Senior Security Analyst (A&A)/Assessor - NIST

ITC Federal, LLC

Gaithersburg, Northern (MD, KY)

Hybrid

USD 120,000 - 150,000

Full time

3 days ago
Be an early applicant
Application generator

Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.

Get past ATS filters

Benefits offered by this job

Health, Dental and Vision
401(k)
FSA
11 Paid Federal Holidays
PTO
Education reimbursement

Job summary

ITC Federal, LLC is seeking a Senior Security Analyst/A&A SME to support NIST systems in a fully remote capacity. The role focuses on Security Assessment & Authorization activities, vulnerability analysis, and reporting to senior management within a federal contracting framework.

The ideal candidate brings 5–8 years implementing NIST 800 Series, RMF experience, and CISSP/CISM/CISA credentials or advanced degree, with hands-on experience using security tools like RSA Archer, Tenable, and

Qualifications

  • 5–8 years implementing NIST 800 Series.
  • Experience with RMF, interviewing, examining and testing controls.
  • Security Test & Evaluation and Security Assessment Reports for senior management.
  • Ability to present risk and remediation plans to management.

Responsibilities

  • Conduct A&A activities for NIST systems.
  • Collaborate with NIST staff to remediate risks and provide solutions.
  • Coordinate/conduct vulnerability scans and analyze results.
  • Prepare Security Assessment Reports with technical and policy aspects.
  • Review and update A&A packages based on feedback.

Skills

NIST RMF
Vulnerability analysis
Security assessment reports
Documentation & reporting
Oral & written communication

Education

CISSP
CISM
CISA
Advanced degree

Tools

RSA Archer
CSAM
Tenable
WebInspect
AppDetective

Job description

Overview

JOB TITLE: Senior Security Analyst/A&A SME

GOVERNMENT AGENCY: NIST – National Institute of Standards & Technology

POSITION INFORMATION: Full-Time Position; Government contractor supporting NIST

LOCATION: Fully remote

BENEFITS: Health, Dental and Vision, 401(k), Flexible Spending Account (FSA), 11 Paid Federal Holidays, PTO, education reimbursement

ITC Federal, LLC (ITC) connects technology advancements in automation and AI, customer experience, and financial services to solve government mission challenges, enabling smoother operational efficiency and bolstering national security. We leverage the latest technology innovations and proven approaches to better serve the mission and support the DHS, DOJ, and DoW workforce, customers, and programs, regardless of scale or complexity. ITC is located in Fairfax, VA and offers outstanding compensation and benefits plan and a challenging and rewarding professional work environment.

Senior Security Analyst will be focused on Security Assessment & Authorization (A&A) of systems for the National Institute of Standards and Technology (NIST). The Senior Security Analyst is expected to be capable of lending subject matter expertise while performing A&A activities. The Senior Security Analyst will demonstrate a strong knowledge of Security Requirement Analysis, Security Architecture , Enterprise Security Program Assessment, evaluating Vulnerability Assessment results and perform other duties as required.

Responsibilities
  • Conducting A&A activities for NIST systems working individually or as part of a team.
  • Work with NIST staff to provide technical and policy driven solutions to remediate or mitigate identified risks.
    • Support system personnel with remediation plans for A&A findings.
    • Provide guidance to Information System Security Officers (ISSO) on system documentation.
  • Coordinate/conduct vulnerability scans and analyze results.
  • Complete Security Assessment Reports involving both technical and policy related aspects of the assessment.
  • Review and update A&A packages based on management feedback.
Qualifications
  • 5 - 8 years of experience implementing the NIST 800 Series Special Publications.
  • Demonstrable experience:
    • Conducting IT assessor activities based on the NIST Risk Management Framework, to include the interviewing, examining and testing of related control sets; the review and/or updates of core system documents- System Security Plans, Contingency Plans, Privacy Threshold Assessments, hardware and software inventories, and system diagrams.
    • Performing Security Test and Evaluation and developing Security Assessment Reports for NIST senior management.
    • Delivering risk and vulnerability briefings confidently to management and government customers.
  • Experience working with vulnerability data, writing Assessment Reports, POA&Ms and Risk Acceptance justifications
  • Knowledge of the formation and implementation of IT security policies to ensure confidentiality, integrity and availability of information systems.
  • Strong technical oral, writing and customer service skills as you will regularly interact with NIST colleagues and senior managers.
PREFERRED:
  • Prior federal or GOVCON experience
  • Cloud Experience (AWS or Azure)
  • Active Certified Information Systems Security Professional (CISSP), Certified Information Security Manager (CISM), Certified Information Security Auditor (CISA) or comparable certification
  • Advanced Degree in computer science or related field or related experience
  • Direct experience with NIST or other academic environments.
  • Expertise with COTS based security tools (i.e. RSA Archer, CSAM, Tenable, WebInspect, AppDetective) used to establish security baselines and assess continuing compliance.
SECURITY CLEARANCE REQUIREMENTS:
  • Ability to successfully pass a National Agency Check with Local Agency Check (NACLC)

WORK ENVIRONMENT AND PHYSICAL DEMANDS: Candidate must be able to function in general office environment.

ITC Federal is an equal opportunity employer and will not discriminate against any application for employment on the basis of age, race, color, gender, national origin, religion, creed, disability, veteran status, marital status, sexual orientation, genetic information, military status, disability, or sex including pregnancy and childbirth or related medical condition or on any other basis prohibited by law.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Senior Security Analyst – A&A & NIST Assessments (Remote)
Senior Security Analyst – A&A & NIST Assessments (Remote)

ITC Federal, LLC • Gaithersburg (MD), Northern (KY)

Hybrid
USD 120,000 - 150,000
Health, Dental and Vision
401(k)
FSA
+3
Information Assurance Analyst Senior
Information Assurance Analyst Senior

Paragon • Washington

On-site
USD 110,000 - 160,000
Cyber & A&A Security Specialist - Hybrid Remote
Cyber & A&A Security Specialist - Hybrid Remote

Attainx Inc. • Silver Spring (MD)

Hybrid
USD 98,000 - 110,000
Paid vacation
Medical, dental, and vision coverage
Matching 401(k) plan
+1
Information Assurance Analyst Senior
Information Assurance Analyst Senior

Paragon Technology • Washington

On-site
USD 120,000 - 170,000
Information System Security Officer (ISSO)
Information System Security Officer (ISSO)

Nava • Washington, Northern (KY)

Hybrid
USD 86,000 - 202,000
Medical insurance
Dental insurance
Disability insurance
+5
Information Assurance Compliance Analyst
Information Assurance Compliance Analyst

Itezz • Annapolis (MD)

On-site
USD 75,000 - 250,000
Information Assurance Analyst Senior
Information Assurance Analyst Senior

Paragon Technology Group, Inc. • Washington

On-site
USD 120,000 - 180,000
Information System Security Officer
Information System Security Officer

PlanIT Group, LLC • Falls Church (VA)

On-site
USD 120,000 - 180,000
Security Control Assessor / IA Specialist
Security Control Assessor / IA Specialist

CACI International Inc • Alexandria (VA)

On-site
USD 87,000 - 182,000
SME Security Control Assessor
SME Security Control Assessor

imagineeer-llc • Arlington (VA)

Hybrid
USD 80,000 - 100,000
Competitive salary
Flexible work from home options