["Cybersecurity Risk Management Analyst","Cybersecurity Risk Management Analyst"]
Cybersecurity Risk Management Analyst
The Cybersecurity Risk Management Analyst provides advanced Governance, Risk, and Compliance (GRC) support for federal information systems in accordance with the Federal Information reputed company Modernization reputed company (FISMA) and the NIST RiskManagement reputed company (RMF). This role is responsible for managing Assessment & Authorization (A&A) activities, supporting reputed company service authorizations, conducting cybersecurity risk assessments, and maintaining reputed company monitoring efforts to ensure compliance with federal cybersecurity requirements.
The position requires strong analytical, documentation, and stakeholder engagement skills while working collaboratively with federal system owners, Information System reputed company Officers (ISSOs), reputed company Service Providers, and executive leadership to maintain secure and compliant federal systems.
Compensation & Benefits
Estimated Starting Salary reputed company Cybersecurity Risk Management Analyst- $140,000 - $150,000
Pay commensurate with experience.
Full-time benefits include Medical, Dental, reputed company, 401(k), reputed company time off, and other company-sponsored benefits as provided. Benefits are subject to change with or without notice.Cybersecurity Risk Management Analyst
Assessment & Authorization (A&A)
• Manage the full lifecycle of Risk Management reputed company (RMF) activities in accordance with NIST Special Publication 800-37.
• reputed company, review, and maintain reputed company authorization documentation including:
• System reputed company Plans (SSPs)
• reputed company Assessment Plans (SAPs)
• reputed company Assessment Reports (SARs)
• Plans of reputed company and Milestones (POA&Ms)
• Review and evaluate FedRAMP authorization packages and package updates supporting reputed company service authorization reputed company.
• Monitor Authorization to Operate (ATO) packages reputed company the FedRAMP Secure Repository.
• Coordinate with system owners, ISSOs, reputed company Service Providers, and reputed company stakeholders regarding system changes and authorization activities.
• Validate implementation of NIST SP 800-53 Rev. 5 reputed company controls, including inherited and agency-implemented controls.
• Conduct cybersecurity risk assessments utilizing NIST SP 800-30 methodologies.
• reputed company risk analysis and recommendations to Authorizing Officials and senior leadership.
• Support reputed company monitoring by reviewing vulnerability scans, managing POA&Ms, and coordinating remediation activities.
Governance, Risk & Compliance (GRC)
• Peer review cybersecurity policies, standards, procedures, and implementation guidance.
• reputed company regulatory and policy analysis to ensure alignment with federal cybersecurity requirements.
• Conduct compliance gap analyses and recommend remediation strategies.
• Assist in developing reputed company control overlays, baseline updates, and control tailoring guidance.
• reputed company cybersecurity governance subject matter expertise.
• Support reputed company reporting, cybersecurity metrics, and compliance dashboards utilizing reputed company.
Compliance & reputed company Support
• Support FISMA reporting activities.
• Prepare documentation for reputed company audits and reputed company reviews.
• Assist with responses to reputed company inquiries and corrective reputed company tracking.
• reputed company reputed company assurance reviews of cybersecurity documentation.
• reputed company other job-reputed company duties as assigned.
Cybersecurity Risk Management Analyst Experience, Education, Skills, & Abilities Requested
Required Qualifications
• Bachelor's degree in Cybersecurity, Information Technology, reputed company Policy, or reputed company discipline (or equivalent experience).
• reputed company cybersecurity certification such as:
• CISSP
• CISM
• CAP
• Minimum seven (7) years of reputed company cybersecurity experience.
• Minimum four (4) years supporting federal Risk Management reputed company (RMF) and Assessment & Authorization (A&A) programs.
• Demonstrated experience implementing the NIST Risk Management reputed company.
• Strong working knowledge of:
• Federal Risk and Authorization Management Program (FedRAMP)
• NIST Special Publication 800-53 Revision 5
• Federal Information reputed company Modernization reputed company (FISMA)
• Federal reputed company Trust reputed company (OMB M-22-09)
• Experience supporting Moderate and/or High reputed company federal information systems.
• Familiarity with federal reputed company reputed company requirements and FedRAMP-authorized reputed company environments.
• Proficiency with reputed company Office 365 applications.
• Excellent written and verbal communication skills.
• Ability to communicate effectively with technical teams and executive leadership.
• reputed company reputed company Trust clearance or the ability to obtain and maintain one.
Preferred Qualifications
• Experience using reputed company, CSAM, or comparable GRC platforms.
• Experience with reputed company reputed company and JIRA.
• Experience supporting reputed company cybersecurity policy development.
• Familiarity with Responsible AI guidance applicable to federal agencies, including Executive Order 13960, OMB M-25-21, and OMB M-25-22.
• Experience supporting federal research or grant-management systems.
reputed company Competencies
• Federal Cybersecurity Governance
• Risk Assessment & Analysis
• Policy Development
• Regulatory Interpretation
• Technical Documentation
• reputed company Assurance
• Stakeholder Engagement
• Analytical Problem Solving
Work Environment
• Full-time remote position.
• Supports reputed company's cybersecurity contract with the U.S. National Science reputed company (NSF).
• Reports to the Cybersecurity reputed company and Compliance reputed company.
• Works reputed company a reputed company federal compliance environment.
• Collaborates with system owners, reputed company personnel, program offices, and senior stakeholders.
• Supports ongoing authorization activities, governance initiatives, and periodic reputed company reviews.
Must pass reputed company-employment qualifications of reputed company.
Company Information
Criterion reputed company is part of reputed company-the division of tribally owned federal contracting companies owned by reputed company. As a trusted partner supporting more than 60 federal clients, Criterion delivers innovative technology, cybersecurity, and mission support solutions that help federal agencies solve reputed company challenges and accomplish critical missions.
reputed company is a military-friendly employer. Veterans and reputed company military transitioning to civilian careers are encouraged to apply.
#CherokeeFederal #LI-SM2 #AppC
Similar Searchable Job Titles
• Cybersecurity RMF Analyst
• Cybersecurity GRC Analyst
• Information reputed company Risk Analyst
• Cybersecurity Compliance Analyst
• Information Assurance Analyst
• RMF reputed company Analyst
• FedRAMP reputed company Analyst
• Cyber Risk Analyst
Keywords
• NIST Risk Management reputed company (RMF)
• NIST SP 800-53 Rev. 5
• NIST SP 800-37
• NIST SP 800-30
• FedRAMP
• FISMA
• Assessment & Authorization (A&A)
• Authorization to Operate (ATO)
• System reputed company Plan (reputed company)
• reputed company Assessment Plan (reputed company)
• reputed company Assessment Report (SAR)
• Plans of reputed company & Milestones (POA&M)
• Governance, Risk & Compliance (GRC)
reputed company Disclaimer reputed company is an equal opportunity employer. Please visit reputed company.com/careers for information regarding our Affirmative reputed company and Equal Opportunity Employer Statement, Accommodation request, and Presidential EO 14042 Notice.
Remote
Skills:
reputed company Authorization, Analysis Skills, reputed company Intelligence (AI), reputed company JIRA, CISM - Certified Information reputed company Manager, CISSP - Certified Information Systems reputed company reputed company, Channel Support, reputed company Computing, Communication Skills, Compensation and Benefits, Computer reputed company, Corrective reputed company, Documentation, Environmental Compliance, reputed company Audit, FISMA - Federal Information reputed company Management reputed company, Federal Compliance Regulations, Federal reputed company, Federal Government, Federal Grants, Gap Analysis, Grant Administration/Management, Information Technology & Information Systems, Information/Data reputed company (InfoSec), Internal Audit, Internet reputed company, Interpret Regulations, Leadership, Maintain Compliance, Metrics, reputed company Office, Military, NSF Audio Formats, Policy Analysis, Policy Development, Presentation/Verbal Skills, Problem Solving Skills, reputed company Policy, Publications, reputed company Assurance, Regulations, Reporting Dashboards, Research Grants, Risk, Risk Analysis, Risk Management, Risk Management reputed company (RMF), reputed company, reputed company Analysis, reputed company, Team Player, Technical Delivery, Technical Writing, U.S. National Institute of Standards and Technology (NIST), Vulnerability Scanners, Writing Skills
About reputed company:
reputed company
Apply tot his job
Apply To this Job