Information Security Analyst Sr Principal - Cloud - Hybrid
$142.79k - $184kFull-time
GDIT
Responsibilities for this Position
Location: USA MD Fort MeadeFull Part/Time: Full time
Job Req: RQ227262 Type of Requisition:
Regular Clearance Level Must Currently Possess:
Secret Clearance Level Must Be Able to Obtain:
Secret Public Trust/Other Required:
None Job Family:
Cyber and IT Risk Management Job Qualifications: Skills:
Cybersecurity, Information Security, RMF, Security Requirements, System Security
Certifications:
None
Experience:
8 + years of related experience
US Citizenship Required:
Yes Job Description: As an Information Security Analyst Sr Principal, you will be responsible for the ICAM program's network accreditation on both unclassified and classified networks. You will also be responsible for executing and reviewing security assessments of computing environments to identify points of vulnerability, non-compliance with established IA standards and regulations, and recommend mitigation strategies. In this role, a typical day will include:
- Execute success in obtaining an accreditation and maintaining the accreditation for ICAM on a classified network.
- Perform Risk Management Framework (RMF) actions in eMASS such as control assessments, PPSM, upload and manage ICAM assets in hardware/software list, upload STIG checklists and ACAS vulnerability reports.
- Define, draft, publish, and maintain Information Security policies, standards, and guidelines such as Access Control Plan, Identification and Authentication Plan, Auditing and Accountability Plan, Contingency Plan, Incident Response Plan, Vulnerability Management, Continuous Monitoring, Backup and Recovery, System Integrity Plan, Key Management, Media Protection, etc.
- Develop and finalize RMF documentation to include Security Plans, Implementation Plans, Plans of Action and Milestones (POA&Ms), and Risk Assessment Reports
- Assess system compliance against NIST, DoD, and DHA security requirements to include the NIST 800-53 controls, and DISA Security Technical Implementation Guides (STIGs) and Security Requirements Guides (SRGs).
- Spearhead support government compliance assessments such as penetration testing and accreditation and compliance inspections assessments and mitigations to system security threats/risks throughout the program life cycle.
- Work with the internal and external stakeholders to resolve compliance or audit issues in a timely manner. Enforce the design and implementation of trusted relations among external systems and architectures.
- Ensure system security needs are established and maintained for operations development, security requirements definition, security risk assessment, systems analysis, systems design, security test and evaluation, certification and accreditation, systems hardening, vulnerability, testing and scanning, incident response, disaster recovery, and business continuity planning; and provides analytical support for security policy development and analysis.
- Other related work as directed.
- Active DoD Security Clearance of SECRET, or higher
- Minimum eight (8) + years' experience and proven track record supporting IT customers as part of an enterprise environment.
- BA/BS and 8+ years of Computer Science or equivalent experience
- CISSP, CASP, CISA, CISM or similar for IAM Level III DoD 8570/8140 certification
- Experience with FedRAMP Cloud processes
- Knowledge of the DoD cybersecurity and policy requirements set forth in DoDI 8500.01 "Cybersecurity", NIST 800-53v5 Assessing Privacy and Security Controls and DoDI 8510.01 "Risk Management Framework
- Extensive and experience in NIST 800-53, Risk Framework security controls in eMASS
- Ability to lead in highly collaborative, fast-paced, growth-focused environment.
- Experience and knowledge in cybersecurity tools such as Nessus ACAS, Microsoft Defender Endpoint, McAfee
- Extensive experience and knowledge with Incident Response testing/plans and Contingency testing/plans
- Experience with systems that deploy API gateways, firewalls, access control lists, IP subnetting, NAT and other network device in Cloud.
- Experience communicating with and coordinating across multiple stakeholders and teams to align to and execute unified goals and plans.
- The ability to effectively communicate with people ranging from non-technical to engineering level.
- Familiarization with DoD enterprise environments
- Familiarization with Agile work environments
- Familiarization with Microsoft Azure Cloud environment
40 Travel Required:
25-50% Telecommuting Options:
Hybrid Work Location:
USA MD Fort Meade Additional Work Locations: Total Rewards at GDIT:
Our benefits package for all US-based employees includes a variety of medical plan options, some with Health Savings Accounts, dental plan options, a vision plan, and a 401(k) plan offering the ability to contribute both pre and post-tax dollars up to the IRS annual limits and receive a company match. To encourage work/life balance, GDIT offers employees full flex work weeks where possible and a variety of paid time off plans, including vacation, sick and personal time, holidays, paid parental, military, bereavement and jury duty leave. To ensure our employees are able to protect their income, other offerings such as short and long-term disability benefits, life, accidental death and dismemberment, personal accident, critical illness and business travel and accident insurance are provided or available. We regularly review our Total Rewards package to ensure our offerings are competitive and reflect what our employees have told us they value most. Our Identity Verification Process:
As part of the hiring process, we will ask you to complete an identity verification process that leverages advanced biometrics and artificial intelligence to ensure authenticity and protect against identity fraud. You are expected to be on camera during virtual interviews. We reserve the right to take your picture to verify your identity and prevent fraud. By proceeding, you authorize the collection, processing, and use of your biometric data for identity verification and security purposes. About Our Work:
We are GDIT. A global technology and professional services company that delivers technology solutions and mission services to every major agency across the U.S. government, defense and intelligence community. Our 26,000 experts extract the power of technology to create immediate value and deliver solutions at the edge of innovation. We operate across 50+ countries worldwide, offering leading mission-ready capabilities in AI, cloud, cyber and software development. Join our Talent Community to stay up to date on our career opportunities and events at
gdit.com/tc . Equal Opportunity Employer / Individuals with Disabilities / Protected Veterans
PI286797332
As an Information Security Analyst Sr Principal, you will be responsible for the ICAM program's network accreditation on both unclassified and classified networks. You will also be responsible for executing and reviewing security assessments of computing environments to identify points of vulnerability, non-compliance with established IA standards and regulations, and recommend mitigation strategies.
In this role, a typical day will include:
- Execute success in obtaining an accreditation and maintaining the accreditation for ICAM on a classified network.
- Perform Risk Management Framework (RMF) actions in eMASS such as control assessments, PPSM, upload and manage ICAM assets in hardware/software list, upload STIG checklists and ACAS vulnerability reports.
- Define, draft, publish, and maintain Information Security policies, standards, and guidelines such as Access Control Plan, Identification and Authentication Plan, Auditing and Accountability Plan, Contingency Plan, Incident Response Plan, Vulnerability Management, Continuous Monitoring, Backup and Recovery, System Integrity Plan, Key Management, Media Protection, etc.
- Develop and finalize RMF documentation to include Security Plans, Implementation Plans, Plans of Action and Milestones (POA&Ms), and Risk Assessment Reports
- Assess system compliance against NIST, DoD, and DHA security requirements to include the NIST 800-53 controls, and DISA Security Technical Implementation Guides (STIGs) and Security Requirements Guides (SRGs).
- Spearhead support government compliance assessments such as penetration testing and accreditation and compliance inspections assessments and mitigations to system security threats/risks throughout the program life cycle.
- Work with the internal and external stakeholders to resolve compliance or audit issues in a timely manner. Enforce the design and implementation of trusted relations among external systems and architectures.
- Ensure system security needs are established and maintained for operations development, security requirements definition, security risk assessment, systems analysis, systems design, security test and evaluation, certification and accreditation, systems hardening, vulnerability, testing and scanning, incident response, disaster recovery, and business continuity planning; and provides analytical support for security policy development and analysis.
- Other related work as directed.
Required Qualifications:
- Active DoD Security Clearance of SECRET, or higher
- Minimum eight (8) + years' experience and proven track record supporting IT customers as part of an enterprise environment.
- BA/BS and 8+ years of Computer Science or equivalent experience
- CISSP, CASP, CISA, CISM or similar for IAM Level III DoD 8570/8140 certification
- Experience with FedRAMP Cloud processes
- Knowledge of the DoD cybersecurity and policy requirements set forth in DoDI 8500.01 "Cybersecurity", NIST 800-53v5 Assessing Privacy and Security Controls and DoDI 8510.01 "Risk Management Framework
- Extensive and experience in NIST 800-53, Risk Framework security controls in eMASS
- Ability to lead in highly collaborative, fast-paced, growth-focused environment.
- Experience and knowledge in cybersecurity tools such as Nessus ACAS, Microsoft Defender Endpoint, McAfee
- Extensive experience and knowledge with Incident Response testing/plans and Contingency testing/plans
- Experience with systems that deploy API gateways, firewalls, access control lists, IP subnetting, NAT and other network device in Cloud.
- Experience communicating with and coordinating across multiple stakeholders and teams to align to and execute unified goals and plans.
- The ability to effectively communicate with people ranging from non-technical to engineering level.
Desired Qualifications:
- Familiarization with DoD enterprise environments
- Familiarization with Agile work environments
- Familiarization with Microsoft Azure Cloud environment
The likely salary range for this position is $142,792 - $184,000. This is not, however, a guarantee of compensation or salary. Rather, salary will be set based on experience, geographic location and possibly contractual requirements and could fall outside of this range.
Scheduled Weekly Hours:
40
Travel Required:
25-50%
Telecommuting Options:
Hybrid
Work Location:
USA MD Fort Meade
Additional Work Locations:
Total Rewards at GDIT:
Our benefits package for all US-based employees includes a variety of medical plan options, some with Health Savings Accounts, dental plan options, a vision plan, and a 401(k) plan offering the ability to contribute both pre and post-tax dollars up to the IRS annual limits and receive a company match. To encourage work/life balance, GDIT offers employees full flex work weeks where possible and a variety of paid time off plans, including vacation, sick and personal time, holidays, paid parental, military, bereavement and jury duty leave. To ensure our employees are able to protect their income, other offerings such as short and long-term disability benefits, life, accidental death and dismemberment, personal accident, critical illness and business travel and accident insurance are provided or available. We regularly review our Total Rewards package to ensure our offerings are competitive and reflect what our employees have told us they value most.
Our Identity Verification Process:
As part of the hiring process, we will ask you to complete an identity verification process that leverages advanced biometrics and artificial intelligence to ensure authenticity and protect against identity fraud. You are expected to be on camera during virtual interviews. We reserve the right to take your picture to verify your identity and prevent fraud. By proceeding, you authorize the collection, processing, and use of your biometric data for identity verification and security purposes.
About Our Work:
We are GDIT. A global technology and professional services company that delivers technology solutions and mission services to every major agency across the U.S. government, defense and intelligence community. Our 26,000 experts extract the power of technology to create immediate value and deliver solutions at the edge of innovation. We operate across 50+ countries worldwide, offering leading mission-ready capabilities in AI, cloud, cyber and software development.
Join our Talent Community to stay up to date on our career opportunities and events at
gdit.com/tc .
Equal Opportunity Employer / Individuals with Disabilities / Protected Veterans
PI286797332
Vacancy posted 2 days ago
Similar jobs that could be interesting for youBased on the Information Security Analyst Sr Principal - Cloud - Hybrid in Maryland vacancy
- .... Make an impact by connecting and securing critical operations across the globe... .... Job Description As an Information Security Analyst Sr Principal, you will be responsible for the ICAM... ...certification Experience with FedRAMP Cloud processes Knowledge of the DoD...PrincipalCloudSenior
$94.49k - $131.16k
...can achieve. Together.SummaryThe Senior Information Security Analyst is responsible for identifying,... ...Northern Virginia office and offers a hybrid work schedule.ResponsibilitiesMentoring... ...Security Operations Center) operations. Cloud Security: Knowledge of cloud infrastructure...CloudSeniorFull timeWork at officeRemote workRelocationVisa sponsorshipRelocation package$77k - $172k
Senior Information Security Analyst (Finance) Saalex Corporation is seeking a Senior Information Security... ...depending on experience) Work Location: Hybrid remote/in-office (see onsite... ...Professional-Designer-NG (FITSP-D) GIAC Cloud Security Automation (GCSA) GIAC Security...CloudSeniorFull timeTemporary workInterim roleWork at officeRemote work2 days per week- DLA Piper is seeking a Senior Information Security Analyst to identify, investigate, and mitigate internal and external threats, driving advanced... ...security vendors, and elevating the firm's security posture in a hybrid work environment across multiple offices in the US. #J-18...Senior
- VITG is looking for an Cloud Information Security Analyst (CISA) responsible for taking the lead on implementing security tools, security tool usage,... ...hours support depending on deployment schedule Work Type: Hybrid remote in Ellicott City, MD 21043 1 to 2 days in office...CloudFull timeWork experience placementWork at officeRemote workShift work
- ...Hanover, MD 21076 Category: Information Technology Schedule: Day... ...-life balance - This is a hybrid role-Hanover, MD. Must... ...Position Summary: The IT SECURITY ANALYST III is responsible for... ...Demonstrated experience securing cloud environments (Azure...CloudFull timeLocal areaDay shift
$76.4k - $138.6k
...fueled by vast amounts of information. Data is more valuable... ...in EY Information Security has a critical role to... ...an Offensive Security Analyst on the Attack Surface... ...web applications, APIs, cloud environments, networks... ...and leader-enabled hybrid model. Our expectation...CloudSummer holidayLocal areaFlexible hours- ...Senior Information Security Analyst Remote Contract to Hire Hours: Core overlap with CST business hours required Senior Information... ...across vulnerability management, security controls, cloud operations, data protection, governance, risk, compliance,...CloudSeniorContract workRemote work
- Create/Update all client security deliverables (SSP, CP, ISRA, CP, PTA/PIA, etc.) Work with team members to ensure security functions are... ...for a program (SCA/ACT, A-123, IRS 1070, etc.) Experience with cloud-based systems (e.g., AWS, Salesforce) Experience in creating...CloudSenior
- IT - Information Security/Privacy Analyst I Summary: The CIOCC Tier 1 Analyst shall be responsible for the following, but not limited to: Analyze and... ...000-0600) depending on staffing needs. This position is hybrid on-site in Rockville, MD. #J-18808-Ljbffr PLANIT GroupShift workAfternoon shift
- ...to improve the lives and ensure the security of all Americans—from soldiers and veteran... ...of Scope: We are seeking an Information Security Analyst who is responsible for providing security... ...in cybersecurity architecture, cloud security, DevSecOps, security engineering...CloudWork experience placementRemote work
- ...Project Manager - Team Lead / Information Security Analyst - SME Zantech is looking for a talented Project Manager - Team Lead / Information... ...supporting U.S. Citizenship & Immigration Services (USCIS) on a Hybrid basis (40% On-site / 60% Remote) in Camp Springs, MD....Contract workRemote work
$55 - $60 per hour
DescriptionPosition Overview The Information Security Analyst II (GRC) provides support for Governance, Risk, and Compliance activities aligned... ...Leave (PTO, Vacation or Sick Leave)Workplace TypeThis is a hybrid position in Columbia,MD.Application DeadlineThis position...Contract workTemporary work- Futrend Technology Inc. is seeking an IT Cloud Security Analyst to join our security compliance team.... ...will work closely with the customer's Information Systems Security Officer (ISSO) and... ...and compliance visibility across NLM’s hybrid environment Investigate and respond to...CloudWork experience placement3 days per week
- We are seeking an experienced Info Security Analyst IV to support FIPS 140 validation projects within a hands-on lab environment. This role focuses on security analysis, cryptographic validation testing, product evaluations, automation, and technical reporting in support...SeniorLocal area
- ...Senior Information Security Analyst As a Senior Information Security Analyst, you will be a key member of our security team, responsible for safeguarding our organization's systems and data from cyber threats. Your primary focus will be assessing security risks, developing...SeniorContract workWork experience placementWork at office2 days per week
$85k - $101k
...Job Description Job Description Sigma Defense is currently seeking an Information Security Analyst to work in support of the Army for the Network Modernization & Mission Network Technical Service Support program (NetMod). NetMod sets forth the work efforts required...Work at officeRemote work- ...Description Job Description iQuasar is seeking to fill an Information Security Analyst IV position. At iQuasar, we strive to provide the next... ...merit, and business need. Best Regards, Khalid Banday Sr. Recruitment Professional iQuasar, LLC 6 Pidgeon...Contract work
$55k - $60k
Technology Security Associates, Inc. is seeking a Junior Information Security Analyst to support secure facilities on NAS Patuxent River. Your role will include assisting with access control and maintaining compliance with US Government security regulations. You will ensure...- ...professional to join our team at Fort Meade, Maryland. This hybrid position offers the possibility of remote days, with responsibilities... ..., along with a strong understanding of IT audits and information security. Competitive compensation, health benefits, and retirement...Remote work
- ...Work-life balance - This is a hybrid role-Hanover, MD. Must... ...Position Summary: The IT SECURITY ANALYST III is responsible for implementing and supporting information security engineering for all... ...Demonstrated experience securing cloud environments (Azure Government...CloudFull time
- A-TEK, Inc. in the Washington, DC area is seeking a Security Assessment and Continuous Monitoring Analyst to support RMF/A&A activities for a federal agency.... ...maintain authorization packages for assessor reviews, with hybrid work options. The ideal candidate has experience...
- A-TEK, Inc. is seeking a Security Assessment and Continuous Monitoring Analyst to support annual security assessments, continuous monitoring, and POA&M management... ..., and GRC tools, and must be able to work in a hybrid setup in the Washington, DC metro area #J-18808-Ljbffr...
$100k - $330k
...Innovations is a trusted national security partner, dedicated to... ...practices. We focus on challenges in Information Warfare, Cyber Operations,... ...in national security.Principal Information Security Specialist... ...regarding containerization and cloud infrastructure.Key ResponsibilitiesATO...PrincipalCloudSenior- ...cyber professional to join our Fort Meade, Maryland team in a hybrid capacity with on-site emphasis and potential 1-2 remote days... ...needs. The role focuses on implementing and administering information security policies, procedures, and technologies to protect systems, applications...Remote work
$112.2k - $168.2k
...think is impossible. Our employees are not only part of history, they're making history.Northrop Grumman is seeking a Sr. Principal Industrial Security Analyst 4/Lead CPSO to support multiple program(s) as it relates to all applicable classified federal, contractual,...PrincipalSeniorFull timeWork experience placementRelocationShift work$107.9k - $195.05k
The C5ISR Center Cyber Security Service Provider (CSSP) is a premier... ...vulnerability management across cloud and on-premises environments,... ...experienced Endpoint Security Analyst to support a highly visible, strategic... ...cyber threats.Location: Hybrid - 3 days on site at Adelphi,...CloudFull timeImmediate start- Banner Life Insurance Company in Frederick, MD is looking for a Principal Software Engineer to drive innovation and develop one of the... ..., and a passion for creating reliable systems. The position is hybrid and offers competitive benefits and compensation. #J-18808-Ljbffr...PrincipalCloud
$90k - $100k
...IT Security Analyst The Baltimore Orioles organization is a storied Major League Baseball franchise with a proud tradition, passionate... ...Qualifications ~ Bachelor's degree in Cybersecurity, Information Technology, or related field (or equivalent experience). ~...Remote workFlexible hours$112.2k - $168.2k
...Sr. Principal Industrial Security Analyst 4/Lead CPSO RELOCATION ASSISTANCE: No relocation assistance available CLEARANCE REQUIRED FOR START: Yes CLEARANCE TYPE: Secret TRAVEL: Yes, 10% of the Time Description At Northrop Grumman, our employees have incredible opportunities...PrincipalSeniorWork experience placementRelocationShift work
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Information Security Analyst Sr Principal - Cloud - Hybrid. Be the first to apply!
Related searches
- data analyst supply chain analytics Maryland
- senior data management analyst Maryland
- data analyst bank Maryland
- data analyst Maryland
- information systems analyst Maryland
- provider data analyst Maryland
- report analyst Maryland
- senior financial data analyst Maryland
- data integrity analyst Maryland
- remote data analyst part time Maryland


