Cybersecurity Analyst

AmentumMcLean, VA
Onsite

About The Position

Amentum is seeking a Cybersecurity Analyst to join their team in McLean, VA. The role involves performing Assessment and Authorization (A&A) efforts under the NIST Risk Management Framework (RMF) for a federal civilian agency. The analyst will conduct cybersecurity analysis, review and validate cybersecurity documentation and technical controls, and work within a team to conduct A&A activities. Key responsibilities include developing System Security Plans (SSP), Contingency Plans, Business Impact Analyses (BIA), Plan of Action and Milestones (POA&Ms), Security Assessment Report (SARs), Security Assessment Plan (SAPs), and other RMF documentation. The position also involves identifying risks, validating mitigation plans, analyzing system designs, and assisting with A&A issues. The role supports RMF implementation by developing documentation and updating policies, procedures, and processes, and assesses and mitigates system security threats/risks throughout the program life cycle. This includes contributing to security planning, assessment, risk analysis, risk management, certification, and awareness activities. The analyst will create and review A&A Body of Evidence documentation, develop and execute Security Test Plans (STP), and manage Continuous Monitoring (CONMON) to maintain system authorization.

Requirements

  • 5+ years of experience in Cybersecurity policy, procedures, and processes, including RMF and NIST 800-53 and A&A's
  • Experience developing A&A documentation from scratch and performing assessments; RMF step 1 through 4
  • Familiar with NIST publications, specifically RMF and NIST controls
  • Minimum DoD 8570 Information Assurance Management Technology (IAM) level II
  • Familiar with dealing with defense-in-depth, and other information security and assurance principles and associated supporting technologies
  • Hands on experience and detailed familiarity with the A&A processes
  • Experience working in Xacta, Greenlight/Roadrunner
  • Excellent customer service and organization skills
  • Must demonstrate proficiency in multi-tasking, critical thinking; and the ability to work quickly, efficiently and accurately in a dynamic and fluid environment
  • Must have a Top-Secret Clearance with polygraph
  • Must be able to read, speak, write, and understand the English language

Nice To Haves

  • BA/BS Degree
  • One or more of the following certifications preferred (Security+, CAP, CISSP, CISM, GSEC, GCIH, or GSLC)
  • Excellent oral and written communication skills
  • Ability to interact and relay security technical requirements at all levels of leadership and work force
  • Ability to work both independently and as a member of a team

Responsibilities

  • Identify key stakeholders in A&A efforts and ensure system documentation reflects current system security configurations to include hardware and software components, data flow, interconnections, and ports, protocols, and services, etc.
  • Identify potential risks associated with system configurations and advise on mitigation strategies
  • Participate in A&A status meetings and facilitate moving systems toward a successful A&A effort
  • Assist to estimate Level of Effort (LOE) involved in performing A&A activities
  • Assist customer program offices in interpreting and applying mitigation strategies
  • Conduct thorough reviews of all vulnerabilities, architecture, and defense in depth strategies and report findings in POA&Ms document
  • Document residual risks and provide the cybersecurity risk analysis and mitigation determination results
  • Maintain cybersecurity policy and processes as assigned
  • Analyze, interpret, and apply Federal cybersecurity guidance to customer needs
  • Communicate the security posture of systems through designated reporting mechanism
  • Collaborate with other team members in cybersecurity
  • Develop System Security Plans (SSP), Contingency Plans, Business Impact Analyses (BIA), Plan of Action and Milestones (POA&Ms), Security Assessment Report (SARs), Security Assessment Plan (SAPs), and other RMF documentation.
  • Assess and mitigate system security threats/risks throughout the program life cycle.
  • Contribute to the security planning, assessment, risk analysis, risk management, certification and awareness activities for system and networking operations.
  • Create and review A&A Body of Evidence documentation, providing feedback on completeness and compliance of its content.
  • Develop and execute Security Test Plan (STP) in close cooperation with team members.
  • Manage and ensure Continuous Monitoring (CONMON) to maintain system authorization.

Benefits

  • Health, dental, and vision insurance
  • Paid time off and holidays
  • Retirement benefits (including 401(k) matching)
  • Educational reimbursement
  • Parental leave
  • Employee stock purchase plan
  • Tax-saving options
  • Disability and life insurance
  • Pet insurance
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service