System Security Analyst
Strategic Innovation Group, LLC · Arlington, VA · 1 wk ago
Information TechnologyFull-time
About the role
The System Security Analysts will support the security, compliance, and risk management of production systems and applications for client programs. This role involves analyzing production systems and applications to identify security vulnerabilities, documenting security requirements, and implementing security controls.
Responsibilities
- Analyze current production systems and applications to identify security vulnerabilities and risks.
- Document security requirements for production systems and applications.
- Identify and recommend the security controls and control families necessary to secure production environments.
- Define and document system security boundaries in coordination with system owners and technical teams.
- Inherit, review, and manage current Plans of Action and Milestones (POA&Ms) and prior security findings.
- Develop mitigation and implementation strategies to remediate identified vulnerabilities and findings.
- Build planning schedules and task timelines to drive POA&Ms toward closure.
- Track and report POA&M status and remediation progress to stakeholders.
- Conduct control assessments and control testing (e.g., NIST SP 800-53A) to validate control implementation and support audit readiness.
- Perform continuous monitoring activities to sustain system authorization and ongoing control effectiveness.
- Support audit readiness activities, including review of vendor SOC reports and third-party penetration test results.
- Test and maintain contingency plans (ISCP/DRP/IRP) to support system resiliency.
- Integrate automated security scanning into CI/CD pipelines and review findings with development teams.
- Provide advisory support to program-level security teams and development teams on security best practices and compliance requirements.
Requirements
- Bachelor's degree in Computer Science, Cybersecurity, Information Technology, or a related field (equivalent experience considered).
- Must have a relevant certification (e.g., Security+, CISSP, CAP, or similar) - candidates with certifications will be given priority.
- 15+ years of relevant security analysis experience. 13+ years if you have a Master's degree.
- Demonstrated experience conducting security assessments of production systems and applications.
- Working knowledge of security control frameworks and control families (e.g., NIST SP 800-53 or equivalent).
- Experience managing and remediating POA&Ms and security findings, including inherited/legacy findings.
- Ability to develop mitigation and remediation plans, including task sequencing and scheduling.
- Experience conducting formal control assessments/testing to validate control implementation.
- Experience with continuous monitoring processes and sustaining system authorization.
- Experience reviewing third-party/vendor risk artifacts (e.g., SOC reports, penetration test results).
- Strong written communication skills for documenting security requirements and findings.
- Experience advising both security and engineering/developer teams on remediation approaches.
- Must be a US Citizen and able to obtain a Public Trust Clearance.