Security Analyst
Washington (District of Columbia) Bachelor's Degree Infra / Networks / Telecom
Job description
Job Description
Security Analyst
Position Description
The ideal Security Analyst will have had prior experience working in a highly technical environment, be well versed in the current state of Information Security and be able to interpret security requirements of relevant governing bodies (NIST, OMB, DHS, etc). The candidate will interface with federal employees and contractors to perform required support activities. The ideal candidate will have prior experience performing similar governance, risk and/or compliance activities consistent with the experience/skill requirements documented below for a federal client in FTE and/or consultant capacity. Your future duties and responsibilities
- Create, compile and maintain security authorization packages and documentation as required by Federal security authorization guidelines described in NIST and OMB requirement documents.
- Enforce policies and guidelines as outlined within NIST SP 800-53 and DHS 4300A Sensitive Systems Policy.
- Provide guidance in the implementation of system specific features and security controls to ensure effective compliance with federal requirements as well promoting a healthy security posture for the implementation team and key stakeholders.
- Provide IT security consultation to system owners as to the other security documents, for example, security incident reports, equipment/software inventories, technical vulnerability reports and contingency plans.
- Perform the necessary review, analysis and reporting of key system attributes, weaknesses and changes to the Information Systems Security Manager, System Owner and Department Risk Management body to support the Continuous Monitoring of supported systems.
- Initiate, track and manage the creation, opening and closure of weaknesses via Department prescribed Plan of Action and Milestone (POAM) processes and procedures.
- Effectively communicate the risk and security posture to the Information Systems Security Manager, System Owner, Key Stakeholders and consumers of security controls within your purview.
- Reporting IT security incidents in accordance with established policies and procedures. Required qualifications to be successful in this role
- Due to the nature of the government contract requirements and/or clearance requirements, US citizenship is required.
- Bachelor's degree or equivalent combination of education and experience.
- Experience with information assurance compliance tools (Xacta, TAF, etc.).
- Knowledge of Federal Government Authorization processes (NIST 800-53, DHS 4300A, DIACAP).
- 2+ years of information security experience or equivalent combination of information security and engineering/administration.
Preferred qualifications:
- Experience supporting cloud application/security efforts. Previous AWS (Amazon Web Services) experience is preferred, but not required.
- Experience with identity management solutions (MIM, FIM, ADFS, Active Directory).
- Experience with Linux-based and Windows-based server operating systems.
- General knowledge of industry security requirements, standards and best practices.
- Experience creating, maintaining and reviewing security compliance documentation (Systems Security Plan, Contingency Plan, Risk Assessment, POAMs).
- Security professional certifications (CISSP, CISM, CGEIT, CRISC, CAP, CEH).
- Knowledge of policies, procedures and requirements.
- Experience with security analysis tools (Nessus, HP Fortify, HP Web Inspect, AppDetective).
- Experience with Splunk.
*LI-MC3 Build your career with us.
It is an extraordinary time to be in business. As digital transformation continues to accelerate, CGI is at the center of this change—supporting our clients’ digital journeys and offering our professionals exciting career opportunities.
At CGI, our success comes from the talent and commitment of our professionals. As one team, we share the challenges and rewards that come from growing our company, which reinforces our culture of ownership. All of our professionals benefit from the value we collectively create.
Be part of building one of the largest independent technology and business services firms in the world.
Learn more about CGI at www.cgi.com.
No unsolicited agency referrals please.
CGI is an equal opportunity employer.
Qualified applicants will receive consideration for employment without regard to their race, color, religion, sex, gender Identity, sexual orientation, national origin, age, disability, veteran status, pregnancy, or other status protected by law. CGI will not discharge or in any other manner discriminate against employees or applicants because they have inquired about, discussed, or disclosed their own pay or the pay of another employee or applicant. However, employees who have access to the compensation information of other employees or applicants as a part of their essential job functions cannot disclose the pay of other employees or applicants to individuals who do not otherwise have access to compensation information, unless the disclosure is (a) in response to a formal complaint or charge, (b) in furtherance of an investigation, proceeding, hearing, or action, including an investigation conducted by the employer, or (c) consistent with CGI’s legal duty to furnish information.
Skills
· English
Reference
570830