Information Security Analyst Sr Principal - Cloud - Hybrid

Clearance Level
Secret
Category
Cyber and IT Risk Management
Location
Fort Meade, Maryland
(Hybrid Workplace)
Key Skills For Success

Cybersecurity

Information Security

RMF

Security Requirements

System Security

REQ#: RQ227262
Public Trust: None
Requisition Type: Regular
Your Impact

Own your opportunity to support our nation's defense. Make an impact by connecting and securing critical operations across the globe, keeping our country safe and secure.

Job Description

As an Information Security Analyst Sr Principal, you will be responsible for the ICAM program’s network accreditation on both unclassified and classified networks. You will also be responsible for executing and reviewing security assessments of computing environments to identify points of vulnerability, non-compliance with established IA standards and regulations, and recommend mitigation strategies.

In this role, a typical day will include:

  • Execute success in obtaining an accreditation and maintaining the accreditation for ICAM on a classified network.
  • Perform Risk Management Framework (RMF) actions in eMASS such as control assessments, PPSM, upload and manage ICAM assets in hardware/software list, upload STIG checklists and ACAS vulnerability reports.
  • Define, draft, publish, and maintain Information Security policies, standards, and guidelines such as Access Control Plan, Identification and Authentication Plan, Auditing and Accountability Plan, Contingency Plan, Incident Response Plan, Vulnerability Management, Continuous Monitoring, Backup and Recovery, System Integrity Plan, Key Management, Media Protection, etc.
  • Develop and finalize RMF documentation to include Security Plans, Implementation Plans, Plans of Action and Milestones (POA&Ms), and Risk Assessment Reports
  • Assess system compliance against NIST, DoD, and DHA security requirements to include the NIST 800-53 controls, and DISA Security Technical Implementation Guides (STIGs) and Security Requirements Guides (SRGs).
  • Spearhead support government compliance assessments such as penetration testing and accreditation and compliance inspections assessments and mitigations to system security threats/risks throughout the program life cycle.
  • Work with the internal and external stakeholders to resolve compliance or audit issues in a timely manner. Enforce the design and implementation of trusted relations among external systems and architectures.
  • Ensure system security needs are established and maintained for operations development, security requirements definition, security risk assessment, systems analysis, systems design, security test and evaluation, certification and accreditation, systems hardening, vulnerability, testing and scanning, incident response, disaster recovery, and business continuity planning; and provides analytical support for security policy development and analysis.
  • Other related work as directed.

Required Qualifications:

  • Active DoD Security Clearance of SECRET, or higher
  • Minimum eight (8) + years’ experience and proven track record supporting IT customers as part of an enterprise environment.
  • BA/BS and 8+ years of Computer Science or equivalent experience
  • CISSP, CASP, CISA, CISM or similar for IAM Level III DoD 8570/8140 certification
  • Experience with FedRAMP Cloud processes
  • Knowledge of the DoD cybersecurity and policy requirements set forth in DoDI 8500.01 “Cybersecurity”, NIST 800-53v5 Assessing Privacy and Security Controls and DoDI 8510.01 “Risk Management Framework
  • Extensive and experience in NIST 800-53, Risk Framework security controls in eMASS
  • Ability to lead in highly collaborative, fast-paced, growth-focused environment.
  • Experience and knowledge in cybersecurity tools such as Nessus ACAS, Microsoft Defender Endpoint, McAfee
  • Extensive experience and knowledge with Incident Response testing/plans and Contingency testing/plans
  • Experience with systems that deploy API gateways, firewalls, access control lists, IP subnetting, NAT and other network device in Cloud.
  • Experience communicating with and coordinating across multiple stakeholders and teams to align to and execute unified goals and plans.
  • The ability to effectively communicate with people ranging from non-technical to engineering level.

Desired Qualifications:

  • Familiarization with DoD enterprise environments
  • Familiarization with Agile work environments
  • Familiarization with Microsoft Azure Cloud environment

Work Requirements

Years of Experience

8 + years of related experience

* may vary based on technical training, certification(s), or degree

Certification

GIAC Security Essentials (GSEC) | Global Information Assurance Certification (GIAC) - Global Information Assurance Certification (GIAC)

CompTIA Security+ CE | CompTIA - CompTIA

CompTIA SecurityX CE | CompTIA - CompTIA

Certified Information Security Manager (CISM) | Information Systems Audit and Control Association (ISACA) - Information Systems Audit and Control Association (ISACA)

Certified Information Systems Security Professional (CISSP) | International Information System Security Certification Consortium (ISC2) - International Information System Security Certification Consortium (ISC2)

Travel Required

25-50%

Citizenship

U.S. Citizenship Required

Salary and Benefit Information

The likely salary range for this position is $142,792 - $184,000. This is not, however, a guarantee of compensation or salary. Rather, salary will be set based on experience, geographic location and possibly contractual requirements and could fall outside of this range.
View information about benefits and our total rewards program.

Our Identity Verification Process

As part of the hiring process, we will ask you to complete an identity verification process that leverages advanced biometrics and artificial intelligence to ensure authenticity and protect against identity fraud. You are expected to be on camera during virtual interviews. We reserve the right to take your picture to verify your identity and prevent fraud. By proceeding, you authorize the collection, processing, and use of your biometric data for identity verification and security purposes.

About Our Work

We are GDIT. A global technology and professional services company that delivers technology solutions and mission services to every major agency across the U.S. government, defense and intelligence community. Our 26,000 experts extract the power of technology to create immediate value and deliver solutions at the edge of innovation. We operate across 50+ countries worldwide, offering leading mission-ready capabilities in AI, cloud, cyber and software development.

Join our Talent Community to stay up to date on our career opportunities and events at gdit.com/tc.

Equal Opportunity Employer / Individuals with Disabilities / Protected Veterans