Information Assurance Security Analyst
6314 Remote/Teleworker US
The Information Assurance Security Analyst is a member of the Leidos – Antarctic Support Contract (ASC) Information Security (InfoSec) team responsible for applying cybersecurity principles and best practices to proactively protect and maintain the confidentiality, integrity, and availability, of USAP data, information systems, and enterprise network. Personnel in this position must have an elevated level of trust, with access to sensitive and private information, which must be handled with integrity and respect in accordance with USAP policies and procedures.
The Security Analyst will be responsible for coordination, oversight, execution and enhancement of consistent security practices for all information systems within the USAP. The Security Analyst will ensure effective information security controls are documented and delivered to safeguard USAP business operations, prevent unauthorized system access, and to protect sensitive information.
This individual filling this position will contribute to delivering analysis and assessment of compliance with security and privacy laws, regulations, guidance, and direction, including the Federal Information Security Management Act (FISMA); National Institute of Standards and Technology (NIST) guidance; Federal Information Processing Standards (FIPS); applicable Office of Management and Budget (OMB) memoranda; National Science Foundation (NSF); and United States Antarctic Program (USAP) policies and instructions.
Primary Responsibilities:
- Maintains applicable security controls in the annual System Security Plan in accordance with NIST SP 800-53 rev 5, Security and Privacy Controls for Federal Information Systems and Organizations, and NIST SP 800-37, Risk Management Framework.
- Provides configuration control over Security Assessment and Authorization (SA&A) packages.
- Responds to audit requests and creation of deliverables.
- Coordinates with Security Engineers and IT Operations teams to update and maintain the Plan of Actions and Milestones (POA&M), Acceptance of Risk (AOR) and other required security documentation.
- Conducts and documents security assessments to determine the effectives and compliance of planned and implemented security controls.
- Facilitates and documents contingency planning exercises.
- Performs systems security evaluations, audits, and server logging reviews to verify secure operations.
- Updates and maintains annual information security awareness and training program.
- Develops information security reports for stakeholders, customers and management based on Information Security operational metrics, security assessments and security reviews.
- Conducts continuous security reviews, recommends mitigations and corrective actions.
Basic Qualifications:
- Bachelor's degree in Cybersecurity and 4+ years relevant experience. Additional years of experience and relevant certifications will be considered in lieu of degree.
- Knowledgeable in the application of FISMA requirements such as NIST SP 800-53 rev 5 and NIST SP 800-37 to US Government programs.
- …
This job isn't fresh anymore!
Search Fresh JobsJob Profile
RestrictionsRemote/Teleworker US
Benefits/Perks Tasks- Analysis
- Conduct security assessments
- Configuration
- Documentation
- Planning
- Risk Management
Analysis Best Practices Business Operations Communication Compliance Configuration Coordination Cybersecurity Data Documentation Education Execution FISMA Governance Information Assurance Information security Infrastructure ITIL IT Infrastructure IT Operations Nessus Network NIST NIST SP 800-53 Operations Patch Management Project Management Risk Management Risk Management Framework Security Security Controls Security Documentation Security management Support Teams Training Verbal communication Vulnerability Management
Experience4 years
EducationAS Bachelor's Bachelor's degree Bachelor's Degree in Cybersecurity Business Information Security Information Systems IT Science Security
Certifications