Security Analyst
United States
Full Time Entry-level / Junior Clearance required USD 92K - 120K
Synergy
Synergy is an IT firm that implements innovative solutions that are faster to build, easier to change, and cheaper to maintain.- We are seeking a mid-level Security Analyst. The candidate will work for the engineering division that supports developing and managing a suite of enterprise services and applications. The candidate should have a strong Dev/Sec/Ops background that will focus embedding security practices into the automated software development lifecycle, ensuring systems meet federal government compliance standards. The candidate will work closely with our DevOps, Support, and administrative teams in an agile environment to maintain the security posture of systems.
- Execution of Risk Management Framework (RMF)
- Perform Security Impact Assessment for all application and environment updates
- Counsel to ensure auditing, testing, preventive and reactive measures are being adequately implemented for systems with an active Authorization to Operate (ATO).
- Practical knowledge and skills in working with cloud computing platforms, while adhering to the strict security standards set by the Federal Risk and Authorization Management Program (FedRAMP)
- Develop an in-depth understanding of customer requirements to quantify security and application risks, and perform impact assessments
- Maintaining ongoing vigilance to ensure adherence to regulatory requirements through continuous monitoring of critical processes
- Oversight, expertise, technical security strategy, standards, and best practices for security categorizations (low, moderate and high).
- Reviews, testing and implementation of security requirements within project plan timelines.
- Research and tracking of Agency security standards, policies, and procedures.
- Support for multiple project assignments with strong and effective communication, time management and collaboration skills.
- Documented experience executing Risk Management Framework (RMF, NIST-800-53)
- Experience with agile software development
- General knowledge of security best practices and compliance requirements
- Excellent organizational and communication skills are mandatory for various stakeholder audiences
- Experience collaboratively establishing secure configuration baselines for technologies
- Knowledge or experience with conducting Assessment and Authorization (A&A) and Continuous Monitoring following NIST guidelines
- Knowledge or experience developing security documentation and conducting reviews for A&A packages
- Maintain, track, and communicate detailed project tasks
- Manage initial and reauthorization System Assessment and Authorization (SAA)/ Security Controls Assessment (SCA) task and milestone, task dependencies for low, moderate, and high security systems
- Identify and visually demonstrate system boundaries, select security controls, and ensure implemented controls are adequate for COTS or proprietary web applications. Provide recommendations as necessary to meet or improve controls
- Ensure security policies are developed, maintained and updated to meet IT security best business practices and standards, including Federal Info Security Management Act (FISMA), and National Institute of Standards and Technology (NIST) 800-53 – IPS federal info processing standard
- Be able to review security scans, advise on triaging vulnerabilities, and be able to provide recommendations on mitigating security risks
- Assists with documenting and managing artifacts in Atlassian Suite (JIRA, Confluence) and CSAM security repositories, including but not limited to writing implementation statements
- Assists Information Systems Security Managers (ISSMs) in generating ATO packages
- Conduct continuous monitoring and reporting of security control implementations
- Must evaluate business strategies and requirements to develop security strategies, assess risk, research standards, and determine security requirements as necessary
- Track and coordinate POA&M remediation activity with different functional teams across multiple systems
- Experience with security tools such as Splunk, Nessus, SonarQube, SIEMs and Static Code Analyzers
- Other duties as assigned
- 5+ years’ experience in an enterprise security role preferred
- Experience in Dev\Sec\Ops
- Experience in CSAM
- Proficient in the Atlassian suite of agile tools: Confluence and Jira
- Experience with Java and other programming languages
- Experience with Federal Government systems
- Federal Government Secret Clearance preferred
- Must have a security+ certification
- Must be a US citizen
- Ability to obtain and maintain Federal Government Position of Trust
- Must pass a background investigation.
Tags: Agile Analytics Audits Clearance Cloud Compliance Confluence Data Analytics DevOps FedRAMP FISMA IPS Java Jira Monitoring Nessus NIST NIST 800-53 POA&M Risk management RMF SaaS SDLC Security strategy SIEM SonarQube Splunk Strategy Vulnerabilities
Perks/benefits: 401(k) matching Career development Fitness / gym Gear Health care Insurance Medical leave Salary bonus Startup environment Wellness
More jobs like this
Explore more career opportunities
Find even more open roles below ordered by popularity of job title or skills/products/technologies used.