Information Security Analyst IV
eSimplicityAbout the role
Description
About Us
eSimplicity is a modern digital services company that works across government, partnering with our clients to improve the health and lives of millions of Americans, ensure the security of all Americans—from soldiers and veterans to kids and the elderly, and defend national interests on the battlefield. Our engineers, designers, and strategists cut through complexity to create intuitive products and services that courageously equip Federal agencies with solutions to transform today for a better tomorrow for all Americans.
Purpose of Scope:
We’re seeking a Information Security Analyst IV responsible for providing security support services while meeting security control compliance requirements for a systems portfolio at various stages of maturity and modernization. This role will support continuously monitoring systems' cybersecurity posture to secure against cyber threats. The SO’s primary responsibility is to facilitate security tool implementation and security tool usage, ensuring tools remain compliant and configured properly, all the while ensuring a successful program Authorization to Operate (ATO). Additionally, the SO is expected to take ownership of communication and visualization of security issues, especially where coordination between product teams, information owners, engineering, and infrastructure staff is necessary for remediation. The SO owns coordination and response to the agency’s security-related inquiries, compliance with agency policy, security controls, and maintenance of security documentation and artifacts. The SO will act as the primary liaison to provide timely and accurate responses to security-related data calls (System Security & Compliance Status, Vulnerability, and Compliance scanning issues). Provide subject matter expertise throughout all phases of the system development lifecycle. SO will interface with multiple stakeholders through multiple touchpoints weekly.
Responsibilities:
- Work closely with the Product Owners, ISSOs, and engineering and infrastructure staff to provide guidance on the implementation of security policies, standards, and procedures.
- Analyze new or updated security requirements, collaborate with stakeholders, and develop clear and accurate responses.
- Support the review and update of ATO artifacts such as System Security Plans, Information System Contingency Plans, Configuration and Change Management Plans, Incident Response Plans, Privacy Impact Analysis, and more.
- Interpret security risk assessment, review security scan results, assess security vulnerabilities, and support the development and remediation of vulnerability and compliance issues via Plan of Action and Milestones (POA&Ms)
- Support the development of implementation and design documentation relating to security feature implementation.
- Work with engineering and infrastructure personnel to document remediation for vulnerabilities and non-compliance issues.
- Analyze and interpret agency security requirements and provide governance communication to non-security personnel.
- Collaborate with product teams, ISSOs, and other stakeholders to support continuous monitoring and ATO efforts.
- Conducts vulnerability assessments and monitors systems, networks, databases, and Web-based assets for potential system breaches. Recommends and takes the lead on implementing changes to enhance security systems, prevent unauthorized access, and help mitigate security vulnerabilities.
- Responds to alerts from information security tools. Reports, investigates, and resolves higher-level security incidents.
- Respond to security tool outages and degradations in service, tune security rules and alerts, and set/maintain security tool dashboards and reporting.
- Research security trends, new methods, and techniques used in unauthorized data access to preemptively eliminate the possibility of system breaches. Ensures compliance with regulations and privacy laws. Conducts research to identify new attack vectors.
- Educates and communicates security requirements and procedures to all users and new employees.
- Recommend process improvements to the information system for risk mitigation.
- It applies iterative security automation to all program aspects, increasing overall security posture iteratively and never accepting the status quo.
- Provide audit log review in Splunk, present findings to ISSO, and plan for investigation or remediation activities.
- Periodic user and privileged access reviews.
Requirements
Required Qualifications:
- Minimum of 7+ years related experience.
- A bachelor's degree in computer science, Information Systems, Engineering, Business, or other related scientific or technic
Apply for this role
Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.
Apply Now →Generate Application KitFree account required — sign up in 30s