Information Assurance Support Analyst with Security Clearance

Astrion

Rockville (MD)

On-site

USD 90,000 - 130,000

Full time

11 hours ago
Be an early applicant
Application generator

Stand out for this role — generate a tailored resume and cover letter in about a minute.

Get past ATS filters

Job summary

Astrion is seeking an Information Assurance Support Analyst in Rockville, MD to support NRC-CPSS contracts. The role requires security clearance eligibility, strong IA expertise, and experience with RMF, NIST SPs, and FedRAMP.

The candidate will collaborate with system admins, ISSOs, and AO to ensure security across the system lifecycle. The position involves performing vulnerability assessments, supporting security documentation, and reviewing cloud-based FedRAMP packages with attention to risk

Qualifications

  • BA/BS or 5 years additional equivalent experience.
  • 6 years IT experience, with 4 years specialized in Information Assurance.
  • Secret Clearance; the ability to obtain an NRC Security Clearance; US citizenship required
  • Must hold at least one of the stated certifications (e.g., Security+, CISSP, CISA, GIAC certifications)
  • Strong understanding of FISMA and NIST SP 800-37/800-53
  • Experience with vulnerability scanning tools (Tenable) and CIS benchmarks
  • Knowledge of cloud models (SaaS, PaaS, IaaS) and FedRAMP security documentation
  • Experience reviewing FedRAMP packages and risk sharing responsibilities

Responsibilities

  • Work with system admins, ISSOs, and AO to support FISMA systems through SA&A.
  • Assess confidentiality, integrity, and availability impact levels and determine FIPS 199 categorization.
  • Develop and maintain RMF system security documentation across all phases.
  • Analyze risks from security control assessments per NIST SP 800-30 and recommend mitigations.
  • Perform vulnerability scans and configuration compliance checks against DISA STIGs and CIS Benchmarks.
  • Analyze FedRAMP security packages to document customer responsibilities for cloud-based services.
  • Review monthly CSPs' continuous monitoring deliverables and third-party assessments for FedRAMP.
  • Create and track POA&Ms; participate in project meetings to ensure security throughout lifecycle.

Skills

IT experience
IA specialization
Security clearance
NIST RMF/NIST SP 800-53
Vulnerability scanning
Cloud platforms (Azure/AWS)
PowerShell scripting
Strong communication

Education

BA/BS or 5 years additional equivalent experience

Tools

Tenable Security Center
DISA STIGs/SCAP
CIS Benchmarks
FedRAMP knowledge
Azure/AWS tooling

Job description

Overview Information Assurance Support Analyst LOCATION: Rockville, MD CLEARANCE: NRC Clearance JOB STATUS: Full-Time TRAVEL: 10% Occasional Domestic Travel Astrion has an exciting opportunity for a Information Assurance Support Analyst for the NRC-CPSS Contract, supporting the Civilian Division.

Required Qualifications / Skills
  • BA/BS or 5 years additional equivalent experience
  • 6 years IT experience, with 4 years specialized in Information Assurance
  • Secret Clearance; the ability to obtain an NRC Security Clearance; US citizenship required
  • Must hold at least one of the following certifications: CompTIA Security+, CISSP, ISACA CISA, GIAC GSEC, GIAC GSNA, GIAC GPEN, CEH, CAP, CASP+, CRISC, or CCSK PREFERRED QUALIFICATIONS / SKILLS
  • A strong understanding of FISMA and NIST Special Publications, especially NIST SP 800-37 and NIST SP 800-53
  • Excellent written and oral communication skills; attention to detail is a must
  • Experience with vulnerability scanning tools, such as Tenable Security Center
  • Working knowledge of DISA STIGs, SCAP content/ audit files, and CIS Benchmarks
  • Understanding of cloud service models (SaaS, PaaS, IaaS) and protections as described in FedRAMP security documentation
  • Experience reviewing FedRAMP authorization packages and understanding how to ensure customer responsibilities are addressed in accordance with the shared responsibility model
  • Experience with performing technical architecture reviews of complex systems with a strong understanding of a system's authorization
  • Knowledge of major cloud platforms (Azure/ Amazon Web Services [AWS]), virtualization, networking devices (e.g., routers and switches), web services (e.g., IIS, Apache Tomcat), network security appliances (e.g., firewalls, VPNs), databases (e.g., Microsoft SQL), and intrusion prevention/ anti-malware software
  • Knowledge of system and application security threats and vulnerabilities
  • Proficiency with Microsoft Office applications
  • Ability to prioritize and complete tasks efficiently and effectively
  • Comfortable working individually and as part of a team
  • Scripting ability (e.g., PowerShell, VBA) is a plus
  • Familiarity with the use of artificial intelligence (AI) tools such as chat technologies to enhance personal productivity
Responsibilities
  • Work closely with all levels of personnel, including system administrators, Information System Security Officers (ISSOs), and Authorizing Official (AO), to support FISMA systems through the Security Assessment & Authorization (SA&A)
  • Assess the confidentiality, integrity, and availability impact levels of information stored, possessed, and transmitted by systems to determine the FIPS 199 security categorization
  • Develop and maintain system security documentation throughout all phases of the NIST Risk Management Framework (RMF). This includes security categorizations, digital identity risk assessments, system security plans, system policy and procedures, privacy impact assessments, contingency plans, configuration management plans, incident response plans, vulnerability assessment reports, deviation requests, and any other documents necessary to support systems' authorization and continuous monitoring
  • Analyze risks identified during security control assessments and continuous monitoring activities in accordance with NIST SP 800-30. This includes making a determination regarding the likelihood and impact of the risk being exploited, along with a supporting rationale, and providing recommendations for mitigation/remediation
  • Perform and document the results of vulnerability scans and configuration compliance checks against configuration standards such as DISA STIGs and CIS Benchmarks
  • Analyze FedRAMP security packages to document and assess customer responsibility for cloud-based
  • Assist in the review of monthly continuous monitoring deliverables produced by Cloud Service Providers (CSPs) and annual assessments (produced by third party assessors [3PAOs]) in support of FedRAMP requirements to ensure that cloud services maintain an appropriate risk
  • Create, track, and manage system Plans of Action and Milestones (POA&Ms)
  • Attend project meetings and collaborate with stakeholders to ensure security is addressed throughout the entire system lifecycle
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Information Assurance Analyst Senior
Information Assurance Analyst Senior

Paragon Technology Group, Inc. • Washington

On-site
USD 120,000 - 180,000
Information Assurance Specialist I (Information Security Analyst)
Information Assurance Specialist I (Information Security Analyst)

By Light Professional IT Services • Butlerville (IN)

On-site
USD 70,000 - 90,000
Information Assurance Analyst Senior
Information Assurance Analyst Senior

Paragon Technology Group • Washington

On-site
USD 120,000 - 170,000
Information Assurance Analyst Senior
Information Assurance Analyst Senior

Paragon • Washington

On-site
USD 110,000 - 160,000
Information Assurance Analyst Senior
Information Assurance Analyst Senior

Paragon Technology • Washington

On-site
USD 120,000 - 170,000
Information Assurance Engineer
Information Assurance Engineer

Agile IT Synergy, LLC • Tampa (FL)

On-site
USD 90,000 - 130,000
Sr. Information Assurance Specialist
Sr. Information Assurance Specialist

NR Labs LLC • Washington, Northern (KY)

Hybrid
USD 140,000 - 190,000
Information Assurance Security Engineer
Information Assurance Security Engineer

Jobtailor • Town of Montana (WI)

On-site
USD 100,000 - 160,000
Information Security Analyst
Information Security Analyst

CALIBRE Systems Inc • Washington

Hybrid
USD 80,000 - 90,000
Information Assurance Security Specialist
Information Assurance Security Specialist

International Executive Service Corps • Washington

On-site
USD 90,000 - 120,000