ForgeApply
Try it free

ForgeApply · Job listing

Information Security Analyst Sr Principal - Cloud - Hybrid

GDIT

USA MD Fort Meade, US$143k – $184khybrid

See all 252 open roles at GDIT

Tailor your resume for this GDIT job in about a minute.

ForgeApply tailors your resume and cover letter to this exact posting, then hands you a ready-to-submit application for GDIT's site. Free trial, no card required.

About this role

Type of Requisition: Regular

Clearance Level Must Currently Possess: Secret

Clearance Level Must Be Able to Obtain: Secret

Public Trust/Other Required: None

Job Family: Cyber and IT Risk Management

Job Qualifications: Skills: Cybersecurity, Information Security, RMF, Security Requirements, System Security Certifications: None Experience: 8 + years of related experience US Citizenship Required: Yes

Job Description: As an Information Security Analyst Sr Principal, you will be responsible for the ICAM program’s network accreditation on both unclassified and classified networks. You will also be responsible for executing and reviewing security assessments of computing environments to identify points of vulnerability, non-compliance with established IA standards and regulations, and recommend mitigation strategies. In this role, a typical day will include: • Execute success in obtaining an accreditation and maintaining the accreditation for ICAM on a classified network. • Perform Risk Management Framework (RMF) actions in eMASS such as control assessments, PPSM, upload and manage ICAM assets in hardware/software list, upload STIG checklists and ACAS vulnerability reports. • Define, draft, publish, and maintain Information Security policies, standards, and guidelines such as Access Control Plan, Identification and Authentication Plan, Auditing and Accountability Plan, Contingency Plan, Incident Response Plan, Vulnerability Management, Continuous Monitoring, Backup and Recovery, System Integrity Plan, Key Management, Media Protection, etc. • Develop and finalize RMF documentation to include Security Plans, Implementation Plans, Plans of Action and Milestones (POA&Ms), and Risk Assessment Reports • Assess system compliance against NIST, DoD, and DHA security requirements to include the NIST 800-53 controls, and DISA Security Technical Implementation Guides (STIGs) and Security Requirements Guides (SRGs). • Spearhead support government compliance assessments such as penetration testing and accreditation and compliance inspections assessments and mitigations to system security threats/risks throughout the program life cycle. • Work with the internal and external stakeholders to resolve compliance or audit issues in a timely manner. Enforce the design and implementation of trusted relations among external systems and architectures. • Ensure system security needs are established and maintained for operations development, security requirements definition, security risk assessment, systems analysis, systems design, security test and evaluation, certification and accreditation, systems hardening, vulnerability, testing and scanning, incident response, disaster recovery, and business continuity planning; and provides analytical support for security policy development and analysis. • Other related work as directed.

Required Qualifications: • Active DoD Security Clearance of SECRET, or higher • Minimum eight (8) + years’ experience and proven track record supporting IT customers as part of an enterprise environment. • BA/BS and 8+ years of Computer Science or equivalent experience • CISSP, CASP, CISA, CISM or similar for IAM Level III DoD 8570/8140 certification • Experience with FedRAMP Cloud processes • Knowledge of the DoD cybersecurity and policy requirements set forth in DoDI 8500.01 “Cybersecurity”, NIST 800-53v5 Assessing Privacy and Security Controls and DoDI 8510.01 “Risk Management Framework • Extensive and experience in NIST 800-53, Risk Framework security controls in eMASS • Ability to lead in highly collaborative, fast-paced, growth-focused environment. • Experience and knowledge in cybersecurity tools such as Nessus ACAS, Microsoft Defender Endpoint, McAfee • Extensive experience and knowledge with Incident Response testing/plans and Contingency testing/plans • Experience with systems that deploy API gateways, firewalls, access control lists, IP subnetting, NAT and other network device in Cloud. • Experience communicating with and coordinating across multiple stakeholders and teams to align to and execute unified goals and plans. • The ability to effectively communicate with people ranging from non-technical to engineering level.

Desired Qualifications: • Familiarization with DoD enterprise environments • Familiarization with Agile work environments • Familiarization with Microsoft Azure Cloud environment

The likely salary range for this position is $142,792 - $184,000. This is not, however, a guarantee of compensation or salary. Rather, salary will be set based on experience, geographic location and possibly contractual requirements and could fall outside of this range.

Scheduled Weekly Hours: 40

Travel Required: 25-50%

T elecommuting Options: Hybrid

Work Location: USA MD Fort Meade

Additional Work Locations:

Total Rewards at GDIT: Our benefits package for all US-based employees includes a variety of medical plan options, some with Health Savings Accounts, dental plan options, a vision plan, and a 401(k) plan offering the ability to contribute both pre and post-tax dollars up to the IRS annual limits and receive a company match. To encourage work/life balance, GDIT offers employees full flex work weeks where possible and a variety of paid time off plans, including vacation, sick and personal time, holidays, paid parental, military, bereavement and jury duty leave. To ensure our employees are able to protect their income, other offerings such as short and long-term disability benefits, life, accidental death and dismemberment, personal accident, critical illness and business travel and accident insurance are provided or available. We regularly review our Total Rewards package to ensure our offerings are competitive and reflect what our employees have told us they value most.    

Our Identity Verification Process: As part of the hiring process, we will ask you to complete an identity verification process that leverages advanced biometrics and artificial intelligence to ensure

Tailor your resume for this GDIT role before you apply.

Tailor my resume for this job

Similar jobs

More like this: Security & Cybersecurity Jobs · Browse all jobs

Free ATS checker · How to Tailor Your Resume to a Job Description (Step by Step)