The Information Assurance Systems Analyst provides technical execution of information assurance functions to include operational monitoring, incident response, applying established procedures within a defined scope to governance, compliance, cybersecurity and risk management to protect information assets, and to facilitate compliance with federal, state and local cybersecurity requirements (e.g., NIST 800-171, CMMC – Cybersecurity Maturity Model Certification). This position analyzes sensitive data, identifies vulnerabilities, and collaborates with various teams to implement and maintain information security measures as a member of the Information Security Team. Analyze and maintain System Security Plans (SSPs) with supporting documentation aligned with NIST 800-171 and CMMC practices; assist with regular information security control assessments, perform gap analyses, and update Plans of Action and Milestones (POA&Ms); coordinate security authorization and compliance activities across IT systems and applications. This position reports directly to the Manager, IS Information Assurance. Additional duties outlined below: Perform ongoing information security technical reviews of applications, infrastructure, and business processes to verify compliance and identify improvements; recommend remediation actions, track remediation efforts, and collaborate closely with IT, DevOps, and business teams; execute comprehensive cybersecurity audits to ensure compliance with CMMC, DFARS 7012, NIST 800-171, and other relevant regulations; analyze and assess various data types, including Controlled Unclassified Information (CUI), Controlled Technical Information (CTI), Federal Contract Information (FCI), International Traffic in Arms Regulations (ITAR), and Export Administration Regulation (EAR99); collaborate with system and network administrators to implement audit features that are configured and enabled correctly. Perform third-party/vendor information security reviews as part of the procurement and onboarding process; review supplier security documentation and manage risks associated with external data sharing and service providers. Participate in incident response activities, including documentation, coordination, and lessons learned reviews; help improve incident detection, containment, and prevention through policy, training, and technical improvements. Utilize GRC (Governance, Risk, and Compliance) tools to document and track risk assessments, policy compliance, and mitigation efforts; identify and evaluate risks to information assets; assist in the development of risk treatment and remediation plans; review and analyze policy exceptions to assess impact and risk, track approvals, and monitor mitigation within target remediation timeline. Collaborate with internal stakeholders to ensure alignment of technical and administrative controls with risk management practices; support the development and rollout of security awareness training to ensure users understand responsibilities and best practices; monitor training completion and maintain accurate compliance records; other duties as assigned.
Stand Out From the Crowd
Upload your resume and get instant feedback on how well it matches this job.
Job Type
Full-time
Career Level
Mid Level
Education Level
High school or GED