Job Description & How to Apply Below
The IA Analyst continuously monitors the security posture, manages vulnerabilities, and maintains the formal documentation required to achieve and sustain the Authority to Operate (ATO). This individual acts as the critical link between operational/engineering teams and the formal security accreditation process for both on-premise network services and cloud environments.
Roles & Responsibilities :
• Shall manage and maintain the security posture of enterprise cloud and network services throughout all phases of the Risk Management Framework (RMF) lifecycle.
• Shall conduct regular vulnerability scans of network and cloud assets using government-approved tools, analyze scan results, and coordinate with technical teams to prioritize remediation actions.
• Shall perform continuous monitoring and compliance validation of network devices, servers, and cloud resources against Security Technical Implementation Guides (STIGs) and other agency-specific benchmarks.
• Shall analyze and verify compliance within the enterprise cloud environment (e.g., AWS, Azure), ensuring alignment with FedRAMP controls and proper implementation of the shared responsibility model.
• Shall develop, update, and maintain all necessary RMF documentation, including the System Security Plan (SSP), security control traceability matrices, and Plans of Action and Milestones (POA&M).
• Shall serve as a primary point of contact for internal and external security audits, responsible for gathering and presenting evidence of control implementation to auditors.
• Shall track, interpret, and report on Information Assurance Vulnerability Management (IAVM) directives, coordinating with technical teams to ensure timely remediation and reporting.
• Shall provide information assurance expertise and guidance to network and cloud engineering teams to ensure security controls are integrated into the design and implementation of new services (“security by design”). Other Duties:
Please note this job description is not designed to cover or contain a comprehensive listing of activities, duties or responsibilities that are required of the employee for this job. Duties, responsibilities and activities may change at any time with or without notice. Desired/
Required Skills:
• Active Department of Defense Top Secret security clearance required.
• Must hold a certification meeting DoD 8570/8140 IAM Level II requirements (e.g., CompTIA CASP+, CISM, or CISSP).
• Must have a minimum of five (5) years of dedicated experience in Information Assurance or Cybersecurity. This experience must include:
• Direct, hands-on application of the Risk Management Framework (RMF) from initiation to continuous monitoring.
• Experience conducting vulnerability assessments using tools such as ACAS, Nessus, or equivalent systems.
• Experience implementing and auditing systems against Security Technical Implementation Guides (STIGs).
• At least two (2) years of experience must involve securing cloud environments (e.g., AWS, Azure) and a working knowledge of FedRAMP controls.
About the Company:
Nex Gen Data Systems is an emerging technologies focused company providing expert systems and network engineering solutions to the Department of Defense. Nex Gen Data Systems promotes a culture of knowledge and career advancement through continued learning, keeping our team current on the latest advances in systems and networking, and enabling our team to provide the best available solutions to our clients.
Benefits:
• Company covers 100% of premiums for the employee’s medical, dental, and vision insurance and subsidizes premiums for spouse and dependents.
• Company provides short and long term disability plans.
• 401(k) match…
To View & Apply for jobs on this site that accept applications from your location or country, tap the button below to make a Search.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
Search for further Jobs Here:
×