What are the responsibilities and job description for the System Security Analyst (Mid level) position at AgileTek Solution LLC?
POSITION SUMMARY -
Security Analyst (Mid-Level)
This role serves as a "hands-on" mid-level security analyst who will be responsible for interfacing with the security engineering, operations and build teams, assisting with the development and / or maintenance of various System Security Plans (SSP) and associated documentation for multiple environments, gathering the security control implementations information for the security controls and documenting their implementation in the SSP, as well as updating associated security documentation as needed (i.e., plans, procedures, processes). Additionally, this role will assist with the security assessments (i.e. FedRAMP, FISMA, HIPPA, SOC, etc.), to include supporting collection of evidence.
The Security Analyst will be responsible for maintenance of the security documentation for the various environments; which may include development of the metrics / trends, input of security documentation into Xacta, assisting with the FedRAMP or FISMA authorization processes to include prep of the operations team, and documentation summary and update as required. This role serves as a mid level security analyst who assists with the security documentation and can provide thoughtful recommendations on processes and procedures, as well as implementation of security controls. This role must communicate between security, engineering, development and operations teams as required, and be able to interpret and document the results of data gathering. Key deliverables for success will be a monthly maintenance of various POAM, security documentation in Xacta is current and useful, processes and procedures are current and up to date, and assists with assurance that all FedRAMP / FISMA security controls are successfully implemented and associated security documentation is developed and implemented.
GENERAL RESPONSIBILITES :
- Gather information, architecture diagrams and implementation of the security controls through interfacing with the security engineering, operations and build teams
- Develop security documentation such as, but not limited to, System Security Plans (SSP), security plans, procedures, and processes
- Maintain, via review and update, of all security documentation
- Understand the intent of the FedRAMP security controls, FISMA security controls and communicate as needed
- Assist with the FedRAMP or FISMA authorization to include, but not limited to, prep of operations team through training and mock interviews, update documentation as required, and support FedRAMP PMO / Agency / CISO requests
GENERAL QUALIFICATIONS :
SPECIFIC TECHNICAL SKILLS DESIRED :