Unknown Company

Security Analyst

mc lean, va • Posted 3 days ago
Onsite Full Time General

Security AnalystJoin our team at Core One! Our mission is to be at the forefront of devising analytical, operational and technical solutions to our Nation's most complex national security challenges. In order to achieve our mission, Core One values people first!

We are committed to recruiting, nurturing, and retaining top talent! We offer a competitive total compensation package that sets us apart from our competition. Core One is a team-oriented, dynamic, and growing company that values exceptional performance!Clearance Required: Active TS/SCI with PolygraphSummaryWe are seeking a Security Analyst to support cybersecurity operations, compliance, and risk management for FedRAMP-authorized and Intelligence Community (IC) systems.

This role is responsible for ensuring systems meet stringent federal security requirements while enabling secure, scalable, and compliant cloud and on-premises solutions.The ideal candidate brings deep expertise in NIST frameworks, FedRAMP authorization processes, continuous monitoring (ConMon), and ATO lifecycle management, along with the ability to operate in classified or high-security environments.Key ResponsibilitiesLead and support FedRAMP Moderate/High and IC ATO authorization processesDevelop, review, and maintain security documentation: System Security Plans (SSP), Security Assessment Reports (SAR), Plan of Action & Milestones (POA&M)Ensure compliance with NIST SP 800-53 / 800-37 RMF, FedRAMP baselines, ICD 503Perform risk assessments, control assessments, and gap analysesImplement and manage RMF lifecycle activities (Categorize ? Monitor)Track and manage POA&M remediation activitiesFacilitate security control inheritance and shared responsibility modelsExecute continuous monitoring strategies and reportingAnalyze security posture using Vulnerability scans and Configuration complianceProduce monthly/quarterly ConMon deliverablesMonitor and analyze security events and alertsSupport incident response and forensic analysisCoordinate with SOC teams and stakeholders for threat mitigationConduct root cause analysis and lessons learnedSecure cloud environments aligned with FedRAMP controlsImplement identity and access controlsSupport 3PAO assessments and auditsPrepare evidence artifacts for FedRAMP JAB/Agency ATO reviews and Inspector General (IG) auditsCoordinate with internal/external auditorsUtilize security tools for monitoring and compliance: Splunk, Sentinel, Vulnerability management tools, ServiceNowSupport automation of compliance and reporting workflowsAct as liaison between Engineering teams, ISSOs / ISSMs, and Compliance and audit teamsProvide security guidance during system design and change managementMentor junior analysts and support team developmentPromote a culture of security-first engineering and compliance excellenceContribute to security governance and policy developmentQualificationsActive TS/SCI with PolygraphBachelor's degree or higher in Cybersecurity, IT, or related field and 5+ years' experience in Cybersecurity in federal or IC environmentsOR Masters and 3+ years of experience in Cybersecurity in federal or IC environmentsStrong Knowledge of NIST RMF (800-37), NIST 800-53 controls, and FedRAMP requirementsAt least one of the following certifications: CISM or CISA, CompTIA Security+ (baseline), Certified Authorization Professional (CAP), CCSP (cloud security)Experience in the following tools: NIST 800-53, RMF, FedRAMP, ICD 503, ServiceNow GRC, Splunk, Azure Sentinel, Nessus, ACAS, AWS GovCloud, Azure Government, GCP, SCAP, STIG ViewerDesired QualificationsExperience with cloud-native security toolsKnowledge of Zero Trust ArchitectureExperience with cross-domain solutionsExperience with ICD 503Familiarity with DevSecOps pipelines in regulated environmentsCore One is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, gender identity, sexual orientation, national origin, or protected veteran status and will not be discriminated against on the basis of disability.

Back to Job Search