About the job
Location: Herndon, VA 20171 (1 day a week in-office)
Employment Type: Full-time with Benefits
Remote Work: 4 days a week
We are seeking a skilled Cybersecurity Systems Analyst to support the FedRAMP and FISMA authorization of cutting-edge Cloud Products and third-party applications within diverse cloud environments. This role will involve providing security assessment support, developing essential security documentation, such as the System Security Plan (SSP), and conducting continuous monitoring activities.
- Conduct thorough analysis of vulnerability scans.
- Assess the security posture of Cloud Systems, evaluating vulnerabilities, Risk Management Framework (RMF) package status, accreditation models, compliance with PPS, and patching requirements, as well as Cyber Security Vulnerability Assessments (CSVA) mechanisms.
- Exhibit a robust understanding of current FedRAMP and NIST security controls and technologies, particularly in vulnerability management.
- Comprehend enterprise operating environments, including their security posture and the associated security controls.
- Document information system specifications and security controls, incorporating logical and physical diagrams, connectivity, and communication/data flow diagrams for both internal and external systems.
- Collaborate with security engineering, operations, and build teams to gather information and implement security controls.
- Contribute to the development of security documentation and input for technical control implementation.
- Understand the intent behind FedRAMP moderate security controls and FISMA security controls, communicating requirements effectively.
- Assist in the FedRAMP or FISMA authorization process, which includes preparing security engineering, build, and operations teams through training and mock interviews, updating implementation language in security documentation, developing necessary processes, and supporting FedRAMP PMO/Agency/CISO requests.
- Respond promptly to customer concerns regarding Continuous Monitoring (ConMon) activities.

