
Senior Security Analyst – A&A, Assessor – NIST
Posted 1 day ago

Posted 1 day ago
This is a fully remote position, open to applicants in Maryland.
• Execute A&A activities for NIST systems either independently or as part of a collaborative team.
• Collaborate with NIST personnel to develop technical and policy-oriented solutions to address or reduce identified risks.
• Assist system staff in formulating remediation plans for A&A findings.
• Offer guidance to Information System Security Officers (ISSO) regarding system documentation.
• Organize and perform vulnerability scans while analyzing the results.
• Prepare Security Assessment Reports that encompass both technical and policy-related components of assessments.
• Review and revise A&A packages in accordance with management feedback.
• 5 - 8 years of experience in implementing the NIST 800 Series Special Publications.
• Proven experience in carrying out IT assessor activities based on the NIST Risk Management Framework, including interviewing, examining, and testing relevant control sets.
• Experience in reviewing and/or updating System Security Plans, Contingency Plans, Privacy Threshold Assessments, hardware and software inventories, and system diagrams.
• Background in performing Security Test and Evaluation and creating Security Assessment Reports for NIST senior management.
• Experience presenting risk and vulnerability briefings to management and government stakeholders.
• Familiarity with vulnerability data, drafting Assessment Reports, POA&Ms, and Risk Acceptance justifications.
• Knowledge in developing and enforcing IT security policies that address the confidentiality, integrity, and availability of information systems.
• Excellent technical oral and written communication skills, along with strong customer service abilities.
• Capability to successfully complete a National Agency Check with Local Agency Check (NACLC).
• Candidates should be able to operate effectively in a general office setting.
• Previous federal or GOVCON experience is preferred.
• Experience with cloud platforms (AWS or Azure) is preferred.
• Active certifications such as CISSP, CISM, CISA, or equivalent are preferred.
• An advanced degree in computer science or a related field, or equivalent experience, is preferred.
• Direct experience with NIST or similar academic environments is preferred.
• Proficiency with COTS-based security tools like RSA Archer, CSAM, Tenable, WebInspect, and AppDetective is preferred.
• Health, Dental, and Vision coverage.
• 401(k) plan.
• Flexible Spending Account (FSA).
• 11 Paid Federal Holidays.
• Paid Time Off (PTO).
• Education reimbursement.
• Exceptional compensation and benefits package.
• A challenging and rewarding professional work environment.
Vivo (Telefônica Brasil)
DraftKings Inc.
Get handpicked remote jobs straight to your inbox weekly.