Cybersecurity Analyst
Job description
About the role
The is responsible for safeguarding the compliance posture of a mission-critical Government Cloud environment by executing strategic oversight of security documentation and control implementation. You will serve as the primary liaison for managing Plan of Action and Milestones (POA&M) tracking, ensuring all remediation activities are monitored to closure in alignment with strategic timelines. The role requires ownership of the Technical Reference Model (TRM) submission lifecycle, including drafting, justification, and maintenance of all associated artifacts for review by authorizing officials. You will manage the Business Partner Extranet (BPE) request process, coordinating with internal stakeholders to gather necessary information and maintain active workflows. This position demands meticulous attention to detail when maintaining security documentation such as System Security Plans, Vulnerability Management Plans, and Plans of Action and Milestones across a multi-tenant platform. You will ensure strict adherence to National Institute of Standards and Technology (NIST) control families and Control Correlation Identifiers (CCI) to maintain regulatory compliance. The role involves close collaboration with federal agency representatives to address authorization and accreditation activities. Effective communication is critical as you translate complex security findings into clear mitigation strategies for technical and executive audiences.
Key facts
What you'll do
- Execute comprehensive POA&M management by creating, tracking, and updating remediation efforts within the System Notification of Authorization (SNOW) Authorization Monitoring (CAM) framework.
- Synthesize POA&M verbiage that directly aligns with identified findings, articulating precise mitigation strategies and residual risk assessments for portfolio information systems.
- Oversee the lifecycle of POA&Ms, ensuring they are appropriately closed out once mitigated, resolved through events of OBE, or deemed no longer relevant to the associated system.
- Author detailed Technical Reference Model (TRM) submissions, providing thorough justifications for software and application usage requests to support agency operational needs.
- Attend and contribute to TRM approval meetings, presenting technical and security implications to facilitate informed decision-making by review boards.
- Initiate and manage Business Partner Extranet (BPE) requests, including comprehensive information gathering and coordination of required team meetings to validate system interconnections.
- Maintain an exhaustive catalog of BPE submissions, tracking status updates and ensuring timely responses to information requests from integrated business partners.
- Preserve the integrity of security documentation by consistently updating System Security Plans (SSP), Information System Vulnerability Management Plans (ISVMP), and Plan of Action and Milestones (POA&M) artifacts.
- Conduct thorough analysis of security assessment artifacts, including Security Impact Analyses (SIA), Privacy Impact Assessments (PIA), and Plan of Security Testing (PTA) to identify compliance gaps.
- Implement rigorous Configuration Management Plan (CMP) oversight to ensure system baselines are consistently maintained and deviations are promptly addressed.
- Provide robust support to federal agency oversight bodies by supplying accurate data, reports, and documentation in compliance with regulatory mandates.
- Champion continuous improvement by identifying process enhancements within the authorization lifecycle that increase efficiency and strengthen security postures.
- Utilize advanced analytical skills to correlate control implementation across complex environments using Control Correlation Identifiers (CCI).
- Demonstrate proactive problem-solving by anticipating potential compliance risks and developing preemptive mitigation strategies.
- Serve as a subject matter expert for the platform, mentoring colleagues on best practices for security documentation and authorization processes.
Requirements
- Possess a minimum of 5 years of cumulative experience in cybersecurity and information assurance within a professional environment.
- Hold a Bachelor's Degree in cybersecurity, information technology, or a closely related field; a related degree or Certified Authorization Professional (CAP) certification is strongly preferred.
- Exhibit excellent experience in the creation, maintenance, and periodic review of POA&Ms to ensure alignment with evolving threat landscapes.
- Demonstrate excellent ability to ensure POA&M activities align precisely with NIST control families and associated Control Correlation Identifiers (CCI).
- Show excellent experience in drafting, revising, and maintaining Technical Reference Model (TRM) submissions for complex system integrations.
- Display excellent ability to submit, track, and maintain Business Partner Extranet (BPE) requests, managing workflows from initiation to closure.
- Maintain above average experience in managing and updating security documentation, including System Security Plans and Vulnerability Management Plans.
- Provide evidence of experience supporting a federal agency through complex authorization and accreditation processes.
- Demonstrate excellent verbal and written communication skills, with the ability to convey technical concepts to diverse stakeholders.
- Meet the eligibility requirements for a Federal Civilian Public Trust clearance, which includes a comprehensive background investigation.
- Be a U.S. Citizen or a Permanent Resident that has lived in the United States for at least 3 years.
- Pass standard background checks that include a review of financial history and criminal records.
- Successfully complete suitability reviews involving interviews with agency representatives and personal references.
- Maintain the ability to obtain and hold a Public Trust Clearance, requiring adherence to strict security guidelines.
Practical notes
Hours: Full-time (40 hours per week).
Employment: Remote in any reputed company jurisdiction not excluded from this job advertisement.
Visa sponsorship: Not available.
Deadline: No deadline specified.