About The Position

The Cyber Security Analyst III serves as an experienced practitioner within the organization’s GRC program, managing NIST RMF lifecycle activities, conducting risk and control assessments and coordinating assurance and privacy initiatives for federal information systems. The analyst ensures that security documentation, continuous monitoring and remediation efforts meet FISMA and NIST standards, supporting ongoing authorization and compliance maturity.

Requirements

  • Bachelor’s degree in Cybersecurity, Information Systems, or related technical discipline.
  • Five (5) years of progressive experience in cybersecurity, including experience supporting or leading FISMA RMF compliance or cybersecurity governance functions.
  • Ability to pass a background and drug screening.
  • Must have identification compliant with the Real ID Act at time of hire.
  • Must be able to obtain Department of Energy access badge.
  • Must be able to obtain and maintain a U.S. government security clearance.

Nice To Haves

  • Proficiency with GRC platforms (e.g., RegScale, ServiceNow GRC, Archer, eMASS or similar).
  • Experience coordinating FedRAMP Moderate or High inheritance reviews.
  • Certifications such as CISM, CISA, CAP/CGRC, CRISC or CIPP/US.
  • Demonstrated success leading cross-functional audit or authorization activities.

Responsibilities

  • Lead system-level RMF activities, ensuring SSPs, risk assessments and POA&Ms are current and complete.
  • Conduct independent risk assessments, evaluating the impact and likelihood of findings and recommending mitigation strategies.
  • Manage POA&M lifecycle, ensuring closure of findings through remediation or documented risk acceptance.
  • Perform control assurance reviews, validating implementation and effectiveness across control families.
  • Coordinate cloud and third-party compliance assessments, reviewing FedRAMP packages and continuous monitoring deliverables.
  • Support privacy compliance, ensuring alignment with NIST privacy requirements.
  • Generate and present risk and compliance status reports to system owners and cybersecurity leadership.
  • Provide mentorship and guidance to junior analysts on RMF and GRC documentation standards.
  • Collaborate across Security, IT and Privacy teams to ensure alignment between operational controls and compliance objectives.
  • Perform other duties as appropriate and as assigned.

Benefits

  • Paid holidays
  • Paid time off
  • 401k with employer match
  • Dental insurance
  • Vision insurance
  • Health insurance plans through the Federal Employee Health Benefits (FEHB) program
  • Life and disability benefits
© 2024 Teal Labs, Inc
Privacy PolicyTerms of Service