Cybersecurity Analyst

Paycom

Bethesda (MD)

On-site

USD 95,000 - 130,000

Full time

8 days ago
Application generator

A complete application in a minute — tailored resume and cover letter, ready to send.

Get past ATS filters

Job summary

TIAG is hiring a Cyber Security Analyst to support USUHS in Bethesda, MD. The role focuses on modernizing RMF ATO packages for Google Cloud, Google Workspace, and ServiceNow GCC-High to IL-4.

You will craft narratives, manage POAMs, and ensure accurate control mappings in eMASS/ServiceNow environments. Required active DoD Secret clearance, IAM/IAT Level certifications, and 2+ years of cyber experience with RMF and control narratives.

Qualifications

  • DoD 8140/8570 IAT Level II or IAM Level I equivalent certs required (Security+ CE, CASP/CGR C, SSCP etc).
  • Experience writing control narratives and tracking POAMs in RMF ATO processes.
  • Familiarity with RMF, NIST SP 800-53 Rev.5, and DoD IL-4 requirements.

Responsibilities

  • Support RMF lifecycle from gap analysis to final ATO package closeout recommendations.
  • Create and modernize RMF packages: SSP, SAR, POA&M, and Continuous Monitoring Plan.
  • Draft control narratives reflecting actual system configurations (not generic baselines).
  • Prepare and manage POA&Ms for identified gaps requiring remediation.
  • Upload and map artifacts to Control Objectives in ServiceNow GRC.

Skills

IAT Level II / IAM Level I cert
RMF
DoD 8140/8570 familiarity
2+ years cyber security
ServiceNow GRC
eMASS / Xacta experience
HitL validation
Control narratives development
FedRAMP assessment familiarity

Tools

eMASS
Xacta
CSAM
ServiceNow GRC

Job description

TIAG is hiring Cyber Security Analyst to support our team at the Uniform Services University of Health Sciences (USUHS) in Bethesda, MD. The Cyber Analyst will support the modernization of the Authorization to Operate (ATO) packages for enterprise platforms, specifically targeting Google Cloud, Google Workspace, and ServiceNow GCC-High instances.This role focuses on transitioning system environments from legacy NIST SP 800-53 Revision 3 documentation and existing DISA eMASS baselines to completely modernized, organizationally tailored NIST SP 800-53 Revision 5 and DoD Impact Level 4 (IL-4) authorization packages.Key ResponsibilitiesProvide comprehensive support across the full RMF lifecycle, driving the ATO modernization process from initial gap analysis through final package validation and closeout recommendations.Create and modernize complete RMF authorization packages, which must include the System Security Plan (SSP), Security Assessment Report (SAR), Plan of Action and Milestones (POA&M), and Continuous Monitoring Plan.Draft and refine implementation-specific control narratives (answering controls) to ensure they accurately reflect the system's actual configuration, directly replacing generic baseline statements.Develop, document, and manage POA&Ms for any control gaps identified during technical discovery that require future remediation.Prepare all required fields, supporting documentation, artifacts, and attachments to support eMASS readiness and Government upload.Upload and map artifacts, technical evidence, control responsibilities, and POA&M information to individual Control Objectives within the ServiceNow GRC Policy and Compliance module.Evaluate Cloud Service Provider FedRAMP packages to determine control inheritance, tailoring the baseline to reflect local Agency implementation, shared responsibilities, and DoD IL-4 requirements.Perform 100% Human-in-the-Loop (HitL) validation on all AI-assisted technical content to ensure narratives accurately address Rev 5 controls and contain no unsupported technical statements.Document organizational tuning decisions in coordination with system stakeholders, capturing risk acceptances, organizational overrides, compensatory mitigations, and tool-specific authorizations.Required Experience:Active DoD Secret clearance required.DoD 8140/8570 IAT Level II or IAM Level I certification required (e.g., Security+ CE, CAP/CGRC, SSCP). Note: IAM Level II (e.g., CASP+, CISM) is highly preferred.2+ years of relevant cybersecurity and information assurance experience, with hands-on exposure to writing control narratives, tracking POAMs, and supporting the RMF ATO process.Ability to collaborate seamlessly with a specialized technical team, supporting the efforts of the Senior Cloud Security Engineer, Senior ISSE, and Senior ServiceNow GRC Specialist.Familiarity with the Risk Management Framework (RMF), NIST SP 800-53 Revision 5, and DoD Cloud Computing Security Requirements Guide IL-4.Hands-on experience preparing artifacts and required fields using an RMF repository (e.g., eMASS, Xacta, CSAM).Familiarity with ServiceNow GRC or similar platforms, with an understanding of mapping granular evidence to Control Objectives rather than bulk document uploads.Technical ability to understand actual system realities and translate them into accurate control narratives, moving beyond generic baseline statements.Active DoD Secret clearance required.Strong technical validation skills to ensure control narratives align with actual system realities rather than generic baseline statements.TIAG is an equal opportunity employer and federal contractor or subcontractor. Consequently, the parties agree that, as applicable, they will abide by the requirements of 41 CFR 60-1.4(a), 41 CFR 60-300.5(a), and 41 CFR 60-741.5(a) and employment decisions shall be based solely on merit and without regard disability, or protected veteran status, or any other characteristic protected by local, state, or federal laws, rules, or regulations. TIAG takes proactive steps to employ and advance in employment qualified individuals without regard to disability or protected veteran status. The parties also agree that, as applicable, they will abide by the requirements and may be subject and required to take action pursuant to the following laws and accompanying regulations:The Vietnam Era Veterans Readjustment Assistance Act of 1974, as amended (and its implementing regulations at 41 C.F.R. 60-300);Section 503 of the Rehabilitation Act of 1973, as amended (and its implementing regulations at 41 C.F.R 60-741); andExecutive Order 13496 (and its implementing regulations at 29 C.F.R. part 471, Appendix A to Subpart A).
Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Cybersecurity Analyst
Cybersecurity Analyst

TIAG • Bethesda (MD)

On-site
USD 80,000 - 90,000
SIEM Modernization Security Engineer
SIEM Modernization Security Engineer

TIAG • Chevy Chase (MD)

Hybrid
USD 130,000 - 170,000
SIEM Architect
SIEM Architect

TIAG • Chevy Chase (MD)

Hybrid
USD 140,000 - 170,000
Cybersecurity Analyst
Cybersecurity Analyst

Paycom • Brunswick (GA)

Remote
USD 90,000 - 120,000
Junior Endpoint Engineer
Junior Endpoint Engineer

TIAG • Chevy Chase (MD)

Hybrid
USD 70,000 - 100,000
IT Support Specialist
IT Support Specialist

TIAG • Chevy Chase (MD)

On-site
USD 42,000 - 64,000
Enterprise Architect
Enterprise Architect

Informatics Applications Group Inc • Arlington (VA)

On-site
USD 160,000 - 190,000
Systems Engineer
Systems Engineer

TIAG • Mount Pleasant (SC)

On-site
USD 120,000 - 140,000
Systems Engineer / Windows Administrator
Systems Engineer / Windows Administrator

Paycom • Arlington (VA)

On-site
USD 120,000 - 160,000
Equal opportunity employer
On-site work at ONR Arlington
Cybersecurity Analyst — RMF ATO & DoD IL-4
Cybersecurity Analyst — RMF ATO & DoD IL-4

Paycom • Bethesda (MD)

On-site
USD 95,000 - 130,000