Information Assurance Analyst DoS CSS

OneZero Solutions

Washington (District of Columbia)

Remote

USD 85,000 - 110,000

Full time

7 days ago
Be an early applicant
Application generator

Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.

Get past ATS filters

Benefits offered by this job

Health insurance
Dental insurance
Vision insurance
Life insurance
401(k) with company matching
Paid time off
Holiday pay
Employee referral program
Educational assistance

Job summary

OneZero Solutions is seeking an Information Assurance Analyst to support RMF and continuous monitoring for government systems. You will prepare authorization artifacts, manage evidence and POA&Ms, and coordinate assessments and contingency tests while ensuring audit readiness.

Remote within the National Capital Region (NCR) with occasional travel as needed. The role requires 3+ years of information assurance experience, DoD 8570/IAT level certification or equivalent, and an active SECRET

Qualifications

  • Three or more years of information assurance or cybersecurity compliance experience with hands-on exposure to NIST RMF / FISMA
  • Knowledge of NIST SP 800-53 Rev. 5, SP 800-37 Rev. 2, and FIPS 199; SSP, POA&M, and contingency plan structure
  • DoD 8140/8570 IAT II or IAM I baseline certification or ability to obtain within 6 months
  • Active, final SECRET security clearance; U.S. citizenship
  • Strong written communication and attention to detail; ability to produce government-format documents
  • Proficiency with Word, Excel, PowerPoint, Visio, and SharePoint

Responsibilities

  • Develop and update RMF artifacts (SSP sections, POA&M entries, system inventories, data-flow diagrams)
  • Build and maintain evidence index, inherited controls matrix, and data packages
  • Review iPost scores weekly and track remediation status
  • Update POA&M entries in the GRC tool within 5 business days of status changes
  • Review vulnerability and compliance scan results and document remediation in POA&M(s)
  • Support annual Contingency Plan tests and Annual Control Assessments
  • Prepare Security Control Review materials and assist with control demonstrations (RMF Step 4)
  • Capture meeting minutes and maintain action-item logs
  • Assemble Audit and Data Call Response Packages and respond to data calls within timelines
  • Register and maintain system records in the GRC tool; support asset inventory
  • Collect data for quarterly FISMA metrics and weekly reports

Skills

Information assurance
Cybersecurity compliance
NIST RMF

Education

Bachelor's degree in Computer Science, Information Technology, Cybersecurity

Tools

NIST SP 800-53 Rev. 5
NIST SP 800-37 Rev. 2
FIPS 199
SSP/POA&M
Tenable/Nessus
Wiz
STIG tooling

Job description

We are an employee-centric company that truly values our team members and the contributions they make to our customers and the missions they support. We pride ourselves on being forward-leaning thinkers and on building teams that are, and continue to be, technically proficient across a broad range of cyber mission areas. OneZero full-time employees receive a highly competitive benefits package, including health, dental, vision, and life insurance, a 401(k) with company matching, paid time off and holidays, an employee referral program, and educational assistance. Additional details are available on our website: https://www.onezerollc.com/careers/

Position Title: Information Assurance Analyst

Location: Remote; must reside within the National Capital Region (NCR).

Work Schedule: Full-time, 40 hours per week. Must be available during Department core hours of 9:00 a.m. – 3:00 p.m. ET, Monday – Friday, and flex working hours as needed to meet CST day-to-day and emergent requirements. No work is performed on Federal holidays or during Government closures.

Employment Type: Full-Time, Exempt (W-2), contingent upon Call Order award

Clearance: Secret

Position Summary

The Information Assurance Analyst supports SME and Senior Information Security Analysts in operating the Risk Management Framework and continuous monitoring program for DT/EA/CST consular systems. The Analyst develops and maintains authorization artifacts and evidence, runs the weekly and monthly continuous monitoring cadence, supports assessments and contingency plan tests, and captures the meeting minutes and data-call responses that keep systems audit-ready. Analysts who demonstrate proficiency may be assigned as ISSO of record for lower-complexity systems.

Key Responsibilities
  • Develop and update RMF artifacts under the direction of the assigned ISSO: SSP sections and Security Control Implementation Statements, POA&M entries, system inventories, network and data-flow diagrams, SIAs, and CP/IRP/CMP updates.
  • Build and maintain the Evidence Index, Inherited Controls Matrix, and System Boundary & Data Flow Package for assigned systems; collect configuration baselines, SOPs, ACLs, screenshots, and log samples as control evidence (RMF Steps 1–3).
  • Review iPost scores weekly for assigned systems, identify findings driving elevated risk, and track remediation status; maintain the list of findings open more than 30 days.
  • Update POA&M entries in the GRC tool at least monthly and within 5 business days of status changes; gather and attach closure evidence for ISSO validation.
  • Review vulnerability and compliance scan results within 5 business days of scan completion; track critical and high findings to BOD timelines; document remediation in POA&M(s).
  • Support annual Contingency Plan tests and Annual Control Assessments: draft test plans, coordinate participants, record results and lessons learned.
  • Prepare Security Control Review Meeting materials and collect artifacts requested by the Security Control Assessor; assist with control demonstrations (RMF Step 4).
  • Capture and distribute meeting minutes for system meetings; maintain action-item logs.
  • Assemble Audit and Data Call Response Packages (SSP, POA&Ms, vulnerability reports, assessment results, CP test reports) and respond to HVA, BOD, OMB, OIG, and CDM data calls within DT/EA/CST timelines.
  • Register and maintain system records in the GRC tool; support asset inventory and iPost application grouping accuracy.
  • Collect data for quarterly FISMA metrics and weekly Issue Resolution, Remediation Status, and Risk Acceptance Recommendation reports.
Required Qualifications
  • Three (3)+ years of information assurance or cybersecurity compliance experience with hands-on exposure to NIST RMF / FISMA authorization activities.
  • Working knowledge of NIST SP 800-53 Rev. 5, SP 800-37 Rev. 2, and FIPS 199, and of SSP, POA&M, and contingency plan structure.
  • DoD 8140/8570 IAT Level II or IAM Level I baseline certification (e.g., Security+ CE, CySA+, SSCP, CGRC/CAP) or ability to obtain within 6 months.
  • Active, final SECRET security clearance; U.S. citizenship.
  • Strong written communication and attention to detail; able to produce Government-format documents.
  • Proficiency with Microsoft Word, Excel, PowerPoint, Visio, and SharePoint.
Preferred Qualifications
  • CISSP or Associate of ISC2, CGRC/CAP, or CISA.
  • Department of State experience; ArchAngel and iPost familiarity.
  • Experience interpreting Tenable/Nessus, Wiz, or STIG scan output.
  • Familiarity with cloud (AWS/Azure) security concepts and FedRAMP.
Technical Skills
  • NIST SP 800-53 Rev. 5 control families and implementation statements; POA&M lifecycle; FIPS 199 categorization.
  • GRC platforms (ArchAngel or equivalent) and continuous monitoring dashboards (iPost or equivalent).
  • Reading vulnerability and compliance scan results (Tenable, Wiz, STIG Viewer, SCAP).
  • Visio, Word, Excel, SharePoint; disciplined version control and document management.
Education

Bachelor's degree in Computer Science, Information Technology, Cybersecurity, or a related field preferred; an additional four (4) years of directly relevant experience may substitute for the degree.

Remote/Hybrid/On-site and any other relevant work-environment requirement

Remote. Duties are performed remotely; the selected candidate must reside within the National Capital Region (NCR). The Government does not furnish equipment; OneZero provides the laptop and collaboration tools. Position requires an OpenNet account, DoS PIV badge, multifactor authentication, and adherence to DoS SBU/CUI handling requirements. Local travel within the National Capital Region; minimal other travel.

Position Status:

New Position, contingent upon Call Order award

OneZero Solutions LLC is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability, or protected veteran status.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Senior Information Security Analyst DoS CSS
Senior Information Security Analyst DoS CSS

OneZero Solutions • Washington

Remote
USD 110,000 - 170,000
Health, dental, vision, life insurance
401(k) with company matching
Paid time off and holidays
+2
Senior Information Security Analyst DoS CSS
Senior Information Security Analyst DoS CSS

OneZero Solutions • Washington

Remote
USD 110,000 - 150,000
SME – Information Security Analyst DoS CSS
SME – Information Security Analyst DoS CSS

OneZero Solutions • Washington

Remote
USD 150,000 - 190,000
Health insurance
Dental insurance
Vision insurance
+6
ISSO Lead DoS CSS
ISSO Lead DoS CSS

OneZero Solutions • Washington

Remote
USD 140,000 - 190,000
Health insurance
Dental insurance
Vision insurance
+5
Program Manager DoS CSS
Program Manager DoS CSS

OneZero Solutions • Washington

Remote
USD 150,000 - 210,000
Health, dental, vision, life insurance
401(k) with company matching
Paid time off and holidays
+2
Deputy Program Manager DoS CSS
Deputy Program Manager DoS CSS

OneZero Solutions • Washington

Remote
USD 120,000 - 160,000
Health insurance
Dental insurance
Vision insurance
+5
Information Assurance Specialist III
Information Assurance Specialist III

OneZero Solutions • Arlington (VA)

On-site
USD 110,000 - 150,000
Health insurance
Dental insurance
Vision insurance
+5
Information Assurance Specialist III
Information Assurance Specialist III

onezerollc • Arlington (VA)

Hybrid
USD 120,000 - 150,000
Health insurance
Dental insurance
Vision insurance
+6
Technical Writer DoS CSS
Technical Writer DoS CSS

OneZero Solutions • Washington

Remote
USD 90,000 - 130,000
Health insurance
Dental insurance
Vision insurance
+6
Cybersecurity SME Level II
Cybersecurity SME Level II

OneZero Solutions • Alexandria (VA)

On-site
USD 120,000 - 150,000
Health insurance
Dental insurance
Vision insurance
+6