Information Security Analyst

Cherokee Federal•Washington, DC
•Onsite

About The Position

The Information Security Analyst will provide Information Technology General Controls (ITGC) testing to develop and execute software test plans to identify procedural issues related to software configurations resulting in financial risk. This role will assist stakeholders in designing, implementing, and effectively operating IT controls and processes that protect financial data. The analyst will support in performing IT Benchmarking tasks, assist in the development of a strategy for Benchmarks considering available resources, and perform an initial A-123 ITGC assessment scoping each Fiscal Year (FY) based on the organization strategy. Additionally, the role involves establishing plans of action and milestones (POA&M) or Remediation Work Plans for identified deficiencies, conducting Test of Design (TOD) and Test of Effectiveness (TOE) for IT programs used for internal controls over Financial Systems, and providing support to ad-hoc IT Assessments. The analyst will collaborate with cross-functional teams, work under general supervision, and report to a manager or head of a unit/department.

Requirements

  • Minimum education includes a bachelor’s degree in a business field, systems engineering, computers, or other related fields.
  • Minimum experience includes having two (2) years of government IT financial or system testing, including one year of federal internal controls ITGC experience.
  • Knowledge of Federal and Department of Homeland Security (DHS) policies and guidance, OMB A-123 attachment R-4300A, DISA STIGS, DHS hardening guidance, DHS Control Evaluation Matrix (CEM) framework, DHS CEM Testing and POA&M management
  • Strong communication and interpersonal skills, with the ability to collaborate effectively with senior management, technical teams, and stakeholders.
  • Ability to work independently and prioritize tasks in a fast-paced environment.
  • Must be able to obtain a Public Trust and DHS suitability
  • Must pass pre-employment qualifications of Cherokee Federal.

Responsibilities

  • Provide Information Technology General Controls (ITGC) testing to develop and execute software test plans to identify procedural issues related to software configurations resulting in financial risk.
  • Assist stakeholders in designing, implementing, and effectively operating IT controls and processes that protect financial data.
  • Support in performing IT Benchmarking tasks which are used to demonstrate through testing that a sufficiently strong IT internal control environment for CFO Systems (internal and external) is designed and operated effectively that will lead to a downgrade of the IT deficiencies.
  • Assist in the development of a strategy that will enable the Benchmarks in consideration of available resources within the organization. Additional support is required to perform an initial A-123 ITGC assessment scoping each Fiscal Year (FY) based on the organization strategy.
  • Establish plans of action and milestones (POA&M) or Remediation Work Plans for all identified deficiencies within required timeframes per DHS 4300A and OCISO guidance.
  • Conduct Test of Design (TOD) for the IT program used for internal controls, over Financial Systems. Includes but not limited to evaluating the design of a control to determine whether the control should sufficiently address the corresponding control requirement and objective as well as relevant standards and regulations such as NIST 800-53, Rev. 5 and DHS Sensitive Systems Policy Directive 4300A.
  • Conduct Test of Effectiveness (TOE) for the IT program used for internal controls, over Financial Systems. Includes but not limited to evaluating the operating effectiveness of a control to determine whether the control is correctly implemented and operated as designed.
  • Provide support to ad-hoc IT Assessments to include but not limited to critical IT controls (CIC), Financial and related financial system ATOs, Accounting Treatment Manual Assessment and Testing (ATM), etc.
  • Collaborate with cross-functional teams to integrate security requirements into system planning, fieldwork, and reporting.
  • Work general supervision, relying on experience and judgment to plan and accomplish goals, while demonstrating a wide degree of creativity and latitude in problem-solving.
  • Report to a manager or head of a unit/department, providing regular updates on security initiatives, risks, and mitigation strategies.
  • Performs other job-related duties as assigned.

Benefits

  • Medical
  • Dental
  • Vision
  • 401K
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service