Full-Time Information System Security Analyst
Job Description
We are looking for an experienced Information System Security Analyst to join our team in Florida. This role involves applying Information System (IS) security principles, practices, and procedures under the Risk Management Framework (RMF) to ensure compliance with security regulations such as NIST, CNSSI, CMMC, and NISPOM for classified information systems. You will manage the program’s security efforts and represent the program to the sponsor’s security organization. The ideal candidate will be a strong advocate for integrating security into all stages of the program lifecycle and will oversee the implementation and sustainment of security controls throughout the program.
Responsibilities:
- Develop and maintain documentation related to information security, ensuring it aligns with the relevant security frameworks and standards.
- Implement, monitor, and maintain security controls across all systems, ensuring they are effective in mitigating risks.
- Advise development teams on integrating security requirements into system design, implementation, and maintenance processes.
- Manage relationships with hardware and software vendors to ensure compliance with security requirements and provide guidance on securing products.
- Achieve and maintain Authorization to Operate (ATO) for classified information systems, ensuring they meet regulatory compliance requirements.
- Coordinate and collaborate with the sponsor’s security organization and corporate security teams to ensure seamless communication and compliance.
- Oversee the Continuous Monitoring program to track, assess, and report security posture of systems and resolve any identified vulnerabilities.
- Provide security-related training and guidance to program management and staff to promote a security-aware culture within the organization.
- Ensure personal eligibility for security clearance and support the security clearance process for other program personnel.
- Perform risk assessments, manage risk, and support ongoing security efforts throughout the system lifecycle, addressing security vulnerabilities and ensuring continuous compliance.
Qualifications:
- Bachelor’s degree in Computer Science, Information Systems, Cybersecurity, or related field (Master’s degree preferred).
- Minimum of 3 years of experience in cybersecurity, with at least 1 year in a supervisory role (preferred).
- Active Secret clearance (preferred).
- IAM Level III certification in accordance with DoD 8570.01M, or CompTIA Security+ certification.
- High-level security or IT certification with practical experience in security management.
- In-depth knowledge of NIST 700/800 series, CNSSI 1253, NISPOM Chapter 8, CMMC, and related publications.
- Familiarity with the RMF process and experience in drafting RMF documentation.
- Experience in performing risk assessments and risk management for information systems (cloud, subscription-based, and on-premise).
- Practical experience implementing and monitoring technical, administrative, and operational security controls.
- Proven success managing classified information systems and working within established security frameworks.
- Strong organizational skills, with the ability to prioritize tasks and meet deadlines.
- Familiarity with CMMC 2.0, STIGs, NIST CVEs, IAVAs, Compliance Checker (SCC), and Cloud Security concepts.
- Strong writing skills and experience in collaborative teamwork.
- Must lawfully reside in the United States and be eligible for employment (Planate does not sponsor visas or work permits).
64 total views, 0 today