
Cybersecurity Analyst, Information Systems Security
Posted 2 days ago

Posted 2 days ago
This is a fully remote position, open to applicants in Virginia.
• Assist in the implementation and ongoing application of the NIST Risk Management Framework alongside DHS/FEMA security policies and procedures.
• Create, sustain, and revise System Security Plans, Security Assessment Reports, Plans of Action and Milestones, Contingency Plans, Configuration Management Plans, and other related authorization documents.
• Support Assessment and Authorization efforts for FEMA systems, applications, and cloud environments.
• Preserve security documentation and evidence within the relevant DHS/FEMA governance, risk, and compliance systems.
• Execute and document security control assessments, while aiding in the application and validation of NIST SP 800-53 controls.
• Monitor cybersecurity findings, vulnerabilities, POA&Ms, remediation efforts, and risk acceptance until closure.
• Analyze vulnerability scanning and security monitoring outputs from Tenable/Nessus, CrowdStrike, Elastic, and other sanctioned security platforms.
• Collaborate with system administrators, cloud engineers, DevSecOps teams, application teams, and system owners to address vulnerabilities and configuration issues.
• Contribute to continuous monitoring initiatives, including regular security control reviews, vulnerability management, configuration compliance, and necessary reporting.
• Evaluate proposed system and infrastructure modifications for cybersecurity implications and ensure security requirements are integrated throughout the system lifecycle.
• Aid in adherence to DHS security directives, FEMA policies, FISMA, FedRAMP, NIST guidance, and federal cybersecurity standards.
• Support incident response, security investigations, audit inquiries, and cybersecurity reporting.
• Engage in security assessments, technical meetings, change management processes, and coordination with FEMA cybersecurity stakeholders.
• Identify cybersecurity risks and offer suggestions for mitigation, remediation, or risk management strategies.
• Maintain audit-ready security documentation and relevant supporting evidence.
• Bachelor's degree in Cybersecurity, Information Technology, Computer Science, Information Systems, or a related field; equivalent experience may be accepted in place of a degree.
• Over 5 years of experience in cybersecurity or information assurance, ideally within federal government settings.
• Proficient in supporting RMF, A&A, security control implementation, continuous monitoring, vulnerability management, and POA&M oversight.
• Solid understanding of NIST SP 800-53, NIST SP 800-37, FISMA, FedRAMP, and federal cybersecurity standards.
• Experience in developing and maintaining cybersecurity authorization and compliance documentation.
• Familiarity with enterprise and cloud environments, including AWS and/or Microsoft Azure.
• Excellent written and verbal communication skills for engaging with both technical and non-technical stakeholders.
• U.S. Citizenship is required.
• Ability to obtain and maintain the necessary DHS/FEMA suitability and security clearance/access requirements.
• Preference is given to candidates with FEMA Public Trust Clearance or DHS Public Trust obtained within the last 3 years, or those with active/current Public Trust.
• Preferred: Previous experience supporting FEMA, DHS, or another federal civilian agency.
• Preferred: Experience in securing AWS GovCloud and/or Azure Government environments.
• Preferred: Background in vulnerability management, SIEM, endpoint security, and continuous monitoring technologies.
• Preferred: Experience collaborating with Agile and DevSecOps engineering teams.
• Preferred: Understanding of Zero Trust architecture and federal cloud security requirements.
• Preferred: One or more relevant certifications, such as CISSP, CAP/CGRC, Security+, CISM, CCSP, or equivalent cybersecurity certification.
• Competitive salary based on experience and clearance level.
• Comprehensive medical, dental, and vision insurance.
• 401(k) plan with company contributions.
• Paid time off.
• Eleven federal holidays.
• Reimbursement for certifications and training programs.
• Life and disability insurance.
• Opportunities for long-term career advancement on stable, multi-year programs.
Rimini Street
Rimini Street
Get handpicked remote jobs straight to your inbox weekly.