Req ID: RQ201168
Type of Requisition: Regular
Clearance Level Must Be Able to Obtain: Secret
Public Trust/Other Required: None
Job Family: Information Security
Skills:
Azure Active Directory (AD),ISSO,System Security,System Security Plans
Certifications:
CISSP: Certified Information Systems Security Professional - ISC2
Experience:
10 + years of related experience
Job Description:
Information Security Analyst Sr Advisor
Your Impact
Own your opportunity to work alongside federal civilian agencies. Make an impact by providing services that help the government ensure the wellbeing of U.S. citizens.
Job Description
We are seeking a qualified, motivated individual to join GDIT as an Information Security Analyst Senior Advisor (Security 1 Lead ISSO) . This position will play a dual role as the Security Lead as well as the projects ISSO. Your focus will be on the Systems Security Plan (SSP) and Authorization To Operate (ATO) package documentation, Policy and Controls, and any other duties that fall under the ISSO / Information Assurance role. You will maintain security postures across several development environments, conducting risk assessments, and ensuring all system changes undergo proper security reviews, while keeping abreast of evolving government cybersecurity directives. You will collaborate with GDIT technical leadership, Government customers, and other key stakeholders to assess our existing and new systems infrastructure.
How You'll Make an Impact:
Ensure security policies and procedures are implemented
Authors Standard Operating Procedures, policies, and IA plans of action to ensure systems compliance with Federal/DoD guidance
Identifying corrective actions/mitigation strategies to achieve/sustain (Risk Management Framework (RMF) compliance
Review and analyze system implementation plans
Advising system owners and stakeholders on new deployments and advanced cyber security techniques
Information Security Analyst Senior Advisor Duties and Responsibilities
Serve as the primary authority on System security
Oversee the implementation of NIST SP 800-53 controls, Classified National Security Information (CNSI) and FedRAMP requirements across Azure Gov and Azure Secret cloud environments
Develop and maintain security documentation (System Security Plans, security policies, procedures)
Manage the ATO process by conducting risk assessments, coordinating with authorizing officials, and tracking Plans of Action & Milestones (POA&Ms) for identified gaps
Monitor system security posture daily by reviewing audit logs and SIEM alerts (Splunk, Azure Sentinel) for suspicious activity or policy violations
Ensure timely incident investigation and response with the DevOps team
Guide DevOps and Engineering teams on secure configuration baselines (applying DISA STIGs or CIS benchmarks to servers, containers, and network devices)
Verify that all system changes pass security review and change controls
Coordinate regular vulnerability scanning and penetration testing of cloud infrastructure and applications (using approved tools like Nessus, Fortify)
Ensure any discovered vulnerabilities are remediated within required timeframes
Enforce robust access controls and identity management
Regularly review user accounts and privileges in Azure AD and Azure Gov environments
Ensure multifactor authentication and PKI usage in accordance with federal security policies
Provide security training and guidance to engineering teams
Foster a culture of security awareness, and stay up to date on government cybersecurity directives to adapt security strategies
Information Security Analyst Senior Advisor Requirements and Qualifications
Bachelor's degree in computer science or IT related degree; master's degree or equivalent professional experience in information security is preferred
Ability to create and maintain system BOE documents to include SSPs, architecture diagrams, contingency planning, and continuous monitoring documentation
Ability to write and modify documents to include SOPs, processes, and other guidance documentation
Comprehensive knowledge of corporate Systems/Solutions Architecture processes and trends
Strong leadership, organizational, and communication skills
Secret Clearance to start
Knowledge of Agile software development process
Experience with Azure AD
?
Required Technical Skills:
SCAP, STIG, Patching, eMASS, and related RMF tools
Cybersecurity, Systems Administration, implementation of RMF tools and processes
Excellent communication skills
Experience working in Agile software development teams
Experience with secure development, coding and engineering practices
Experience with Cybersecurity, Information Security, and Information Technology Security processes, protocols, and procedures.
Experience with tools such as Splunk, Azure Sentinel, Nessus, Fortify
Experience
10 years of relevant experience
Experience with Cloud Security
Experience working with leading firewall, network scanning and authentication technologies
Experience working with internet, web, application and network security techniques
Experience in Agile methodology
Experience in Jira to support development team in agile environment
Experience working in Federal or State government environments
Ability to work independently and remotely
Certification: CISSP desired, Active DoD 8570 IAT Level II Certification (Security+ CE)
Travel Required: Little to no travel anticipated (may be required upon customer request)
Location: Hybrid
US Citizenship : U.S. Citizenship required
GDIT Is Your Place:
401K with company match
Comprehensive health and wellness packages
Internal mobility team dedicated to helping you own your career
Professional growth opportunities including paid education and certifications
Cutting-edge technology you can learn from
Full-flex work week to own your priorities at work and at home
The likely salary range for this position is $144,500 - $195,500. This is not, however, a guarantee of compensation or salary. Rather, salary will be set based on experience, geographic location and possibly contractual requirements and could fall outside of this range.
Our benefits package for all US-based employees includes a variety of medical plan options, some with Health Savings Accounts, dental plan options, a vision plan, and a 401(k) plan offering the ability to contribute both pre and post-tax dollars up to the IRS annual limits and receive a company match. To encourage work/life balance, GDIT offers employees full flex work weeks where possible and a variety of paid time off plans, including vacation, sick and personal time, holidays, paid parental, military, bereavement and jury duty leave. To ensure our employees are able to protect their income, other offerings such as short and long-term disability benefits, life, accidental death and dismemberment, personal accident, critical illness and business travel and accident insurance are provided or available. We regularly review our Total Rewards package to ensure our offerings are competitive and reflect what our employees have told us they value most.
We are GDIT. A global technology and professional services company that delivers consulting, technology and mission services to every major agency across the U.S. government, defense and intelligence community. Our 30,000 experts extract the power of technology to create immediate value and deliver solutions at the edge of innovation. We operate across 50 countries worldwide, offering leading capabilities in digital modernization, AI/ML, Cloud, Cyber and application development. Together with our clients, we strive to create a safer, smarter world by harnessing the power of deep expertise and advanced technology.
Join our Talent Community to stay up to date on our career opportunities and events at https://gdit.com/tc.
Equal Opportunity Employer / Individuals with Disabilities / Protected Veterans