IT Security Analyst T3

Johnson Technology Systems Inc

Reston (VA)

Hybrid

USD 120,000 - 126,000

Full time

14 hours ago
Be an early applicant
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Job summary

Johnson Technology Systems, Inc. (JTSi) seeks an IT Security Analyst T3 to support FedRAMP compliance and security documentation. The role requires working in-office in Herndon 3 days a week (Tuesday-Thursday) with potential increase to 5 days as needed.

Candidate must be a US citizen, possess security-focused expertise, and collaborate with the cyber team to address vulnerabilities and regulatory requirements.

Qualifications

  • Must understand FedRAMP requirements and related security controls.
  • Experience with NIST RMF and DISA SRG guidance is preferred.
  • Proficiency in documenting system security controls and risk mitigation options.

Responsibilities

  • Assist with creation, update, and maintenance of FedRAMP security documentation and CCM requirements.
  • Support POA&M development and tracking to ensure compliance.
  • Advise stakeholders on regulatory changes affecting cloud and FedRAMP policies.

Education

Bachelor's degree in computer information systems or math/sciences

Tools

Python
Bash
Java
Powershell
AWS ECR
Container scanning tools
FedRAMP knowledge

Job description

\"WE DO WHAT WE SAY \" JTSi is a federal government consulting firm, providing technical services to the Federal Government, i.e., DoD, Client and various Civilian Agencies. We are proud to have earned the reputation of honesty, integrity and the ability to build long-term professional relationships with our employees and clients. Please visit our website at www.JTSUSA.com to learn more about who we are and what we do.

\"WE DO WHAT WE SAY \" JTSi is a federal government consulting firm, providing technical services to the Federal Government, i.e., DoD, Client and various Civilian Agencies. We are proud to have earned the reputation of honesty, integrity and the ability to build long-term professional relationships with our employees and clients. Please visit our website at www.JTSUSA.com to learn more about who we are and what we do.

Company Name: - JTSi (Johnson Technology Systems, Inc.)

Title: IT Security Analyst T3

Location: Hybrid - This role requires in office (Herndon) 3 days a week (Tuesday, Wednesday & Thursday) but may increase to 5 days a week as business needs change.

Salary : $120K-$126K

Description

*Must be a US Citizen & ONLY hold US Citizenship (No Dual Citizens)*

*This role requires in office (Herndon) 3 days a week (Tuesday, Wednesday & Thursday) but may increase to 5 days a week as business needs change.*

Security Analyst (SA) will work as a member of the cyber team. The SA will assist with the creation, update, and maintenance of FedRAMP required security documentation, associated artifacts, and Continuous Compliance Monitoring (CCM) requirements such as the Plan of Action and Milestones (POAM) and assisting the Cloud Operations team with the identification and corrective actions associated with known vulnerabilities. Additionally, the SA provides advisement to stakeholders on changing regulatory, government and Cloud / FedRAMP policies, procedures, agreements, etc., including risk assessment, business impact analysis, system categorization, security authorization and accreditation/certification activities (A&A), security control inheritance from various providers, and other artifacts needed to validate control compliance.

Required Skills The Candidate Must Be Able To
  • Understand/document information system specifications and security controls, including logical and physical diagrams, connectivity, communication, and data flow diagrams, both internal and external to the system.
  • Advise stakeholders on multiple courses of action in an environment with changing unconfirmed policy, e.g., NIST RMF and DISA SRG.
  • Document multiple courses of action and identify risk mitigation recommendations in accordance with FedRAMP requirements, policy, procedures, and best practices, with associated benefits/drawbacks to each.
  • Apply enterprise security frameworks and capabilities, such as FISMA, NIST SP 800, etc. towards existing initiatives such as cloud environments.
  • Develop/update policies and procedures to implement FedRAMP compliance as well as compliant with NIST 800-171 security requirements and other DFAR clauses.
  • Knowledge of Risk Based Vulnerability Framework and how to prioritize, assess, and remediate vulnerabilities that is and can be exploited
  • Ability to create automation scripts to minimize manual workload behind identifying and analyzing vulnerabilities across various scanning tools
  • Ability to analyze Container Vulnerabilities in secure cloud environments and identify the remediation path forward to address vulnerabilities from an Operating System and application level.
  • Understand enterprise operating environments, including security posture, application environment, and associated security controls.
  • Demonstrate familiarity with current FedRAMP, DOD and NIST Security controls and technologies, including vulnerability management capabilities.
  • Identify and assess Cloud System state, including vulnerabilities, RMF package status/accreditation model, PPS compliance, and patching/CSVA mechanisms.
Required Technical Experience
  • Experience in creating automation scripts through coding programs such as Python, Bash Java, and Powershell
  • Knowledge of Scanning Containers and experience with container scanning tools
  • Knowledge of the CI/CD pipelines, AWS ECR, Container Image Mirroring
  • Knowledge of determining attack vectors in the environment to determine if the vulnerability is exploitable
  • Knowledge in SAP products Required RMF Experience
  • Demonstrated knowledge and the ability to analyze systems for Cybersecurity compliance.
  • Ability to work in fast-paced, team-oriented environment.
  • Knowledge of Federal and DoD policies and risk assessment methodologies, including FedRAMP. NIST SPs and RMF overlays
  • Knowledge and hands on experience of DISA STIGs requirements and SRGs, Committee for National Security Systems Instructions and NIST Risk Management Framework.
  • Experience in writing or executing system security documentation, authorization to operate packages, POA&Ms, and policies.
  • Presentation and public speaking skills required.
  • Knowledge and understanding of systems and networking technologies and concepts.
  • Ability to interpret and assess network diagrams and drawings using Visio.
  • Familiarity with Testing, Development, Staging, and pre-production environment requiring cyber security support.
  • Knowledge of Privacy Act.
Education And Certifications

Bachelor's degree in computer information systems or math/sciences

We recruit, employ, train, compensate and promote without regard to race, religion, color, citizenship, national origin, age, sex, gender, gender identity/expression, sexual orientation, marital status, disability, genetic information, veteran status or any other characteristic protected by federal, state, or local law.

Disclaimer:

Nothing in this job description/posting shall constitute an offer or promise of employment. If you are not reviewing this job posting on our Careers' site http://jtsusa.com/careers or one of our approved job boards we cannot guarantee the validity of this posting. For a list of our current postings, please visit us at http://jtsusa.com/careers

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

IT Security Analyst T3 (580)
IT Security Analyst T3 (580)

Sharp Decisions • Herndon (VA)

Hybrid
USD 110,000 - 160,000
IT Security Analyst
IT Security Analyst

Paradigm Global Consulting • Herndon (VA)

Hybrid
USD 120,000 - 160,000
Federal IT Security Analyst III – FedRAMP/Cloud
Federal IT Security Analyst III – FedRAMP/Cloud

Johnson Technology Systems Inc • Reston (VA)

Hybrid
USD 120,000 - 126,000
Cybersecurity Analyst
Cybersecurity Analyst

jt4currentopeningscx3 • Salt Lake City (UT)

On-site
USD 100,000 - 160,000
Cybersecurity Analyst
Cybersecurity Analyst

Jt4, Llc • Magna (UT)

On-site
USD 95,000 - 130,000
Senior DevOps Engineer � Private Cloud Edition (PCE)
Senior DevOps Engineer � Private Cloud Edition (PCE)

Johnson Technology Systems Inc • Reston (VA)

Hybrid
USD 146,000 - 151,000
Functional & Integration Test Analyst 1
Functional & Integration Test Analyst 1

Johnson Technology Systems Inc • Reston (VA)

Hybrid
USD 167,000 - 172,000
Vulnerability Management and Endpoint Security Administrator
Vulnerability Management and Endpoint Security Administrator

JCS Solutions LLC • Fort Belvoir (VA)

On-site
USD 70,000 - 100,000
Vulnerability Management and Endpoint Security Administrator
Vulnerability Management and Endpoint Security Administrator

JCS Solutions LLC • Fort Belvoir (VA), Northern (KY)

Hybrid
USD 70,000 - 100,000
CyberSecurity Analyst
CyberSecurity Analyst

Pitech Solutions, Inc. • Washington, Northern (KY)

On-site
USD 130,000 - 185,000