Today
Public Trust
Unspecified
Unspecified
IT - Security
Washington, DC (On-Site/Office)
Overview
SOSi is seeking highly qualified Senior Information Security Analysts to support the U.S. Courts Information Security & Validation Staff (ISVS) Governance, Risk, and Compliance (GRC) program. The analysts will perform hands-on RMF support, security assessments, vulnerability management, and compliance documentation in alignment with federal cybersecurity requirements.
Essential Job Duties
Minimum Requirements
Work Environment
Working at SOSi
All interested individuals will receive consideration and will not be discriminated against for any reason.
SOSi is seeking highly qualified Senior Information Security Analysts to support the U.S. Courts Information Security & Validation Staff (ISVS) Governance, Risk, and Compliance (GRC) program. The analysts will perform hands-on RMF support, security assessments, vulnerability management, and compliance documentation in alignment with federal cybersecurity requirements.
Essential Job Duties
- Perform RMF activities across all lifecycle stages: Prepare, Categorize, Select, Implement, Assess, Authorize, and Monitor.
- Draft, review, and update security documentation, including System Security Plans (SSPs), Plans of Action and Milestones (POA&Ms), and Continuous Monitoring Plans.
- Conduct system risk assessments, vulnerability analysis, and mitigation tracking.
- Execute Nessus-based vulnerability scanning and analysis (agent-based and network scanning).
- Input, manage, and maintain security data in the Cybersecurity Assessment and Management (CSAM) system.
- Support control implementation activities and ensure adherence to JISF/NIST 800-53 frameworks.
- Prepare risk assessment reports, authorization packages, and compliance deliverables.
- Engage with stakeholders, technical teams, and federal representatives to align security activities with mission needs.
- Contribute to quality assurance processes and continuous improvement initiatives in security governance and compliance.
Minimum Requirements
- 5+ years of relevant experience in Information Security, Governance, Risk Management, and Compliance (GRC) in federal environments.
- Deep knowledge of RMF, NIST 800-53 Rev 5, FISMA, and federal continuous monitoring programs.
- Experience with vulnerability management tools (e.g., Nessus) and GRC tools (e.g., CSAM).
- Proven ability to develop, manage, and maintain security artifacts and compliance reports.
- Relevant certifications preferred (e.g., CISSP, CAP, Security+, CISM).
- Strong written and verbal communication skills, with experience working in client-facing environments.
Work Environment
- Normal office conditions with potential to perform duties in deployed locations.
- Core hours of operation are Monday through Friday, 0600 - 1700.
- May be requested to work evenings and weekends to meet program and contract needs.
Working at SOSi
All interested individuals will receive consideration and will not be discriminated against for any reason.
group id: 10237746