Information Security Analyst Lead

eSimplicity

Fort Meade (MD)

Hybrid

USD 110,000 - 160,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Medical, dental, vision coverage
401(k) retirement benefits
Paid time off and holidays
Life and disability insurance
Wellness and employee support programs

Job summary

eSimplicity is seeking an Information Security Analyst to support security controls across systems with varying maturity levels. You will drive ATO readiness, coordinate with product teams and ISSOs, and maintain security artifacts while monitoring posture and responding to data calls.

This role requires interfacing with multiple stakeholders weekly across federal-aligned security programs. The candidate will own vulnerability management, incident response, and security tool dashboards,

Qualifications

  • Minimum of eight years of experience in cybersecurity architecture, cloud security, DevSecOps or related field.
  • Security+ certification is required.
  • Experience with Cloud and IaC security, applications and data-centric systems.
  • Familiarity with Agile methodologies and security governance.
  • Working knowledge of AWS or Azure security tools.
  • Ability to document risk analyses and remediation steps.
  • Active Secret clearance.

Responsibilities

  • Coordinate with product teams, ISSOs, engineering and infrastructure to implement security policies.
  • Analyze and respond to security requirements and produce clear, accurate responses.
  • Review and update ATO artifacts and security documentation.
  • Interpret risk assessments, review scans, and manage POA&Ms for vulnerabilities.
  • Develop design docs for security feature implementations and remediation plans.
  • Document remediation for vulnerabilities and non-compliance with engineering staff.
  • Provide governance communication to non-security personnel.
  • Collaborate with stakeholders to support continuous monitoring and ATO efforts.
  • Conduct vulnerability assessments and lead security improvements to prevent breaches.
  • Respond to alerts, investigate incidents, and coordinate remediation activities.
  • Tune security rules, maintain dashboards, and report security metrics.
  • Research trends and attack vectors to preempt breaches; ensure regulatory compliance.
  • Educate users on security requirements and procedures.
  • Suggest process improvements for risk mitigation and apply iterative security automation.

Skills

Cybersecurity architecture
Cloud security
DevSecOps
Security governance
Agile methodologies
Threat modeling
Communication
Stakeholder collaboration
Security incident response

Education

Bachelor’s degree in Computer Science or related field
Security+ certification
Active Secret Clearance

Tools

Splunk
AWS security tools
Azure security tools
Security automation tooling

Job description

Description

About Us:

eSimplicity is modern digital services company that work across government, partnering with our clients to improve the lives and ensure the security of all Americans—from soldiers and veteran to kids and the elderly, and defend national interests on the battlefield. Our engineers, designers and strategist cut through complexity to create intuitive products and services that equip Federal agencies with solutions to courageously transform today for a better tomorrow for all Americans.

Purpose of Scope:

We are seeking an Information Security Analyst who is responsible for providing security support services while meeting security control compliance requirements for a portfolio of systems at various states of maturity and modernization. This role will provide support for continuously monitoring the cybersecurity posture of systems to secure against cyber threats.

The primary responsibility is to facilitate security tool and control implementation, security tool usage, and ensure tools and controls remain compliant and configured properly, all the while ensuring a successful program Authorization to Operate (ATO). Additionally, the expectation is to take ownership of communication and visualization of security issues, especially where coordination between product teams, information owners, engineering, and infrastructure staff is necessary for remediation.

The candidate will own coordination and response to the agency’s security-related inquiries, compliance with agency policy, security controls, and the maintenance of security documentation and artifacts. You will function as the primary liaison to provide timely and accurate responses to security-related data calls (System Security & Compliance Status, Vulnerability, and Compliance scanning issues) and provide security guidance throughout the system development lifecycle. This role requires interfacing with multiple stakeholders through multiple touchpoints weekly.

Responsibilities:
  • Work closely with the Product Owners, ISSOs, engineering and infrastructure staff to provide guidance on implementation if security policies, standards, and procedures
  • Analyze new or updated security requirements, collaborate with stakeholders, and develop responses that are clear and accurate.
  • Support the review and update of ATO artifacts such as System Security Plans, Information System Contingency Plans, Configuration and Change Management Plans, Incident Response Plans, Privacy Impact Analysis, and more.
  • Interpret security risk assessment, review security scan results, assess security vulnerabilities and support the development and remediation of vulnerability and compliance issues via Plan of Action and Milestones (POA&Ms).
  • Support the development of implementation and design documentation relating to security feature implementation.
  • Work with engineering and infrastructure personnel to document remediation for vulnerabilities and non-compliance issues.
  • Analyze and interpret agency security requirements and provide governance communication to non-security personnel.
  • Collaborate with product teams, ISSOs and other stakeholders in support of continuous monitoring and ATO efforts.
  • Conducts vulnerability assessments and monitors systems, networks, databases and Web-based assets for potential system breaches. Recommends and takes the lead on implementing changes to enhance security systems, prevent unauthorized access, and help mitigate security vulnerabilities.
  • Responds to alerts from information security tools. Reports, investigates, and resolves higher level security incidents.
  • Responds to security tool outages, degradations in service, tune security rules and alerts, and setup/maintain security tool dashboards and reporting.
  • Research security trends, new methods, and techniques used in unauthorized access of data to preemptively eliminate the possibility of system breach. Ensures compliance with regulations and privacy laws. Conducts research to identify new attack vectors.
  • Educates and communicates security requirements and procedures to all users and new employees.
  • Recommend process improvements to the information system for risk mitigation.
  • Applies iterative security automation to all program aspects increasing overall security posture iteratively and never accepts the status quo.
  • Provide audit log review in Splunk, present any findings to ISSO, and plan for any investigation or remediation activities.
  • Periodic user and privileged access reviews.
Requirements
Required Qualifications:
  • Minimum of eight years of experience in cybersecurity architecture, cloud security, DevSecOps, security engineering, or a related technical field. Bachelor’s degree in Computer Science, Information Systems, Engineering, or a related field preferred but not required.
  • Must hold a current Security+ certification.
  • Experience designing security "baked-in" to architectures including Cloud and IaC, applications, web applications, data processing, data-centric applications, AI/ML, and CI/CD pipelines.
  • A proven track record
  • Familiarity with Agile methodologies.
  • Working knowledge of AWS or Azure security tools, their functionality, and their purpose.
  • Ability to assist customers with defining appropriate management processes (responsible for documenting application criticality, privacy, and security impact analysis).
  • Knowledge of hardening standards (DISA STIG, CIS).
  • Experience with the NIST Risk Management Framework, NIST 800-53 rev5, and NIST 800-171.
  • Active secret clearance.
Desired Qualifications:
  • Federal Government contracting work experience.
  • Experience as an ISSO for the DoD.
  • Highly preferred industry certifications such as CISSP, CEH, GIAC, etc.
  • Experience with Security Information and Event Management (SIEM) systems (e.g., Splunk).
Location and Hours

Location: This role is primarily remote; however, the employee must be able to report on-site to Fort Meade, MD when requested due to customer or business needs. The frequency and timing of on-site support may vary and cannot be guaranteed in advance.

Hours: Expected hours are 9:00 AM to 5:00 PM Eastern Time unless otherwise directed by your manager.

Travel: Occasional travel for training and project meetings, estimated to be less than 5% per year.

Benefits:

eSimplicity offers a comprehensive benefits package, including medical, dental, and vision coverage, 401(k) retirement benefits, paid time off, paid holidays, life and disability insurance, and additional wellness and employee support programs. Eligibility may vary based on employment status and applicable plan terms.

Reasonable Accommodation:

eSimplicity is committed to providing reasonable accommodations to qualified individuals with disabilities during the application and hiring process. Applicants who need assistance or an accommodation should contact Human Resources.

Equal Employment Opportunity:

eSimplicity is an Equal Opportunity Employer, including disability and protected veteran status. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, age, protected veteran status, disability, or any other legally protected status.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Information System Security Engineer
Information System Security Engineer

CSCI Consulting • Illinois

On-site
USD 90,000 - 130,000
Competitive salaries
Full health benefits
401(k) retirement plan
Cybersecurity Systems Analyst, Sr.
Cybersecurity Systems Analyst, Sr.

TJ Consulting Group • Coronado (CA)

On-site
USD 120,000 - 170,000
PTO
Holiday Pay
401K with a 4% Match
+13
Information Systems Security Engineer SME
Information Systems Security Engineer SME

ECS • Stafford (VA)

On-site
USD 120,000 - 150,000
Cyber Security Analyst I
Cyber Security Analyst I

Scientific Research Corporation • North Charleston (SC)

On-site
USD 90,000 - 120,000
Senior Engineer, Cloud and System Security
Senior Engineer, Cloud and System Security

SES Satellites • McLean (VA)

On-site
USD 140,000 - 180,000
Systems Security Analyst
Systems Security Analyst

ADG Tech Consulting, LLC • Vienna (VA)

Hybrid
USD 90,000 - 120,000
Information System Security Engineer
Information System Security Engineer

SAIC • McLean (VA)

On-site
USD 120,000 - 160,000
Principal Information Security Engineer
Principal Information Security Engineer

Clarity Innovations • Fort Meade (MD)

On-site
USD 117,000 - 292,000
Lead Security Engineer
Lead Security Engineer

Dev Technology • Suitland (MD)

On-site
USD 120,000 - 190,000
Generous time-off policy
Flexible work schedules
401K matching
+1
Senior Information Systems Security Engineer
Senior Information Systems Security Engineer

ECS • Washington

On-site
USD 120,000 - 150,000