IT Security Analyst (FedRAMP/RMF)

Information Consulting Services
  • Herndon, VA
  • Quick Apply
14 days ago

Job Description

Contract Details
" Work Mode: Hybrid (in-office Tuesday Thursday; may increase to 5 days/week)
" Location: Herndon, VA
" Schedule: 40 hours/week
" Duration: 08/10/2026 08/09/2027

About the Opportunity
This role supports cloud security compliance for a government-focused environment. You will develop and maintain FedRAMP-required security documentation and artifacts, drive Continuous Compliance Monitoring (CCM), manage POA&Ms, and advise stakeholders on evolving regulatory and cloud security policies.

The position partners closely with Cloud Operations to identify, prioritize, and remediate vulnerabilities (including container security) while applying frameworks such as NIST RMF and FISMA to ensure sustained authorization and control compliance.

Key Responsibilities

  • Create, update, and maintain FedRAMP security documentation and associated artifacts (e.g., ATO packages, POA&Ms, CCM evidence).
  • Advise stakeholders on regulatory and cloud security policies (e.g., NIST RMF, DISA SRG) and document multiple courses of action with risk/benefit tradeoffs.
  • Apply enterprise security frameworks (FISMA, NIST SP 800 series, NIST 800-171, DFARS) to cloud environments and related initiatives.
  • Develop/update policies and procedures to implement and sustain FedRAMP and NIST 800-171 compliance.
  • Assist with vulnerability management, using a risk-based approach to prioritize and drive remediation.
  • Automate security and vulnerability analysis workflows using scripts (Python, Bash, PowerShell, Java).
  • Analyze container vulnerabilities and define remediation paths across OS and application layers; leverage container scanning tools.
  • Support CI/CD security integration, including AWS ECR and container image mirroring.
  • Assess cloud system posture (vulnerabilities, RMF package status, patching/CSVA mechanisms) and interpret system/network diagrams.
  • Contribute to security support across testing, development, staging, and pre-production environments.

Required Qualifications

  • US citizenship is required; dual citizenship is not permitted.
  • Hybrid onsite presence in Herndon, VA (Tuesday Thursday) with the ability to increase to 5 days/week as needed.
  • Hands-on experience producing and managing FedRAMP authorization documentation and artifacts (ATO packages, POA&Ms, CCM).
  • Strong knowledge of NIST RMF, FISMA, NIST SP 800 series (including 800-171) and DFARS.
  • Experience with DISA STIGs/SRGs and CNSSI.
  • Vulnerability management expertise, including container vulnerability assessment and remediation planning.
  • Scripting/automation skills with Python, Bash, PowerShell, and/or Java.
  • Experience with container scanning tools, CI/CD pipelines, AWS ECR, and container image mirroring.
  • Solid understanding of systems and networking concepts; ability to interpret network diagrams (e.g., Visio).
  • Effective presentation and public speaking skills.
  • Bachelor s degree in computer information systems or math/sciences.

Preferred Qualifications

  • Experience with SAP products.

Work Environment

  • Fast-paced, team-oriented environment collaborating closely with Cloud Operations and cross-functional stakeholders.

Numbers & Facts

LocationHerndon, VA

Skills

  • Amazon Web Services (AWS)unmatched
  • Analysis Skillsunmatched
  • Bash Scriptingunmatched
  • Cloud Computingunmatched
  • Computer Securityunmatched
  • Continuous Deployment/Deliveryunmatched
  • Continuous Integrationunmatched
  • Cross-Functionalunmatched
  • Defense Federal Acquisition Regulations Supplement (DFARS)unmatched
  • Defense Information Systems Agency (DISA)unmatched
  • Document Managementunmatched
  • Documentationunmatched
  • Enterprise Protectionunmatched
  • Establish Prioritiesunmatched
  • FISMA - Federal Information Security Management Actunmatched
  • Information Technology & Information Systemsunmatched
  • Javaunmatched
  • Maintain Complianceunmatched
  • Mathematicsunmatched
  • Microsoft Visiounmatched
  • Operating Systemsunmatched
  • Policy Developmentunmatched
  • Policy Implementationunmatched
  • Presentation/Verbal Skillsunmatched
  • Procedure Developmentunmatched
  • Procedure Implementationunmatched
  • Production Systemsunmatched
  • Python Programming/Scripting Languageunmatched
  • Regulationsunmatched
  • Riskunmatched
  • SAPunmatched
  • Scripting (Scripting Languages)unmatched
  • Security Analysisunmatched
  • Software Patchesunmatched
  • Systems Analysisunmatched
  • Team Playerunmatched
  • Test Plan/Scheduleunmatched
  • U.S. National Institute of Standards and Technology (NIST)unmatched
  • United States Citizenunmatched
  • Windows PowerShellunmatched
  • Workflow Analysisunmatched

Be found by employers

5,500+ employers search our resume database daily. Add yours to get found by recruiters looking for candidates like you.

Level up your application

Professional resume templates

Browse dozens of recruiter approved resume templates, layouts and formats. Choose your favorite and make it your own in minutes.

Free resume templates

Free resume builder

Improve your existing resume or start from scratch and create a standout, ATS-friendly resume. Add job-specific content, download and apply.

Free resume builder