Loading jobs…
Loading jobs…
Boku Inc. — Fairfax, Virginia
All hired employees are expected to have experience with Microsoft Copilot and / or an approved equivalent AI solution. DSA is hiring a Senior Information Security Analyst. This is a full-time position supporting a customer in the DC Metro area with a HYBRID Schedule.
This position supports the Environmental Protection Agency (EPA). DSA is the Prime and has been working with this customer on this contract for more than 13 years. S.
citizens. Location is Hybrid: Allows the candidate the ability to work onsite at DSA or customer site with potential for telework. DSA work locations include Fairfax, VA.
Work Location is flexible with telework as approved. The ability to work onsite each week is required. Core work hours dedicated to DSA and our direct customers are 8 am est to 5 pm est.
Responsibilities
and assisting senior agency officials with information security and privacy
The Senior Information Security Analyst will be an integral part of a team responsible for supporting the development and maturation of an Agency-wide information security (InfoSec) program for a large civilian Federal agency. The candidate will serve as a subject matter expert with regards to the Risk Management Framework (RMF) and all associated information security policies and procedures and should possess in-depth knowledge of applying, selecting and testing the NIST family of security controls.
: Advising senior-level stakeholders on InfoSec initiatives including compliance, awareness and training, and security operations.
Requirements
Leveraging the existing Governance, Risk, and Compliance (GRC) tool, Telos Xacta (or an alternate like CSAM or RSA Archer), to track and reconcile findings from assessments, audits, and vulnerability scans. ) and monthly reports. Assessing the effectiveness of the InfoSec and privacy training program and leading the collection, analyzing, and presentation of enterprise-level InfoSec performance metrics.
Managing InfoSec Program POA Ms, including advising on remediation efforts. Working closely with senior agency security officials, system owners, information system security officers (ISSOs) and other stakeholders to advise and implement security solutions. Identify opportunities for efficiencies in work process and innovative approaches.
Participating in team problem solving efforts and offer ideas to solve client issues. Conducting relevant research, data analysis, and developing reports. Preparing and assisting in the development of policy and procedures.
Implementing processes and procedures to monitor risk across programs / projects. Preparing briefings to the executive team to debrief the results of studies, analyses, and plans. Assisting the client leadership in reviewing monthly project progress, documenting issues, and monitoring resolution.
Required Qualifications
: Ability to obtain a Public Trust. Bachelor’s degree in information technology or related field and 8 years of relevant IA experience. g.
CISSP) for 2 years of experience. 3+ years in a leadership role Strong data analysis skills. Excellent written and verbal communication skills.
Possess in-depth knowledge of applying, selecting and testing the NIST 800-53 Rev 4 security controls. Possess in-depth knowledge of NIST 800-37 Risk Management Framework.