Haystack
← Back to Jobs
Technology
SD

IT Security Analyst

Sharp DecisionsVA🇺🇸United StatesPosted 20 Aug 2026

Quick Overview

Work Type
On Site
Level
Mid Senior

Job Description

Herndon, VA - Hybrid (Tue / Wed / Thu Onsite)
No Dual Citizenship

FedRAMP / RMF DoD / NIST

The Security Analyst will work as a member of our client's cyber team, assisting with the creation, update, and maintenance of FedRAMP-required security documentation, associated artifacts, and Continuous Compliance Monitoring (CCM) requirements such as the Plan of Action and Milestones (POA&M). The role also supports the Cloud Operations team with identification and corrective actions associated with known vulnerabilities, and provides advisement to stakeholders on changing regulatory, government, and Cloud/FedRAMP policies - including risk assessment, business impact analysis, system categorization, security authorization and accreditation/certification activities (A&A), security control inheritance, and other artifacts needed to validate control compliance.

? Critical Requirements

Required Skills

Compliance & Governance
  • Understand and document information system specifications and security controls, including logical and physical diagrams, connectivity, communication, and data flow diagrams - both internal and external to the system
  • Advise stakeholders on multiple courses of action in environments with changing or unconfirmed policy (e.g., NIST RMF, DISA SRG)
  • Document courses of action and identify risk mitigation recommendations in accordance with FedRAMP requirements, client policy, and best practices - including associated benefits and drawbacks
  • Apply enterprise security frameworks (FISMA, NIST SP 800, etc.) to existing cloud environment initiatives
  • Develop and update policies and procedures to implement FedRAMP compliance, NIST 800-171 security requirements, and other DFAR clauses
  • Demonstrate familiarity with current FedRAMP, DoD, and NIST security controls and technologies, including vulnerability management capabilities
  • Identify and assess cloud system state including vulnerabilities, RMF package status, accreditation model, PPS compliance, and patching/CSVA mechanisms


Vulnerability Management
  • Knowledge of Risk-Based Vulnerability Framework and how to prioritize, assess, and remediate exploitable vulnerabilities
  • Ability to create automation scripts to minimize manual workload behind identifying and analyzing vulnerabilities across various scanning tools
  • Ability to analyze container vulnerabilities in secure cloud environments and identify remediation paths at the OS and application level
  • Understand enterprise operating environments including security posture, application environment, and associated security controls


Required Technical Experience

Technical Skills

Python, Bash, Java & PowerShell Scripting

Container Scanning Tools

CI/CD Pipelines & AWS ECR

Container Image Mirroring

Attack Vector Analysis

Network Diagrams & Visio

SAP Products

Testing / Dev / Staging Environments

RMF & Compliance Experience
  • Demonstrated knowledge and ability to analyze systems for cybersecurity compliance
  • Knowledge of Federal and DoD policies and risk assessment methodologies including FedRAMP, NIST SPs, and RMF overlays
  • Hands-on experience with DISA STIG requirements and SRGs, CNSSI, and NIST Risk Management Framework
  • Experience writing or executing system security documentation, Authorization to Operate (ATO) packages, POA&Ms, and policies
  • Knowledge and understanding of systems and networking technologies and concepts
  • Ability to interpret and assess network diagrams using Visio
  • Familiarity with Testing, Development, Staging, and pre-production environments requiring cybersecurity support
  • Knowledge of the Privacy Act
  • Presentation and public speaking skills required
  • Ability to work in a fast-paced, team-oriented environment


#LI-EW1

Skills

Python
Java
PowerShell
Bash
AWS

Similar jobs