Security Compliance Analyst II

H4 EnterprisesWashington, DC
$83 - $85Hybrid

About The Position

The Security Compliance Analyst II will assist the assigned Government Division Chief and assigned team leader with various Information Technology (IT) security support duties that will guide the Department of State's classified systems through various computer security requirements and meet Department and Office of the Director of National Intelligence (ODNI) security mandates. This position is responsible for participating in security assessments and compliance reviews of Sensitive Compartmented Information (SCI) systems. The contractor will help improve the security posture of the organization by implementing best practices and controls to prevent or mitigate security risks and exposures.

Requirements

  • U.S. Citizenship required
  • Bachelor's degree in an IT field
  • Must possess the following current certifications: Certified Information Systems Security Professional (CISSP), Certified in Risk and Information Systems Control (CRISC), Certified Information Security Manager (CISM), Cybersecurity and Infrastructure Security Agency (CISA), Certified Ethical Hacker (CEH) Or DoD 8570 Information Assurance Management (IAM) II equivalent certifications
  • Over ten (10) years of hands-on IT experience
  • Technical background and ability to review complex configurations for validation
  • Experience with the Risk Management Framework (RMF) process from both a package preparation and assessor perspective
  • Experience in the use of the XACTA, ACAS, and HBSS security tools
  • Experience with federal policies and procedures to acquire and maintain an Information System's Authority to Operate (ATO) under FISMA Act following NIST 800-53 guidelines and NIST- 800-53a security controls assessment practices
  • Excellent written and oral communication skills and the ability to work independently or as a member of a team
  • Experience with the RFM, POA&Ms, Security Authorization and Assessments
  • Experience conducting and documenting vulnerability assessments
  • Knowledge of and experience with NIST SP 800-53, 800-53A, and 800-37
  • Understanding of FISMA compliance
  • Experience with maintenance, installation, and use of WebInspect, Nessus scans, or similar tools
  • Must possess or obtain/maintain minimum a TOP SECRET clearance with ability to obtain special access requirements (SCI).

Nice To Haves

  • Preferred: Department of State experience

Responsibilities

  • Creates and develops Standard Operating Procedures, Policy, in support of the Information Assurance Branch (IAB)
  • Participates in all steps of the Security Authorization and Assessment process for Information Systems
  • Works closely with the Information Assurance Branch Chief and Chief Information Security Officer (CISO) to provide guidance and oversight for all requested initiatives
  • Assists with the delivery of all required system documentation using the current National Institute of Standards and Technology (NIST), Diplomatic Security (DS), & Intelligence Community (IC) approved templates, forms, regulations, policies, methods, and standards
  • Provides advisement to stakeholders to assign resources and establish timelines to ensure the successful security authorization of a system
  • Ensures software installed in the production environment is evaluated and provides guidance regarding the potential for the software to introduce risk into the environment
  • Continuously maintains a thorough understanding of all configurations, architecture, installed software, accounts (both Operating System and Application), data flows, ports, protocols, and other relevant data for each IT System
  • Coordinates with the appropriate operational group to accurately update the System Design Document for each IT system to reflect the approved state of each IT system
  • Analyzes Information Assurance Vulnerability Alert (IAVA) bulletins, security, and vulnerability assessment results, provides leadership with details on any required actions and related timelines, and creates mitigation plans
  • Analyzes system weaknesses identified during system security assessments and the related mitigation plans
  • Provides, tracks, and reports security requirements throughout the project life cycle of all projects that are within the accreditation boundary of assigned systems
  • Performs in depth reviews of logs and other artifacts for each IT system
  • Reviews and validates all relevant NIST 800-53 Security Controls and/or applicable departmental policies for each IT system assigned
  • Performs oversight of compliance with Vulnerability Alerts
  • Ensures that all Information Assurance Vulnerability Management (IAVM) review items are tracked and reported
  • Reviews and validates Plan of Actions & Milestones (POA&Ms) for each noncompliant control for each managed IT System prior to authorizing closure and ensures that proper documentation to support the POA&M lifecycle is filed and updated as required, including well documented waivers and exceptions detailing the potential risk to the Authorizing Official
  • Develops, documents, and executes internal audit programs, including the Federal Information Security Management Act (FISMA), to ensure that audits, inspections, and assessments appropriately address risks and management concerns
  • Provides oversight and guidance regarding requests to modify technical policies such as firewall rules, ports, protocols, etc. for each IT system
  • Coordinates with and briefs Federal staff on all activities pertaining to each IT system as requested
  • Leads and facilitates walkthroughs with external auditors, explaining the various processes, improvements, and responses, and provides detailed and timely responses to audits and data calls

Benefits

  • Reasonable Accommodations are available, including, but not limited to, for disabled veterans, individuals with disabilities, and individuals with sincerely held religious beliefs, in all phases of the application and employment process.
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service