Senior Business Analyst

ECS Corporate Services

Washington (District of Columbia)

Hybrid

USD 130,000 - 147,000

Full time

8 days ago
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Job summary

ECS Corporate Services in Washington, DC offers a Senior Business Analyst role in a hybrid office setting. You will lead cybersecurity process development, document SOPs, elicit and translate business requirements, and collaborate with IT and business units through the project lifecycle.

You will develop business cases, perform risk analyses, and support U.S. government standards, including RMF and NIST controls. Active clearance is implied; prior security experience is valued.

Qualifications

  • Bachelor's degree in Computer Science, MIS/IT, Engineering, Information Security/Assurance, or a related field.
  • Minimum five (5) years of information security experience.
  • Demonstrated experience with NIST SP 800-53 controls and RMF.
  • Ability to translate business needs into functional specifications and use cases.

Responsibilities

  • Lead development and implementation of cybersecurity processes and workflows in a GRC environment.
  • Document processes and SOPs in SharePoint and a GRC.
  • Elicit, analyze, and document business requirements and translate them into use cases.
  • Conduct data and process analysis to identify improvement opportunities.
  • Develop business cases, cost/benefit analyses, and strategic recommendations.
  • Oversee UAT and QA activities and coordinate vendor management when required.

Skills

Cybersecurity
GRC processes
Requirements analysis
Data analysis
UAT
Vendor management
Cloud onboarding

Education

Bachelor's degree in Computer Science, MIS/IT, Engineering, Information Security/Assurance, or a related field

Tools

SharePoint
GRC application

Job description

ECS is seeking a Senior Business Analyst to work in our Washington, DC (hybrid) office. Please Note: This position is contingent upon contract award.

Job Responsibilities
  • Lead the development and implementation of cybersecurity processes and security assessment workflows for information systems, including national security systems, that are managed in a governance, risk management, compliance (GRC) application, and that are governed by federal laws and Department of State policies and standards.
  • Document cybersecurity processes and standard operating procedures as needed and manage the same in SharePoint and a GRC.
  • Elicit, analyze, and document business requirements, translating high-level needs into detailed functional specifications and use cases.
  • Conduct in-depth data analysis, process modeling, and workflow analysis to identify areas for improvement and propose innovative solutions.
  • Develop and present compelling business cases, cost/benefit analyses, and strategic recommendations to senior leadership and key stakeholders.
  • Act as a liaison between business units and IT teams, facilitating effective communication and collaboration throughout the project lifecycle.
  • Lead or mentor less experienced business analysts, providing guidance on best practices and fostering a culture of continuous learning.
  • Oversee and participate in user acceptance testing (UAT) and quality assurance activities, ensuring solutions meet business requirements and are delivered on time and within budget.
  • May also be responsible for tasks like vendor management and system administration, depending on the specific role requirements.
  • Provide governance support over common control projects and cloud service provider on-boarding

Salary Range: $130,000-$147,000

General Description of Benefit
  • Bachelor's degree in Computer Science, MIS/IT, Engineering, Information Security/Assurance, or a related field
  • Minimum five (5) years of information security experience
  • Demonstrated experience conducting full-scope technical security control testing across component types, including development of security and privacy assessment plans
  • Working knowledge of RMF Steps 1-6
  • Strong understanding of NIST SP 800-53 controls, the NIST Cybersecurity Framework, and applicable information security/privacy laws and regulations
  • Ability to analyze information system configurations and technical specifications against NIST SP 800-53 and related overlays
  • Experience developing risk-based documentation
  • Excellent written and verbal communication skills, with the ability to present control requirements and deficiencies clearly to both technical and non-technical audiences
  • Active Secret clearance required with eligibility to get Top Secret clearance
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Security Controls Assessor
Security Controls Assessor

ECS Corporate Services • Washington

Hybrid
USD 150,000 - 168,000
Senior Business Analyst
Senior Business Analyst

Everforth ECS • Washington

Hybrid
USD 110,000 - 170,000
Senior Cybersecurity & GRC Analyst
Senior Cybersecurity & GRC Analyst

Everforth ECS • Washington

Hybrid
USD 110,000 - 170,000
Information Security Analyst
Information Security Analyst

CALIBRE Systems Inc • Washington

Hybrid
USD 80,000 - 90,000
Cyber Business Analyst
Cyber Business Analyst

ECS • Arlington (VA)

Hybrid
USD 120,000 - 140,000
Security Controls Assessor
Security Controls Assessor

ECS • Washington

Hybrid
USD 150,000 - 168,000
Business Analyst, Cybersecurity
Business Analyst, Cybersecurity

MANTECH • Springfield (VA)

On-site
USD 90,000 - 120,000
Systems Security Analyst
Systems Security Analyst

ADG Tech Consulting, LLC • Vienna (VA)

Hybrid
USD 90,000 - 120,000
Business Process Analyst - III
Business Process Analyst - III

Base One Technologies • Arlington (VA)

On-site
USD 80,000 - 100,000
Business Analyst II
Business Analyst II

Electrosoft • Arlington (VA)

On-site
USD 65,000 - 95,000
Equal Opportunity Employer