SAIC is looking for a Risk and Compliance Analyst to join our team supporting an important US government agency in the National Capital Region. This is an exciting opportunity to work with a team responsible for IT Security Risk and Compliance support by providing direct support to the Information System Security and Privacy Officer (ISSPO) in managing and documenting the ongoing security posture of the agency. The Risk and Compliance Analyst will support the IT management with Control assessment and maintenance, Risk assessment and response development. Specifically, this job requires the following:
- Conduct detailed security impact analysis for any change that introduces new (type of) hardware or software, requires modification to a security baseline, requires a new connection to an external entity, significantly changes a publicly facing application or DMZ infrastructure.
- Provide appropriate Security Impact recommendations or information in writing to service/application owners and change coordinators.
- Conduct risk assessments on security issues impacting the general support system and other department owned systems and propose necessary resolution(s).
- Develop and maintain IT security controls related to and offered by the agency to the standards set forth in the NIST Special Publication 800-53 as described in Agency Security Policy. Collect information from subject matter experts to develop and validate control implementation statements.
- Consult with subject matter experts and review approved work instructions in development of IT security controls to ensure they accurately reflect the agency control implementation.
- Document and communicate any control deficiencies identified during control development for POA&M consideration.
- Review outputs from POA&Ms to assess completeness and make recommendations for additional work needed or POA&M closure.
- Support agency IT Governance, Risk and Compliance Activities such as management of standards, approvals, and waivers.
- Support Continuous Security Monitoring of infrastructure and functional areas accordance with agency- defined parameters, for compliance with agency Security Policy (SP) and all System Security Plans (SSPs).
- Provide expertise and assistance in the development of the security policies and procedures and assist ensuring compliance with those policies and procedures.
- Update the agency system security documentation (SSP and other) with approved new, significant changes requiring updates including updating boundary and technical descriptions.
- Support the PM by providing information for status reports, status briefings, schedules, project plans, etc., both in written and oral form.
EDUCATION & EXPERIENCE:
- Bachelors degree with seven (7) years or Master degree with five (5) years IT controls or IT security experience in a technical environment with a variety of IT systems.
- One or more current Security certification (CISSP, CISM, Security+).
- Experience with National Institute of Standards and Technology (NIST) Risk Management and Cybersecurity Framework.
- Experience with FISMA, NIST 800-53, general IT control implementation, assessment, and maintenance process.
- Familiarity with Governance, Risk and Compliance (GRC) frameworks and tools, such as, RSAM, CSAM, or experience with SA&A tools, such as Xacta.
- Ability to tailor information security processes and tools, based on ever evolving and changing landscapes, doctrine, and risk scenarios.
- Good understanding of Office of Management and Budget (OMB) circulars A-123 and A-130, Federal Manager’s Financial Integrity Act (FMFIA), FISCAM processes and procedures.
- Fluency in both spoken and written English, including the ability to work with highly technical and specialized content. Must be able both prepare and deliver such content, verbally and in writing, but also comprehend such content from others, in both spoken and written form.
- Ability to prepare deliverables with sufficient quality such that very few minor, or no, edits are required to be made prior to conveyance to the client.
- Quickly review the work products of others, employ your own knowledge of federal security doctrine, and ensure that timely and accurate feedback and recommended edits are delivered to the author(s). All work products should be ready for delivery to the client after only one review has been performed.
- Ability to work in a fast-paced environment.
- Outstanding customer service skills.
- Ability to document processes as needed.
- Proficiency in explaining complex policies and protocols in simple terms.
- Stay up to date on information technology trends and security standards.
- Excellent analytical thinking and problem-solving skills to be able to assess potential risks and developing possible solutions.
Candidates for consideration must be eligible to obtain and maintain a Public Trust clearance.
DESIRED SKILLS: A solid understanding of IT security controls, tools, and concepts. A good working understanding of and technical experience in IT platforms such as Microsoft, Cisco, Oracle, etc. are also a plus.
SAIC is a premier technology integrator solving our nation's modernization and readiness challenges. Our offerings across defense, space, civilian, and intelligence markets include high-end solutions in engineering, IT, and mission outcomes. We integrate the best components from our portfolio with our partner's ecosystem to deliver innovative and effective solutions. We are 25,500 strong; driven by mission, united by purpose, and inspired by opportunities. Headquartered in Reston, VA, SAIC has annual revenues of nearly $7.1 billion. For information, visit saic.com or Working at SAIC for benefits details. SAIC is an Equal Opportunity Employer empowering people no matter their race, color, religion, sex, gender identity, sexual orientation, national origin, disability, or veteran status. We strive to create a diverse, inclusive and respectful work culture that values all.