Information Security Analyst 3
C-HIT
Job Description: The Information Security Officer (ISO) will work closely with Project and Technical management to plan, design and implement Dynamic Application Security Testing (DAST) and/or Static Application Security Testing (SAST) security methodologies into the technical solution of a program within the Centers for Medicare and Medicaid Services (CMS). The ISO will be responsible for assuring all CMS security and privacy considerations and requirements are assessed, addressed and documented for the given application, designing the solution so that it passes the required Annual Security Assessment Testing (within CMS referred to ACT or Adaptive Capabilities Testing) and maintains the system Authority to Operate (ATO).
The primary responsibilities of the position include but are not limited to:
• Promote a professional work ethic with the ability to meet commitments, scheduled timelines and take ownership of problems.
• Lead, support and document all security incident response activities.
• Perform annual security assessment audits (such as ACT, PenTest, etc.).
• Perform Web Application Penetration and Continuous Diagnostic Monitoring (CDM) testing.
• Mitigate and/or address the security specific vulnerabilities and document via Plan of Action and Milestones (POA&M).
• Support ad hoc security requests from the customer and program management.
• Conduct security impact assessments for new or existing architecture changes. Required Skills:
• 3+ years of experience with NIST and Federal security documentation.
• Active CISSP or equivalent security related certification.
• Capable of obtaining Level Five: Public Trust security clearance.
• Proven experience with FISCAM and FedRAMP requirements.
• Experience writing and maintaining security related documents, including the System Security Plan (SSP), Contingency Plan and Test (CP), Information System Risk Assessment (ISRA), Security Assessment Plan/Report (SAP/SAR) and the Privacy Impact Assessment (PIA).
• Ability to resolve complex support issues by leveraging user forums, support forums, or opening support cases with vendors and following them to closure. Strong ability to find mitigation and alternative approaches.
• Knowledge of current as well as emerging security threats.
• Understanding of and experience with Agile Development and DevSecOps/DevOps.
• Proven experience with Cloud Technologies (AWS)
• Proven experience with Microsoft Office Tools (Outlook, Word, Excel, PowerPoint). Desired Skills and Certifications:
• Working experience within CMS including with CMS Information Systems Security and Privacy Policy (IS2P2), NIST 800-53, NIST 800-63, CMS Acceptable Risk Safeguards (ARS), CMS Risk Management Handbook (RMH) and CMS Federal Information Security Management Act (FISMA) Controls Tracking System (CFACTS).
• Proven experience with Security tools such as Burp, SonarQube, AWS Security Tools
• Proven experience with networking concepts, such as, DHCP, DNS, VLANs, Routing and VPNs Salary & Benefits Information:
"C-HIT is an EOE, including disability and veterans"
The primary responsibilities of the position include but are not limited to:
• Promote a professional work ethic with the ability to meet commitments, scheduled timelines and take ownership of problems.
• Lead, support and document all security incident response activities.
• Perform annual security assessment audits (such as ACT, PenTest, etc.).
• Perform Web Application Penetration and Continuous Diagnostic Monitoring (CDM) testing.
• Mitigate and/or address the security specific vulnerabilities and document via Plan of Action and Milestones (POA&M).
• Support ad hoc security requests from the customer and program management.
• Conduct security impact assessments for new or existing architecture changes. Required Skills:
• 3+ years of experience with NIST and Federal security documentation.
• Active CISSP or equivalent security related certification.
• Capable of obtaining Level Five: Public Trust security clearance.
• Proven experience with FISCAM and FedRAMP requirements.
• Experience writing and maintaining security related documents, including the System Security Plan (SSP), Contingency Plan and Test (CP), Information System Risk Assessment (ISRA), Security Assessment Plan/Report (SAP/SAR) and the Privacy Impact Assessment (PIA).
• Ability to resolve complex support issues by leveraging user forums, support forums, or opening support cases with vendors and following them to closure. Strong ability to find mitigation and alternative approaches.
• Knowledge of current as well as emerging security threats.
• Understanding of and experience with Agile Development and DevSecOps/DevOps.
• Proven experience with Cloud Technologies (AWS)
• Proven experience with Microsoft Office Tools (Outlook, Word, Excel, PowerPoint). Desired Skills and Certifications:
• Working experience within CMS including with CMS Information Systems Security and Privacy Policy (IS2P2), NIST 800-53, NIST 800-63, CMS Acceptable Risk Safeguards (ARS), CMS Risk Management Handbook (RMH) and CMS Federal Information Security Management Act (FISMA) Controls Tracking System (CFACTS).
• Proven experience with Security tools such as Burp, SonarQube, AWS Security Tools
• Proven experience with networking concepts, such as, DHCP, DNS, VLANs, Routing and VPNs Salary & Benefits Information:
- The actual salary offer will carefully consider a wide range of factors, including your skills, qualifications, experience, and location.
- C-HIT offers Healthcare Benefits, Remote Working Options, Paid Time Off, PTO cash-out, Training/Certification opportunities, Healthcare Savings Account & Flexible Savings Account, Paid Life Insurance, Short-term & Long-term Disability, 401K Match, Employee Assistance Program, Paid Holidays, and much more perks and Voluntary benefits!
- Employees of C-HIT shall, as an enduring obligation throughout their term of employment, adhere to all information security requirements as documented in company policies and procedures.
"C-HIT is an EOE, including disability and veterans"
Vacancy posted 23 hours ago
Similar jobs that could be interesting for youBased on the Information Security Analyst 3 in Columbia, MD vacancy
- ...Senior Information Security Analyst As a Senior Information Security Analyst, you will be a key member of our security team, responsible for safeguarding... ...development, database, and systems management ~3 or more years of experience must be in an information security...SuggestedContract workWork experience placementWork at office2 days per week
- We are seeking an experienced Info Security Analyst IV to support FIPS 140 validation projects within a hands-on lab environment. This role focuses... ...initiatives. The team consists of 12 team members and 3 project managers supporting secure communications and product...SuggestedLocal area
$100k - $125k
...Zachary Piper Solutions is hiring a Information Security Analyst (Tier 2) for a leading cybersecurity operations team supporting secure government environments... ...Analyst: Active Secret Clearance (required) 1-3 years of SOC or security analyst experience (Tier 2...Suggested2 days per week$55 - $60 per hour
Position Overview The Information Security Analyst II (GRC) provides support for Governance, Risk, and Compliance activities aligned to NIST CSF, NIST... ...to address risk and compliance gaps Minimum Requirements 3-5 years of experience in information security, risk, or compliance...SuggestedContract work- ...Junior Security Analyst The Junior Security Analyst will oversee, evaluate, and support the documentation... ...approaches, as needed, to maximize information security • Ensures appropriate... ...systems or a related area • At least 3 years of information security experience...SuggestedImmediate start
- ...seeking a National Access Elsewhere Security Oversight Center (NAESOC) Analyst to support the Defense... ...strategies Minimum Requirements: ~3+ years’ experience with security-related... ...orientation, gender identity, genetic information, or expression of another protected...
- ...Network Security Analyst We are looking for a detail-oriented and proactive Network Security Analyst to join our cybersecurity team.... ...incidents, and implementing measures to safeguard sensitive information. Collaborating with cross-functional teams, you will play a...Temporary workFor contractorsImmediate startFlexible hours
- ...ideal candidate will have four years of relevant experience or a degree in business and proficiency in Microsoft Excel. This full-time position requires U.S. citizenship and offers opportunities to support critical national security missions. #J-18808-Ljbffr Synergy ECPFull time
$100k - $245k
The Johns Hopkins University Applied Physics Laboratory is seeking an Information Technology & Data Analyst to enhance enterprise IT systems. The candidate will analyze data to inform decision-making, design dashboards, and support IT operations in compliance with regulations...$55 - $60 per hour
TEKsystems is looking for an Information Security Analyst II in Columbia, MD. This role involves supporting compliance initiatives aligned to regulatory frameworks like NIST and HIPAA, while performing risk assessments and control testing. The ideal candidate should possess...Contract work$100k - $245k
...Johns Hopkins Applied Physics Lab is seeking an AI National Security Analyst to develop and apply Generative AI tools that enhance National Security Analysis. This role involves collaborating with various teams to translate mission needs into effective AI-enabled solutions...$100k
...important work at the intersection of National Security Analysis and Generative AI? Are you... .... As an AI National Security Analyst... You will develop and apply Generative... ...requirements for access to classified information. Eligibility requirements include U.S....Temporary workWork experience placementInterim roleRelocation packageFlexible hours- The Johns Hopkins Applied Physics Laboratory is seeking a Modeling & Simulation Analyst in Laurel, MD. The candidate will utilize AFSIM tools to evaluate operations in national security. Key qualifications include a Bachelor's degree in a technical field and at least three...
$100k
...you searching for important work at the intersection of National Security Analysis and advanced Modeling & Simulation (M&S)? Are you... ...using simulation tools to analyze complex operational problems and inform real-world decisions? If so, we're looking for someone like...Interim role$100k - $245k
...Physics Lab in Laurel, MD is looking for a Modeling and Simulation Specialist to apply advanced analytical techniques to national security challenges. Candidates should hold a relevant Bachelor’s degree coupled with a minimum of three years of experience in modeling and...$100k - $245k
Johns Hopkins Applied Physics Lab in Laurel, Maryland is seeking a Forensic Insider Threat Analyst to identify and mitigate insider risks. This role requires expertise in cybersecurity and digital forensics, with responsibilities including monitoring user activity, investigating...$100k - $245k
The Johns Hopkins University Applied Physics Laboratory is seeking a National Security M&S Analyst to utilize modeling and simulation tools like AFSIM to analyze complex operational problems in national security. Candidates should have a Bachelor's in a technical field...- ...SAIC is seeking an experienced Program Security Officer to join a team of qualified and diverse... ...group support, personnel security, information assurance, counterintelligence, physical... ...has annual revenues of approximately $7.3 billion. For more information, visit saic...
$85k - $141k
...Obtain Public Trust What You Will Do: The Cloud Security & Authorization Technical Analyst provides deep technical expertise in securing,... ...San Francisco. If you have visited our website for information about employment opportunities, or to apply for a position...Temporary workFlexible hours$117k - $167k
...This Business Finance Professional 3 will assist in the execution of the Program... ...management system that include all necessary information and documentation (PSC#, PAR, SPAT, BER#,... ...supporting the missions of National Security, BCT's leadership knows their business better...Contract workWork experience placementInternshipWork at officeLocal areaHome office$124.5k - $214.6k
...Overview We are looking for a Principal Cybersecurity & Microsoft Security Platform Technology Consultant - CTJ - POLY to join the... ...and secure DevSecOps integration with Azure environments. Information Protection & Data Security: Microsoft Purview Information Protection...Ongoing contractLocal area- ...regulations, and best practices. Completes other tasks and duties as assigned. QUALIFICATIONS AND EDUCATION REQUIREMENTS ~3+ years' experience specifically with domestic truck brokerage. ~2+ years' experience specifically with LTL and air freight forwarding...Work at office
- CFS is seeking a Senior Accountant in Columbia, MD (Hybrid - 3 days onsite) to join their growing finance team. This role offers direct visibility to senior leadership and ownership of month-end close responsibilities, including journal entries and account reconciliations...
$123.68k - $200.2k
...provide you more specific details for this role. Line of Business: Technology Solutions Job Description: The Business Information Security Officer (BISO) leads development and/or implementation of significant or Bank-wide Technology Controls / Information...Work at officeLocal areaWork from homeFlexible hours$67.14k - $92.5k
...Range: $67,143.00 - $92,500.00 Security Clearance: Secret Level of... ...seeking a Program Financial Analyst to support the ASMO Broadband... ...effective budget execution, and informed program decision-making.... ...Minimum Qualifications ~3 years relevant experience with...Full timeContract workWork experience placementWork at officeLocal areaWorldwideRelocation- ...infrastructure from base to battlefield. We bring 120 years of successful mission support to improve security, streamline logistics, and enhance readiness. Aligned around a shared purpose, our $3.9B company and 16,000 people work alongside our clients, here and abroad, to tackle...Work at office
- Security Manager, CxM page is loaded## Security Manager, CxMlocations: Columbia: USA - Remote - Marylandtime type: 全职posted on: 今天发布job... ...:****Role purpose**The purpose of this role is to lead information security for the CxM Practice Area, building on dentsu’s enterprise...Contract workLocal areaRemote workShift workEarly shift
- ...Health will never askfor sensitive, personal information or payment information during the hiring... ...members. We're Hiring an Actuarial Analyst to Join Our Team! We are seeking a highly... ...Mathematics, Economics, or related field. 1-3 years of experience in actuarial or...
$67.78k - $106.69k
...Financial Analyst We are Lennar Lennar is one of the... ...finance is preferred Minimum of 3 years general accounting or... ...#LI-ST1, #CB ~ This information is intended to be a general overview... ...Company Match up to 5%, helps secure their financial future, while...Live inLocal areaFlexible hours$50 - $60 per hour
DataAnnotation is committed to creating high-quality AI. Join our team to help train the next generation of AI while enjoying the flexibility of remote work and the freedom to set your own schedule. This role is designed to fit a variety of lifestyles — whether you’re ...Hourly payContract workWork experience placementRemote workFlexible hours
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Information Security Analyst 3. Be the first to apply!
Related searches
- data analyst Columbia, MD
- neuroscience data analyst Columbia, MD
- data protection analyst Columbia, MD
- remote data analyst Columbia, MD
- data analyst supply chain analytics Columbia, MD
- data analyst part time work from home Columbia, MD
- remote data analyst intern Columbia, MD
- report analyst Columbia, MD
- data analyst bank Columbia, MD
- senior financial data analyst Columbia, MD


