ECS is seeking a Senior Business Analyst to work in our Washington, DC (hybrid) office. Please Note: This position is contingent upon contract award.
Job Responsibilities
- Lead the development and implementation of cybersecurity processes and security assessment workflows for information systems, including national security systems, that are managed in a governance, risk management, compliance (GRC) application, and that are governed by federal laws and Department of State policies and standards.
- Document cybersecurity processes and standard operating procedures as needed and manage the same in SharePoint and a GRC.
- Elicit, analyze, and document business requirements, translating high-level needs into detailed functional specifications and use cases.
- Conduct in-depth data analysis, process modeling, and workflow analysis to identify areas for improvement and propose innovative solutions.
- Develop and present compelling business cases, cost/benefit analyses, and strategic recommendations to senior leadership and key stakeholders.
- Act as a liaison between business units and IT teams, facilitating effective communication and collaboration throughout the project lifecycle.
- Lead or mentor less experienced business analysts, providing guidance on best practices and fostering a culture of continuous learning.
- Oversee and participate in user acceptance testing (UAT) and quality assurance activities, ensuring solutions meet business requirements and are delivered on time and within budget.
- May also be responsible for tasks like vendor management and system administration, depending on the specific role requirements.
- Provide governance support over common control projects and cloud service provider on-boarding
Salary Range: $130,000-$147,000
General Description of Benefit
Qualifications
- Bachelor's degree in Computer Science, MIS/IT, Engineering, Information Security/Assurance, or a related field
- Minimum five (5) years of information security experience
- Demonstrated experience conducting full-scope technical security control testing across component types, including development of security and privacy assessment plans
- Working knowledge of RMF Steps 1-6
- Strong understanding of NIST SP 800-53 controls, the NIST Cybersecurity Framework, and applicable information security/privacy laws and regulations
- Ability to analyze information system configurations and technical specifications against NIST SP 800-53 and related overlays
- Experience developing risk-based documentation
- Excellent written and verbal communication skills, with the ability to present control requirements and deficiencies clearly to both technical and non-technical audiences
- Active Secret clearance required with eligibility to get Top Secret clearance
Learn more about this Employer on their Career Site
