Demo

IT Security Policy Analyst

Procession Systems
Washington, DC Full Time
POSTED ON 1/17/2025
AVAILABLE BEFORE 4/15/2025

Job Description

OVERVIEW :

We are seeking an IT Security Policy Analyst / ISSO for our mission-critical customer in Washington, DC. You will work as part of a fantastic team providing security compliance expertise on a high-priority project.

GENERAL DUTIES :

Developing, maintaining, and assessing Security Assessment & Authorization (SA&A) packages resulting in an authority to operate (ATO) for IT systems.

Creating and maintaining SSPs and supporting documentation in accordance with agency guidelines and directives. This includes writing implementation statements, creating supporting documentation (e.g., Contingency Plans, Incident Response Plans, Account Management Plans, etc.), and performing self- assessments, while working with system stakeholders.

Develop, coordinate, test, and train personnel on Incident Response Plans and Contingency Plans.

Ensuring that information systems are accredited, maintain their ATO, and are being continuously monitored.

Performing risk assessments for government systems, to include cloud-based systems.

Performing security control assessments to include collecting supporting artifacts / evidence and interviewing system owner / owner representatives.

Having an in-depth knowledge of the Risk Management Framework (RMF).

Maintaining and tracking system POA&Ms.

Conducting vulnerability management and analysis.

Reviewing and analyzing government policy.

  • Taking ownership on various projects and efforts related to the items highlighted above.

Improving on processes and procedures and making recommendations to improve the security posture of the agency's IT systems and applications.

Required Skills

REQUIRED QUALIFICATIONS :

6 years’ experience with NIST, FISMA, and Security Assessment & Authorization.

FedRAMP and Cloud (Azure, AWS, Oracle (OCI)) experience.

Familiarity with various security-related NIST publications (e.g., SP 800-53r5, SP 800-53A, SP 800-18r1, etc.)

Certifications : CISSP required

CLEARANCE :

US Citizenship required with the ability to obtain a Public Trust clearance

Desired Skills

DESIRED QUALIFICATIONS :

Familiarity with the security control families from the NIST guidance covered by the documents that they are responsible for evaluating.

Ability to provide subject matter expert-level knowledge to the project team to ensure compliance with applicable requirements.

Demonstrated knowledge of IT Security policy implementation statements, the regulatory structure of policy, the role of the Department of Homeland Security (DHS), the Office of Management and Budget (OMB), and the National Institute of Standards and Technology (NIST).

Hands-on experience using a Governance, Risk, and Compliance tool, such as CSAM or eMASS.

Ability to conduct gap analysis on non-federated vendor audit results, such as SOC Type 2, HIPAA comparison review and analyst against NIST SP 800-53 Revision 5 security controls.

Hands-on experience providing C-Level presentation and reporting.

Excellent written communication skills and understand the purpose and use of the System Security Plan (SSP).

Possess an understanding of control inheritance as applied to the Risk Management Framework (RMF) implementation in the CSAM tool.

Ability to accurately manage complex workstreams, comprehend the application of the RMF, and understand the application of security controls across the interface, application, operating system, network, and database layers of modern information systems. Understand the applicable artifacts used as evidence to assess compliance.

Experience with multiple tools providing security functions such as vulnerability management (e.g., Nessus), configuration management (e.g., BigFix, SCCM, ePO), endpoint protection (e.g., antivirus, ATP), data loss prevention, and intrusion detection software and hardware.

Ability to evaluate data flows, network diagrams, and logical security boundaries.

Excellent oral and written communication skills

Familiarity with the use of data analysis tools, including the use of Microsoft Excel or PowerBI to combine data from multiple sources.

About Procession Systems

About us

If your compensation planning software is too rigid to deploy winning incentive strategies, it’s time to find an adaptable solution. Compensation Planning
Enhance your organization's compensation strategy with salary data sets that HR and team managers can use to pay your staff right. Surveys & Data Sets

What is the career path for a IT Security Policy Analyst?

Sign up to receive alerts about other jobs on the IT Security Policy Analyst career path by checking the boxes next to the positions that interest you.
Income Estimation: 
$125,027 - $157,872
Income Estimation: 
$149,432 - $188,965
Income Estimation: 
$70,462 - $84,818
Income Estimation: 
$77,991 - $108,747
Income Estimation: 
$87,093 - $107,335
Income Estimation: 
$140,233 - $181,029
Income Estimation: 
$161,209 - $233,553
Income Estimation: 
$87,093 - $107,335
Income Estimation: 
$111,725 - $147,313
Income Estimation: 
$112,673 - $137,290
Income Estimation: 
$140,233 - $181,029
Income Estimation: 
$161,209 - $233,553
Income Estimation: 
$112,673 - $137,290
Income Estimation: 
$139,945 - $168,577
Income Estimation: 
$140,233 - $181,029
Income Estimation: 
$161,209 - $233,553
Income Estimation: 
$139,945 - $168,577
Income Estimation: 
$164,835 - $201,088
Income Estimation: 
$135,994 - $168,063
Income Estimation: 
$161,209 - $233,553
View Core, Job Family, and Industry Job Skills and Competency Data for more than 15,000 Job Titles Skills Library

Job openings at Procession Systems

Procession Systems
Hired Organization Address Washington, DC Full Time
Job Description GENERAL DUTIES : As the Network Advanced Engineer you will work extensively with networking equipment, s...
Procession Systems
Hired Organization Address Lorton, VA Full Time
Job Description OVERVIEW : Our customers require assistance in establishing robust enterprise-wide solutions for Identit...
Procession Systems
Hired Organization Address Springfield, VA Full Time
Job Description OVERVIEW : In this role, you'll join our Continuous Operations Release Environment (CORE) team, providin...
Procession Systems
Hired Organization Address Reston, VA Full Time
Job Description GENERAL DUTIES : Responsibilities are full time on customer’s onsite and will cover classified programs ...

Not the job you're looking for? Here are some other IT Security Policy Analyst jobs in the Washington, DC area that may be a better fit.

IT Security Policy Analyst

Axiologic Solutions LLC, Virginia, VA

Policy Analyst

Alta It Services, Chantilly, VA

AI Assistant is available now!

Feel free to start your new journey!