Assessment & Authorization (A&A) Analyst
Company: Base One Technology
Location: Ashburn
Posted on: February 3, 2025
|
|
Job Description:
Primary Responsibilities
The information below covers the role requirements, expected
candidate experience, and accompanying qualifications.
The selected candidate will apply experience as an Assessment and
Authorization Analyst by evaluating Agency's Information Systems
being introduced to the environment to determine if they meet the
required security standards and are authorized to operate within
the Agency's network, using the NIST Risk Management Framework
(RMF) or similar methodologies
The candidate will be responsible for evaluating key points in the
System Lifecycle, such as before its deployment or during major
updates. Responsibilities may include creating security
documentation (e.g., System Security Plan, Security Assessment
Report) and obtaining the final authorization to operate (ATO).The
candidate should be able to provide assistance in collecting
information and answering questions in regard to many broad IT
areas including, but not limited to: security management controls,
access controls, provisioning and deprovisioning, transfers,
separation of duties, configuration management, contingency
planning, application security, business process controls,
interface controls, and data management system controls.
The candidate will be responsible for:
Conducting formal assessments and deciding whether the system is
authorized to operate
Conducting a formal assessment of the system's security posture
Evaluating whether security controls meet established standards and
are functioning effectively
Documenting results and making recommendations for improving
security
Recommending whether the system should be authorized to operate
based on assessment outcomes
Ensuring that the system has the necessary security controls to
minimize risks
Basic Qualifications
CANDIDATE MUST BE LOCAL TO ASHBURN, VA - SCHEDULE TBD - EXACT DAYS
TBD - CANDIDATES WITH CBP BI, TS/SCI OR TS PREFERRED
A minimum of a Bachelor's degree coupled with 3-5 years' experience
in the Information Technology, Computer Science, IT,
Information/Cyber Security field from an accredited college or
university arena or Master's Degree with 1+ years of relevant
experience.
Superior writing, communication and critical analysis skills
Deep understanding of Information Assurance, Information Technology
and Information Management concepts, processes and procedures
Experience with supporting the delivery of large and complex
projects on time and within budget in government organizations
Minimum of 1-3 years of experience as an ISSO supporting major
federal information systems/applications
Superior writing, communication and critical analysis skills
Deep understanding of Information Assurance, Information Technology
and Information Management concepts, processes and procedures
Working knowledge of the following policies: NIST SP 800-37, Rev 2,
Risk Management Framework for Information Systems and
Organizations: A System Life Cycle Approach for Security and
Privacy, DHS 4300A Policy and Handbook, CBP Information Systems
Security Policies and Procedures Handbook (HB 1400-05D),
Requirement Certifications
CompTIA Security+
Preferred Qualifications
Prior experience with CBP
DoD 8570 IAT III
CompTIA Certified Advanced Security Practitioner (CASP+)
ISC2 Certified in Governance, Risk and Compliance Certification
(CGRC)
ISC2 Certified Information Systems Security Professional
(CISSP)
ISACA Certified Information Systems Auditor (CISA).
Keywords: Base One Technology, Towson , Assessment & Authorization (A&A) Analyst, Professions , Ashburn, Maryland
Click
here to apply!
|