Information Security Analyst, SME, Lead

Connected Logistics•Springfield, VA
•$120,000 - $130,000•Hybrid

About The Position

Connected Logistics is seeking an Information Security Analyst, SME, RMF Step 6 Lead, to assist in providing the Department of State Directorate of Technology (DT), Enterprise Architecture (EA), Cyber Security Team (CST) comprehensive cybersecurity support services to protect critical consular systems and data. The CST Cyber portfolio ensures compliance with federal mandates including the Federal Information Security Modernization Act (FISMA) and the Risk Management Framework (RMF), encompassing security monitoring, incident response, threat detection, vulnerability management, and continuous authorization activities. The Information Security Analyst, SME (Step 6 /Continuous Monitoring Lead) will direct personnel supporting the operational security and authorization posture of consular systems. The Lead uses system risk, vulnerability exposure, changes, authorization conditions, and reporting obligations to prioritize work and maintain current, traceable RMF records.

Requirements

  • U.S. citizenship and a final Secret clearance or higher
  • Relevant degree in cybersecurity, computer science, information systems, or a related discipline, subject to the SME LCAT and permitted substitutions.
  • Advanced Federal continuous-monitoring and vulnerability-management experience with demonstrated team leadership and ongoing authorization support.
  • Proficiency in POA&M management, security impact analysis, risk prioritization, FISMA reporting, and NIST RMF requirements.
  • Practical understanding of Tenable platform administration, credentialed scanning, cloud posture analysis, integrations, and operational escalation.
  • Availability to support coverage planning and after-hours escalation as assigned; meet applicable certification requirements.
  • Meet applicable LCAT certification requirements and maintain required credentials.

Nice To Haves

  • CISSP, CGRC, CISM, or role-relevant Tenable and cloud credentials.
  • DOS experience with ArchAngel, Wiz, iPost/iMatrix, SIA/NOC processes, and KEV/BOD remediation.
  • Leadership of shift-based vulnerability operations and automated monitoring workflows.

Responsibilities

  • Responsible for directing continuous monitoring, ongoing authorization support, vulnerability and cloud-posture analysis, POA&M tracking, change-impact reviews, and CO1 Tenable operational coverage.
  • Assign ConMon work and review exception queues, authorization milestones, overdue findings, and emerging risk.
  • Oversee scheduled Tenable coverage, relief staffing, shift handoffs, escalation, platform health, and recovery coordination.
  • Correlate Tenable and Wiz findings with CA systems and authorization boundaries using approved system identifiers.
  • Prioritize KEVs, BOD actions, critical and high findings, remediation milestones, and evidence-backed closure.
  • Direct SIA/NOC reviews and related updates to SSPs, diagrams, inventories, privacy artifacts, and POA&Ms.
  • Coordinate annual assessment support, contingency tests, audit responses, FISMA submissions, and incident-related artifact updates.
  • Escalate authorization-impacting conditions and coordinate return to earlier RMF activities when required.
  • Coordinate CO1 tool responsibilities with CO5 through approved responsibility assignments and interfaces.

Benefits

  • health, dental, vision, life, and disability insurance
  • a great 401(k) package
  • generous Paid Time Off
  • ongoing professional development
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service