Job Details

ID #23609554
State Virginia
City Rosslyn
Job type Permanent
Salary USD $125,000 - $150,000 125000 - 150000
Source AMS Staffing Inc.
Showed 2021-11-29
Date 2021-11-28
Deadline 2022-01-27
Category Security
Create resume

IT Security Analyst

Virginia, Rosslyn, 22209 Rosslyn USA

Vacancy expired!

Title: IT Security Analyst

Location: Rosslyn, VA (22209)

Term: Contract to Hire; 3-6 months conversion to FTE

Salary: $125K - $150K Please send resume in Word format if you are interested in this contract to hire IT Security Analyst role with our government client in Rosslyn, VA 22209. This position will pay an hourly rate of $75/HR to $90/HR (dependent on experience) for the initial contract period and convert at an annual salary of $125K to $150K after 3 to 6 months.Due to the required clearance with our government client, only US Citizens, Green Card and Green Card EAD holders may be considered. Clearance requires that the candidates have resided in the US for the past five years. The selected candidate cannot have left the country for longer than 90 consecutive days and no more than 180 cumulative days.

Job DescriptionOur client is currently seeking a IT Security Analyst - Security Operations to work out of their Rosslyn, VA office in support of a federal government agency. The IT Security Office is responsible for information security policies, procedures, and services to protect the confidentiality, integrity, and availability of the information within the information technology infrastructure. The information resources are sensitive assets and are critical in the performance of its mission; therefore, information security services help safeguard the information resources entrusted to the client.

Essential Job Responsibilities
  • Implements and interprets the requirements for agency compliance with policy directives governing IT infrastructure protection.
  • Manages and Administers Security Systems
  • Administers cloud-based security tools such as, Azure Security Center (Sentinel, Log Analytics, Azure WAF, Defender for Identity, Privileged Identity Manager); Microsoft 365 Security Suite (Defender, Advanced Threat Protection, Cloud Application Security, Protection Portal); Microsoft Security and Compliance Center; Microsoft Endpoint Manager (Intune); multi-factor authentication (MFA); web content filtering; and secure document sharing and collaboration solutions.
  • Responsible for primary or alternate management of all IT Security systems including patch management, upgrades, integration engineering, reporting.
  • Executes security policy and compliance management program
  • Identifies current and potential IT security risks and recommends mitigation strategies.
  • Monitors agency compliance with infrastructure protection requirements across IT programs.
  • Participates in the development of security policies.
  • Participates in the system authorization and continuous monitoring processes for systems and major applications.
  • Executes security related operational activities
  • Manages security incident detection, response, remediation.
  • Conducts cyber threat and vulnerability analysis and remediation.
  • Develops security metrics and manages reporting and compliance.
  • Serves as Incident Response Team member.
  • Supports operational implementation of FISMA/NIST standards.
  • Operates cloud-based security tools such as, Azure Security Center (Sentinel, Log Analytics, Azure WAF, Defender for Identity, Privileged Identity Manager); Microsoft 365 Security Suite (Defender, Advanced Threat Protection, Cloud Application Security, Protection Portal); Microsoft Security and Compliance Center; Microsoft Endpoint Manager (Intune); multi-factor authentication (MFA); web content filtering; and secure document sharing and collaboration solutions.
  • Manages IT Security awareness training program in coordination with the Learning Management team, to including developing and delivering IT Security awareness training modules.
  • Manages Password Management system in coordination with Service Desk.
  • Responds to IT Security trouble tickets generated by customers and IT staff. Identifies solutions, works with customer and OCIO team to execute solutions, and manages ticket input, update and resolution in the OCIO ticketing system to maintain service level agreements.
  • Supports Security Engineering and tech solution support and expertise
  • Participates in the system authorization process of systems and applications.
  • Identifies security risks and recommends risk mitigation strategies.
  • Reviews new and existing systems to ensure baseline security requirements are met and to recommend security enhancements.
  • Develops security architecture and technical solutions for security products.
  • Collaborates with staff from OCIO and other business components to develop security controls and solutions for complex business systems and applications.
  • Develops and executes project plans to engineer, construct, deploy, and monitor/manage IT Security infrastructure solutions.
  • Demonstrates in-depth understanding of security requirements associated with cloud-hosted environments, services, and solutions.
  • Evaluates, recommends, and implements security controls associated with cloud-hosted environments, services, and solutions.
  • Evaluates, recommends, and implements security controls for mobile device solutions.

Minimum Qualifications
  • Must have a Bachelors Degree in Information Assurance, Information Systems, Computer Science, or related field.
  • SANS GIAC or ISC(2) certification(s) (or equivalent)
  • Candidate will possess at least 7 years of specialized IT experience with at least 5 years in IT Security.
  • Demonstrated knowledge of and ability to configure, manage, and administer cloud-based security tools such as, Azure Security Center (Sentinel, Log Analytics, Azure WAF, Defender for Identity, Privileged Identity Manager); Microsoft 365 Security Suite (Defender, Advanced Threat Protection, Cloud Application Security, Protection Portal); Microsoft Security and Compliance Center; Microsoft Endpoint Manager (Intune); multi-factor authentication (MFA); web content filtering; and secure document sharing and collaboration solutions.
  • Skill and Ability in executing Security Operations including incident detection, identification, management, response, and reporting. Must have experience in incident response and management.
  • Skill in making recommendations that significantly influence OIG’s information security policies or programs. Experience building policies and preparing briefings to explain security programs and requirements to senior executives.
  • Skill & Ability to provide expert technical advice, guidance, and recommendations to management and other technical specialists on critical information technology security issues.
  • Skill & Ability to assess risk factors and advise on vulnerability to attack from a variety of sources and procedures for protection of systems and applications.
  • Knowledge & Skill in implementing FISMA, NIST, OMB guidelines, and other Federal regulations and guidance. Experience interpreting and implementing FISMA/NIST requirements focused on the operational implementation and documentation of those requirements.
  • Knowledge of security controls for cloud-hosted environments, applications, and services.
  • Experience developing System Security Plans, Security Assessment Reports, Continuous Monitoring Plans, and Plans of Action & Milestones.
  • Ability to ensure coordination and collaboration on security activities.
  • Ability to effectively communicate both orally and in writing with management and other technical specialists.
  • Ability to plan, organize and manage tasks on time with minimal supervision
  • A new Federal Executive Order requires that employees of Federal contractors be fully vaccinated for COVID-19 by December 8, 2021. Accordingly, as a condition of employment, employees will be required to provide proof of full vaccination against COVID-19 or have an approved exemption prior to starting employment.
  • Certification Requirements
  • Microsoft certification(s): Azure Security Engineer Associate, Security Operation Analyst Associate, Identity and Access Administrator Associate, Information Protection Administrator Associate (desired)
  • Clearance: Top Secret Security Clearance (or ability to obtain TS clearance)

Vacancy expired!

Subscribe Report job