Cybersecurity Analysts
Core
Develop, manage, and maintain the security posture of information systems with a focus on Assessment and Authorization (A&A), continuous monitoring, and compliance with NIST & RMF.
Role type
Cybersecurity Analyst (RMF & A&A)
Builds
Security authorization packages, System Security Plans, and compliance artifacts for government systems.
Domain
US Government / Defense Information Systems
Deliverable
client delivery
Required skills
NIST 800-53, CNSSI 1253, DODI 8510.01, Risk Management Framework (RMF), System Security Plans (SSP), Security Control Traceability Matrices (SCTM), Plans of Action and Milestones (POA&Ms), vulnerability scanning, penetration testing, network architecture, LAN configuration, OS hardening, Windows Server, Unix/Linux, virtualization, Nessus, SCAP, App Detective
Preferred skills
Splunk, Elastic, AWS, Azure, GCP, ACAS training, DoD DevSecOps Fundamentals Playbook, A&A process (ICD 503), SIEM tools
Technologies
Nessus, SCAP, App Detective, VMware, Hyper-V, Virtual Box, Windows Server, Windows 10, Windows 11, Apple/MAC OS, Unix/Linux, eMASS, Xacta
Responsibilities
Implement cybersecurity best practices and identify efficiency opportunities; Support cybersecurity activities through all aspects of the systems' life cycle; Support the Risk Management Framework (RMF) lifecycle; Create, manage, and maintain A&A packages; Prepare system documentation including SSPs, SCTMs, and POA&Ms; Manage and implement Continuous Monitoring activities; Coordinate security control implementation with system administrators and engineers; Support data entry into information system security systems of record.
Seniority
Mid-Senior, hands-on IC