Cyber Security Analyst
Overview: DecisionPoint is currently looking for an experienced Cyber Security Analyst to join our team at the Office of the Inspector General at the Department of State in Arlington, VA. Duties & Responsibilities: Support system A activities, to include pre-assessment control reviews, artifact gathering, system security and associated plan updates, and other documentation review and updates for the migrated website and other OIG systems and applicationsSupport creation and maintenance of OIG Federal Risk and Authorization Management Program (FedRAMP) cloud solutions documentationPerform security control reviews of OIG facilities, systems, and applications to support the OIG continuous monitoring strategy plan and annual reviews. Identify and track findings in Plan of Actions and Milestones (POA)Support and initiate the incident response process in accordance with guidelines.Assist System Owner and support staff by providing timely advice, guidance, and templates to complete required tasks and documentationSupport annual incident response and contingency plan training and testing activities.Complete review of system and application configuration settings using automated and manual method.Complete vulnerability scanning of all assets. Compile data to assist remediation activities; coordinate with systems administrators to implement corrective actions. Assist in the development of POA for outstanding risks.Coordinate with system administrators and application/database support to research and resolve security concerns and revise documentationAssist in the preparation of official memorandums, such as Chief Information Officer risk acceptance, POA, and various appointment letters.Research user questions and requests; make recommendations based on Department and OIG policy; complete file transfer requests in accordance with federal and Department of State guidance.Assist in compiling data to support data calls and quarterly Federal Information Security Modernization Act (FISMA) reporting.Support the configuration management process through the completion of preliminary security impact analysesTrack user cybersecurity awareness training and rules of behavior agreements.Monitor the Department continuous monitoring system; coordinate with system administrators to initiative corrective actionsProvide detailed weekly status reports Qualifications: Required:Active Secret ClearanceInformation Assurance (IA) subject matter expert with 5-7 years of Federal government knowledge and experience in applying and implementing the NIST Risk Management Framework and Special Publications 800-53, 800-37; FedRAMP, NIST Cybersecurity Framework, and other FISMA requirementsExperience in configuring and running vulnerability and configuration compliance (SCAP) scans, troubleshooting issues, and analyzing data to identify trends and recommend remediation actions.Complete understanding of Department of Homeland Security Continuous Diagnostics and Mitigation (DHS CDM) program requirements and implementation requirements at a general levelExperience in host-based and network-based security tools, analyzing alerts, and initiating the incident response process, working with operations team and management to analyze and categorize level of threat, take appropriate and timely actions to mitigate threat and associated vulnerabilitiesUnderstanding of operating in multi-network environments that are multi-tiered and risks associated with this type of network architectureExperience working with security information management (SIM) and/or security information and event management (SIEM), user behavior analytics (UBA), and anti-malware toolsExperience with cloud hosted infrastructure and applications environments such as Microsoft Office 365 and Microsoft AzureUnderstanding of threats specifically related to mobile users and mobile devicesExperience in researching different types of technical security threats and recommending mitigating actionsProficient in writing and maintaining system security plans, information security policies, and official memorandums intended for executive leadershipFamiliar with use of Information Technology Infrastructure Library (ITIL), Capability Maturity Model Integration (CMMI), and/or Project Management Professional (PMP) processesDesired:Certified Information Systems Security Professional/Certified Information Security Manager (CISSP/CISM)PMPOur Equal Employment Opportunity Policy:The company is an equal opportunity employer. The company shall not discriminate against any employee or applicant because of race, color, religion, creed, sex, sexual orientation, gender or gender identity (except where gender is a bona fide occupational qualification), national origin, age, disability, military/veteran status, marital status, genetic information or any other factor protected by law. We are committed to equal employment opportunity in all decisions related to employment, promotion, wages, benefits and all other privileges, terms and conditions of employment.