ironquill.tech/board

$ cat jobs/it-security-analyst-assessor-nxtkeycorporation-749059d0bc9a.json

IT Security Analyst / Assessor

Nxtkeycorporation·Worldwide·Washington, US·mid
Apply on smartrecruiters → Get AI match score →
NXTKey Corporation has been delivering Information Technology, Information management, Information Assurance (IA) and cybersecurity solutions to US Federal Government since 2005. NXTKey Corporation is an agile Small Business that places emphasis on teamwork and partnership with our clients to produce optimum contract performance. We have refined our solution from experience supporting highly complex Department of Justice (DOJ) environments such as United States Marshals Service (USMS), Justice Management Division (JMD), Office of Justice Programs (OJP) and Federal Prison Industries (FPI). Our depth of experience allows us to provide IT security support for a wide range of IT General Support Systems (GSS) and major applications (MAs) within the Federal Enterprise and following the guidance in the Federal Enterprise Architecture (FEA) and information systems security support services in accordance with OMB Circular A-130, NIST guidelines and standards, as well as other federal policies and regulations. Information System Security Analyst duties include: Perform Certification & Accreditation (C&A), System Assessment & Authorization (SA&A) as part of NIST SP 800-37 Risk Management Framework (RMF) system and application accreditation Prepare Vulnerability Scanning test plans, coordinate testing, and conduct scans using Nessus, Foundstone, WebInspect, Hailstorm and other scan applications Analyze vulnerability scan results for validation and root cause Technical support in the areas of vulnerability assessment, risk assessment, network security, product evaluation, and security implementation. Responsible for the design and implementation of security solutions to protect the confidentiality, integrity, and availability of sensitive information. Provide technical evaluations of customer CM and CMI solutions and provide security recommendations. Participate in the design of information system business impact analysis, system categorization, contingency plans, privacy docume