Jobs and Careers
IC

Senior Cyber Security Business Analyst (Remote)

ICF
Nationwide Remote Office (US99), United StatesRemotefull_timeVerifiedPosted 10 Nov 2024
💰 $158,076/yr($92,986/yr$158,076/yr)

About the role

*We are open to supporting 100% remote work anywhere within the U.S.* 
 

ICF’s Digital Modernization Division is a rapidly growing, entrepreneurial, technology department, seeking a Senior Cyber Security Business Analyst to support upcoming needs with our federal customers.

ICF is a purpose-driven company with a strong culture and underlying values that prize diversity, opportunity, equality, and respect. Our core values include Embracing Differences, and we seek candidates who are passionate about building a culture that encourages, embraces, and hires dimensions of differences.

Our Digital Modernization Division is an information technology and management consulting department that offers integrated, strategic solutions to its public and private-sector clients. ICF has the expertise, agility, and commitment to design, build, and operate high-performance IT engines to support all aspects of our client’s business.

We are open to supporting 100% remote work anywhere within the U.S., candidates in the Washington DC metro area are preferred.

The Team:

The Application Development Sustainment Services (ADSS) team supports Treasury Enterprise Application (EA) platform systems that are critical to the success of the Department of Treasury IT mission. The ADSS program provides contractor support for both Operations and Maintenance (O&M) activities and Development and Modernization (DM&E) efforts.

Role:

We are seeking a Senior Cyber Security Business Analyst to assist our customers’ business needs with low code system security oversight, policy guidance, audits, and integration and development activities related to ServiceNow and Salesforce Platforms. This role will be a key member of the Cyber Security team, monitoring and supporting the Cyber priorities, associated processes, and external system integration. You will be responsible for developing a strong understanding of the business needs of the stakeholders and how the low-code applications will support those needs. This analyst role will partner with development and IT partners to document and secure the IT low-code platforms.

The Senior Cyber Security Business Analyst serves as a translator between technical teams and the cyber security policies and security community to collect, clarify, analyze, and translate requirements into documentation and provide guidance on which applications and solutions require POA&M action resolution. This position is within the context of low-code Agile teams employing a Scrum development framework. 

This position will be working directly with security stakeholders, serving in both Business Analyst and Project Manager roles as a liaison between the low code platform development teams and the security community, and must be able to communicate effectively via phone and web conferencing as many of the stakeholders work remotely.

In addition to supporting all phases of the project, this position will also be responsible for authoring content and peer-reviewing a wide array of documents, including System Security and Surveillance Plans.

Detailed list of responsibilities includes:

Responsibilities: 

  • Ensure the system is operated, used, maintained, and disposed of IAW documented security policies and procedures. Ensuring security controls are in place and operating as intended. 

  • Advise System Owner of any security risks and obtain assistance from the ISSM, if necessary, in assessing the risk; 

  • Assist system owners in completing and maintaining all System A&A documentation 

  • Ensure System users have the required background investigations, the required authorization, and need-to-know, and are familiar with internal security practices before access is granted to the system. 

  • Promote information security awareness; including privacy awareness

  • Identify, report, and respond to information security incidents 

  • Review system role assignments to validate compliance with principles of least privilege. 

  • Review audit/log reports for potential security issues. 

  • Evaluate Security Advisory Alerts (SAA) and known vulnerabilities to ascertain if additional safeguards are needed; ensure systems are patched and securely configured, as appropriate. 

  • Support the security measures and goals established by the Agency CISO. 

  • Comply with the Agency security awareness training requirements for individuals with significant security responsibilities. 

  • Assist in the identification, implementation, and assessment of a system’s security controls, including common controls. 

  • Coordinate and maintain an accurate inventory of the information system 

  • Work with the system ow

Apply for this role

Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.

Apply Now →Generate Application Kit

Free account required — sign up in 30s

Company

ICF

View company profile →