IT Security Analyst T3 (580)

Sharp Decisions

Herndon (VA)

Hybrid

USD 110,000 - 160,000

Full time

6 days ago
Be an early applicant
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Job summary

Sharp Decisions in Herndon, VA is seeking a Security Analyst to join a FedRAMP/RMF-focused cyber team. You will create, update, and maintain security documentation, artifacts, and CCM requirements such as POA&M, and support the Cloud Operations team with vulnerability remediation and policy advisement.

The role requires knowledge of NIST RMF, FedRAMP, DoD policies, and experience with ATO packages, security controls, risk assessment, system categorization, and security authorization

Qualifications

  • Understand and document information system specifications and security controls.
  • Advise stakeholders on evolving policies (e.g., NIST RMF, DISA SRG).
  • Document actions and risk mitigation per FedRAMP and client policy.
  • Apply enterprise security frameworks to cloud initiatives.
  • Develop/update policies to implement FedRAMP and NIST 800-171 requirements.
  • Familiarity with FedRAMP, DoD and NIST controls, including vulnerability management.
  • Identify and assess cloud system state, RMF status, and patching mechanisms.

Responsibilities

  • Create, update, and maintain FedRAMP-required security documentation and CCM artifacts.
  • Assist with Plan of Action and Milestones (POA&M) processes.
  • Advise stakeholders on regulatory changes and risk assessment.
  • Support Cloud Operations with vulnerability identification and remediation actions.
  • Participate in security authorization activities (ATO), control inheritance, and related artifacts.

Job description

Herndon, VA — Hybrid (Tue / Wed / Thu Onsite)

Contract to Hire US Citizens Only

No Dual Citizenship

FedRAMP / RMF DoD / NIST

The Security Analyst will work as a member of our client's cyber team, assisting with the creation, update, and maintenance of FedRAMP-required security documentation, associated artifacts, and Continuous Compliance Monitoring (CCM) requirements such as the Plan of Action and Milestones (POA&M). The role also supports the Cloud Operations team with identification and corrective actions associated with known vulnerabilities, and provides advisement to stakeholders on changing regulatory, government, and Cloud/FedRAMP policies — including risk assessment, business impact analysis, system categorization, security authorization and accreditation/certification activities (A&A), security control inheritance, and other artifacts needed to validate control compliance.

Critical Requirements
Required Skills
Compliance & Governance
  • Understand and document information system specifications and security controls, including logical and physical diagrams, connectivity, communication, and data flow diagrams — both internal and external to the system
  • Advise stakeholders on multiple courses of action in environments with changing or unconfirmed policy (e.g., NIST RMF, DISA SRG)
  • Document courses of action and identify risk mitigation recommendations in accordance with FedRAMP requirements, client policy, and best practices — including associated benefits and drawbacks
  • Apply enterprise security frameworks (FISMA, NIST SP 800, etc.) to existing cloud environment initiatives
  • Develop and update policies and procedures to implement FedRAMP compliance, NIST 800-171 security requirements, and other DFAR clauses
  • Demonstrate familiarity with current FedRAMP, DoD, and NIST security controls and technologies, including vulnerability management capabilities
  • Identify and assess cloud system state including vulnerabilities, RMF package status, accreditation model, PPS compliance, and patching/CSVA mechanisms
Vulnerability Management
  • Knowledge of Risk-Based Vulnerability Framework and how to prioritize, assess, and remediate exploitable vulnerabilities
  • Ability to create automation scripts to minimize manual workload behind identifying and analyzing vulnerabilities across various scanning tools
  • Ability to analyze container vulnerabilities in secure cloud environments and identify remediation paths at the OS and application level
  • Understand enterprise operating environments including security posture, application environment, and associated security controls
Required Technical Experience
Technical Skills

Python, Bash, Java & PowerShell Scripting

Container Scanning Tools

CI/CD Pipelines & AWS ECR

Container Image Mirroring

Attack Vector Analysis

Network Diagrams & Visio

SAP Products

Testing / Dev / Staging Environments

RMF & Compliance Experience
  • Demonstrated knowledge and ability to analyze systems for cybersecurity compliance
  • Knowledge of Federal and DoD policies and risk assessment methodologies including FedRAMP, NIST SPs, and RMF overlays
  • Hands-on experience with DISA STIG requirements and SRGs, CNSSI, and NIST Risk Management Framework
  • Experience writing or executing system security documentation, Authorization to Operate (ATO) packages, POA&Ms, and policies
  • Knowledge and understanding of systems and networking technologies and concepts
  • Ability to interpret and assess network diagrams using Visio
  • Familiarity with Testing, Development, Staging, and pre-production environments requiring cybersecurity support
  • Knowledge of the Privacy Act
  • Presentation and public speaking skills required
  • Ability to work in a fast-paced, team-oriented environment
Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Security & Compliance Analyst
Security & Compliance Analyst

Endurion • Tampa (FL)

On-site
USD 95,000 - 140,000
Information Security Analyst
Information Security Analyst

CALIBRE Systems Inc • Washington

Hybrid
USD 80,000 - 90,000
Systems Security Analyst
Systems Security Analyst

ADG Tech Consulting, LLC • Vienna (VA)

Hybrid
USD 90,000 - 120,000
Information Security Analyst
Information Security Analyst

Caliber Systems Inc. • Washington, Northern (KY)

Hybrid
USD 89,000 - 110,000
ConMon Security Analyst
ConMon Security Analyst

Prestige Staffing • Chantilly (VA)

Hybrid
USD 96,000 - 103,000
Hybrid work model
In-office 3 days/week
Growth opportunities
+1
Cybersecurity Specialist
Cybersecurity Specialist

Sarela Technology Solutions • Fort Belvoir (VA)

On-site
USD 120,000 - 180,000
401(k)
401(k) matching
Dental insurance
+6
Security Specialist
Security Specialist

Dynamic Solutions Technology LLC • Washington

Hybrid
USD 90,000 - 120,000
Senior Cybersecurity Analyst
Senior Cybersecurity Analyst

Intone Inc • Arlington (VA), Northern (KY)

Hybrid
USD 140,000 - 180,000
Information Security Manager III
Information Security Manager III

Solutions³ LLC • Arlington (TX)

On-site
USD 140,000 - 180,000
Cloud Security Architect
Cloud Security Architect

Pipe Recruit • Palo Alto (CA)

Hybrid
USD 207,000 - 344,000