IT Security Analyst T3 (580)
sharp decisionsMcLean (VA)
About the role
Herndon, VA — Hybrid (Tue / Wed / Thu Onsite) Contract to Hire US Citizens Only No Dual Citizenship FedRAMP / RMF DoD / NIST The Security Analyst will work as a member of our client's cyber team, assisting with the creation, update, and maintenance of FedRAMP-required security documentation, associated artifacts, and Continuous Compliance Monitoring (CCM) requirements such as the Plan of Action and Milestones (POA&M). The role also supports the Cloud Operations team with identification and corrective actions associated with known vulnerabilities, and provides advisement to stakeholders on changing regulatory, government, and Cloud/FedRAMP policies — including risk assessment, business impact analysis, system categorization, security authorization and accreditation/certification activities (A&A), security control inheritance, and other artifacts needed to validate control compliance.?
Critical Requirements
Required Skills:
Compliance & Governance Understand and document information system specifications and security controls, including logical and physical diagrams, connectivity, communication, and data flow diagrams — both internal and external to the system Advise stakeholders on multiple courses of action in environments with changing or unconfirmed policy (e.g., NIST RMF, DISA SRG)Document courses of action and identify risk mitigation recommendations in accordance with FedRAMP requirements, client policy, and best practices — including associated benefits and drawbacks Apply enterprise security frameworks (FISMA, NIST SP 800, etc.) to existing cloud environment initiatives Develop and update policies and procedures to implement FedRAMP compliance, NIST 800-171 security requirements, and other DFAR clauses Demonstrate familiarity with current FedRAMP, DoD, and NIST security controls and technologies, including vulnerability management capabilities Identify and assess cloud system state including vulnerabilities, RMF package status, accreditation model, PPS compliance, and patching/CSVA mechanisms Vulnerability Management Knowledge of Risk-Based Vulnerability Framework and how to prioritize, assess, and remediate exploitable vulnerabilities Ability to create automation scripts to minimize manual workload behind identifying and analyzing vulnerabilities across various scanning tools Ability to analyze container vulnerabilities in secure cloud environments and identify remediation paths at the OS and application level Understand enterprise operating environments including security posture, application environment, and associated security controls Required Technical Experience
Technical Skills:
Python, Bash, Java & Power Shell Scripting Container Scanning Tools CI/CD Pipelines & AWS ECR Container Image Mirroring Attack Vector Analysis Network Diagrams & Visio SAP Products Testing / Dev / Staging Environments RMF & Compliance Experience Demonstrated knowledge and ability to analyze systems for cybersecurity compliance Knowledge of Federal and DoD policies and risk assessment methodologies including FedRAMP, NIST SPs, and RMF overlays Hands-on experience with DISA STIG requirements and SRGs, CNSSI, and NIST Risk Management Framework Experience writing or executing system security documentation, Authorization to Operate (ATO) packages, POA&Ms, and policies Knowledge and understanding of systems and networking technologies and concepts Ability to interpret and assess network diagrams using Visio Familiarity with Testing, Development, Staging, and pre-production environments requiring cybersecurity support Knowledge of the Privacy Act Presentation and public speaking skills required Ability to work in a fast-paced, team-oriented environment
Before you apply
Applying takes about a minute. These four things decide how fast it moves after that.
Your profile is current
It's what we read first. Occupations, seniority and locations matter more than a long history.
Two examples you can talk through
Not a portfolio — just two pieces of work where you can explain the decisions and what you'd change.
A number in mind
What you're on now and what would make you move. We negotiate better when we know both.
Your notice period
Employers plan around it, and it's the question that stalls offers most often.
Once you apply, someone reads it and calls you before anything reaches the employer — usually within two working days.
More like this
