Information Security Analyst Sr Principal - Cloud - Hybrid
Listed on 2026-09-02
-
IT/Tech
Cybersecurity, Information Security & Data Protection, IT Consultant
Information Security Analyst Sr Principal
Location:
USA MD Fort Meade Full Part/Time:
Full time Job Req: RQ227262 Type of
Requisition :
Regular Job Family:
Cyber and IT Risk Management
Job Qualifications:
Skills:
Cybersecurity, Information Security, RMF, Security Requirements, System Security
Certifications:
None
Experience:
8 + years of related experience US Citizenship
Required:
Yes
Job Description:
As an Information Security Analyst Sr Principal, you will be responsible for the ICAM program's network accreditation on both unclassified and classified networks. You will also be responsible for executing and reviewing security assessments of computing environments to identify points of vulnerability, non-compliance with established IA standards and regulations, and recommend mitigation strategies. In this role, a typical day will include:
- Execute success in obtaining an accreditation and maintaining the accreditation for ICAM on a classified network.
- Perform Risk Management Framework (RMF) actions in eMASS such as control assessments, PPSM, upload and manage ICAM assets in hardware/software list, upload STIG checklists and ACAS vulnerability reports.
- Define, draft, publish, and maintain Information Security policies, standards, and guidelines such as Access Control Plan, Identification and Authentication Plan, Auditing and Accountability Plan, Contingency Plan, Incident Response Plan, Vulnerability Management, Continuous Monitoring, Backup and Recovery, System Integrity Plan, Key Management, Media Protection, etc.
- Develop and finalize RMF documentation to include Security Plans, Implementation Plans, Plans of Action and Milestones (POA&Ms), and Risk Assessment Reports
- Assess system compliance against NIST, DoD, and DHA security requirements to include the NIST 800-53 controls, and DISA Security Technical Implementation Guides (STIGs) and Security Requirements Guides (SRGs).
- Spearhead support government compliance assessments such as penetration testing and accreditation and compliance inspections assessments and mitigations to system security threats/risks throughout the program life cycle.
- Work with the internal and external stakeholders to resolve compliance or audit issues in a timely manner. Enforce the design and implementation of trusted relations among external systems and architectures.
- Ensure system security needs are established and maintained for operations development, security requirements definition, security risk assessment, systems analysis, systems design, security test and evaluation, certification and accreditation, systems hardening, vulnerability, testing and scanning, incident response, disaster recovery, and business continuity planning; and provides analytical support for security policy development and analysis.
- Other related work as directed.
Required Qualifications:
- Active DoD Security Clearance of SECRET, or higher
- Minimum eight (8) + years' experience and proven track record supporting IT customers as part of an enterprise environment.
- BA/BS and 8+ years of Computer Science or equivalent experience
- CISSP, CASP, CISA, CISM or similar for IAM Level III DoD 8570/8140 certification
- Experience with FedRAMP Cloud processes
- Knowledge of the DoD cybersecurity and policy requirements set forth in DoDI 8500.01 "Cybersecurity", NIST 800-53v5 Assessing Privacy and Security Controls and DoDI 8510.01 "Risk Management Framework
- Extensive and experience in NIST 800-53, Risk Framework security controls in eMASS
- Ability to lead in highly collaborative, fast-paced, growth-focused environment.
- Experience and knowledge in cybersecurity tools such as Nessus ACAS, Microsoft Defender Endpoint, Mc Afee
- Extensive experience and knowledge with Incident Response testing/plans and Contingency testing/plans
- Experience with systems that deploy API gateways, firewalls, access control lists, IP subnetting, NAT and other network device in Cloud.
- Experience communicating with and coordinating across multiple stakeholders and teams to align to and execute unified goals and plans.
- The ability to effectively communicate with people ranging from non-technical to engineering level.
Desired
Qualifications:
- Familiarization with DoD enterprise environments
- Familiarization with Agile work environments
- Familiarization with Microsoft Azure Cloud environment
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).