More jobs:
Journeyman Information Security Analyst
Job in
Seattle, King County, Washington, 98127, USA
Listed on 2026-02-19
Listing for:
OCT Consulting, LLC
Full Time
position Listed on 2026-02-19
Job specializations:
-
IT/Tech
Cybersecurity, IT Consultant
Job Description & How to Apply Below
Journeyman Information Security Analyst
OCT Consulting is a business management and technology consulting firm that provides support to Federal Government clients. We provide consulting services in the areas of Strategy, Process Improvement, Change Management, Program and Project Management, Acquisition/Procurement, and Information Technology.
Responsibilities and DutiesOCT currently has an opening for a Journeyman Information Security Analyst to work with our federal client. On this project, you will provide subject matter expertise to execute NIST, FISMA, Office of Management and Budget (OMB), FedRAMP, Treasury, and Internal Revenue Manual (IRM) technical Security Controls Assessments and Risk Analyses on information systems to identify risks and vulnerabilities.
This position is contingent upon contract award. Day to day responsibilities include:- Execute the hands‑on manual technical NIST SP 800-53 security control assessments including any overlays (e.g. high value asset, artificial intelligence, critical software, FedRAMP, etc.)
- Assess the impacts of new laws, regulations, policies, and guidance on client Security Assessment requirement initiatives and advise on recommended process changes. Additionally review current client policies, guidance, manuals, and supporting tools to recommend updates and improvements, and assist with the implementation of any new guidelines
- Recommend process improvements and automated approaches to support testing methodologies, establishing streamlined/agile approaches for Security Controls Assessments
- Maintain key assessment package templates to ensure compliance with current/emerging federal guidance and lessons learned
- Execute security controls assessments and provide training to ensure Government staff understand and can perform security control assessments
- Provide subject matter expertise to incorporate threat modeling & hunting into the security control assessment process, improving the Government’s ability to proactively identify and mitigate risks
- Identify, develop, and implement automation solutions that enhance the efficiency, accuracy, and timeliness of program operations. Evaluate current business processes, workflows, and system interactions to determine opportunities where automation—such as robotic process automation (RPA), workflow orchestration, data transformation tools, or other intelligent automation technologies—can reduce manual workload, eliminate redundancies, and improve mission outcomes
- Must be a U.S. Citizen
- Bachelor’s degree in Cybersecurity, Information Systems, Computer Science, or related field
- Security+ CE certification required
- Higher-level certifications (e.g., CISSP, CISM, CEH, CAP) are highly preferred and may substituted for additional years of experience
- 5 to 8 years of progressively responsible experience in information security, cyber risk management, or IT security operations
- At least 3 years of hands‑on experience in system security analysis, vulnerability management, or incident response within a Federal Information Systems Security or equivalent enterprise environment
- Excellent presentation and verbal communication skills
- Ability to create accurate written work products by following Job Aids and document templates
- Ability to work under pressure and tight timelines for multiple projects with positive attitude and flexibility
- Knowledge of FISMA, NIST Special Publications, OMB, Risk Management Framework (RMF), and ISCM Plan development.
- IT security knowledge with desired Professional Certifications from the International Information System Security Certification Consortium (ISC)2, the International Society for Automation (ISA), the Project Management Institute (PMI), CompTIA, or the SANS Institute
- Knowledge and experience with technology risk assessments covering Webservices, network appliances and software
- Knowledge and experience of the IRS Enterprise Lifecycle and OneSDLC
- Knowledge of System Interconnections to include virtual private network (VPN) and other encryption technologies
- Knowledge and experience with cloud systems, CSPs, and FedRAMP requirements
- Project management experience, experience in monitoring and…
To View & Apply for jobs on this site that accept applications from your location or country, tap the button below to make a Search.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
Search for further Jobs Here:
×