CP

Concept Plus

1 open position available

1 location
1 employment type
Actively hiring
Full-time

Latest Positions

Showing 1 most recent job
CP

Sr. Information Assurance / Cyber Analyst

Concept PlusAnywhereFull-time
View Job
Compensation$85K - 120K a year

Support federal cybersecurity compliance by maintaining RMF packages, continuous monitoring, and coordinating security controls. | Requires 5-7 years federal cybersecurity experience, RMF expertise, and proficiency with tools like eMASS and Nessus. | About the role Concept Plus is seeking a highly experienced Senior Information Assurance / Cyber Analyst to join our team supporting a federal program. The program's systems are deployed across classified and unclassified environments, hosted in both data centers and the cloud. The successful candidate will be responsible for supporting the government Information System Security Manager (ISSM) in maintaining the system's cybersecurity posture in accordance with federal policies. You will be responsible for preparing and maintaining the Risk Management Framework (RMF) package, conducting continuous monitoring, and working closely with technical teams to ensure security is integrated throughout the entire system's lifecycle. This role is pivotal in supporting the system's Authority to Operate (ATO) and ensuring robust security from development through production. What you'll do • Support the ISSM by preparing and maintaining the system's RMF package throughout its lifecycle using the eMASS tool. • Develop, maintain, and update all required RMF documentation. • Conduct continuous monitoring, analyze vulnerability scan results, and track the remediation of vulnerabilities by applying IAVM-directed patches. • Coordinate security engineering input into system designs and the implementation of security controls. • Analyze results from SAST/DAST security scans (e.g., SonarQube, Checkmarx) and collaborate with the development team on remediation. • Track and respond to cybersecurity incidents, ensuring timely reporting and effective recovery efforts. • Ensure compliance with security requirements such as two-factor authentication, data-at-rest encryption, and FIPS standards. • Document and report on cybersecurity performance, contributing to artifacts like the Software Cybersecurity Release Report. • Act as a primary cybersecurity subject matter expert, providing guidance and support to the ISSM and program leadership. • Participating in Agile/DevSecOps development cycles, ensuring security is integrated from concept to deployment. • Review and validate system architecture, configuration changes, and release plans for security impacts. • Prepare for and participate in security assessments, audits, and inspections. • Liaise with external security stakeholders and accrediting authorities as directed. Required Qualifications • US Citizen • Must be able to obtain a Tier-3 Secret Clearance • Bachelor's degree in Cybersecurity, Information Technology, or a related field. • 5-7 years of experience in Federal cybersecurity compliance. • Expert knowledge of federal cybersecurity mandates, including RMF. • Hands-on proficiency with cybersecurity tools such as eMASS, Nessus, SonarQube, and/or Checkmarx. • Strong understanding of NIST 800-53 security controls.

Risk Management Framework (RMF)
Cybersecurity Compliance
Vulnerability Management
Verified Source
Posted about 1 month ago

Ready to join Concept Plus?

Create tailored applications specifically for Concept Plus with our AI-powered resume builder

Get Started for Free

Ready to have AI work for you in your job search?

Sign-up for free and start using JobLogr today!

Get Started »
JobLogr badgeTinyLaunch BadgeJobLogr - AI Job Search Tools to Land Your Next Job Faster than Ever | Product Hunt