远程工作雷达

安全合规分析师

Security Compliance Analyst

开发工程限定地区(需当地身份)
公司ShorePoint Inc
薪资未公开
工作地点United States
地域资格限定地区(需当地身份)
时区要求日间重叠约 9 小时,基本正常作息
用工类型Full Time
发布时间今天
数据来源Himalayas
前往 Himalayas 查看并投递 →
注意地域限制:该职位明确限定在 United States 招聘。如果你是位于中国大陆的求职者,通常需要当地工作身份才能投递,或需与雇主确认是否接受独立合同(Contractor)形式合作。

我们是谁:
ShorePoint 是一家快速发展的、在行业内受到认可并获得奖项的网络安全服务公司,专注于高知名度、高威胁的政府和私营部门客户,这些客户要求有经验并经过验证的安全模型来保护他们的数据。我们秉持“努力工作,尽情享受”的理念,庆祝个人和公司的成功。我们对我们的使命充满热情,致力于超越期望为客户提供服务,同时营造一个支持创造力、责任感、任务成功、批判性思维以及回馈社区的环境。
福利待遇:
作为网络安全精英的一员,我们携手合作,保护国家的关键基础设施,同时在一个注重个人技术和职业成长的文化中,打造有意义且令人兴奋的职业发展机会。我们坚信,当团队成员感到快乐并得到良好的照顾时,他们才能发挥最佳水平。为了践行这一理念,我们提供全面的福利包,包括主要的医疗保险公司。突出的福利包括 144 小时带薪休假、11 个节假日、85% 的保险费用报销、401(k) 计划、继续教育、认证维护及报销等。
我们寻找的人:
我们正在寻找一名安全合规分析师,以支持联邦网络安全合规活动,包括由《联邦信息安全管理现代化法案》(FISMA)驱动的评估与授权(A&A)、持续的风险管理和审计准备。该职位通过协调安全文档、控制实施、持续监控和合规活动,支持安全信息保障经理(SIAM)在身份、凭证和访问管理(ICAM)系统中的工作。安全合规分析师与信息系统负责人(ISOs)、信息系统安全官员(ISSOs)、项目领导和其他利益相关者合作,以保持安全合规并支持联邦要求。这是一个独特的机会,可以在网络安全市场中一家充满活力且快速发展的公司中塑造其增长、发展和文化。
你将负责:

  • 支持 SIAM 执行该计划的信息保障和网络安全合规策略。
  • 与 ISOs 和 ISSOs 协作,维护系统安全文档,跟踪控制实施,并支持运营授权(ATO)和持续运营授权(cATO)活动。
查看英文原文

Who we are:
ShorePoint is a fast-growing, industry-recognized and award-winning cybersecurity services firm focused on high-profile, high-threat public and private sector customers who demand experience and proven security models to protect their data. We embrace a “work hard, play hard” mentality and celebrate individual and company successes. We are passionate about our mission and going above and beyond to deliver for our customers, while fostering an environment that supports creativity, accountability, mission success, critical thinking and a desire to give back to our community.
The Perks:
As recognized members of the Cyber Elite, we work together in partnership to defend our nation’s critical infrastructure while building meaningful and exciting career development opportunities in a culture tailored to the individual’s technical and professional growth. We are committed to the belief that our team members do their best work when they are happy and well cared for. In support of this philosophy, we offer a comprehensive benefits package, major carriers for healthcare providers. Highlighted benefits include 144 hours of PTO, 11 holidays, 85% of insurance premiums covered, a 401(k), continuing education, certification maintenance and reimbursement and more.
Who we’re looking for:
We are seeking a Security Compliance Analyst to support federal cybersecurity compliance activities, including Federal Information Security Modernization Act (FISMA)-driven assessment and authorization (A&A), ongoing risk management and audit readiness. This role supports the Security Information Assurance Manager (SIAM) by coordinating security documentation, control implementation, continuous monitoring and compliance activities across Identity, Credential, and Access Management (ICAM) systems. The Security Compliance Analyst position works with Information System Owners (ISOs), Information System Security Officers (ISSOs), program leadership and other stakeholders to maintain security compliance and support federal requirements. This is a unique opportunity to shape the growth, development and culture of an exciting and fast-growing company in the cybersecurity market.
What you’ll be doing:

  • Support the SIAM in executing the program’s information assurance and cybersecurity compliance strategy.
  • Coordinate with ISOs and ISSOs to maintain system security documentation, track control implementation and support Authorization to Operate (ATO) and continuous ATO (cATO) activities.
  • Support FISMA compliance activities, including annual self-assessments, security control assessments and preparation for Inspector General (IG) and Office of Management and Budget (OMB)-driven audits.
  • Develop, review and maintain security artifacts, including System Security Plans (SSPs), Security Assessment Reports (SARs), Plans of Action and Milestones (POA&Ms) and Risk Assessment Reports (RARs).
  • Support Risk Management Framework (RMF) activities, including control selection, implementation tracking, assessment and continuous monitoring.
  • Track POA&M remediation activities to ensure findings from audits, assessments and vulnerability scans are documented, assigned and closed within required timelines.
  • Assist with the preparation of materials and evidence packages for internal reviews, external audits and compliance inspections (e.g., FISMA, OIG, GAO, or agency-specific audits).
  • Support the security compliance posture of ICAM systems and track security policy, procedure and control updates to maintain alignment with evolving federal requirements.
  • Maintain continuous monitoring documentation and support monthly and quarterly compliance reporting to program leadership and government stakeholders.
  • Participate in security control assessments, walkthroughs and stakeholder interviews to validate control implementation.
  • Maintain organized documentation repositories and audit trails to support inspection readiness.
  • Communicate compliance status, risks and action items to the SIAM and program leadership.

What you need to know:

  • Federal information security compliance and audit practices, including FISMA and A&A activities.
  • NIST RMF, NIST Special Publication (SP) 800-53 security controls and common security compliance artifacts, including SSPs, SARs, POA&Ms, RARs and continuous monitoring reporting.
  • Security documentation, control implementation, continuous monitoring and audit readiness practices.

Must have’s:

  • Bachelor’s degree in Cybersecurity, Information Technology, Information Systems, or a related field, or equivalent professional experience.
  • 2+ years of experience in federal information security compliance, IT security, or a related field.
  • Experience with Governance, Risk, and Compliance (GRC) tools such as Xacta, CSAM, RSA Archer or similar.
  • Demonstrated experience supporting FISMA compliance activities and/or federal security audits.
  • Experience collaborating with ISOs and/or ISSOs on system security documentation and A&A activities.
  • Strong written and verbal communication skills, with the ability to translate technical compliance findings into clear, actionable reporting for government stakeholders.
  • Strong organizational skills and attention to detail, particularly around documentation control and audit readiness.
  • Proven ability to analyze complex requirements and translate them into clear, actionable tasks and processes through critical thinking.
  • Applicants must be a U.S. citizen and eligible to obtain and maintain a Public Trust security clearance, in compliance with federal contract requirements.

Beneficial to have:

  • Experience supporting an ICAM program or similar identity governance initiative.
  • Familiarity with Federal Identity, Credential, and Access Management (FICAM) architecture, NIST SP 800-63 digital identity guidelines or OMB M-19-17 or successor ICAM policy.
  • Relevant certifications such as CompTIA Security+, Certified Authorization Professional (CAP), Certified Information Systems Security Professional (CISSP) or Certified Information Systems Auditor (CISA).
  • Experience supporting continuous monitoring programs or cATO initiatives.
  • Prior experience in a federal contracting environment supporting a civilian or defense agency.

Where it’s done:
· Remote (Herndon, VA).
Originally posted on Himalayas

本页面信息整理自 Himalayas,版权归原发布方所有。职位可能随时关闭,投递请以原始页面为准。 本站只做信息聚合展示,不参与招聘流程,也不向求职者收取任何费用。

该公司其他在招职位

安全架构负责人

ShorePoint IncUnited StatesFull Time今天
开发工程限定地区(需当地身份)

← 返回全部职位