IT Security Analyst / Assessor
Core
Perform Certification & Accreditation (C&A) and System Assessment & Authorization (SA&A) within the NIST RMF framework to accredit systems and applications.
Role type
IT Security Analyst / Assessor
Builds
Security accreditation packages, vulnerability scan reports, and security documentation for federal government systems.
Domain
US Federal Government IT Security / Risk Management Framework (RMF)
Deliverable
client delivery
Required skills
NIST 800-53 security controls, Risk Management Framework (RMF) approach, vulnerability scanning, security control assessment, business impact analysis, contingency planning, audit log review
Preferred skills
Cyber Security Assessment Methodology (CSAM) tool
Technologies
Nessus, Foundstone, WebInspect, Hailstorm
Responsibilities
Prepare C&A and SA&A documentation, conduct vulnerability scanning and analyze results, provide technical evaluations of customer solutions, participate in business impact analysis and system categorization, conduct testing and audit log reviews
Seniority
Mid-Senior, hands-on IC