
FISMA Security Analyst
Posted Sep 16

Posted Sep 16
This is a fully remote position, open to applicants in United States.
• Deliver technical support for the architecture, design, and execution of information technology security systems.
• Investigate security products and services while facilitating the deployment of enterprise security solutions.
• Create, implement, and sustain organization-wide information security capabilities.
• Evaluate enterprise business models and IT systems to identify security risks and considerations for risk management.
• Establish security requirements at both the enterprise and system levels.
• Execute and evaluate security and privacy controls in accordance with NIST SP 800-53 Revision 5 and relevant federal control baselines.
• Carry out the NIST Risk Management Framework lifecycle, which includes control implementation, assessment, authorization, and ongoing monitoring.
• Develop, review, and maintain RMF and FISMA documentation, such as SSPs, SARs, POA&Ms, risk assessments, control implementation statements, procedures, governance documentation, and authorization packages.
• Recommend technical solutions for security architecture and design at the system and application levels.
• Facilitate continuous monitoring, vulnerability management, control assessments, risk tracking, remediation validation, and reporting to stakeholders.
• Evaluate cybersecurity risks linked to APIs, integrations, data exchanges, and automated workflows.
• Examine API designs and implementations for compliance with security standards, secure configurations, access controls, token management, and the protection of sensitive data.
• Assess risks associated with Robotic Process Automation, including bots, workflows, service accounts, credentials, privileges, logging, exception handling, and operational resilience.
• Identify and document risks concerning intelligent automation, RPA, API integrations, and emerging technologies, while recommending appropriate mitigation strategies.
• Engage with staff, clients, government partners, and stakeholders through meetings, briefings, training sessions, and updates on policy and compliance.
• Participate in meetings on camera while safeguarding proprietary company and customer information.
• Travel is not required.
• Capability to obtain a Public Trust Clearance and ITILv4 Foundation Certification.
• Demonstrates and applies a thorough understanding across key tasks and significant assignments.
• Operates as a security authority across various project assignments.
• Proven track record of working independently in a fully or partially remote setting with minimal supervision, and may oversee or lead others.
• Proficient in communicating effectively in both oral and written formats with staff and clients at all levels.
• Adhere to standard working hours as stipulated in the DIGIT contract and be available for meetings and collaborative tasks during those hours.
• Exhibit a demonstrated capability to apply comprehensive knowledge across key tasks and high-impact assignments.
• Preferred certifications include CISSP, CISA, CISM, Security+, or other relevant security credentials.
• Familiarity with CUI requirements for unclassified IT systems is preferred.
• Proven history of successfully obtaining initial A&A and reauthorization.
• Comfortable with unclassified network administration, covering network infrastructure and security best practices, LAN administration and maintenance, user control, VPN access, firewalls, mobile device management, and identity and authentication services management.
• Proficient with Windows operating systems.
• Experience with Linux operating systems.
• Familiarity with Google Suite, Microsoft Office, and ServiceNow.
• 10–15 years of experience along with a bachelor's degree or equivalent qualifications.
• At least 3–5 years of direct experience supporting FISMA and Financial Audit Requirements.
• At least 3–5 years of direct experience in supporting cybersecurity compliance and implementing measures to mitigate threats.
• At least 3–5 years of direct experience providing continuous monitoring security expertise to business units and key stakeholders.
• At least 3–5 years of direct experience in creating and delivering end-user briefings, training, policy, and/or compliance updates.
• Experience as a remote worker showing effective time management, self-discipline, cultural change management, and an Agile mindset.
• If working remotely, maintain a secure home workspace in accordance with information security policies.
• Medical
• Dental
• Vision
• AD&D
• STD
• LTD
• Company-paid Life Insurance
• 401k with employer contribution
• Paid Time Off
• Pet Insurance
Vision Cybersecurity
Stefanini LATAM
Bancorbrás
Kemper
Get handpicked remote jobs straight to your inbox weekly.