Cybersecurity Analyst
AttainXAbout the role
Job Title: Cybersecurity Analyst
Location: Remote
Citizenship: US Citizenship Required
Security Clearance: Must be able to obtain and maintain government agency public trust.
Salary: $100,000.00 $110,000.00 wage range. You will receive a competitive total rewards package that is applicable to the U.S. only. The salary range may vary based on experience, skillset, and geographical location.
Are you passionate about cybersecurity and driven to protect critical information systems from emerging threats? AttainX is seeking a Cybersecurity Analyst where you’ll provide subject matter expertise and support for IT security activities, ensuring the safety and resilience of our client’s key infrastructure. Step into a role that offers the opportunity to safeguard critical systems, drive cybersecurity excellence, and play a key role in shaping a secure digital landscape.
Qualifications:
- Bachelor’s degree from an accredited college or university in computer science, engineering, information science, information systems management, mathematics, statistics or technology management or equivalent related experience.
- 5-7 years’ experience with cybersecurity frameworks and risk management.
- Experience in performing risk assessments, implementing security controls, and conducting CMAs.
- Expertise in preparing security documentation, including System Security Plans.
- Familiarity with the Authorization to Operate (ATO) process.
- Able to develop NIST (SP) 800-53 Revision 5 Security Controls.
- Self-starter with excellent problem-solving skills and attention to detail.
- Excellent verbal and written communication skills.
- Proficient with Microsoft Office, Outlook, SharePoint, MS, Excel, and MS Teams.
- Must have active CompTIA Security+CE and ISC2 Governance, Risk and Compliance (CGRC) certifications.
- Must be able to pass and maintain a security clearance public trust background check.
Key Responsibilities:
Responsible for providing cybersecurity support to the Office of the Chief Financial Officer (OCFO) and Office of Technology Solutions (OTS) security portfolio of financial systems, such as eRecovery, mLINQS, PeoplePlus, Compass Data Warehouse (CDW).
- Continuous Monitoring Assessments (CMA): Prepare and conduct CMAs, validate security controls, perform risk assessments, and review/update security documentation to maintain the highest levels of cybersecurity.
- Security Control Assessments: Enable consistent, comparable, and repeatable assessments of security controls for OTS information systems. Promote better understanding of risks, providing management officials with trustworthy information to make informed security decisions. The contractor shall perform the following functions for all systems to meet the desired certification standards mandated by EPA Policy CIO 2150.3 and NIST800-53.
- Risk Assessment and Management: Categorize information systems based on their criticality and sensitivity, select, and tailor security controls, and supplement those controls based on in-depth risk assessments. Ensure all security measures are documented in the System Security Plan.
- Ensure effective management and protection of EPA’s financial information resources using EPA CIO 2150.5, Information Security Policy and NIST Guidelines that reduce EPA’s exposure to cybersecurity risk.
- Conduct risk and vulnerability analyses assessments using security subject matter expertise (SME) by applying compliant security controls to ensure EPA best practices implementation.
- Report all system changes and updates to the Information Security Officer (ISO) and Information System Security Officer (ISSO) on all matters involving the security posture of EPA information security systems.
- Drafts Annual Tabletop Exercise for each EPA system to include disaster recovery, contingency planning, incident response, roles and responsibilities, current risk scenarios, and debriefing.
- Implementation and Evaluation: Implement and assess the effectiveness of security controls within the information system, determining risk acceptability at the agency level.
- Improve system security plans (SSP), memorandums of understanding (MOU), interconnection security agreements (ISA) and all security rela
Apply for this role
Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.
Apply Now →Generate Application KitFree account required — sign up in 30s