Sign up to access all features of our service.
  • Job search
  • Favorites
  • Create a CV
    New
  • Salaries
  • Subscriptions

Information Security Analyst Sr Principal - Cloud - Hybrid

$142.79k - $184k
Full-time

GDIT

Responsibilities for this Position

Location: USA MD Fort Meade
Full Part/Time: Full time
Job Req: RQ227262

Type of Requisition:
Regular

Clearance Level Must Currently Possess:
Secret

Clearance Level Must Be Able to Obtain:
Secret

Public Trust/Other Required:
None

Job Family:
Cyber and IT Risk Management

Job Qualifications:

Skills:
Cybersecurity, Information Security, RMF, Security Requirements, System Security
Certifications:
None
Experience:
8 + years of related experience
US Citizenship Required:
Yes

Job Description:

As an Information Security Analyst Sr Principal, you will be responsible for the ICAM program's network accreditation on both unclassified and classified networks. You will also be responsible for executing and reviewing security assessments of computing environments to identify points of vulnerability, non-compliance with established IA standards and regulations, and recommend mitigation strategies.

In this role, a typical day will include:
  • Execute success in obtaining an accreditation and maintaining the accreditation for ICAM on a classified network.
  • Perform Risk Management Framework (RMF) actions in eMASS such as control assessments, PPSM, upload and manage ICAM assets in hardware/software list, upload STIG checklists and ACAS vulnerability reports.
  • Define, draft, publish, and maintain Information Security policies, standards, and guidelines such as Access Control Plan, Identification and Authentication Plan, Auditing and Accountability Plan, Contingency Plan, Incident Response Plan, Vulnerability Management, Continuous Monitoring, Backup and Recovery, System Integrity Plan, Key Management, Media Protection, etc.
  • Develop and finalize RMF documentation to include Security Plans, Implementation Plans, Plans of Action and Milestones (POA&Ms), and Risk Assessment Reports
  • Assess system compliance against NIST, DoD, and DHA security requirements to include the NIST 800-53 controls, and DISA Security Technical Implementation Guides (STIGs) and Security Requirements Guides (SRGs).
  • Spearhead support government compliance assessments such as penetration testing and accreditation and compliance inspections assessments and mitigations to system security threats/risks throughout the program life cycle.
  • Work with the internal and external stakeholders to resolve compliance or audit issues in a timely manner. Enforce the design and implementation of trusted relations among external systems and architectures.
  • Ensure system security needs are established and maintained for operations development, security requirements definition, security risk assessment, systems analysis, systems design, security test and evaluation, certification and accreditation, systems hardening, vulnerability, testing and scanning, incident response, disaster recovery, and business continuity planning; and provides analytical support for security policy development and analysis.
  • Other related work as directed.

Required Qualifications:
  • Active DoD Security Clearance of SECRET, or higher
  • Minimum eight (8) + years' experience and proven track record supporting IT customers as part of an enterprise environment.
  • BA/BS and 8+ years of Computer Science or equivalent experience
  • CISSP, CASP, CISA, CISM or similar for IAM Level III DoD 8570/8140 certification
  • Experience with FedRAMP Cloud processes
  • Knowledge of the DoD cybersecurity and policy requirements set forth in DoDI 8500.01 "Cybersecurity", NIST 800-53v5 Assessing Privacy and Security Controls and DoDI 8510.01 "Risk Management Framework
  • Extensive and experience in NIST 800-53, Risk Framework security controls in eMASS
  • Ability to lead in highly collaborative, fast-paced, growth-focused environment.
  • Experience and knowledge in cybersecurity tools such as Nessus ACAS, Microsoft Defender Endpoint, McAfee
  • Extensive experience and knowledge with Incident Response testing/plans and Contingency testing/plans
  • Experience with systems that deploy API gateways, firewalls, access control lists, IP subnetting, NAT and other network device in Cloud.
  • Experience communicating with and coordinating across multiple stakeholders and teams to align to and execute unified goals and plans.
  • The ability to effectively communicate with people ranging from non-technical to engineering level.

Desired Qualifications:
  • Familiarization with DoD enterprise environments
  • Familiarization with Agile work environments
  • Familiarization with Microsoft Azure Cloud environment

The likely salary range for this position is $142,792 - $184,000. This is not, however, a guarantee of compensation or salary. Rather, salary will be set based on experience, geographic location and possibly contractual requirements and could fall outside of this range.

Scheduled Weekly Hours:
40

Travel Required:
25-50%

Telecommuting Options:
Hybrid

Work Location:
USA MD Fort Meade

Additional Work Locations:

Total Rewards at GDIT:
Our benefits package for all US-based employees includes a variety of medical plan options, some with Health Savings Accounts, dental plan options, a vision plan, and a 401(k) plan offering the ability to contribute both pre and post-tax dollars up to the IRS annual limits and receive a company match. To encourage work/life balance, GDIT offers employees full flex work weeks where possible and a variety of paid time off plans, including vacation, sick and personal time, holidays, paid parental, military, bereavement and jury duty leave. To ensure our employees are able to protect their income, other offerings such as short and long-term disability benefits, life, accidental death and dismemberment, personal accident, critical illness and business travel and accident insurance are provided or available. We regularly review our Total Rewards package to ensure our offerings are competitive and reflect what our employees have told us they value most.

Our Identity Verification Process:
As part of the hiring process, we will ask you to complete an identity verification process that leverages advanced biometrics and artificial intelligence to ensure authenticity and protect against identity fraud. You are expected to be on camera during virtual interviews. We reserve the right to take your picture to verify your identity and prevent fraud. By proceeding, you authorize the collection, processing, and use of your biometric data for identity verification and security purposes.

About Our Work:
We are GDIT. A global technology and professional services company that delivers technology solutions and mission services to every major agency across the U.S. government, defense and intelligence community. Our 26,000 experts extract the power of technology to create immediate value and deliver solutions at the edge of innovation. We operate across 50+ countries worldwide, offering leading mission-ready capabilities in AI, cloud, cyber and software development.

Join our Talent Community to stay up to date on our career opportunities and events at
gdit.com/tc .

Equal Opportunity Employer / Individuals with Disabilities / Protected Veterans



PI286797332




As an Information Security Analyst Sr Principal, you will be responsible for the ICAM program's network accreditation on both unclassified and classified networks. You will also be responsible for executing and reviewing security assessments of computing environments to identify points of vulnerability, non-compliance with established IA standards and regulations, and recommend mitigation strategies.



In this role, a typical day will include:

  • Execute success in obtaining an accreditation and maintaining the accreditation for ICAM on a classified network.
  • Perform Risk Management Framework (RMF) actions in eMASS such as control assessments, PPSM, upload and manage ICAM assets in hardware/software list, upload STIG checklists and ACAS vulnerability reports.
  • Define, draft, publish, and maintain Information Security policies, standards, and guidelines such as Access Control Plan, Identification and Authentication Plan, Auditing and Accountability Plan, Contingency Plan, Incident Response Plan, Vulnerability Management, Continuous Monitoring, Backup and Recovery, System Integrity Plan, Key Management, Media Protection, etc.
  • Develop and finalize RMF documentation to include Security Plans, Implementation Plans, Plans of Action and Milestones (POA&Ms), and Risk Assessment Reports
  • Assess system compliance against NIST, DoD, and DHA security requirements to include the NIST 800-53 controls, and DISA Security Technical Implementation Guides (STIGs) and Security Requirements Guides (SRGs).
  • Spearhead support government compliance assessments such as penetration testing and accreditation and compliance inspections assessments and mitigations to system security threats/risks throughout the program life cycle.
  • Work with the internal and external stakeholders to resolve compliance or audit issues in a timely manner. Enforce the design and implementation of trusted relations among external systems and architectures.
  • Ensure system security needs are established and maintained for operations development, security requirements definition, security risk assessment, systems analysis, systems design, security test and evaluation, certification and accreditation, systems hardening, vulnerability, testing and scanning, incident response, disaster recovery, and business continuity planning; and provides analytical support for security policy development and analysis.
  • Other related work as directed.




Required Qualifications:

  • Active DoD Security Clearance of SECRET, or higher
  • Minimum eight (8) + years' experience and proven track record supporting IT customers as part of an enterprise environment.
  • BA/BS and 8+ years of Computer Science or equivalent experience
  • CISSP, CASP, CISA, CISM or similar for IAM Level III DoD 8570/8140 certification
  • Experience with FedRAMP Cloud processes
  • Knowledge of the DoD cybersecurity and policy requirements set forth in DoDI 8500.01 "Cybersecurity", NIST 800-53v5 Assessing Privacy and Security Controls and DoDI 8510.01 "Risk Management Framework
  • Extensive and experience in NIST 800-53, Risk Framework security controls in eMASS
  • Ability to lead in highly collaborative, fast-paced, growth-focused environment.
  • Experience and knowledge in cybersecurity tools such as Nessus ACAS, Microsoft Defender Endpoint, McAfee
  • Extensive experience and knowledge with Incident Response testing/plans and Contingency testing/plans
  • Experience with systems that deploy API gateways, firewalls, access control lists, IP subnetting, NAT and other network device in Cloud.
  • Experience communicating with and coordinating across multiple stakeholders and teams to align to and execute unified goals and plans.
  • The ability to effectively communicate with people ranging from non-technical to engineering level.




Desired Qualifications:

  • Familiarization with DoD enterprise environments
  • Familiarization with Agile work environments
  • Familiarization with Microsoft Azure Cloud environment



The likely salary range for this position is $142,792 - $184,000. This is not, however, a guarantee of compensation or salary. Rather, salary will be set based on experience, geographic location and possibly contractual requirements and could fall outside of this range.



Scheduled Weekly Hours:
40



Travel Required:
25-50%



Telecommuting Options:
Hybrid



Work Location:
USA MD Fort Meade



Additional Work Locations:



Total Rewards at GDIT:
Our benefits package for all US-based employees includes a variety of medical plan options, some with Health Savings Accounts, dental plan options, a vision plan, and a 401(k) plan offering the ability to contribute both pre and post-tax dollars up to the IRS annual limits and receive a company match. To encourage work/life balance, GDIT offers employees full flex work weeks where possible and a variety of paid time off plans, including vacation, sick and personal time, holidays, paid parental, military, bereavement and jury duty leave. To ensure our employees are able to protect their income, other offerings such as short and long-term disability benefits, life, accidental death and dismemberment, personal accident, critical illness and business travel and accident insurance are provided or available. We regularly review our Total Rewards package to ensure our offerings are competitive and reflect what our employees have told us they value most.



Our Identity Verification Process:
As part of the hiring process, we will ask you to complete an identity verification process that leverages advanced biometrics and artificial intelligence to ensure authenticity and protect against identity fraud. You are expected to be on camera during virtual interviews. We reserve the right to take your picture to verify your identity and prevent fraud. By proceeding, you authorize the collection, processing, and use of your biometric data for identity verification and security purposes.



About Our Work:
We are GDIT. A global technology and professional services company that delivers technology solutions and mission services to every major agency across the U.S. government, defense and intelligence community. Our 26,000 experts extract the power of technology to create immediate value and deliver solutions at the edge of innovation. We operate across 50+ countries worldwide, offering leading mission-ready capabilities in AI, cloud, cyber and software development.


Join our Talent Community to stay up to date on our career opportunities and events at

gdit.com/tc .


Equal Opportunity Employer / Individuals with Disabilities / Protected Veterans







PI286797332

Vacancy posted 2 days ago
Similar jobs that could be interesting for youBased on the Information Security Analyst Sr Principal - Cloud - Hybrid in Maryland vacancy
  •  .... Make an impact by connecting and securing critical operations across the globe...  .... Job Description As an Information Security Analyst Sr Principal, you will be responsible for the ICAM...  ...certification Experience with FedRAMP Cloud processes Knowledge of the DoD... 
    Principal
    Cloud
    Senior

    General Dynamics Information Technology

    Maryland, MD
    2 days ago
  • $94.49k - $131.16k

     ...can achieve. Together.SummaryThe Senior Information Security Analyst is responsible for identifying,...  ...Northern Virginia office and offers a hybrid work schedule.ResponsibilitiesMentoring...  ...Security Operations Center) operations. Cloud Security: Knowledge of cloud infrastructure... 
    Cloud
    Senior
    Full time
    Work at office
    Remote work
    Relocation
    Visa sponsorship
    Relocation package

    DLA Piper

    Baltimore, MD
    17 hours ago
  • $77k - $172k

    Senior Information Security Analyst (Finance) Saalex Corporation is seeking a Senior Information Security...  ...depending on experience) Work Location: Hybrid remote/in-office (see onsite...  ...Professional-Designer-NG (FITSP-D) GIAC Cloud Security Automation (GCSA) GIAC Security... 
    Cloud
    Senior
    Full time
    Temporary work
    Interim role
    Work at office
    Remote work
    2 days per week

    Saalex Corporation in

    Saint Inigoes, MD
    3 days ago
  • DLA Piper is seeking a Senior Information Security Analyst to identify, investigate, and mitigate internal and external threats, driving advanced...  ...security vendors, and elevating the firm's security posture in a hybrid work environment across multiple offices in the US. #J-18... 
    Senior

    DLA Piper

    Annapolis, MD
    2 days ago
  • VITG is looking for an Cloud Information Security Analyst (CISA) responsible for taking the lead on implementing security tools, security tool usage,...  ...hours support depending on deployment schedule Work Type: Hybrid remote in Ellicott City, MD 21043 1 to 2 days in office... 
    Cloud
    Full time
    Work experience placement
    Work at office
    Remote work
    Shift work

    VITG

    Ellicott City, MD
    1 day ago
  •  ...Hanover, MD 21076 Category: Information Technology Schedule: Day...  ...-life balance - This is a hybrid role-Hanover, MD. Must...  ...Position Summary: The IT SECURITY ANALYST III is responsible for...  ...Demonstrated experience securing cloud environments (Azure... 
    Cloud
    Full time
    Local area
    Day shift

    Johns Hopkins Medicine

    Hanover, MD
    2 days ago
  • $76.4k - $138.6k

     ...fueled by vast amounts of information. Data is more valuable...  ...in EY Information Security has a critical role to...  ...an Offensive Security Analyst on the Attack Surface...  ...web applications, APIs, cloud environments, networks...  ...and leader-enabled hybrid model. Our expectation... 
    Cloud
    Summer holiday
    Local area
    Flexible hours

    EY

    Annapolis, MD
    3 days ago
  •  ...Senior Information Security Analyst Remote Contract to Hire Hours: Core overlap with CST business hours required Senior Information...  ...across vulnerability management, security controls, cloud operations, data protection, governance, risk, compliance,... 
    Cloud
    Senior
    Contract work
    Remote work

    Navatech

    Maryland, MD
    1 day ago
  • Create/Update all client security deliverables (SSP, CP, ISRA, CP, PTA/PIA, etc.) Work with team members to ensure security functions are...  ...for a program (SCA/ACT, A-123, IRS 1070, etc.) Experience with cloud-based systems (e.g., AWS, Salesforce) Experience in creating... 
    Cloud
    Senior

    Jobtailor

    Annapolis, MD
    1 day ago
  • IT - Information Security/Privacy Analyst I Summary: The CIOCC Tier 1 Analyst shall be responsible for the following, but not limited to: Analyze and...  ...000-0600) depending on staffing needs. This position is hybrid on-site in Rockville, MD. #J-18808-Ljbffr PLANIT Group
    Shift work
    Afternoon shift

    PLANIT Group

    Rockville, MD
    3 days ago
  •  ...to improve the lives and ensure the security of all Americans—from soldiers and veteran...  ...of Scope: We are seeking an Information Security Analyst who is responsible for providing security...  ...in cybersecurity architecture, cloud security, DevSecOps, security engineering... 
    Cloud
    Work experience placement
    Remote work

    eSimplicity

    Maryland, MD
    2 days ago
  •  ...Project Manager - Team Lead / Information Security Analyst - SME Zantech is looking for a talented Project Manager - Team Lead / Information...  ...supporting U.S. Citizenship & Immigration Services (USCIS) on a Hybrid basis (40% On-site / 60% Remote) in Camp Springs, MD.... 
    Contract work
    Remote work

    Zantech

    Suitland, MD
    2 days ago
  • $55 - $60 per hour

    DescriptionPosition Overview The Information Security Analyst II (GRC) provides support for Governance, Risk, and Compliance activities aligned...  ...Leave (PTO, Vacation or Sick Leave)Workplace TypeThis is a hybrid position in Columbia,MD.Application DeadlineThis position... 
    Contract work
    Temporary work

    TEKsystems

    Columbia, MD
    2 days ago
  • Futrend Technology Inc. is seeking an IT Cloud Security Analyst to join our security compliance team....  ...will work closely with the customer's Information Systems Security Officer (ISSO) and...  ...and compliance visibility across NLM’s hybrid environment Investigate and respond to... 
    Cloud
    Work experience placement
    3 days per week

    Futrend Technology

    Bethesda, MD
    2 days ago
  • We are seeking an experienced Info Security Analyst IV to support FIPS 140 validation projects within a hands-on lab environment. This role focuses on security analysis, cryptographic validation testing, product evaluations, automation, and technical reporting in support... 
    Senior
    Local area

    Aptonet

    Columbia, MD
    4 days ago
  •  ...Senior Information Security Analyst As a Senior Information Security Analyst, you will be a key member of our security team, responsible for safeguarding our organization's systems and data from cyber threats. Your primary focus will be assessing security risks, developing... 
    Senior
    Contract work
    Work experience placement
    Work at office
    2 days per week

    Staffing

    Columbia, MD
    5 hours ago
  • $85k - $101k

     ...Job Description Job Description Sigma Defense is currently seeking an Information Security Analyst to work in support of the Army for the Network Modernization & Mission Network Technical Service Support program (NetMod). NetMod sets forth the work efforts required... 
    Work at office
    Remote work

    Sigma Defense

    Belcamp, MD
    6 days ago
  •  ...Description Job Description iQuasar is seeking to fill an Information Security Analyst IV position. At iQuasar, we strive to provide the next...  ...merit, and business need. Best Regards, Khalid Banday Sr. Recruitment Professional   iQuasar, LLC 6 Pidgeon... 
    Contract work

    IQUASAR LLC

    Columbia, MD
    6 days ago
  • $55k - $60k

    Technology Security Associates, Inc. is seeking a Junior Information Security Analyst to support secure facilities on NAS Patuxent River. Your role will include assisting with access control and maintaining compliance with US Government security regulations. You will ensure... 

    Technology Security Associates, Inc.

    Annapolis, MD
    1 day ago
  •  ...professional to join our team at Fort Meade, Maryland. This hybrid position offers the possibility of remote days, with responsibilities...  ..., along with a strong understanding of IT audits and information security. Competitive compensation, health benefits, and retirement... 
    Remote work

    Leidos

    Odenton, MD
    4 days ago
  •  ...Work-life balance -   This is a hybrid role-Hanover, MD.  Must...  ...Position Summary: The IT SECURITY ANALYST III is responsible for implementing and supporting information security engineering for all...  ...Demonstrated experience securing cloud environments (Azure Government... 
    Cloud
    Full time

    Johns Hopkins Medicine

    Maryland
    13 days ago
  • A-TEK, Inc. in the Washington, DC area is seeking a Security Assessment and Continuous Monitoring Analyst to support RMF/A&A activities for a federal agency....  ...maintain authorization packages for assessor reviews, with hybrid work options. The ideal candidate has experience... 

    atek s.r.o.

    Annapolis, MD
    4 days ago
  • A-TEK, Inc. is seeking a Security Assessment and Continuous Monitoring Analyst to support annual security assessments, continuous monitoring, and POA&M management...  ..., and GRC tools, and must be able to work in a hybrid setup in the Washington, DC metro area #J-18808-Ljbffr... 

    A-Tek

    Bethesda, MD
    2 days ago
  • $100k - $330k

     ...Innovations is a trusted national security partner, dedicated to...  ...practices. We focus on challenges in Information Warfare, Cyber Operations,...  ...in national security.Principal Information Security Specialist...  ...regarding containerization and cloud infrastructure.Key ResponsibilitiesATO... 
    Principal
    Cloud
    Senior

    Clarity

    Columbia, MD
    1 day ago
  •  ...cyber professional to join our Fort Meade, Maryland team in a hybrid capacity with on-site emphasis and potential 1-2 remote days...  ...needs. The role focuses on implementing and administering information security policies, procedures, and technologies to protect systems, applications... 
    Remote work

    Leidos

    Odenton, MD
    17 hours ago
  • $112.2k - $168.2k

     ...think is impossible. Our employees are not only part of history, they're making history.Northrop Grumman is seeking a Sr. Principal Industrial Security Analyst 4/Lead CPSO to support multiple program(s) as it relates to all applicable classified federal, contractual,... 
    Principal
    Senior
    Full time
    Work experience placement
    Relocation
    Shift work

    Northrop Grumman

    Baltimore, MD
    2 days ago
  • $107.9k - $195.05k

    The C5ISR Center Cyber Security Service Provider (CSSP) is a premier...  ...vulnerability management across cloud and on-premises environments,...  ...experienced Endpoint Security Analyst to support a highly visible, strategic...  ...cyber threats.Location: Hybrid - 3 days on site at Adelphi,... 
    Cloud
    Full time
    Immediate start

    Leidos

    Adelphi, MD
    3 days ago
  • Banner Life Insurance Company in Frederick, MD is looking for a Principal Software Engineer to drive innovation and develop one of the...  ..., and a passion for creating reliable systems. The position is hybrid and offers competitive benefits and compensation. #J-18808-Ljbffr... 
    Principal
    Cloud

    Banner Life Insurance Company

    Frederick, MD
    2 days ago
  • $90k - $100k

     ...IT Security Analyst The Baltimore Orioles organization is a storied Major League Baseball franchise with a proud tradition, passionate...  ...Qualifications ~ Bachelor's degree in Cybersecurity, Information Technology, or related field (or equivalent experience). ~... 
    Remote work
    Flexible hours

    Baltimore Orioles

    Baltimore, MD
    1 day ago
  • $112.2k - $168.2k

     ...Sr. Principal Industrial Security Analyst 4/Lead CPSO RELOCATION ASSISTANCE: No relocation assistance available CLEARANCE REQUIRED FOR START: Yes CLEARANCE TYPE: Secret TRAVEL: Yes, 10% of the Time Description At Northrop Grumman, our employees have incredible opportunities... 
    Principal
    Senior
    Work experience placement
    Relocation
    Shift work

    Clearance Jobs

    Baltimore, MD
    1 day ago

Do you want to receive more vacancies?

Subscribe and receive similar vacancies to Information Security Analyst Sr Principal - Cloud - Hybrid. Be the first to apply!