Senior Business Analyst

ecsfederal

Washington (District of Columbia)

Hybrid

USD 130,000 - 147,000

Full time

3 days ago
Be an early applicant
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Benefits offered by this job

Hybrid work in Washington, DC

Job summary

ECS Federal in Washington, DC is seeking a Senior Business Analyst to work in our hybrid office. This role supports cybersecurity programs across information systems under GRC governance, with a focus on compliance with federal laws and Department of State policies.

You will lead requirements analysis, document processes in SharePoint, and drive UAT and QA activities, mentoring junior analysts and coordinating with IT and business teams.

Qualifications

  • Bachelor's degree in Computer Science, MIS/IT, Engineering, Information Security/Assurance, or related field.
  • Minimum five (5) years of information security experience.
  • Experience with full-scope technical security control testing and risk assessment plans.
  • Working knowledge of RMF Steps 1-6 and NIST SP 800-53.

Responsibilities

  • Lead development and implementation of cybersecurity processes and security assessment workflows.
  • Document cybersecurity processes and SOPs in SharePoint and a GRC.
  • Elicit, analyze, and document business requirements; translate needs into specs.
  • Lead or mentor analysts and oversee UAT and QA activities.
  • Provide governance support over common control projects and cloud onboarding.

Skills

Information security
RMF
NIST SP 800-53
NIST CSF
Risk assessment
Documentation
Communication

Education

Bachelor's degree in Computer Science, MIS/IT, Engineering, Information Security/Assurance, or related field

Tools

SharePoint

Job description

ECS is seeking a Senior Business Analyst to work in our Washington, DC (hybrid) office. Please Note: This position is contingent upon contract award.

Job Responsibilities
  • Lead the development and implementation of cybersecurity processes and security assessment workflows for information systems, including national security systems, that are managed in a governance, risk management, compliance (GRC) application, and that are governed by federal laws and Department of State policies and standards.
  • Document cybersecurity processes and standard operating procedures as needed and manage the same in SharePoint and a GRC.
  • Elicit, analyze, and document business requirements, translating high-level needs into detailed functional specifications and use cases.
  • Conduct in-depth data analysis, process modeling, and workflow analysis to identify areas for improvement and propose innovative solutions.
  • Develop and present compelling business cases, cost/benefit analyses, and strategic recommendations to senior leadership and key stakeholders.
  • Act as a liaison between business units and IT teams, facilitating effective communication and collaboration throughout the project lifecycle.
  • Lead or mentor less experienced business analysts, providing guidance on best practices and fostering a culture of continuous learning.
  • Oversee and participate in user acceptance testing (UAT) and quality assurance activities, ensuring solutions meet business requirements and are delivered on time and within budget.
  • May also be responsible for tasks like vendor management and system administration, depending on the specific role requirements.
  • Provide governance support over common control projects and cloud service provider on-boarding

Salary Range: $130,000-$147,000

General Description of Benefit

  • Bachelor's degree in Computer Science, MIS/IT, Engineering, Information Security/Assurance, or a related field
  • Minimum five (5) years of information security experience
  • Demonstrated experience conducting full-scope technical security control testing across component types, including development of security and privacy assessment plans
  • Working knowledge of RMF Steps 1-6
  • Strong understanding of NIST SP 800-53 controls, the NIST Cybersecurity Framework, and applicable information security/privacy laws and regulations
  • Ability to analyze information system configurations and technical specifications against NIST SP 800-53 and related overlays
  • Experience developing risk-based documentation
  • Excellent written and verbal communication skills, with the ability to present control requirements and deficiencies clearly to both technical and non-technical audiences
  • Active Secretclearance required with eligibility to get Top Secretclearance
Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Senior Business Analyst
Senior Business Analyst

Everforth ECS • Washington

Hybrid
USD 110,000 - 170,000
Senior Business Analyst - Cyber Risk & GRC (Hybrid)
Senior Business Analyst - Cyber Risk & GRC (Hybrid)

ecsfederal • Washington

Hybrid
USD 130,000 - 147,000
Hybrid work in Washington, DC
Cyber Business Analyst
Cyber Business Analyst

ECS • Arlington (VA)

Hybrid
USD 120,000 - 140,000
Senior Cybersecurity & GRC Analyst
Senior Cybersecurity & GRC Analyst

Everforth ECS • Washington

Hybrid
USD 110,000 - 170,000
Technical Business Analyst
Technical Business Analyst

ECS • Arlington (VA)

Hybrid
USD 120,000 - 140,000
Systems Security Analyst
Systems Security Analyst

ADG Tech Consulting, LLC • Vienna (VA)

Hybrid
USD 90,000 - 120,000
Information Security Analyst
Information Security Analyst

CALIBRE Systems, Inc. • Washington

Hybrid
USD 89,000 - 110,000
Information Security Analyst
Information Security Analyst

CALIBRE Systems Inc • Washington

Hybrid
USD 80,000 - 90,000
Senior Business Analyst
Senior Business Analyst

PlanIT Group, LLC • Arlington (VA)

Hybrid
USD 95,000 - 140,000
Business Analyst
Business Analyst

ecsfederal • Virginia (MN)

Hybrid
USD 60,000 - 75,000