Job was saved successfully.
Job was removed from Saved Jobs.

Job Details

Senior IT Compliance Analyst


Senior Database Analyst


Washington, Washington DC, United States


Job Description:

The mission of the DHS Chief Information Security Officer Directorate (DHS CISOD) is to support the Department’s implementation of all applicable regulatory requirements including the Federal Information Security Modernization Act of 2014 (FISMA), relevant Office of Management and Budget (OMB) Circulars, Executive Orders, Federal laws, directives, policies, and regulations. The DHS CISOD’s mission is to also provide the Department of Homeland Security (DHS) a secure and trusted computing environment. The DHS CISOD assists in ensuring Department compliance with information security requirements. Information security is an essential business function, critical to enabling DHS to conduct its operations and deliver service to the public.

The DHS Cyber Security Support Service Program has a critical need for a Senior Level Information Security Compliance and Assessment Analyst for its Compliance and Process IV&V Support Team. The DHS Cyber Security Support Service Program is responsible for conducting Critical IT Controls (CIC) Assessments, POA&M Monitoring, IV&V over Component V&V of remediated controls, Quality Assurance Reviews of POA&Ms, and other Assessments. This is a full time, fully funded position based in Washington, DC.

Primary Responsibilities:

Primary responsibilities of the Senior Information Security Compliance and Assessment Analyst include assisting with program planning and execution of the Critical IT Controls (CIC) Assessment Program using the NIST Framework. The incumbent will perform CIC assessments on DHS systems, perform Quality Assurance reviews over assessments, and assist with other types of assessments and compliance activities. Additional duties include drafting program policy and procedure documents, creating SOPs, creating, and updating testing procedures (based on NIST 800-53A) for assessing information systems. The Information Security Compliance and Assessment Analyst will perform technical security assessments, analyze vulnerability scans, and interpretate technical security assessment artifacts.

Other duties include creating Component training materials and updating guidance documentation to reflect changes in policies. The incumbent will be responsible for analyzing system security documents for compliance with DHS 4300A and other mandates; perform POA&M Monitoring and Compliance activities for DHS HQ and Component Systems. Additional responsibilities include reviewing and validating remediation (IV&V packages), POA&M remediation activities, and performing compliance reviews of IT systems. Knowledge of NIST 800 series, RMF and CSAM are needed to be successful in this role.

This is a significant growth area for us and our customer over the next several years and so this role is extremely strategic. This position is located at L’Enfant Plaza in Washington, DC.

Minimum Requirements include:

  • Bachelor’s degree from an accredited college in an IT or related discipline and 8 years of relevant experience

  • Additional years of experience and relevant certifications will be considered in lieu of degree.

  • Ability to pass a DHS background investigation.

  • Must have experience in conducting technical system security assessments/audits and analyzing technical artifacts.

  • Ability to analyze and interpret vulnerability and scan reports.

  • Candidate must have experience with Federal Information Security Management Act (FISMA) requirements and National Institute of Standards and Technology (NIST) Risk Management Framework.

  • Experience conducting compliance reviews and monitoring activities for POA&Ms, remediation, and related activities.

  • Familiarity with configuration management and IA processes.

  • Excellent written and effective verbal communication skills.

  • POA&M management; IT compliance experience.

Preferred Qualifications:

  • Previous IT Audit experience is ideal.

  • CSAM experience is desired.

  • Prior DHS IT security and/or audit experience preferred.

  • Prior System Administrator experience a plus.

  • Previous IT experience is preferred specifically 7 years of professional experience in a Computer Science discipline is ideal.

Pay Range:Pay Range $81,900.00 - $126,000.00 - $170,100.00

The Leidos pay range for this job level is a general guideline only and not a guarantee of compensation or salary. Additional factors considered in extending an offer include (but are not limited to) responsibilities of the job, education, experience, knowledge, skills, and abilities, as well as internal equity, alignment with market data, applicable bargaining agreement (if any), or other law.