GDIT is seeking an Information Systems Security Senior Analyst (ISSSA) to join our team supporting the U.S. Environmental Protection Agency (EPA). As the ISSSA, you will maintain various EPA System security and privacy control implementation deliverables based on a NIST 800-53 rev5 control framework to ensure the operational security of a critical mission-support system. You will update, maintain, and drive security and privacy documentation designed to protect the cloud- and host-based systems from both internal and external threats. Performance shall include: Review identified cyber security vulnerabilities and assist with the recommendation, documentation, and implementation of appropriate mitigations or countermeasures Conduct and support, when assessed or audited, periodic reviews of the information system to ensure compliance with the security and privacy authorization package (currently NIST 800-53 Rev. 5) Review, create, and enhance security and privacy documentation to the system infrastructure or software to ensure continued compliance with security and privacy requirements Coordinate the response to the annual continuous monitoring assessment audit, and ensure the system’s continued Authorization to Operate (ATO) Ensure audit evidence are collected, reviewed, and documented, including any risk determinations (RDs) and plans of actions and milestones (POA&Ms) Identify and notify the program manager when changes occur that might affect the authorization determination for the information system Provide analysis of systems, hardware, software, and maintenance needs Create and review annually the security- and privacy-related documentation Develop, coordinate and conduct training and tabletop exercises related to continuity of operations, contingency planning, incident handling, awareness, etc. Update control implementation tools like XACTA to maintain compliance against NIST 800-53 rev 5. Coordinate with other EPA organizational entities to ensure compliance with EPA and other federal requirements, specifications, and reporting Prepare reports on the status of system security and privacy, vulnerabilities, responses to
Stand Out From the Crowd
Upload your resume and get instant feedback on how well it matches this job.
Job Type
Full-time
Career Level
Mid Level