Cybersecurity Analyst
Position Summary
JGMS Government Services is looking to hire a cybersecurity professional to join our team. The candidate will be responsible for execution of all aspects of the National Institute of Standards and Technology (NIST) directives to support the Risk Management Framework (RMF). This includes assisting information system owners with development of System Security Plans (SSPs) and Security Assessment Reports (SARs) using the existing RSA Archer application on the local network to support information system authorization. Additionally, the candidate will assist in the development of Plans of Action and Milestone (POA&Ms) and Risk Based Decisions (RBDs) for deficiencies found during the information system authorization process.
Requirements
- Bachelor's degree from an accredited college or university and at least 4 years of combined experience in the following roles: Security Control Assessor, Information System Security Officer (ISSO), or Information System Security Manager (ISSM).
- At least 2 years of experience supporting development of information system security authorization packages in accordance with Risk Management Framework (NIST 800-37, 800-53, 800-53a).
- At least 2 years of experience working with Federal Risk and Authorization Management Program (FedRAMP).
- Security+ Certification
Desired Qualifications
- Experience with the RSA Archer Application.
- At least 2 years of experience working on IT security project teams.
- At least one year of experience managing IT projects.
- Knowledge of IT infrastructure and services (Data Centers, physical and virtual servers, local and wide area networking components, cloud Infrastructure/Platform/Software as a Service, etc.).
- Knowledge of security policies such as NIST Special Publications, Security Technical Implementation Guides (STIGs), DOD Cloud Computing Security Resource Guide (SRG).
- Knowledge of infrastructure security, endpoint protection, vulnerability, management tools.
- Previous work authorizing information systems within a classified DoE or DoD environment.
- Familiarity with NIST 800-171.
- Possession of Information Systems Security Professional (CISSP) certification.
- Possession of Certificate of Cloud Security Knowledge (CCSK).
Security Clearance
Candidates must possess a DOE L or DOE Q security clearance. A pre-employment drug screening and background review that includes checks of personal references, credit, law enforcement records, and employment/education verification is required.
Benefits
- Medical insurance - 100% company paid premiums for employees
- Dental and vision insurance
- 401k plan with company match
- 24 hours of paid community service a year
- Up to 4 weeks paid time off a year
- 10 paid floating holidays
- Life insurance, short- and long-term disability
- Employee Assistance Program (EAP)
- Professional development opportunities