Cybersecurity Analyst, RMF & ATO
Listed on 2026-09-04
-
IT/Tech
Cybersecurity, Information Security & Data Protection
The Cybersecurity Analyst provides cybersecurity, information assurance, risk management, and compliance support across Digital Services initiatives. The role supports Authorization to Operate (ATO) activities, continuous monitoring, security assessments, vulnerability management, and implementation of federal cybersecurity requirements while collaborating with engineering, architecture, product, infrastructure, and program teams throughout the solution lifecycle. The Cybersecurity Analyst will serve as the Information System Security Officer (ISSO) for assigned federal systems and environments.
This position contributes to cybersecurity governance, develops and maintains security documentation, supports security assessments and audits, and helps ensure digital products, cloud environments, and enterprise technology solutions meet applicable federal security and privacy requirements.
Essential Job Functions Cybersecurity Advisory & Secure Solution DeliveryProvide cybersecurity and privacy subject matter expertise across digital products, cloud services, enterprise applications, AI initiatives, and technology modernization efforts.
Advise project teams on identity and access management, security controls, data protection, authorization boundaries, and cybersecurity best practices throughout the system development lifecycle.
Review technical solutions, architectures, and proposed system changes to identify security risks and recommend appropriate mitigations.
Collaborate with software engineering, infrastructure, architecture, product, and data teams to integrate security requirements into solution planning, development, testing, deployment, and operational support.
Support alignment of technology initiatives with applicable federal cybersecurity, privacy, and risk management requirements.
Support identification, analysis, documentation, and tracking of cybersecurity and compliance risks across systems, applications, cloud environments, and operational activities.
Conduct or support security assessments, compliance reviews, technical evaluations, and security control validation activities.
Contribute to governance reviews, technical assessments, risk recommendations, and cybersecurity decision support.
Assist in developing and maintaining cybersecurity policies, procedures, standards, and implementation guidance.
Support continuous improvement of security posture, compliance maturity, and enterprise risk visibility.
Support Authorization to Operate (ATO) and Security Assessment and Authorization (SA&A) activities throughout the system lifecycle.
Develop, coordinate, maintain, and update authorization documentation, including System Security Plans (SSPs), Security Assessment Plans (SAPs), Security Assessment Reports (SARs), Plans of Action and Milestones (POA&Ms), and related security artifacts.
Coordinate security assessments, evidence collection, remediation activities, and documentation required to obtain and maintain system authorization.
Support authorization decisions by collaborating with governance bodies, Authorizing Officials, Information System Security Managers (ISSMs), system owners, and technical teams.
Advise project teams on authorization boundaries, security categorization, inheritance, and applicable federal security requirements.
Support continuous monitoring activities necessary to maintain ongoing authorization.
Coordinate vulnerability identification, remediation tracking, and verification activities in collaboration with engineering, infrastructure, and operations teams.
Review vulnerability scan results, assess security findings, monitor corrective actions, and track remediation through completion.
Support security incident response activities through documentation, coordination, evidence collection, corrective action tracking, and lessons learned.
Monitor changes to systems and cloud environments to help ensure continued compliance with approved security baselines.
Support internal and external audits through evidence collection, documentation, corrective action management, and audit response activities.
Coordinate with project managers, architects, developers, Corporate IT, Data & AI, and governance stakeholders to ensure cybersecurity considerations are integrated throughout project planning and delivery.
Participate in development of governance materials, executive briefings, technical documentation, reports, and other artifacts requiring cybersecurity or compliance input.
Promote secure development practices and provide guidance on applicable cybersecurity requirements across Digital Services initiatives.
Contribute to the continuous improvement of cybersecurity templates, operational procedures, documentation standards, and governance processes.
Bachelor's degree in Cybersecurity, Computer Science, Information…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).