SonicJobs Logo
Left arrow iconBack to search

Cybersecurity Compliance Analyst (SME)

ADEPT Force Group Incorporated
Posted 8 hours ago, valid for 12 days
Location

Alexandria, VA, US

Salary

Competitive

Contract type

Full Time

By applying, a Sonicjobs account will be created for you. Sonicjobs's Privacy Policy and Terms & Conditions will apply.

SonicJobs' Terms & Conditions and Privacy Policy also apply.

Contract Labor Category (LCAT): Cybersecurity Compliance Analyst Subject Matter Expert (SME)

Position: Cybersecurity Compliance Analyst (SME)

Clearance: Secret

Location: Fort Belvoir, VA

Salary:

Type: Exempt, Full Time, Regular

Description

The Cybersecurity Compliance Analyst (SME) will collaborate with project teams, cybersecurity engineers and analysts, solution developers, and Department of Defense (DoD) cybersecurity organizations to ensure and maintain compliance with cybersecurity requirements (e.g., Risk Management Framework (RMF), National Institute of Standards and Technology (NIST)), including cybersecurity health for each solution / system. The Cybersecurity Compliance Analyst (SME) will collaboratively engage in project teams as the cybersecurity compliance resource responsible to guide, manage, track, monitor, maintain, and, where needed, improve each project’s cybersecurity posture.

Duties and Responsibilities

  • Serve as the lead in ensuring and maintaining security solutions that meet standards, guidelines, and statutory and regulatory compliance requirements related to information security, such as NIST Special Publication (SP) 800-37, NIST SP 800-53 
  • Ensure compliance with cybersecurity policies and frameworks
  • Implement and monitor cybersecurity measures, ensuring timely compliance with regulations, and supporting incident response activities
  • Lead/Perform compliance reviews of computer security plans, risk assessments, and security test evaluations and audits, validating results and identifying areas for update / correction / resolution
  • Review / contribute to the development of cybersecurity documents and ensure compliance with content requirements
  • Review / contribute to Plans of Actions and Milestones (POA&M) to assist in the mitigation of cybersecurity weaknesses, providing recommended mitigation actions
  • Lead/Participate in technical assessments and reviews to ensure cybersecurity requirements are accounted for in the solution architecture, design, and implementation
  • Ensure traceability of cybersecurity requirements to the test processes and procedures
  • Utilize cybersecurity tools within Development, Security, and Operations (DevSecOps) environments to validate project cybersecurity posture
  • Prepare for and participate in accreditation activities
  • Coordinate with Information System Security Managers (ISSMs) and Information System Security Officers (ISSOs) on corrective measures when a cybersecurity incident or vulnerability is discovered, identifying required actions to ensure resolution
  • Ensure that a process is in place to formally (1) report all cybersecurity-related events and potential threats and vulnerabilities that may impact system authorizations or security posture to the appropriate leadership, and (2) track resolution and closure
  • Maintain and report system accreditation status, including developing dashboards to provide visibility into process and product completion
  • Alert system proponents when accreditation documentation updates are required; track to completion
  • Review Army and DoD cybersecurity policy changes and assess impact on compliance requirements

Required Qualifications 

  • Bachelor’s Degree and 12+ years of relevant experience; additional experience may be used in lieu of a degree; additional education or relevant higher-level certifications may be used in lieu of experience
  • Experience with cybersecurity frameworks
  • Experience in a cybersecurity role within DoD or Army environments
  • Experience working with Risk Management Framework (RMF) and continuous monitoring processes
  • Knowledge and application of DoD Cybersecurity policies, tools, and techniques
  • Experience with Assured Compliance Assessment Solution (ACAS)
  • Experience with Enterprise Mission Assurance Support Service (eMASS)
  • Experience designing, developing, and implementing secure solutions 
  • Technical experience with application platforms such as Amazon Web Services (AWS) and/or Microsoft Azure
  • Security + Certification 
  • Preferred: Certified Information System Security Professional (CISSP) Certification
  • Must possess and maintain a Secret security clearance

 

If you require a reasonable accommodation for any part of the application or hiring process, please notify the Director of People Operations. Reasonable accommodations are provided to qualified individuals with disabilities in accordance with applicable law.





Learn more about this Employer on their Career Site

Apply now in a few quick clicks

By applying, a Sonicjobs account will be created for you. Sonicjobs's Privacy Policy and Terms & Conditions will apply.

SonicJobs' Terms & Conditions and Privacy Policy also apply.