Cybersecurity Analyst, RMF & ATO

JBS International

Los Angeles (CA)

Hybrid

USD 90,000 - 150,000

Full time

7 days ago
Be an early applicant
Application generator

A complete application in a minute — tailored resume and cover letter, ready to send.

Get past ATS filters

Job summary

JBS International seeks a Cybersecurity Analyst to support cybersecurity, information assurance, risk management, and compliance across Digital Services initiatives. The role serves as the ISSO for assigned federal systems and environments, assisting with ATO activities throughout the solution lifecycle.

You will work with engineering, architecture, product, and operations to embed security into the SDLC, conduct security assessments, and monitor continuously.

Qualifications

  • Bachelor's degree in Cybersecurity, Computer Science, Information Technology, Engineering, or a related field.
  • 3 years of experience supporting cybersecurity, information assurance, security compliance, enterprise security, or risk management programs.
  • 3 years of experience applying federal cybersecurity frameworks and standards (e.g., FISMA, RMF, NIST 800-53).
  • 3+ years of experience supporting ATO/SA&A, continuous monitoring, or related activities.
  • Experience developing/security documentation (SSPs, SAPs, SARs, POA&Ms).
  • Experience coordinating with software engineering, cloud, infrastructure, architecture, product teams to embed security requirements.
  • Knowledge of cloud platforms (AWS/Azure) and IAM; SDLC security best practices.
  • Professional cybersecurity certifications (e.g., Security+, CySA+, CISSP, CGRC, SSCP) required.
  • Strong written and verbal communication skills.

Responsibilities

  • Provide cybersecurity and privacy subject matter expertise across digital products, cloud services, and enterprise apps.
  • Advise teams on IAM, security controls, data protection, and SDLC security practices.
  • Review system designs to identify risks and mitigations.
  • Collaborate with engineering and product teams to integrate security requirements.
  • Support alignment with federal cybersecurity, privacy, and risk management requirements.
  • Coordinate vulnerability identification and remediation activities with engineering and operations teams.
  • Review vulnerability findings and support remediation and audit activities.
  • Assist in governance and documentation to improve security posture and risk visibility.

Skills

Cybersecurity
Information Assurance
Risk Management
Compliance
Security Assessments
IAM

Education

Bachelor's degree in Cybersecurity or related field

Tools

Tenable
Nessus
AWS Inspector
Microsoft Defender

Job description

The Cybersecurity Analyst provides cybersecurity, information assurance, risk management, and compliance support across Digital Services initiatives. The role supports Authorization to Operate (ATO) activities, continuous monitoring, security assessments, vulnerability management, and implementation of federal cybersecurity requirements while collaborating with engineering, architecture, product, infrastructure, and program teams throughout the solution lifecycle. The Cybersecurity Analyst will serve as the Information System Security Officer (ISSO) for assigned federal systems and environments.

This position contributes to cybersecurity governance, develops and maintains security documentation, supports security assessments and audits, and helps ensure digital products, cloud environments, and enterprise technology solutions meet applicable federal security and privacy requirements.

Essential Job Functions
Cybersecurity Advisory & Secure Solution Delivery
  • Provide cybersecurity and privacy subject matter expertise across digital products, cloud services, enterprise applications, AI initiatives, and technology modernization efforts.

  • Advise project teams on identity and access management, security controls, data protection, authorization boundaries, and cybersecurity best practices throughout the system development lifecycle.

  • Review technical solutions, architectures, and proposed system changes to identify security risks and recommend appropriate mitigations.

  • Collaborate with software engineering, infrastructure, architecture, product, and data teams to integrate security requirements into solution planning, development, testing, deployment, and operational support.

  • Support alignment of technology initiatives with applicable federal cybersecurity, privacy, and risk management requirements.

Risk Management & Compliance
  • Support identification, analysis, documentation, and tracking of cybersecurity and compliance risks across systems, applications, cloud environments, and operational activities.

  • Conduct or support security assessments, compliance reviews, technical evaluations, and security control validation activities.

  • Contribute to governance reviews, technical assessments, risk recommendations, and cybersecurity decision support.

  • Assist in developing and maintaining cybersecurity policies, procedures, standards, and implementation guidance.

  • Support continuous improvement of security posture, compliance maturity, and enterprise risk visibility.

Authorization to Operate (ATO) & Security Authorization
  • Support Authorization to Operate (ATO) and Security Assessment and Authorization (SA&A) activities throughout the system lifecycle.

  • Develop, coordinate, maintain, and update authorization documentation, including System Security Plans (SSPs), Security Assessment Plans (SAPs), Security Assessment Reports (SARs), Plans of Action and Milestones (POA&Ms), and related security artifacts.

  • Coordinate security assessments, evidence collection, remediation activities, and documentation required to obtain and maintain system authorization.

  • Support authorization decisions by collaborating with governance bodies, Authorizing Officials, Information System Security Managers (ISSMs), system owners, and technical teams.

  • Advise project teams on authorization boundaries, security categorization, inheritance, and applicable federal security requirements.

  • Support continuous monitoring activities necessary to maintain ongoing authorization.

Security Operations & Continuous Monitoring
  • Coordinate vulnerability identification, remediation tracking, and verification activities in collaboration with engineering, infrastructure, and operations teams.

  • Review vulnerability scan results, assess security findings, monitor corrective actions, and track remediation through completion.

  • Support security incident response activities through documentation, coordination, evidence collection, corrective action tracking, and lessons learned.

  • Monitor changes to systems and cloud environments to help ensure continued compliance with approved security baselines.

  • Support internal and external audits through evidence collection, documentation, corrective action management, and audit response activities.

Governance, Collaboration & Delivery Integration
  • Coordinate with project managers, architects, developers, Corporate IT, Data & AI, and governance stakeholders to ensure cybersecurity considerations are integrated throughout project planning and delivery.

  • Participate in development of governance materials, executive briefings, technical documentation, reports, and other artifacts requiring cybersecurity or compliance input.

  • Promote secure development practices and provide guidance on applicable cybersecurity requirements across Digital Services initiatives.

  • Contribute to the continuous improvement of cybersecurity templates, operational procedures, documentation standards, and governance processes.

Minimum Qualifications
  • Bachelor's degree in Cybersecurity, Computer Science, Information Technology, Engineering, or a related field.

  • 3 years of experience supporting cybersecurity, information assurance, security compliance, enterprise security, or risk management programs.

  • 3 years of experience applying federal cybersecurity frameworks and standards, including FISMA, NIST Risk Management Framework (RMF), NIST SP 800-53, FICAM, or comparable federal requirements.

  • 3+ years of experience supporting Authorization to Operate (ATO), Security Assessment and Authorization (SA&A), continuous monitoring, or related authorization activities.

  • Experience supporting the security lifecycle of one or more FIPS 199 Moderate-impact federal information systems, including security documentation, security control implementation, assessment support, Authorization to Operate (ATO), and continuous monitoring activities.

  • Experience developing and maintaining security authorization documentation, including SSPs, SAPs, SARs, POA&Ms, and related security artifacts.

  • Experience supporting security assessments, compliance reviews, vulnerability management, audit support, or enterprise risk management activities.

  • Experience collaborating with software engineering, cloud, infrastructure, architecture, product, and project teams to integrate cybersecurity requirements into technology solutions.

  • Working knowledge of cloud platforms (AWS and/or Azure), identity and access management, secure system development lifecycle (SDLC), and cybersecurity best practices.

  • One or more professional cybersecurity certifications such as CompTIA Security+, CompTIA CySA+, ISC2's Certified in Cybersecurity (CC), Certified in Governance, Risk and Compliance (CGRC), Systems Security Certified Practitioner (SSCP), or an equivalent cybersecurity certification is required.

  • Strong analytical, organizational, written, and verbal communication skills with the ability to communicate effectively with both technical and non-technical stakeholders.

Security Clearance
  • This position requires the ability to obtain a Public Trust.

Location
  • Remote with the consideration that if a candidate lives within a 50-mile radius of JBS's North Bethesda, MD or San Mateo, CA offices, the position will be considered hybrid.

Physical Requirements
  • Ability to sit forprolonged periods at a desk or computer workstation.

  • Regularly uses a computer, keyboard, and mouse.

  • Normal or corrected vision to read documents, view computer screens, and perform tasks that require visual accuracy.

  • Ability to hear and understand spoken information in person and over the phone.

  • Minimal lifting and carrying may be required, typically light office supplies or documents.

  • Ability to move within the office environment to access equipment, files, and interact with colleagues.

  • Ability to handle occasional stress related to deadlines, workloads, or challenging tasks.

Preferred Qualifications
  • Advanced cybersecurity certifications such as ISC2 CISSP, ISACA CISM, or equivalent.

  • Experience supporting FedRAMP-authorized cloud environments.

  • Experience with vulnerability management and security assessment tools such as Tenable, Nessus, AWS Inspector, Microsoft Defender, or comparable technologies.

  • Familiarity with DevSecOps, secure software development lifecycle (Secure SDLC), or cloud-native application security practices.

  • Experience supporting web applications, cloud-native solutions, AI-enabled technologies, APIs, or enterprise business systems.

  • Experience supporting privacy, data protection, or governance initiatives within federal environments.

Other Duties Assigned

This position description should not be construed to imply that these requirements are the exclusive standards of the position, nor will it be the sole basis for any subsequent employee evaluations. Incumbents will follow any other instructions and perform any other related duties as may be required by their supervisor.

This position is subject to availability of funds and to any and all restrictions contained in the contract or contracts that provide funding for this position.

Our company is an equal opportunity/affirmative action employer. Applicants can learn more about the company's status as an equal opportunity employer by viewing the federal "EEO" poster at EEOPost.pdf. Qualified applicants will receive consideration for employment without regard to race, color, religion, sex, gender identity, sexual orientation, national origin, disability, or protected Veteran status.

If you need a reasonable accommodation for any part of the employment process, please contact us by email at jobs@jbsinternational.com and let us know the nature of your request and your contact information.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Cybersecurity Analyst, RMF & ATO
Cybersecurity Analyst, RMF & ATO

JBS International • San Mateo (CA)

Hybrid
USD 120,000 - 160,000
Cybersecurity Analyst, RMF & ATO
Cybersecurity Analyst, RMF & ATO

JBS International • North Bethesda (MD)

Hybrid
USD 90,000 - 130,000
Cybersecurity Analyst, RMF & ATO
Cybersecurity Analyst, RMF & ATO

JBS International • Hayward Park (CA)

Hybrid
USD 120,000 - 150,000
Cybersecurity Analyst, RMF & ATO
Cybersecurity Analyst, RMF & ATO

JBS International • Virginia Beach (VA)

Hybrid
USD 90,000 - 140,000
Cybersecurity Analyst, RMF & ATO
Cybersecurity Analyst, RMF & ATO

JBS International, Inc. • San Mateo (CA), Northern (KY)

Hybrid
USD 110,000 - 150,000
401(k) contributions
Tuition assistance
Employee recognition program
+2
Cybersecurity Systems Analyst, Sr.
Cybersecurity Systems Analyst, Sr.

TJ Consulting Group • Coronado (CA)

On-site
USD 120,000 - 170,000
PTO
Holiday Pay
401K with a 4% Match
+13
Senior Security Analyst – ATO / RMF (Active TS/SCI Clearance)
Senior Security Analyst – ATO / RMF (Active TS/SCI Clearance)

Strategic Business Systems • Chantilly (VA)

On-site
USD 140,000 - 195,000
Telework and flexible schedule where
401(k) retirement plan with company 4%
Paid Time Off and holidays
+1
Cybersecurity Systems Analyst, Intermediate
Cybersecurity Systems Analyst, Intermediate

TJ Consulting Group • Fort Walton Beach (FL)

On-site
USD 90,000 - 120,000
PTO
Holiday Pay
401K with Match
+6
Compliance & Audit Support (Mid)
Compliance & Audit Support (Mid)

Koniag Government Services • Washington

Hybrid
USD 70,000 - 110,000
Health, dental and vision insurance
401K with company matching
Flexible spending accounts
+2
Cybersecurity Analyst
Cybersecurity Analyst

Amentum • McLean (VA)

On-site
USD 130,000 - 160,000
Health Insurance
Dental Insurance
Vision Insurance
+2