Information Security Analyst Duties and Responsibilities:
Your Impact
Join a team supporting federal civilian agencies and contribute to protecting and enabling mission‑critical systems that serve U.S. citizens.
Information System Security Officer – Duties & Responsibilities:
- Support government personnel in authorizing secure networks/applications in Azure Government Secret environments
- Develop and submit A&A packages in eMASS
- Configure and manage security controls, auditing, logging, vulnerability management, and CONMON activities across Microsoft Defender, Key Vault, Azure Policy, and other Azure security services
- Provide guidance for SIEM/SOAR integrations (e.g., Microsoft Sentinel IL6) for monitoring, logging, and incident response
- Support engineering teams in implementing remediations aligned with NIST 800‑53, DoD STIGs/SRGs, and CIS Benchmarks
- Collaborate with mission owners, compliance teams, and developers to ensure secure DevSecOps pipelines
- Support ATO processes by developing security documentation, gathering control evidence, and assisting with audits
- Navigate federal systems through the authorization process to achieve and maintain ATO
- Work closely with Program and DOC ITD IA teams to maintain required security authorizations
- Develop System Security Plans (SSPs) documenting implementation of NIST 800‑53 Rev 5 and overlay controls
- Coordinate with third‑party assessors for security assessments
- Manage POA&Ms to address identified vulnerabilities
- Ensure continuous monitoring plans meet agency requirements
- Prepare authorization packages for government review
- Maintain compliance through established change‑management processes
- Serve as liaison between technical teams and authorizing officials
- Translate security requirements into actionable technical tasks
- Ensure all documentation meets federal information system requirements
Key Skills for Success
- Microsoft Azure Security Stack (Sentinel, Defender, Auditing)
- RMF for classified systems/applications
- Plan of Action & Milestones (POA&M) management
- Experience with GRC tools (CSAM, eMASS)
Requirements & Qualifications:
- Bachelor’s degree in Information Systems Security, IT, or Networking
- Active Secret clearance
- 5+ years of cloud security experience, including 2+ years in Azure Government or DoD environments
- Strong knowledge of Azure-native security tools, IL6 data-handling, cloud networking, and architectural validation
- Experience with DoD SRG/STIG/CIS Benchmarks
- Hands‑on experience with classified enclaves, hardened images, and enclave‑to‑enclave connectivity
- Deep experience with auditing, logging, vulnerability management, and secure configuration management
- Strong communication skills; customer-facing experience
- Knowledge of Agile software development
- Secret clearance required for start
Required Technical Skills:
- SCAP, STIGs, patching, eMASS, and related RMF tools
- Cybersecurity and A&A package development
- Experience obtaining ATOs and navigating the assessment/authorization process
- Experience across cybersecurity, information security, and IT security protocols and procedures
Experience:
- 5 years of relevant experience (may vary based on training, certifications, or degree)
- Cloud security experience (Azure Government) and SIPRNet exposure
- Experience with internet, web, application, and network security techniques
- Experience working in federal environments
- Ability to work independently and remotely
Certification Requirements:
- Active DoW 8570 IAT Level II/III (Security+, CISSP, CISM)
Additional Details:
- Travel: Up to 10% (may vary based on customer needs)
- Location: Onsite at least 3 days per week; must reside in the DMV area
- Citizenship: U.S. Citizenship required