
Security Compliance Analyst
Posted 1 day ago

Posted 1 day ago
This is a fully remote position, open to applicants in Virginia.
• Assist the SIAM in implementing the program’s cybersecurity compliance and information assurance strategy.
• Coordinate security documentation, the execution of controls, and ATO and cATO activities in collaboration with ISOs and ISSOs.
• Aid in FISMA compliance efforts, including annual self-assessments, security control evaluations, and IG/OMB-driven audits.
• Create, review, and uphold SSPs, SARs, POA&Ms, and RARs.
• Support RMF activities such as control selection, monitoring of implementation, assessment, and ongoing surveillance.
• Monitor POA&M remediation efforts, ensuring that findings are documented, assigned, and resolved punctually.
• Assemble materials and evidence packages for internal reviews, external audits, and compliance assessments.
• Contribute to the compliance posture of ICAM systems, tracking updates to policies, procedures, and controls.
• Maintain documentation for continuous monitoring and assist with monthly and quarterly compliance reporting.
• Engage in control assessments, walkthroughs, and stakeholder interviews.
• Manage documentation repositories and audit trails to ensure readiness for inspections.
• Report compliance status, risks, and action items to the SIAM and program leadership.
• Bachelor’s degree in Cybersecurity, Information Technology, Information Systems, or a related discipline, or equivalent professional experience.
• Over 2 years of experience in federal information security compliance, IT security, or a related area.
• Proficient with Governance, Risk, and Compliance (GRC) tools such as Xacta, CSAM, RSA Archer, or similar platforms.
• Proven experience in supporting FISMA compliance activities and/or federal security audits.
• Experience working with ISOs and/or ISSOs on system security documentation and A&A initiatives.
• Exceptional written and verbal communication abilities.
• Strong organizational capabilities and attention to detail, especially concerning documentation control and audit readiness.
• Capacity to analyze complex requirements and distill them into clear, actionable tasks and processes.
• Must be a U.S. citizen.
• Eligible to acquire and maintain a Public Trust security clearance.
• Preferred: experience in supporting an ICAM program or a comparable identity governance initiative.
• Preferred: knowledge of FICAM architecture, NIST SP 800-63 digital identity guidelines, or OMB M-19-17 or subsequent ICAM policy.
• Preferred: relevant certifications such as CompTIA Security+, CAP, CISSP, or CISA.
• Preferred: experience in supporting continuous monitoring programs or cATO initiatives.
• Preferred: prior experience in a federal contracting environment supporting a civilian or defense agency.
• 144 hours of paid time off (PTO).
• 11 holidays observed.
• 85% of insurance premiums covered.
• Healthcare coverage through major insurance providers.
• 401(k) plan.
• Opportunities for continuing education.
• Certification maintenance and reimbursement.
• Career development opportunities.
• Technical and professional growth options.
Positivo S+
General Dynamics Information Technology
Gifthealth
General Dynamics Information Technology
Get handpicked remote jobs straight to your inbox weekly.