IT Security Analyst T3

Johnson Technology Systems Inc
  • Reston, VA
  • $120,000–$126,000 Per Year
  • Instant Apply
1 day ago

Job Description

"WE DO WHAT WE SAY "

JTSi
is a federal government consulting firm, providing technical services to the Federal Government, i.e., DoD, Client and various Civilian Agencies. We are proud to have earned the reputation of honesty, integrity and the ability to build long-term professional relationships with our employees and clients. Please visit our website at www.JTSUSA.com to learn more about who we are and what we do.

Company Name: - JTSi (Johnson Technology Systems, Inc.)
Title: IT Security Analyst T3
Location: Hybrid - This role requires in office (Herndon) 3 days a week (Tuesday, Wednesday & Thursday) but may increase to 5 days a week as business needs change.
Salary : $120K-$126K



Description:

*Must be a US Citizen & ONLY hold US Citizenship (No Dual Citizens)*
*This role requires in office (Herndon) 3 days a week (Tuesday, Wednesday & Thursday) but may increase to 5 days a week as business needs change.*

Security Analyst (SA) will work as a member of the cyber team. The SA will assist with the creation, update, and maintenance of FedRAMP required security documentation, associated artifacts, and Continuous Compliance Monitoring (CCM) requirements such as the Plan of Action and Milestones (POAM) and assisting the Cloud Operations team with the identification and corrective actions associated with known vulnerabilities. Additionally, the SA provides advisement to stakeholders on changing regulatory, government and Cloud / FedRAMP policies, procedures, agreements, etc., including risk assessment, business impact analysis, system categorization, security authorization and accreditation/certification activities (A&A), security control inheritance from various providers, and other artifacts needed to validate control compliance.

Required Skills The candidate must be able to:

· Understand/document information system specifications and security controls, including logical and physical diagrams, connectivity, communication, and data flow diagrams, both internal and external to the system.
· Advise stakeholders on multiple courses of action in an environment with changing unconfirmed policy, e.g., NIST RMF and DISA SRG.
· Document multiple courses of action and identify risk mitigation recommendations in accordance with FedRAMP requirements, policy, procedures, and best practices, with associated benefits/drawbacks to each.
· Apply enterprise security frameworks and capabilities, such as FISMA, NIST SP 800, etc. towards existing initiatives such as cloud environments.
· Develop/update policies and procedures to implement FedRAMP compliance as well as compliant with NIST 800-171 security requirements and other DFAR clauses.
· Knowledge of Risk Based Vulnerability Framework and how to prioritize, assess, and remediate vulnerabilities that is and can be exploited
· Ability to create automation scripts to minimize manual workload behind identifying and analyzing vulnerabilities across various scanning tools
· Ability to analyze Container Vulnerabilities in secure cloud environments and identify the remediation path forward to address vulnerabilities from an Operating System and application level.
· Understand enterprise operating environments, including security posture, application environment, and associated security controls.
· Demonstrate familiarity with current FedRAMP, DOD and NIST Security controls and technologies, including vulnerability management capabilities.
· Identify and assess Cloud System state, including vulnerabilities, RMF package status/accreditation model, PPS compliance, and patching/CSVA mechanisms.

Required Technical Experience

· Experience in creating automation scripts through coding programs such as Python, Bash Java, and Powershell
· Knowledge of Scanning Containers and experience with container scanning tools
· Knowledge of the CI/CD pipelines, AWS ECR, Container Image Mirroring
· Knowledge of determining attack vectors in the environment to determine if the vulnerability is exploitable
· Knowledge in SAP products Required RMF Experience
· Demonstrated knowledge and the ability to analyze systems for Cybersecurity compliance.
· Ability to work in fast-paced, team-oriented environment.
· Knowledge of Federal and DoD policies and risk assessment methodologies, including FedRAMP. NIST SPs and RMF overlays
· Knowledge and hands on experience of DISA STIGs requirements and SRGs, Committee for National Security Systems Instructions and NIST Risk Management Framework.
· Experience in writing or executing system security documentation, authorization to operate packages, POA&Ms, and policies.
· Presentation and public speaking skills required.
· Knowledge and understanding of systems and networking technologies and concepts.
· Ability to interpret and assess network diagrams and drawings using Visio.
· Familiarity with Testing, Development, Staging, and pre-production environment requiring cyber security support.
· Knowledge of Privacy Act.

Education and certifications:

Bachelor's degree in computer information systems or math/sciences


We recruit, employ, train, compensate and promote without regard to race, religion, color, citizenship, national origin, age, sex, gender, gender identity/expression, sexual orientation, marital status, disability, genetic information, veteran status or any other characteristic protected by federal, state, or local law.

Disclaimer: Nothing in this job description/posting shall constitute an offer or promise of employment. If you are not reviewing this job posting on our Careers' site http://jtsusa.com/careers or one of our approved job boards we cannot guarantee the validity of this posting. For a list of our current postings, please visit us at http://jtsusa.com/careers

Numbers & Facts

LocationReston, VA
Salary$120,000–$126,000 Per Year

Skills

  • Access Authorizationunmatched
  • Amazon Web Services (AWS)unmatched
  • Analysis Skillsunmatched
  • Applications Securityunmatched
  • Bash Scriptingunmatched
  • Best Practicesunmatched
  • Business impact analysis (BIA)unmatched
  • Cloud Computingunmatched
  • Computer Securityunmatched
  • Consultingunmatched
  • Continuous Deployment/Deliveryunmatched
  • Continuous Integrationunmatched
  • Corrective Actionunmatched
  • Defense Information Systems Agency (DISA)unmatched
  • Documentationunmatched
  • Employee Relationsunmatched
  • Enterprise Protectionunmatched
  • Establish Prioritiesunmatched
  • FISMA - Federal Information Security Management Actunmatched
  • Federal Governmentunmatched
  • Government Regulationsunmatched
  • Information Technology & Information Systemsunmatched
  • Internet Securityunmatched
  • Javaunmatched
  • Maintain Complianceunmatched
  • Mathematicsunmatched
  • Microsoft Visiounmatched
  • Network Performance/Analysisunmatched
  • Production Systemsunmatched
  • Python Programming/Scripting Languageunmatched
  • Riskunmatched
  • Risk Analysisunmatched
  • Risk Managementunmatched
  • Risk Management Framework (RMF)unmatched
  • SAPunmatched
  • Scripting (Scripting Languages)unmatched
  • Security Analysisunmatched
  • Software Patchesunmatched
  • Systems Analysisunmatched
  • T-3 / DS3unmatched
  • Team Playerunmatched
  • Test Plan/Scheduleunmatched
  • U.S. National Institute of Standards and Technology (NIST)unmatched
  • United States Citizenunmatched
  • United States Department of Defense (DoD)unmatched
  • Vulnerability Scannersunmatched
  • Windows PowerShellunmatched

Be found by employers

5,500+ employers search our resume database daily. Add yours to get found by recruiters looking for candidates like you.

Level up your application

Professional resume templates

Browse dozens of recruiter approved resume templates, layouts and formats. Choose your favorite and make it your own in minutes.

Free resume templates

Free resume builder

Improve your existing resume or start from scratch and create a standout, ATS-friendly resume. Add job-specific content, download and apply.

Free resume builder