Senior Information Security Analyst

Data Systems Analysts, Inc.
Fairfax, VA, United States
Full-time

DSA is hiring a Senior Information Security Analyst. This is a full-time position in the DC Area.

This position supports the Environmental Protection Agency (EPA). DSA is the Prime and has been working with this customer on this contract for more than 13 years.

It is a dynamic team with a passion for supporting Federal programs that serve US Citizens.

Location is Hybrid : Allows the candidate the ability to work onsite at DSA or customer site with potential for telework.

Work Location flexible with telework as approved.

The Environmental Protection Agency (EPA) Office of Information Security and Privacy (OISP) is responsible for developing and maintaining agency wide information security and privacy programs;

developing and maintaining information security and privacy policies, procedures, and control techniques; training personnel with significant information security responsibilities and assisting senior agency officials with information security and privacy responsibilities.

The Senior Information Assurance Analyst will be an integral part of a team responsible for supporting the development and maturation of an Agency-wide information security (InfoSec) program for a large civilian Federal agency.

The candidate will serve as a subject matter expert with regards to the Risk Management Framework (RMF) and all associated information security policies and procedures and should possess in-depth knowledge of applying, selecting and testing the NIST family of security controls.

The candidate will report directly to the program manager and have strong leadership skills and the ability to lead teams, tasks and projects of 5+ junior, mid, and senior level resources with limited supervision.

Primary Responsibilities :

Advising senior-level stakeholders on InfoSec initiatives including compliance, awareness and training, and security operations.

Leading Independent Validation and Verification (IV&V) efforts on security authorization / ATO packages to ensure compliance to agency requirements.

Leveraging the existing Governance, Risk, and Compliance (GRC) tool, Telos Xacta (or an alternate like CSAM or RSA Archer), to track and reconcile findings from assessments, audits, and vulnerability scans.

Coordinating government data calls (FISMA, FMFIA, BDR, etc.) and monthly reports.

Assessing the effectiveness of the InfoSec and privacy training program and leading the collection, analyzing, and presentation of enterprise-level InfoSec performance metrics.

Managing InfoSec Program POA&Ms, including advising on remediation efforts.

Working closely with senior agency security officials, system owners, information system security officers (ISSOs) and other stakeholders to advise and implement security solutions.

Identify opportunities for efficiencies in work process and innovative approaches.

Participating in team problem solving efforts and offer ideas to solve client issues.

Conducting relevant research, data analysis, and developing reports.

Preparing and assisting in the development of policy and procedures.

Implementing processes and procedures to monitor risk across programs / projects.

Preparing briefings to executive team to debrief the results of studies, analyses, and plans.

Assisting the client leadership in reviewing monthly project progress, documenting issues, and monitoring resolution.

Required Qualifications :

Bachelor’s degree in Information Technology or related field and 8 years of relevant IA experience. May substitute security certification (e.

g. CISSP) for 2 years of experience.

3+ years in a leadership role

Strong data analysis skills.

Excellent written and verbal communication skills.

Possess in-depth knowledge of applying, selecting and testing the NIST 800-53 Rev 4 security controls.

Possess in-depth knowledge of NIST 800-37 Risk Management Framework.

Experience with a Governance, Risk and Compliance tool (e.g., Xacta, RSA Archer, CSAM or eMASS).

Excellent attention to detail.

Ability to handle and prioritize multiple tasks and deadlines.

Desired Qualifications :

Advanced level cybersecurity certification (e.g., CompTIA CISM, ISC2 CISSP)

In-depth knowledge of applying, selecting and testing the NIST 800-53 Rev 5 security controls.

Many of DSA's positions require the ability to obtain a security clearance. Security clearances may only be granted to U.

S. citizens. In addition, applicants who accept a conditional offer of employment may be subject to government security investigation(s) and must meet eligibility requirements for access to classified information.

DSA is proud to be an Affirmative Action / Equal Opportunity Employer. DSA is committed to treating all employees and applicants for employment with respect and dignity and maintaining a workplace

that is free from unlawful discrimination. All applicants will be considered for employment without regard to race, color, religion, age, national origin, ancestry, ethnicity, gender (including pregnancy, childbirth, breastfeeding or other related medical conditions), gender identity, gender expression, sexual orientation, marital status, veteran status, disability, genetic information, citizenship status, characteristic or membership in any other group protected by federal, state or local laws.

DSA requires background checks, where permitted , by law. DSA is an E-Verify Employer.

LI-AH1

11 days ago
Related jobs
Promoted
ManTech
Chantilly, Virginia

Hold at least one of the following certifications: Certified Information Systems Security Professional (CISSP), Global Information Security Professional (GISP), or the CompTIA Advanced Security Practitioner (CASP) or other certifications exemplifying skill sets such as those described in DoD Instruc...

Promoted
ManTech
Chantilly, Virginia

Currently, ManTech is seeking a motivated, career and customer-oriented Information Security Analysis to join our team in the Chantilly, VA area. At ManTech International Corporation, you’ll help protect our national security while working on innovative projects that offer opportunities for advancem...

Promoted
ANSER
Arlington, Virginia

ANSER is seeking a Senior Administrative Operations Analyst to support the Industrial Base Analysis and Sustainment (IBAS) program within the Office of the Assistant Secretary of Defense for Industrial Base Policy (IBP). ANSER enhances national and homeland security by strengthening public instituti...

Promoted
Accenture Federal Services
McLean, Virginia

Additionally, employees who have access to the compensation information of other employees or applicants as a part of their essential job functions cannot disclose the pay of other employees or applicants to individuals who do not otherwise have access to compensation information, unless the disclos...

Promoted
Aeyon
Arlington, Virginia

The contractor shall support proposal development and evaluation activities by collecting and disseminating TMI proposal information, reviewing proposal information to ensure that it meets the requirements of the TMI program and addresses the evaluation criteria, and coordinating information with al...

Promoted
Peraton
McLean, Virginia

In support of another IC element, responded to public and official requests for review and release of classified and/or sensitive information under the Freedom of Information Act (FOIA), Privacy (PA), and/or Mandatory Declassification Review; assisted the IC element and other relevant organizations ...

Promoted
Koniag Information Security Services, LLC
Chantilly, Virginia
Remote

Koniag Government Services company, is seeking a Senior Test Engineer to support. The selected candidate must be knowledgeable and experienced as a Quality Assurance Senior Automation Test Engineer for web applications, UI, and server-based application software testing, having experience both creati...

Olgoonik
Arlington, Virginia

The CSIS Senior Security Analyst will support Diplomatic Security at the Department of State in the Office of the Chief Technology Officer (CTO). Implement a NIST-compliant continuous monitoring process across all major information systems to provide periodic assurance to senior management on the se...

Acclaim Technical Services
Chantilly, Virginia

Senior Information Security System Engineer (ISSE). Identifying and implementing appropriate information security architectures and functionality to ensure uniform application of security policy and enterprise solutions. Bachelor’s Degree in computer science, Information Assurance, Information Secur...

Node.Digital
Arlington, Virginia

Cyber Security Subject Matter Expert (SME) / Information System Security Analyst - Principal II. M IAT Level II Technical Certification (Security+ CE, CCNA + Security, SSCP, CYSA+) or equivalent AND an Incident Response Certification (CEH, GCIH, GCIA, GNFA, or comparable certification) AND relevant ...