About the job
**This position is contingent upon contract award**
SOSi is looking for a dedicated Security & Compliance Analyst to fulfill mission requirements by developing, integrating, and maintaining a scalable and federated data ecosystem. This role is crucial for enhancing interoperability, governance, and mission-driven analytics for our Department of Defense (DoD) client. The primary goal is to address operational challenges between DoD, Intelligence Community (IC), interagency, and international partners, facilitating real-time information exchange and customized analytical capabilities.
Key Responsibilities:
- Oversee and validate Kubernetes and data lake deployments to ensure compliance with Risk Management Framework (RMF), NIST 800-53, and DoD IL4/IL5 standards, in collaboration with cybersecurity teams.
- Maintain continuous monitoring dashboards and conduct vulnerability assessments of the deployed infrastructure and workloads, supporting the agency’s Authority to Operate (ATO) process and overall risk posture.
- Draft and update security documentation, including System Security Plans (SSPs), Security Assessment Reports (SARs), and Plans of Action and Milestones (POA&Ms) to reflect architectural changes and risk conditions.
- Implement encryption, logging, and identity access management policies (IAM, RBAC, audit logging) to ensure accountability across the Kubernetes-based data environment.
- Compile the Security & Compliance Assessment Report, summarizing control effectiveness, findings, and suggested remediation measures.
