安全合规分析师
Security Compliance Analyst
职位类型:
常规职位
当前必须具备的保密级别:
无
能够获得的保密级别:
无
其他要求:
无
职位类别:
网络安全与IT风险管理
职位资格:
技能:
网络安全风险、安全合规、漏洞评估、漏洞管理
认证:
无
经验:
5年以上相关经验
美国公民要求:
否
职位描述:
抓住机会,为案件管理现代化(CMM)计划做出个人贡献。CMM计划是支持美国法院行政办公室(AO)开发现代云解决方案的举措,以支持美国204多个联邦法院。
GDIT是你发挥有意义贡献并发展有回报职业生涯的地方。安全与合规分析师将作为CMM数据现代化和治理团队的一员,负责交付集成的数据治理、工程、数据平台、报告、分析和人工智能(AI)/机器学习(ML)功能,以支持运营决策,并实现AO在CMM计划中的数据和分析目标。
为保护CMM计划的操作环境,GDIT要求7x24小时补充监控,对关键性影响服务的问题在30分钟内快速升级,并每月进行事件/问题报告。在此嵌入的安全分析师确保在发布期间和之后操作保持合规和响应。
安全与合规分析师定义数据隐私、安全、保留和分类规则,并在整个项目中管理数据分类、敏感数据治理和数据共享协议。
安全与合规分析师将执行以下职责:
- 支持对CMM操作环境中的系统、程序和/或规划活动进行分析。
- 进行研究以支持政策、程序和其他技术文档,并支持对IA/网络安全相关程序和倡议进行分析。
- 研究并分析选项,以在专业领域内建立关系并解决解决问题的方案。
- 分析信息保障相关的技术问题,并提供工程和技术支持以解决这些问题。
- 设计、开发、工程和实施符合网络安全部署要求的解决方案。
- 对计算机系统进行漏洞和风险分析。
查看英文原文
Type of Requisition:
RegularClearance Level Must Currently Possess:
NoneClearance Level Must Be Able to Obtain:
NonePublic Trust/Other Required:
NoneJob Family:
Cyber and IT Risk ManagementJob Qualifications:
Skills:
Cyber Risks, Security Compliance, Vulnerability Assessments, Vulnerability ManagementCertifications:
NoneExperience:
5 + years of related experienceUS Citizenship Required:
NoJob Description:
Seize your opportunity to make a personal impact supporting the Case Management Modernization (CMM) Program. The CMM program is an initiative to support the Administrative Office of the US Courts (AO) in developing a modern cloud-based solution to support all 204+ federal courts across the United States.
GDIT is your place to make meaningful contributions to challenging projects and grow a rewarding career. The Security & Compliance Analyst will work as part of the CMM Data Modernization and Governance team responsible for delivering an integrated data governance, engineering, data platform, reporting, analytics, and Artificial Intelligence (AI)/Machine Learning (ML) capabilities that support operational decision-making and fulfill AO's data and analytics objectives in support of the CMM program.
To protect the CMM program's operational environment, GDIT mandates 24/7 supplemental monitoring, rapid escalation within 30 minutes for critical, service-impacting issues, and monthly incident/problem reporting. Security analysts embedded here ensure operations remain compliant and responsive during and after releases.
The Security & Compliance Analyst defines data privacy, security, retention, and classification rules, and manages data classification, sensitive data governance, and data sharing agreements across the program.
The Security & Compliance Analyst will execute the following responsibilities:
- Support analysis of systems, programs, and/or planning activities across the CMM operational environment.
- Perform research in support of policies, procedures, and other technical documentation, and support analysis of IA/Cyber-related programs and initiatives.
- Research and analyze options to develop relationships and solutions that resolve problems within the specialty area.
- Analyze information assurance-related technical problems and provide engineering and technical support in solving them.
- Design, develop, engineer, and implement solutions that meet network security requirements.
- Perform vulnerability and risk analyses of computer systems and applications during all phases of the system development life cycle.
- Establish and satisfy complex system-wide information security requirements based on the analysis of user, policy, regulatory, and resource demands.
- Support customers in the development and implementation of security policies.
- Provide 24/7 supplemental monitoring of the operational environment and escalate critical, service-impacting issues within 30 minutes.
- Prepare monthly incident and problem management reports, ensuring operations remain compliant and responsive during and after releases.
- Define data privacy, security, retention, and classification rules; manage data classification, sensitive data governance, and data sharing agreements.
- Support Authority to Operate (ATO) documentation and gather supporting artifacts for ATO packages.
- Monitor performance scans and system logs, analyzing and reporting vulnerabilities.
- Investigate and analyze security issues and incidents, leveraging SIEM tools for monitoring and log analysis.
- Maintain awareness of emerging security threats and modern attack methods to inform monitoring and response activities.
QUALIFICATIONS
- BS/BA degree with 5+ years of experience of general experience in information systems providing enterprise cybersecurity through policy, architecture, and training processes.
- Experience developing plans to safeguard sensitive data against accidental or unauthorized modification, destruction, or disclosure.
- Experience working with Agile teams and SAFe, responding to security assessments, and providing oversight of vulnerability audits and assessments.
- Experience may be considered in lieu of degree.
- Experience using tools to detect cloud-based security issues (1-2+ years' experience).
- Exposure to SIEM tools such as Splunk for monitoring and log analysis (1-2+ years' experience).
- Prior experience performing incident response and forensics (1-2+ years' experience).
- Knowledge of modern security methods, vulnerabilities, and emerging threats.
- Experience with software and security testing, including containerized applications.
- Understanding of data privacy, retention, and classification requirements in a regulated environment.
- Familiarity with data governance, metadata management, and data quality practices.
- Experience with SQL for data querying and validation.
- Proficiency with BI/reporting tools such as Power BI, Tableau, or QuickSight.
- Familiarity with statistical analysis tools/techniques (e.g., Excel, R, Python) preferred.
- Experience with cloud data platforms (Snowflake, Databricks, AWS preferred).
- Understanding of data architecture concepts (data lake, lakehouse, warehouse).
- Strong analytical, problem‑solving, & statistical analysis skills with attention to detail and data accuracy.
- Preferred: Certified Information Systems Security Professional (CISSP).
COMMUNICATION & ORGANIZATIONAL
- Excellent presentation and communication (oral and written) skills.
- Consultant mindset with the ability to work with high level customer stakeholders and build excellent customer relationships.
- Experience identifying and applying industry tools, solutions, methods best practices, and emerging technologies.
- Strong analytical skills and problem-solving skills with the ability to formulate and communicate recommendations for improvement.
- Demonstrated ability to work effectively, independently, and as part of a team.
- Strong compliance mindset, with the ability to translate security and privacy requirements into clear governance guidance for stakeholders and leadership.
The likely salary range for this position is $96,569 - $130,651. This is not, however, a guarantee of compensation or salary. Rather, salary will be set based on experience, geographic location and possibly contractual requirements and could fall outside of this range.Scheduled Weekly Hours:
40Travel Required:
NoneTelecommuting Options:
RemoteWork Location:
Any Location / RemoteAdditional Work Locations:
Total Rewards at GDIT:
Our benefits package for all US-based employees includes a variety of medical plan options, some with Health Savings Accounts, dental plan options, a vision plan, and a 401(k) plan offering the ability to contribute both pre and post-tax dollars up to the IRS annual limits and receive a company match. To encourage work/life balance, GDIT offers employees full flex work weeks where possible and a variety of paid time off plans, including vacation, sick and personal time, holidays, paid parental, military, bereavement and jury duty leave. GDIT typically provides new employees with 15 days of paid leave per calendar year to be used for vacations, personal business, and illness and an additional 10 paid holidays per year. Paid leave and paid holidays are prorated based on the employee’s date of hire. The GDIT Paid Family Leave program provides a total of up to 160 hours of paid leave in a rolling 12 month period for eligible employees. To ensure our employees are able to protect their income, other offerings such as short and long-term disability benefits, life, accidental death and dismemberment, personal accident, critical illness and business travel and accident insurance are provided or available. We regularly review our Total Rewards package to ensure our offerings are competitive and reflect what our employees have told us they value most.
Our Identity Verification Process:
As part of the hiring process, we will ask you to complete an identity verification process that leverages advanced biometrics and artificial intelligence to ensure authenticity and protect against identity fraud. You are expected to be on camera during virtual interviews. We reserve the right to take your picture to verify your identity and prevent fraud. By proceeding, you authorize the collection, processing, and use of your biometric data for identity verification and security purposes.About Our Work:
We are GDIT. A global technology and professional services company that delivers technology solutions and mission services to every major agency across the U.S. government, defense and intelligence community. Our 26,000 experts extract the power of technology to create immediate value and deliver solutions at the edge of innovation. We operate across 50+ countries worldwide, offering leading mission-ready capabilities in AI, cloud, cyber and software development.Join our Talent Community to stay up to date on our career opportunities and events atgdit.com/tc.
Equal Opportunity Employer / Individuals with Disabilities / Protected VeteransOriginally posted on Himalayas