Sr. Information Assurance / Cyber Analyst at Concept Plus, LLC
United States
<meta><p style="font-family:"Basel Grotesk",Arial,sans-serif;font-size:11pt;font-weight:400;line-height:1.6;letter-spacing:0.25px;margin:4px 0px;padding:0px;"><b><strong style="font-size:18pt;white-space:pre-wrap;">About the role</strong></b></p><p style="font-family:"Basel Grotesk",Arial,sans-serif;font-size:11pt;font-weight:400;line-height:1.6;letter-spacing:0.25px;margin:4px 0px;padding:0px;"><span style="white-space:pre-wrap;">Concept Plus is seeking a highly experienced Senior Information Assurance / Cyber Analyst to join our team supporting a federal program. The program's systems are deployed across classified and unclassified environments, hosted in both data centers and the cloud. </span></p><p style="font-family:"Basel Grotesk",Arial,sans-serif;font-size:11pt;font-weight:400;line-height:1.6;letter-spacing:0.25px;margin:4px 0px;padding:0px;"><br></p><p style="font-family:"Basel Grotesk",Arial,sans-serif;font-size:11pt;font-weight:400;line-height:1.6;letter-spacing:0.25px;margin:4px 0px;padding:0px;"><span style="white-space:pre-wrap;">The successful candidate will be responsible for supporting the government Information System Security Manager (ISSM) in maintaining the system's cybersecurity posture in accordance with federal policies. </span></p><p style="font-family:"Basel Grotesk",Arial,sans-serif;font-size:11pt;font-weight:400;line-height:1.6;letter-spacing:0.25px;margin:4px 0px;padding:0px;"><br></p><p style="font-family:"Basel Grotesk",Arial,sans-serif;font-size:11pt;font-weight:400;line-height:1.6;letter-spacing:0.25px;margin:4px 0px;padding:0px;"><span style="white-space:pre-wrap;">You will be responsible for preparing and maintaining the Risk Management Framework (RMF) package, conducting continuous monitoring, and working closely with technical teams to ensure security is integrated throughout the entire system’s lifecycle. This role is pivotal in supporting the system's Authority to Operate (ATO) and ensuring robust security from development through production. </span></p><p style="font-family:"Basel Grotesk",Arial,sans-serif;font-size:11pt;font-weight:400;line-height:1.6;letter-spacing:0.25px;margin:4px 0px;padding:0px;"><br></p><p style="font-family:"Basel Grotesk",Arial,sans-serif;font-size:11pt;font-weight:400;line-height:1.6;letter-spacing:0.25px;margin:4px 0px;padding:0px;"><b><strong style="font-size:18pt;white-space:pre-wrap;">What you'll do</strong></b></p><ul data-pattern="discCircleSquare" data-depth="1" style="font-family:"Basel Grotesk",Arial,sans-serif;font-size:11pt;font-weight:400;margin:8px 0px;line-height:1.6;padding:0px 0px 0px 32px;list-style-type:disc;"><li style="margin:3px 0px;font-size:11pt;line-height:1.6;letter-spacing:0.25px;"><span style="font-size:11pt;white-space:pre-wrap;">Support the ISSM by preparing and maintaining the system's RMF package throughout its lifecycle using the eMASS tool. </span></li><li style="margin:3px 0px;font-size:11pt;line-height:1.6;letter-spacing:0.25px;"><span style="font-size:11pt;white-space:pre-wrap;">Develop, maintain, and update all required RMF documentation.</span></li><li style="margin:3px 0px;font-size:11pt;line-height:1.6;letter-spacing:0.25px;"><span style="font-size:11pt;white-space:pre-wrap;">Conduct continuous monitoring, analyze vulnerability scan results, and track the remediation of vulnerabilities by applying IAVM-directed patches. </span></li><li style="margin:3px 0px;font-size:11pt;line-height:1.6;letter-spacing:0.25px;"><span style="font-size:11pt;white-space:pre-wrap;">Coordinate security engineering input into system designs and the implementation of security controls. </span></li><li style="margin:3px 0px;font-size:11pt;line-height:1.6;letter-spacing:0.25px;"><span style="font-size:11pt;white-space:pre-wrap;">Analyze results from SAST/DAST security scans (e.g., SonarQube, Checkmarx) and collaborate with the development team on remediation. </span></li><li style="margin:3px 0px;font-size:11pt;line-height:1.6;letter-spacing:0.25px;"><span style="font-size:11pt;white-space:pre-wrap;">Track and respond to cybersecurity incidents, ensuring timely reporting and effective recovery efforts. </span></li><li style="margin:3px 0px;font-size:11pt;line-height:1.6;letter-spacing:0.25px;"><span style="font-size:11pt;white-space:pre-wrap;">Ensure compliance with security requirements such as two-factor authentication, data-at-rest encryption, and FIPS standards. </span></li><li style="margin:3px 0px;font-size:11pt;line-height:1.6;letter-spacing:0.25px;"><span style="font-size:11pt;white-space:pre-wrap;">Document and report on cybersecurity performance, contributing to artifacts like the Software Cybersecurity Release Report. </span></li><li style="margin:3px 0px;font-size:11pt;line-height:1.6;letter-spacing:0.25px;"><span style="font-size:11pt;white-space:pre-wrap;">Act as a primary cybersecurity subject matter expert, providing guidance and support to the ISSM and program leadership. </span></li><li style="margin:3px 0px;font-size:11pt;line-height:1.6;letter-spacing:0.25px;"><span style="font-size:11pt;white-space:pre-wrap;">Participating in Agile/DevSecOps development cycles, ensuring security is integrated from concept to deployment. </span></li><li style="margin:3px 0px;font-size:11pt;line-height:1.6;letter-spacing:0.25px;"><span style="font-size:11pt;white-space:pre-wrap;">Review and validate system architecture, configuration changes, and release plans for security impacts. </span></li><li style="margin:3px 0px;font-size:11pt;line-height:1.6;letter-spacing:0.25px;"><span style="font-size:11pt;white-space:pre-wrap;">Prepare for and participate in security assessments, audits, and inspections. </span></li><li style="margin:3px 0px;font-size:11pt;line-height:1.6;letter-spacing:0.25px;"><span style="font-size:11pt;white-space:pre-wrap;">Liaise with external security stakeholders and accrediting authorities as directed. </span></li></ul><p style="font-family:"Basel Grotesk",Arial,sans-serif;font-size:11pt;font-weight:400;line-height:1.6;letter-spacing:0.25px;margin:4px 0px;padding:0px;"><br></p><p style="font-family:"Basel Grotesk",Arial,sans-serif;font-size:11pt;font-weight:400;line-height:1.6;letter-spacing:0.25px;margin:4px 0px;padding:0px;"><b><strong style="font-size:18pt;white-space:pre-wrap;">Required Qualifications</strong></b></p><ul data-pattern="discCircleSquare" data-depth="1" style="font-family:"Basel Grotesk",Arial,sans-serif;font-size:11pt;font-weight:400;margin:8px 0px;line-height:1.6;padding:0px 0px 0px 32px;list-style-type:disc;"><li style="margin:3px 0px;font-size:11pt;line-height:1.6;letter-spacing:0.25px;"><span style="font-size:11pt;white-space:pre-wrap;">US Citizen</span></li><li style="margin:3px 0px;font-size:11pt;line-height:1.6;letter-spacing:0.25px;"><span style="font-size:11pt;white-space:pre-wrap;">Must be able to obtain a Tier-3 Secret Clearance </span></li><li style="margin:3px 0px;font-size:11pt;line-height:1.6;letter-spacing:0.25px;"><span style="font-size:11pt;white-space:pre-wrap;">Bachelor’s degree in Cybersecurity, Information Technology, or a related field. </span></li><li style="margin:3px 0px;font-size:11pt;line-height:1.6;letter-spacing:0.25px;"><span style="font-size:11pt;white-space:pre-wrap;">5-7 years of experience in Federal cybersecurity compliance. </span></li><li style="margin:3px 0px;font-size:11pt;line-height:1.6;letter-spacing:0.25px;"><span style="font-size:11pt;white-space:pre-wrap;">Expert knowledge of federal cybersecurity mandates, including RMF.</span></li><li style="margin:3px 0px;font-size:11pt;line-height:1.6;letter-spacing:0.25px;"><span style="font-size:11pt;white-space:pre-wrap;">Hands-on proficiency with cybersecurity tools such as eMASS, Nessus, SonarQube, and/or Checkmarx. </span></li><li style="margin:3px 0px;font-size:11pt;line-height:1.6;letter-spacing:0.25px;"><span style="font-size:11pt;white-space:pre-wrap;">Strong understanding of NIST 800-53 security controls. </span></li></ul><p style="font-family:"Basel Grotesk",Arial,sans-serif;font-size:11pt;font-weight:400;line-height:1.6;letter-spacing:0.25px;margin:4px 0px;padding:0px;"><br></p><p style="font-family:"Basel Grotesk",Arial,sans-serif;font-size:11pt;font-weight:400;line-height:1.6;letter-spacing:0.25px;margin:4px 0px;padding:0px;"><i><em style="font-size:11pt;white-space:pre-wrap;">Concept Plus is an Equal Opportunity Employer. As such, we will give your application full consideration without regard to your race, color, religion, sex, age, national origin, disability, veteran status, sexual orientation, gender identity, or any other classification protected by federal, state, or local law.</em></i></p><p style="font-family:"Basel Grotesk",Arial,sans-serif;font-size:11pt;font-weight:400;line-height:1.6;letter-spacing:0.25px;margin:4px 0px;padding:0px;"><br></p>
Apply Now