Business Analyst
Custom Software Systems, Inc.About the role
Custom Software Systems, Inc. (CSS) is seeking a mid-level Business Analyst to anchor compliance work and to bring the same analytical discipline to application development support. On the governance side, this means owning the documentation and coordination work that keeps clients’ system portfolio compliant: system security plans, ATO cycles, PIA reviews, data classification, and records obligations. On the application side, it means working alongside the development team to determine what applications should do — translating what program staff describes into structured requirements that developers can build against.
This IT section is small. Governance, business analysis, and project coordination are not
separate departments here — they are responsibilities the same small group shares fluidly. This
role will work directly with the economists, bank examiners, policy analysts, and attorneys
whose work both generates the compliance obligations and drives the application backlog. The
governance work and the application work are not as separate as they might appear: a PIA for a
new system and a requirements document for that same system draw on the same conversations.
Responsibilities
IT Governance and Compliance
- Maintain and update FISMA documentation for the client’s IT system portfolio, including
system security plans (SSPs), security categorizations, and related artifacts.
- Coordinate the Authority to Operate (ATO) process for applicable systems, including
working with the clients’ security and privacy offices through assessment and
authorization cycles.
- Draft, review, and maintain Privacy Impact Assessments (PIAs) for client systems that
collect, process, or maintain personally identifiable information.
- Maintain clients' IT system inventory, ensuring records are current and aligned with
agency reporting requirements.
- Support data governance and privacy obligations, including data classification, records
management, and retention schedule compliance.
- Serve as a working-level point of contact with the client's security, privacy, and
compliance functions on matters related to DCCA’s IT systems and application portfolio.
- Identify and escalate compliance gaps or changes in system posture that may require
updated documentation or reassessment.
- Prepare and maintain documentation packages for periodic reviews, assessments, and
audits.
Business Analysis and Requirements
- Work directly with client program staff — economists, policy analysts, bank examiners,
and attorneys — to elicit, refine, and document business requirements for new and
modified applications.
- Translate stakeholder descriptions of workflow and data needs into structured
requirements, process diagrams, and functional specifications that the development
team can act on.
- Develop and maintain process flow diagrams, use cases, and data flow documentation
to support application design and, where applicable, governance activities.
- Help prioritize and scope requirements in coordination with the technical lead and project
manager, surfacing dependencies and tradeoffs early.
- Contribute to user acceptance testing by developing test cases, coordinating with
business users, and documenting outcomes.
- Bridge communication between technical developers and business stakeholders,
reducing friction during discovery, design, and delivery.
This role will participate in QA activities — contributing test cases, supporting UAT coordination,
and helping verify that delivered applications meet business requirements — but does not serve
as a dedicated QA resource. Testing support is a component of the BA function here, not a
primary accountability.
Citizenship
· US Citizenship
Required Qualifications
- Demonstrated experience with FISMA compliance documentation, including system
security plans, security categorizations, and related assessment and authorization
artifacts.
- Experience drafting or maintaining Privacy Impact Assessments for systems that
process personally identifiable information.
- Familiarity with NIST frameworks applicable to federal IT compliance, including NIST SP
800-53 and NIST SP 800-37.
- Experience supporting or coordinating ATO processes, including preparing
documentation for
Apply for this role
Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.
Apply Now →Generate Application KitFree account required — sign up in 30s