Jobs and Careers
Washington, United StatesRemotecontractVerifiedPosted 3 Mar 2026

About the role

Custom Software Systems, Inc. (CSS) is seeking a mid-level Business Analyst to anchor compliance work and to bring the same analytical discipline to application development support. On the governance side, this means owning the documentation and coordination work that keeps clients’ system portfolio compliant: system security plans, ATO cycles, PIA reviews, data classification, and records obligations. On the application side, it means working alongside the development team to determine what applications should do — translating what program staff describes into structured requirements that developers can build against.

 

This IT section is small. Governance, business analysis, and project coordination are not

separate departments here — they are responsibilities the same small group shares fluidly. This

role will work directly with the economists, bank examiners, policy analysts, and attorneys

whose work both generates the compliance obligations and drives the application backlog. The

governance work and the application work are not as separate as they might appear: a PIA for a

new system and a requirements document for that same system draw on the same conversations.

Responsibilities

IT Governance and Compliance

  • Maintain and update FISMA documentation for the client’s IT system portfolio, including

system security plans (SSPs), security categorizations, and related artifacts.

  • Coordinate the Authority to Operate (ATO) process for applicable systems, including

working with the clients’ security and privacy offices through assessment and

authorization cycles.

  • Draft, review, and maintain Privacy Impact Assessments (PIAs) for client systems that

collect, process, or maintain personally identifiable information.

  • Maintain clients' IT system inventory, ensuring records are current and aligned with

agency reporting requirements.

  • Support data governance and privacy obligations, including data classification, records

management, and retention schedule compliance.

  • Serve as a working-level point of contact with the client's security, privacy, and

compliance functions on matters related to DCCA’s IT systems and application portfolio.

  • Identify and escalate compliance gaps or changes in system posture that may require

updated documentation or reassessment.

  • Prepare and maintain documentation packages for periodic reviews, assessments, and

audits.

Business Analysis and Requirements

  • Work directly with client program staff — economists, policy analysts, bank examiners,

and attorneys — to elicit, refine, and document business requirements for new and

modified applications.

  • Translate stakeholder descriptions of workflow and data needs into structured

requirements, process diagrams, and functional specifications that the development

team can act on.

  • Develop and maintain process flow diagrams, use cases, and data flow documentation

to support application design and, where applicable, governance activities.

  • Help prioritize and scope requirements in coordination with the technical lead and project

manager, surfacing dependencies and tradeoffs early.

  • Contribute to user acceptance testing by developing test cases, coordinating with

business users, and documenting outcomes.

  • Bridge communication between technical developers and business stakeholders,

reducing friction during discovery, design, and delivery.

 

This role will participate in QA activities — contributing test cases, supporting UAT coordination,

and helping verify that delivered applications meet business requirements — but does not serve

as a dedicated QA resource. Testing support is a component of the BA function here, not a

primary accountability.

Citizenship

·        US Citizenship

Required Qualifications

  • Demonstrated experience with FISMA compliance documentation, including system

security plans, security categorizations, and related assessment and authorization

artifacts.

  • Experience drafting or maintaining Privacy Impact Assessments for systems that

process personally identifiable information.

  • Familiarity with NIST frameworks applicable to federal IT compliance, including NIST SP

800-53 and NIST SP 800-37.

  • Experience supporting or coordinating ATO processes, including preparing

documentation for

Apply for this role

Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.

Apply Now →Generate Application Kit

Free account required — sign up in 30s

Company

Custom Software Systems, Inc.

View company profile →