Own your opportunity to work alongside federal civilian agencies. Make an impact by providing services that help the government ensure the well being of U.S. citizens.
Job DescriptionInformation Security Analyst Sr Advisor
Your Impact
Own your opportunity to work alongside federal civilian agencies. Make an impact by providing services that help the government ensure the wellbeing of U.S. citizens.
Job Description
We are seeking a qualified, motivated individual to join GDIT as an Information Security Analyst Senior Advisor (Security 1 Lead ISSO). This position will play a dual role as the Security Lead as well as the projects ISSO. Your focus will be on the Systems Security Plan (SSP) and Authorization To Operate (ATO) package documentation, Policy and Controls, and any other duties that fall under the ISSO / Information Assurance role. You will maintain security postures across several development environments, conducting risk assessments, and ensuring all system changes undergo proper security reviews, while keeping abreast of evolving government cybersecurity directives. You will collaborate with GDIT technical leadership, Government customers, and other key stakeholders to assess our existing and new systems infrastructure.
How You’ll Make an Impact:
Ensure security policies and procedures are implementedAuthors Standard Operating Procedures, policies, and IA plans of action to ensure systems compliance with Federal/DoD guidanceIdentifying corrective actions/mitigation strategies to achieve/sustain (Risk Management Framework (RMF) complianceReview and analyze system implementation plansAdvising system owners and stakeholders on new deployments and advanced cyber security techniquesInformation Security Analyst Senior Advisor Duties and Responsibilities
Serve as the primary authority on System securityOversee the implementation of NIST SP 800-53 controls, Classified National Security Information (CNSI) and FedRAMP requirements across Azure Gov and Azure Secret cloud environmentsDevelop and maintain security documentation (System Security Plans, security policies, procedures)Manage the ATO process by conducting risk assessments, coordinating with authorizing officials, and tracking Plans of Action & Milestones (POA&Ms) for identified gapsMonitor system security posture daily by reviewing audit logs and SIEM alerts (Splunk, Azure Sentinel) for suspicious activity or policy violationsEnsure timely incident investigation and response with the DevOps teamGuide DevOps and Engineering teams on secure configuration baselines (applying DISA STIGs or CIS benchmarks to servers, containers, and network devices)Verify that all system changes pass security review and change controlsCoordinate regular vulnerability scanning and penetration testing of cloud infrastructure and applications (using approved tools like Nessus, Fortify)Ensure any discovered vulnerabilities are remediated within required timeframesEnforce robust access controls and identity managementRegularly review user accounts and privileges in Azure AD and Azure Gov environmentsEnsure multifactor authentication and PKI usage in accordance with federal security policiesProvide security training and guidance to engineering teamsFoster a culture of security awareness, and stay up to date on government cybersecurity directives to adapt security strategiesInformation Security Analyst Senior Advisor Requirements and Qualifications
Bachelor’s degree in computer science or IT related degree; master's degree or equivalent professional experience in information security is preferredAbility to create and maintain system BOE documents to include SSPs, architecture diagrams, contingency planning, and continuous monitoring documentationAbility to write and modify documents to include SOPs, processes, and other guidance documentationComprehensive knowledge of corporate Systems/Solutions Architecture processes and trendsStrong leadership, organizational, and communication skillsSecret Clearance to startKnowledge of Agile software development processExperience with Azure AD
Required Technical Skills:
SCAP, STIG, Patching, eMASS, and related RMF toolsCybersecurity, Systems Administration, implementation of RMF tools and processesExcellent communication skillsExperience working in Agile software development teamsExperience with secure development, coding and engineering practicesExperience with Cybersecurity, Information Security, and Information Technology Security processes, protocols, and procedures. Experience with tools such as Splunk, Azure Sentinel, Nessus, FortifyExperience
10 years of relevant experienceExperience with Cloud SecurityExperience working with leading firewall, network scanning and authentication technologiesExperience working with internet, web, application and network security techniquesExperience in Agile methodologyExperience in Jira to support development team in agile environmentExperience working in Federal or State government environmentsAbility to work independently and remotelyCertification: CISSP desired, Active DoD 8570 IAT Level II Certification (Security+ CE)
Travel Required: Little to no travel anticipated (may be required upon customer request)
Location: Hybrid
US Citizenship: U.S. Citizenship required
GDIT Is Your Place:
401K with company match Comprehensive health and wellness packages Internal mobility team dedicated to helping you own your career Professional growth opportunities including paid education and certifications Cutting-edge technology you can learn from Full-flex work week to own your priorities at work and at home