Back to Jobs
SESCO
AI & Machine Learning 1d ago

SME FISMA Security Analyst

SESCO
United StatesUnited States
Contract
Not Disclosed
Senior-Level

Job Description

Key Skills Required

Master these to land this role

Robotic Process Automation (RPA)NIST SP 800-53ServiceNowCybersecurityAPI SecurityITILv4 FoundationGoogle Suite

Want to know if you're a match for this job?

Calculate My Match Score

The SES is seeking a Subject Matter Expert (SME) FISMA Security Analyst to support federal compliance and governance requirements for all systems supported by the Task Order. This role assists the XGen DIGIT Director of Enterprise Security in managing and executing GSA IT Enterprise Security Management and IT Continuity Management Services.

The team leverages forward-leaning technologies and best practices to transform GSA’s IT capabilities, shifting offerings to provide a more flexible service delivery model. This aligns with the agency’s transition to a fully digital experience and adoption of advanced technologies like intelligent automation, artificial intelligence, and machine learning.

Requirements

The FISMA Security Analyst will perform the following activities:

  • Provides technical support to divisions and branches developing security architecture and supporting the design and implementation of information technology security systems
  • Supports research of new security products and services, and aids in the rollout of enterprise security solutions leveraging single Department-wide license agreements with vendors and service providers
  • Leads the development, implementation, and maintenance of enterprise-wide information security capabilities
  • Analyzes enterprise business models and IT systems to determine security risks and risk management considerations
  • Defines enterprise- and system-level security requirements
  • Supports the implementation and assessment of security and privacy controls in accordance with NIST SP 800-53 Revision 5 and applicable federal control baselines
  • Supports the execution of the NIST Risk Management Framework (RMF) lifecycle, including control implementation, assessment, authorization, and continuous monitoring
  • Assists with the development, review, and maintenance of RMF and FISMA documentation, including System Security Plans, Security Assessment Reports, Plans of Action and Milestones, risk assessments, control implementation statements, procedures, governance documentation, and authorization packages
  • Proposes technical solutions for systems and application-level security architecture and design to reduce risk and support compliance objectives
  • Supports continuous monitoring activities, including vulnerability management, control assessments, risk tracking, remediation validation, and reporting to stakeholders
  • Assesses cybersecurity risks associated with APIs, integrations, data exchanges, and automated workflows, including authentication, authorization, encryption, logging, monitoring, and data protection considerations
  • Supports API security risk management by reviewing API design and implementation for compliance with security requirements, secure configuration, access controls, token management, and protection of sensitive data
  • Supports Robotic Process Automation (RPA) risk management by assessing bots, workflows, service accounts, credential management, privilege assignments, logging, exception handling, and operational resilience
  • Identifies and documents security risks related to intelligent automation, RPA, API integrations, and emerging technologies, and recommends mitigation strategies aligned with enterprise risk tolerance

Required Skills:

  • Ability to obtain a Public Trust Clearance and ITILv4 Foundation Certification
  • Comprehensive knowledge across key tasks and high-impact assignments
  • Functions as a security expert across multiple project assignments
  • Proven ability to work independently in a full or partial remote environment with limited supervision and may supervise/lead others
  • Strong communication skills, both oral and written, to effectively interact with all levels of staff and clients
  • Maintain standard working hours and availability for meetings and collaborative efforts
  • Ability to apply comprehensive knowledge to accomplish tasks using practical experience and training

Preferred Skills:

  • CISSP, CISA, CISM, Security+ or other relevant security certifications
  • Familiarity with CUI (Controlled Unclassified Information) requirements for unclassified IT systems
  • Track record of competency in obtaining initial Authorization to Operate (A&A) and reauthorization
  • Experience with unclassified network administration, including:
    • Network infrastructure and security best practices
    • Local Area Network (LAN) administration and maintenance, including user control and VPN access
    • Firewalls
    • Mobile Device Management
    • Identity and Authentication Services Management
  • Comfortable with Windows operating systems
  • Willingness and ability to independently take on IT Compliance tasks
  • Experience with Linux operating systems
  • Familiarity with Google Suite (Gmail, Calendar, Chat, Meet, Docs, Slides, Sheets), Microsoft Office (Word, Excel, PowerPoint, Outlook), and ServiceNow

Education and Experience:

  • 10-15 years of experience and a bachelor's degree or equivalent
  • Minimum 3-5 years of direct experience supporting FISMA and Financial Audit Requirements
  • Minimum 3-5 years of direct experience supporting cybersecurity compliance and implementing threat mitigation steps
  • Minimum 3-5 years of direct experience with continuous monitoring security expertise to business units and key stakeholders
  • Minimum 3-5 years of direct experience creating and delivering end-user-related briefings, training, policy, and compliance updates
  • Experience as a remote worker demonstrating time management, self-discipline, cultural change management, and an Agile mindset

Physical Requirements:

  • If remote, maintain a safe home workspace in line with information security policies
  • Communicate verbally and in writing, primarily using a keyboard
  • Appear on camera for meetings with co-workers and government partners, ensuring protection of proprietary information
  • View computer screens and sit for long periods of time
  • No travel required

How would you rate this job post?

See what other professionals think about this role.

banner

SESCO (operating at sescoration.com) is a specialized platform focused on providing solutions for the energy sector, particularly in the realm of energy efficiency and sustainability. Founded in an unspecified year, the company operates with a mission to address critical challenges in energy management and consumption. Under the hood, SESCO likely leverages advanced technologies and data analytics to optimize energy usage, reduce waste, and enhance operational efficiency for its clients. This allows businesses and organizations to achieve significant cost savings, improve sustainability metrics, and align with regulatory requirements. While specific details regarding funding or investors are not available, SESCO appears to cater to industries where energy optimization is a priority, such as manufacturing, commercial buildings, and utilities.

Safety First

  • Never pay for a job application.
  • Do not share sensitive bank info.
  • Verify the client before starting work.
Learn More