Federal Risk and Authorization Management Program Cybersecurity Analyst job at Motorola Solutions in US National
Job description
About the role
At Motorola Solutions, we believe that everything starts with our people. We are a global close-knit community, united by the relentless pursuit to help keep people safer everywhere. We build and connect technologies to help protect people, property and places. This role owns the execution of cybersecurity assessments and automation that directly supports the security authorization of client information systems. The hire will engage directly with clients through verbal communication to perform interviews, understand their needs, and provide effective solutions based on FISMA, NIST RMF, and FedRAMP standards. They will apply scripting skills to develop and improve automations that streamline assessment processes and evidence collection. The position requires working independently or as part of a client delivery team in a fast-paced, deadline-driven, remote environment with travel up to 25% as required. The Cybersecurity Analyst plays a critical role in preparing clear and accurate reports and documentation, emphasizing the creation of scripts to automate analysis and report generation.
Key facts
What you'll do
Conduct comprehensive assessments by analyzing cybersecurity documentation and performing evidence collection, interviews, and tests to evaluate compliance with relevant standards such as FISMA, NIST RMF, and FedRAMP.
Create scripts and utilize scripting skills to automate repetitive tasks and improve the efficiency of security assessments, reporting, and evidence collection.
Perform system and network vulnerability scanning and analysis using tools such as Nessus/ACAS, SCC, and DISA STIGs/STIG Viewer.
Prepare clear and accurate reports and documentation, with an emphasis on creating scripts to automate analysis and report generation.
Engage directly with clients through verbal communication to perform interviews for assessments, understand their needs, and provide effective solutions.
Work independently or as part of a client delivery team in a fast-paced, deadline-driven, remote environment.
Travel up to 25% for client engagements as required.
Apply knowledge of Cloud Computing, FedRAMP, FISMA, NIST/DoD RMF, and NIST SP 800-series publications to assess and analyze cybersecurity documentation for client information systems.
Utilize beginner knowledge of testing tools such as Nessus/ACAS, SCC, and DISA STIGs/STIG Viewer to support assessment activities.
Requirements
Strong verbal communication skills with the ability to articulate ideas clearly and confidently in face-to-face and phone interactions with clients.
Basic knowledge of Cloud Computing, FedRAMP, FISMA, NIST/DoD RMF, and NIST SP 800-series publications.
Demonstrable scripting skills in at least one language (e.g., Python, PowerShell, Bash) for task automation.
Beginner knowledge of testing tools such as Nessus/ACAS, SCC, DISA STIGs/STIG Viewer.
Strong organizational, planning, and attention to detail skills.
Self-motivated with a strong technical aptitude.
Must obtain a FedRAMP required (A2LA R311) industry certification within 3 months.
Ability to work in high security areas governed by the US Department of Justice's "Criminal Justice Information Services (CJIS) Security Policy" and therefore requires successfully passing a more stringent fingerprint-based background check.
Nice to have
1+ years of experience in performing or participating in FISMA-based security Assessment and Authorization (A&A) activities.
Experience in creating and maintaining scripts for cybersecurity tools and processes, such as vulnerability scanning or compliance checks.
Proficiency in performing technical assessments using standard industry tools such as Nessus, DB Protect, Acunetix, and ACAS (for DoD).
Ability to identify and mitigate cyber security risks through formal assessment activities.
Experience and technical knowledge in security engineering, secure architecture development, system and network security, authentication and security protocols, applied cryptography, and application security.
Practical notes
Travel up to 25% for client engagements as required.
Must obtain a FedRAMP required (A2LA R311) industry certification within 3 months.
This position is subject to working in high security areas governed by the US Department of Justice's "Criminal Justice Information Services (CJIS) Security Policy" and therefore requires successfully passing a more stringent fingerprint-based background check.