The Senior Information Security Analyst will provide security compliance, risk management, vulnerability management, audit, and continuous monitoring support for a Centers for Medicare & Medicaid Services (CMS) program. This role requires extensive knowledge of FISMA, the NIST Risk Management Framework, NIST SP 800-53, and CMS Acceptable Risk Safeguards (ARS). The analyst will independently develop and maintain detailed security control implementation statements, evaluate supporting evidence, conduct Security Impact Analyses, support Authorization to Operate activities, and prepare systems for security assessments and audits. The analyst will also manage vulnerability and compliance findings throughout their lifecycle, including validation, remediation coordination, POA&M management, risk exception development, retesting, and closure. This position will work closely with CMS ISSOs, product owners, engineers, infrastructure teams, security assessors, auditors, and program leadership. The successful candidate must be able to produce accurate, audit-ready security documentation, identify compliance gaps, communicate security risks clearly, and drive assigned activities to completion with minimal supervision.
Stand Out From the Crowd
Upload your resume and get instant feedback on how well it matches this job.
Job Type
Full-time
Career Level
Senior