Parallel PartnersWashington, DC, US
    serp_jobs.job_card.full_time
    Cybersecurity Compliance Analyst.We are currently looking for a Cybersecurity Compliance Analyst for a great opportunity in Washington, DC. This position is primarily on-site but may allow for hybri...serp_jobs.internal_linking.show_moreserp_jobs.last_updated.last_updated_variable_days
    • serp_jobs.job_card.promoted
    Cybersecurity Compliance Analyst

    Cybersecurity Compliance Analyst

    Next Step SystemsWashington, DC, US
    serp_jobs.job_card.full_time
    Cybersecurity Compliance Analyst.We are currently looking for a Cybersecurity Compliance Analyst for a great opportunity in Washington, DC. This position is primarily on-site but may allow for hybri...serp_jobs.internal_linking.show_moreserp_jobs.last_updated.last_updated_variable_days
    • serp_jobs.job_card.promoted
    Cybersecurity Analyst

    Cybersecurity Analyst

    9th Way InsigniaAshburn, VA, US
    serp_jobs.job_card.full_time
    Way Insignia is a service-disabled, veteran-owned small business bringing transformative technology to our government customers so they can achieve their missions. Our specialties include cybersecur...serp_jobs.internal_linking.show_moreserp_jobs.last_updated.last_updated_variable_days
    • serp_jobs.job_card.promoted
    Senior Risk Analyst

    Senior Risk Analyst

    Zip Co LimitedWashington, DC, US
    serp_jobs.job_card.full_time
    Join our Risk team at Zip, where we focus on ensuring the success and profitability of portfolio.Our team leverages analytics to manage exposure, improve customer engagement, and continually manage...serp_jobs.internal_linking.show_moreserp_jobs.last_updated.last_updated_variable_days
    • serp_jobs.job_card.promoted
    Cybersecurity Analyst - Intermediate

    Cybersecurity Analyst - Intermediate

    ITC DefenseKing George, VA, US
    serp_jobs.job_card.full_time
    Cybersecurity Analyst IAM II Intermediate.ITC Defense has an immediate need for a Cybersecurity Analyst Intermediate supporting the Missile Defense Agency (MDA) Aegis Ballistic Missile Defense (BMD...serp_jobs.internal_linking.show_moreserp_jobs.last_updated.last_updated_variable_days
    • serp_jobs.job_card.promoted
    Principal Risk Management Analyst

    Principal Risk Management Analyst

    Northrop GrummanMc Lean, VA, US
    serp_jobs.job_card.full_time
    At Northrop Grumman, our employees have incredible opportunities to work on revolutionary systems that impact people's lives around the world today, and for generations to come.Our pioneering and i...serp_jobs.internal_linking.show_moreserp_jobs.last_updated.last_updated_30
    • serp_jobs.job_card.promoted
    Senior Cybersecurity Architect

    Senior Cybersecurity Architect

    SPECIAL AEROSPACE SECURITY SERVICES INCWashington, DC, US
    serp_jobs.job_card.full_time
    The Senior Cybersecurity Architect will lead enterprise-level cybersecurity strategy, architecture design, and compliance for DCIO(IE & SAP-IT) systems. This role ensures alignment with DoD dire...serp_jobs.internal_linking.show_moreserp_jobs.last_updated.last_updated_30
    • serp_jobs.job_card.promoted
    Senior Program Analyst - Cybersecurity Budget Execution (TS / SCI)

    Senior Program Analyst - Cybersecurity Budget Execution (TS / SCI)

    Clearance JobsWashington, DC, US
    serp_jobs.job_card.full_time
    Senior Program Analyst - Cybersecurity Budget Execution.Koniag IT Systems, LLC, a Koniag Government Services company, is seeking a Senior Program Analyst - Cybersecurity Budget Execution with a TS / ...serp_jobs.internal_linking.show_moreserp_jobs.last_updated.last_updated_variable_days
    • serp_jobs.job_card.promoted
    Senior Risk Management Specialist

    Senior Risk Management Specialist

    Clearance JobsWashington, DC, US
    serp_jobs.job_card.full_time
    Senior Risk Management Specialist.LMI is seeking a skilled Senior Risk Management Specialist to design, develop, and implement a comprehensive ERM framework for a national agency.The Senior Risk Ma...serp_jobs.internal_linking.show_moreserp_jobs.last_updated.last_updated_30
    • serp_jobs.job_card.promoted
    • serp_jobs.job_card.new
    Joint Cybersecurity Analyst

    Joint Cybersecurity Analyst

    Blue Water ThinkingWashington, DC, US
    serp_jobs.job_card.full_time
    Guided by our principles of value generation, continuous innovation, customer-centricity, and vested collaboration, Blue Water Thinking proudly supports our Federal clients in achieving their Agenc...serp_jobs.internal_linking.show_moreserp_jobs.last_updated.last_updated_variable_hours
    • serp_jobs.job_card.promoted
    Risk Management Analyst

    Risk Management Analyst

    Lockheed MartinBethesda, MD, US
    serp_jobs.job_card.full_time +1
    Lockheed Martin is seeking candidates desiring new skillsets, willing to transform processes, dive into analyses to solve challenges and grow. Our risk management analysts provide comprehensive supp...serp_jobs.internal_linking.show_moreserp_jobs.last_updated.last_updated_30
    • serp_jobs.job_card.promoted
    Cybersecurity Analyst

    Cybersecurity Analyst

    Idea EntityHerndon, VA, US
    serp_jobs.job_card.full_time
    Belcamp, MD, Orlando, FL, Camden, AR, Fullerton, CA, Santa Clarita, CA, Rustburg, VA.Notes : No C2C, must be US Citizen.We are seeking a detail-oriented Compliance Analyst to support compliance docu...serp_jobs.internal_linking.show_moreserp_jobs.last_updated.last_updated_variable_days