Information Assurance Analyst
TalentAlly · United States · 1 wk ago
RemoteRemoteOTHRFull-time
Key Responsibilities
- Lead the development and maintenance of comprehensive ATO packages, including SSPs, SARs, RARs, and POA&Ms.
- Ensure documentation aligns with NIST SP 800-53, FISMA, and Department-specific security requirements.
- Oversee all phases of the Risk Management Framework lifecycle from system categorization through continuous monitoring.
- Facilitate authorizations and reauthorizations.
- Interpret and apply Departmental cybersecurity policies, including 12 FAM, 5 FAH-6, and CSB guidelines.
- Recommend improvements to internal policies, controls, and procedures to align with emerging federal mandates.
- Lead Security Impact Analyses (SIA) for system changes.
- Review vulnerability scan results, update control implementation statements, and track remediation progress through governance systems such as ArchAngel.
- Coordinate internal and external audit activities, prepare evidence packages, and respond to data calls.
- Ensure all documentation is audit-ready, consistent, and current with evolving control requirements.
- Mentorship and cross-functional coordination.
- Serve as a primary liaison to cloud architects, infrastructure engineers, and system owners to ensure security is integrated into all IT planning and operations.
Requirements
- Active Security Clearance
- Bachelor's degree in Cybersecurity, Information Assurance, or a related field (or equivalent experience)
- Minimum of 8 years of information assurance experience in federal environments
- Extensive knowledge of NIST RMF, FISMA, and NIST SP 800-53 controls
- Proven experience leading ATO efforts and supporting complex IT systems through the full security lifecycle
- Strong writing skills with experience producing high-quality SSPs, SARs, and related artifacts
Preferred Qualifications
- Prior experience supporting Department of State or similarly structured federal agencies
- Familiarity with ArchAngel, eMASS, or other A&A governance platform
- DoD 8570 compliant certification (CISSP, CISM, CAP, or equivalent)
- Background in hybrid environments, including cloud ATOs and continuous monitoring
- Experience participating in cross-agency audits and briefing executive stakeholders