Security Compliance Analyst II

H4 Enterprises
  • Washington, DC
  • Full-time
  • Quick Apply
Today

Job Description

H4 Enterprises is currently seeking the following:TITLESecurity Compliance Analyst IILEVELMidRELATIONSHIPSAssigned Team LeaderEDUCATIONBachelor's degree in an Information Technology fieldEXPERIENCE10+ years of hands-on IT experienceCLEARANCETop Secret minimumPLACE OF PERFORMANCENational Capital RegionPOSITION SUMMARYThe Security Compliance Analyst II will assist the assigned Government Division Chief and assigned team leader with various Information Technology (IT) security support duties that will guide the Department of State's classified systems through various computer security requirements and meet Department and Office of the Director of National Intelligence (ODNI) security mandates. This position is responsible for participating in security assessments and compliance reviews of Sensitive Compartmented Information (SCI) systems. The contractor will help improve the security posture of the organization by implementing best practices and controls to prevent or mitigate security risks and exposures.RELATIONSHIPSThe Security Compliance Analyst II will receive direct government oversight, assignments, and directions from the assigned Government Office/ Program Director or Division Chief, through an assigned team leader.DUTIES & RESPONSIBILITIESCreates and develops Standard Operating Procedures, Policy, in support of the Information Assurance Branch (IAB)Participates in all steps of the Security Authorization and Assessment process for Information SystemsWorks closely with the Information Assurance Branch Chief and Chief Information Security Officer (CISO) to provide guidance and oversight for all requested initiativesAssists with the delivery of all required system documentation using the current National Institute of Standards and Technology (NIST), Diplomatic Security (DS), & Intelligence Community (IC) approved templates, forms, regulations, policies, methods, and standardsProvides advisement to stakeholders to assign resources and establish timelines to ensure the successful security authorization of a systemEnsures software installed in the production environment is evaluated and provides guidance regarding the potential for the software to introduce risk into the environmentContinuously maintains a thorough understanding of all configurations, architecture, installed software, accounts (both Operating System and Application), data flows, ports, protocols, and other relevant data for each IT SystemCoordinates with the appropriate operational group to accurately update the System Design Document for each IT system to reflect the approved state of each IT systemAnalyzes Information Assurance Vulnerability Alert (IAVA) bulletins, security, and vulnerability assessment results, provides leadership with details on any required actions and related timelines, and creates mitigation plansAnalyzes system weaknesses identified during system security assessments and the related mitigation plansProvides, tracks, and reports security requirements throughout the project life cycle of all projects that are within the accreditation boundary of assigned systemsPerforms in depth reviews of logs and other artifacts for each IT systemReviews and validates all relevant NIST 800-53 Security Controls and/or applicable departmental policies for each IT system assignedPerforms oversight of compliance with Vulnerability AlertsEnsures that all Information Assurance Vulnerability Management (IAVM) review items are tracked and reportedReviews and validates Plan of Actions & Milestones (POA&Ms) for each noncompliant control for each managed IT System prior to authorizing closure and ensures that proper documentation to support the POA&M lifecycle is filed and updated as required, including well documented waivers and exceptions detailing the potential risk to the Authorizing OfficialDevelops, documents, and executes internal audit programs, including the Federal Information Security Management Act (FISMA), to ensure that audits, inspections, and assessments appropriately address risks and management concernsProvides oversight and guidance regarding requests to modify technical policies such as firewall rules, ports, protocols, etc. for each IT systemCoordinates with and briefs Federal staff on all activities pertaining to each IT system as requestedLeads and facilitates walkthroughs with external auditors, explaining the various processes, improvements, and responses, and provides detailed and timely responses to audits and data callsPROFESSIONAL QUALIFICATIONS & SKILLSCitizenshipS. Citizenship requiredEducationBachelor's degree in an IT fieldMust possess the following current certifications:Certified Information Systems Security Professional (CISSP)Certified in Risk and Information Systems Control (CRISC)Certified Information Security Manager (CISM)Cybersecurity and Infrastructure Security Agency (CISA)Certified Ethical Hacker (CEH)OrDoD 8570 Information Assurance Management (IAM) II equivalent certificationsExperienceOver ten (10) years of hands-on IT experiencePreferred: Department of State experienceTechnical background and ability to review complex configurations for validationExperience with the Risk Management Framework (RMF) process from both a package preparation and assessor perspectiveExperience in the use of the XACTA, ACAS, and HBSS security toolsExperience with federal policies and procedures to acquire and maintain an Information System's Authority to Operate (ATO) under FISMA Act following NIST 800-53 guidelines and NIST- 800-53a security controls assessment practicesExcellent written and oral communication skills and the ability to work independently or as a member of a teamExperience with the RFM, POA&Ms, Security Authorization and AssessmentsExperience conducting and documenting vulnerability assessmentsKnowledge of and experience with NIST SP 800-53, 800-53A, and 800-37Understanding of FISMA complianceExperience with maintenance, installation, and use of WebInspect, Nessus scans, or similar toolsCLEARANCE REQUIREMENTPosition will be subject to a U.S. Government Security Investigation. Incumbent must possess or obtain/maintain minimum a TOP SECRET clearance with ability to obtain special access requirements (SCI).PLACE OF PERFORMACEPrimarily, the work will take place at a designated Department of State Location in the National Capital Region.This position is telework eligible and may be authorized in accordance with OPM and DS policy, only with the approval of the assigned Government Office/Program Director.EEO StatementH4 Enterprises, LLC does not discriminate in employment on the basis of race, color, religion, sex (including pregnancy and gender identity), national origin, political affiliation, sexual orientation, marital status, disability, genetic information, age, membership in an employee organization, retaliation, parental status, military service, or other non-merit factor.Working at H4 Working at H4 means applying a passion for meaningful work with intellectual rigor to help solve the leading issues of our day. Smart, compassionate, innovative, committed, H4 employees tackle unprecedented challenges to benefit people, businesses, and governments around the globe. We believe in collaboration, mutual respect, open communication, and opportunity for growth. We can only solve the toughest challenges by building an inclusive workplace that allows everyone to thrive. We are an equal opportunity employer, committed to hiring regardless of any protected characteristic, such as race, ethnicity, national origin, color, sex, gender identity/expression, sexual orientation, religion, age, disability status, or military/veteran status. Together, our employees are empowered to share their expertise and collaborate with others to achieve personal and professional goals. H4 does not discriminate in employment based on race, color, religion, sex (including pregnancy and gender identity), national origin, political affiliation, sexual orientation, marital status, disability, genetic information, age, membership in an employee organization, retaliation, parental status, military service, or other non-merit factor.COVID-19 Policy: New or prospective U.S. employees must provide proof of complete vaccination on the date of their commencement of employment. If selected for employment, you will provide proof of your full vaccination status, defined as vaccinated two weeks after receiving the requisite number of doses of a COVID-19 vaccine approved or authorized for emergency use by the FDA. Reasonable Accommodations are available, including, but not limited to, for disabled veterans, individuals with disabilities, and individuals with sincerely held religious beliefs, in all phases of the application and employment process.

Numbers & Facts

LocationWashington, DC
Job TypeFull-time

Skills

  • Access Authorizationunmatched
  • Address Managementunmatched
  • Analysis Skillsunmatched
  • Best Practicesunmatched
  • CEH - Certified Ethical Hackerunmatched
  • CISA - Certified Information Systems Auditorunmatched
  • CISM - Certified Information Security Managerunmatched
  • CISSP - Certified Information Systems Security Professionalunmatched
  • Communication Skillsunmatched
  • Computer Securityunmatched
  • Design Documentunmatched
  • Documentationunmatched
  • External Auditunmatched
  • FDA (Food and Drug Administration)unmatched
  • FISMA - Federal Information Security Management Actunmatched
  • Firewallsunmatched
  • Geneticsunmatched
  • Governmentunmatched
  • HP WebInspectunmatched
  • IAM - Information Assurance Managementunmatched
  • Information Technology & Information Systemsunmatched
  • Information/Data Security (InfoSec)unmatched
  • Integrated Circuits (ICs)unmatched
  • Intelligence Communityunmatched
  • Internal Auditunmatched
  • Internet Securityunmatched
  • Leadershipunmatched
  • Maintain Complianceunmatched
  • Management of Information Systems/Technology (MIS)unmatched
  • Militaryunmatched
  • Nessusunmatched
  • Operating Systemsunmatched
  • People Managementunmatched
  • Policy Developmentunmatched
  • Presentation/Verbal Skillsunmatched
  • Problem Solving Skillsunmatched
  • Process Improvementunmatched
  • Production Systemsunmatched
  • Project Lifecycleunmatched
  • Regulationsunmatched
  • Riskunmatched
  • Risk Managementunmatched
  • Risk Management Framework (RMF)unmatched
  • Security Analysisunmatched
  • Security Complianceunmatched
  • Security Monitoringunmatched
  • Sensitive Compartmented Information (SCI)unmatched
  • Software Installationunmatched
  • Standard Operating Procedures (SOP)unmatched
  • Standards Developmentunmatched
  • Support Documentationunmatched
  • Systems Administration/Managementunmatched
  • Systems Analysisunmatched
  • Systems Maintenanceunmatched
  • Team Lead/Managerunmatched
  • Time Managementunmatched
  • Top Secret Clearanceunmatched
  • U.S. National Institute of Standards and Technology (NIST)unmatched
  • Vaccinationunmatched
  • Work From Homeunmatched
  • Writing Skillsunmatched

Be found by employers

5,500+ employers search our resume database daily. Add yours to get found by recruiters looking for candidates like you.

Level up your application

Professional resume templates

Browse dozens of recruiter approved resume templates, layouts and formats. Choose your favorite and make it your own in minutes.

Free resume templates

Free resume builder

Improve your existing resume or start from scratch and create a standout, ATS-friendly resume. Add job-specific content, download and apply.

Free resume builder