Cybersecurity Analyst/Information System Secu
SHR Consulting Group · Paris, TX · 3 days ago
On-siteInformation TechnologyFull-time
Key Responsibilities
- Support implementation and ongoing execution of the NIST Risk Management Framework (RMF) and DHS/FEMA security policies and procedures.
- Develop, maintain, and update system security documentation, including System Security Plans (SSPs), Security Assessment Reports (SARs), Plans of Action and Milestones (POA&Ms), Contingency Plans, Configuration Management Plans, and related authorization artifacts.
- Support Assessment and Authorization (A&A) activities for FEMA systems, applications, and cloud environments.
- Maintain security documentation and evidence within applicable DHS/FEMA governance, risk, and compliance (GRC) systems.
- Conduct and document security control assessments and support implementation and validation of NIST SP 800-53 security and privacy controls.
- Track cybersecurity findings, vulnerabilities, POA&Ms, remediation activities, and risk acceptance through closure.
- Review vulnerability scanning and security monitoring results from tools such as Tenable/Nessus, CrowdStrike, Elastic, and other DHS/FEMA-approved security platforms.
- Coordinate with system administrators, cloud engineers, DevSecOps teams, application teams, and system owners to remediate vulnerabilities and configuration deficiencies.
- Support continuous monitoring, including recurring security control reviews, vulnerability management, configuration compliance, and required reporting.
- Review proposed system and infrastructure changes to identify cybersecurity impacts and ensure security requirements are incorporated throughout the system lifecycle.
- Support compliance with applicable DHS security directives, FEMA policies, FISMA, FedRAMP, NIST guidance, and federal cybersecurity requirements.
- Assist with incident response activities, security investigations, audit requests, and cybersecurity reporting as required.
- Participate in security reviews, technical meetings, change management activities, and coordination with FEMA cybersecurity stakeholders.
- Identify cybersecurity risks and provide practical recommendations for mitigation, remediation, or risk management.
- Maintain audit-ready security documentation and supporting evidence.
Minimum Qualifications
- Bachelor's degree in Cybersecurity, Information Technology, Computer Science, Information Systems, or a related discipline; relevant experience may be considered in lieu of a degree.
- 5+ years of cybersecurity or information assurance experience, preferably supporting federal government environments.
- Demonstrated experience supporting RMF, A&A, security control implementation, continuous monitoring, vulnerability management, and POA&M management.
- Working knowledge of NIST SP 800-53, NIST SP 800-37, FISMA, FedRAMP, and federal cybersecurity requirements.
- Experience developing and maintaining cybersecurity authorization and compliance documentation.
- Familiarity with enterprise and cloud environments, including AWS and/or Microsoft Azure.
- Strong written and verbal communication skills with the ability to work effectively with technical and non-technical stakeholders.
Preferred Qualifications
- Previous experience supporting FEMA, DHS, or another federal civilian agency.
- Experience securing AWS GovCloud and/or Azure Government environments.
- Experience with vulnerability management, SIEM, endpoint security, and continuous monitoring technologies.
- Experience working with Agile and DevSecOps engineering teams.
- Familiarity with Zero Trust architecture and federal cloud security requirements.
- One or more relevant certifications, such as CISSP, CAP/CGRC, Security+, CISM, CCSP, or equivalent cybersecurity certification.
Desired Attributes
- Strong attention to detail and ability to maintain accurate, audit-ready security documentation.
- Ability to manage multiple systems, security requirements, findings, and deadlines simultaneously.
- Proactive approach to identifying and resolving cybersecurity risks.
- Ability to translate federal cybersecurity requirements into actionable requirements for engineering and operations teams.
- Strong collaboration skills and ability to work across cybersecurity, engineering, program management, and Government stakeholder organizations.
Benefits
- Competitive salary commensurate with experience and clearance level
- Comprehensive medical, dental, and vision coverage
- 401(k) with company contribution
- Paid time off and eleven federal holidays
- Certification reimbursement and training
- Life and disability insurance
Clearance Requirements
- U.S. Citizenship.
- Ability to obtain and maintain required DHS/FEMA suitability and security clearance/access requirements.
- Prioritization will be given to FEMA Public Trust Clearance or DHS Public Trust within the last 3 years, or to active/current Public Trust.
Priority
- Prioritization will be given to FEMA Public Trust Clearance or DHS Public Trust within the last 3 years, or to active/current Public Trust.