Information Security Analyst Senior
General Dynamics Information TechnologyAbout the role
Type of Requisition:
RegularClearance Level Must Currently Possess:
NoneClearance Level Must Be Able to Obtain:
NoneSuitability:
Public Trust/Other Required:
OtherJob Family:
Information SecurityJob Qualifications:
Skills:
Information Security, Security Audit, Security Policies, Security Risk Assessment, Security StandardsCertifications:
CISSP - ISC2, Security + - CompTIAExperience:
3 + years of related experienceUS Citizenship Required:
NoJob Description:
Seize your opportunity to make a personal impact as a Information Security Analyst Senior supporting the CMS Center for Clinical Standards and Quality (CCSQ) Cloud Operations and Maintenance (CCOM).
GDIT is your place to make meaningful contributions to challenging projects and grow a rewarding career. Transform technology into opportunity as an Information Security Analyst Senior with GDIT. A career in enterprise IT means connecting and enhancing the systems that matter most. At GDIT you’ll be at the forefront of innovation and play a meaningful part in improving how agencies operate.
At GDIT, people are our differentiator. As an Information Security Analyst Senior you will help ensure today is safe and tomorrow is smarter. Our work depends on Information Security Analyst Senior joining our team of Cloud Security professionals supporting our Prime Contractor. The Security Compliance Analyst will, support all security teams in development and maintenance of core security documentation, advise and author additional auditable deliverable preparation, perform interview facilitation for security audits and Adaptive Capabilities Testing (ACT), conduct internal security assessments, run Contingency Planning sessions and Disaster Recovery exercises, and act as the liaison person between the partner ADO, Business Owners, application development teams, and the auditors.
HOW YOU WILL MAKE AN IMPACT:
- Identifies, reports, and resolves security incidents within the system boundary
- Conducts risk assessments and documents results in customer format
- Author and maintain all security artifacts applicable to project (Information Security Risk Assessment (IS RA), System Security Plan (SSP), Privacy Impact Assessment (PIA), Contingency Plan (CP), Business Impact Analysis (BIA), etc.)
- Demonstrates a strong understanding of AWS security concepts, tools, and services
- Possesses extensive experience and actively participate in maintaining active Authority to Operate (ATO) for various CMS FISMA systems and cloud applications
- Experience working in and maintaining security profiles in CMS FISMA Controls Tracking System (CFACTS)
- Demonstrate a strong understanding of CMS Information Systems Security and Privacy Policy (IS2P2), and CMS Acceptable Risk Safeguard (ARS)
- Establishing trust and maintaining a professional working relationship with all business and technology stakeholders
- Working with and understanding the security issues relative to the technologies of our corporate and customer infrastructure
- Demonstrates a strong understanding of HIPAA, FISMA, NIST security standards
- Providing and promoting security and privacy awareness
- Ensure compliance with regulations and privacy laws
- Assists with implementation of countermeasures or mitigating controls
- Researches, evaluates, tests, and implements new security software or devices
- Identifying, controlling, and eliminating (or minimizing) uncertain events that may negatively affect system resources including risk analysis, cost-benefit analysis, selection, implementation and testing, security evaluation of safeguards, and overall security review
- Implements, enforces, communicates, and develops security policies or plans for data, software applications, hardware, telecommunications, and information systems security education/awareness programs
- Demonstrates a strong understanding of AWS security concepts, tools, and services
- Self-motivation with a strong ability to work in a multi-tasking and changing environment
- Works with other functional groups within the organization to ensure compliance with existing security policy
- Performs all procedures necessary to ensure the safety of information systems assets and to protect systems from intentional or inadvertent access or destruction
- Ensures security audit compliance and cooperation and serves as the primary
Apply for this role
Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.
Apply Now →Generate Application KitFree account required — sign up in 30s