Job Requirements
Maclean, VA
Top Secret Polygraph not specified
Senior Level Career (10+ yrs experience)
Salary not specified
Join Premium to unlock estimated salaries
Job Description
Our client, Pueo, is hiring for a CONMON Cyber Security Analyst Expert at Tysons Corner, VA
Responsibilities:
Responsible for supporting the security and maintenance of information systems throughout the RMF lifecycle; from preparation through decommission in alignment with ICD, DIA, and DoD/DoW cybersecurity policies.
This role focuses on executing RMF tasks while actively engaging with DIA ISSMs/SCAs, and client PMs/ISSOs teams to ensure security activities lead to meaningful outcomes.
This includes:
Ensuring ISSOs remain focused on risk‑reduction priorities, not just administrative tasks.
Helping stakeholders understand why certain vulnerabilities matter and how remediation improves the system’s overall security posture.
Providing technical input and continuous monitoring support that contributes to measurable improvements in compliance and audit readiness.
The analyst evaluates cybersecurity impacts of system changes, supports control implementation, and helps maintain accurate, actionable security documentation.
Document vulnerabilities, misconfigurations, and issues clearly and thoroughly to support remediation planning and stakeholder understanding.
Use XACTA to manage risk assessments, security control evidence, POA&M tracking, and compliance status.
Monitor and track POA&M items, ensuring vulnerabilities identified in scans or audits are documented, mitigated, and closed appropriately with a focus on reducing repeat findings.
Collaborate with ISSMs, ISSOs, SCAs, PMs, and other partners by providing guidance, clarifications, and context that help them make informed decisions.
Represent cybersecurity standards and expectations in all engagements, reinforcing mission alignment and transparency.
Knowledge, Skills, and Abilities:
Sound knowledge of RMF, NIST 800‑series, FIPS, SA&A processes, continuous monitoring, POA&M policies, and vulnerability/patch management.
Experience using Cyber Risk Management Platforms (e.g., XACTA) for workflow automation, compliance tracking, and RMF execution.
Strong interpersonal and communication skills to engage stakeholders and explain technical issues in a clear, mission‑focused way.
Hands‑on experience interpreting vulnerability and compliance reports from XACTA, STIGs, ACAS, Prisma, Splunk, Trellix (HBSS), or similar tools.
Solid analytical and problem‑solving skills to identify root causes and recommend practical remediation steps.
Some experience leading or contributing to security initiatives that require coordination across multiple teams.
Ability to collaborate effectively in mixed technical environments and contribute to improving the overall security maturity of supported programs.
Required Qualifications:
Certifications:
Obtain an IAT-III or Maintain IAT Level II Certification in compliance with DoD 8570.01-M and DoD Directive 8140 Cyberspace Workforce Management.
CompTIA Cybersecurity Analyst (SySA+)
CompTIA Security
EC-Council Certified Network Defense CND v3
CCNA Security
Global Industrial Cyber Security Professional (GICSP)
GIAC Security Essentials (GSEC)
Systems Security Certified Practitioner (SSCP)
Education:
Possess a Bachelor’s degree
12 years’ experience in addition to education.
Clearance:
Hold a Top Secret Security Clearance with SCI eligibility.
Ability to Pass CI Poly.
Responsibilities:
Responsible for supporting the security and maintenance of information systems throughout the RMF lifecycle; from preparation through decommission in alignment with ICD, DIA, and DoD/DoW cybersecurity policies.
This role focuses on executing RMF tasks while actively engaging with DIA ISSMs/SCAs, and client PMs/ISSOs teams to ensure security activities lead to meaningful outcomes.
This includes:
Ensuring ISSOs remain focused on risk‑reduction priorities, not just administrative tasks.
Helping stakeholders understand why certain vulnerabilities matter and how remediation improves the system’s overall security posture.
Providing technical input and continuous monitoring support that contributes to measurable improvements in compliance and audit readiness.
The analyst evaluates cybersecurity impacts of system changes, supports control implementation, and helps maintain accurate, actionable security documentation.
Document vulnerabilities, misconfigurations, and issues clearly and thoroughly to support remediation planning and stakeholder understanding.
Use XACTA to manage risk assessments, security control evidence, POA&M tracking, and compliance status.
Monitor and track POA&M items, ensuring vulnerabilities identified in scans or audits are documented, mitigated, and closed appropriately with a focus on reducing repeat findings.
Collaborate with ISSMs, ISSOs, SCAs, PMs, and other partners by providing guidance, clarifications, and context that help them make informed decisions.
Represent cybersecurity standards and expectations in all engagements, reinforcing mission alignment and transparency.
Knowledge, Skills, and Abilities:
Sound knowledge of RMF, NIST 800‑series, FIPS, SA&A processes, continuous monitoring, POA&M policies, and vulnerability/patch management.
Experience using Cyber Risk Management Platforms (e.g., XACTA) for workflow automation, compliance tracking, and RMF execution.
Strong interpersonal and communication skills to engage stakeholders and explain technical issues in a clear, mission‑focused way.
Hands‑on experience interpreting vulnerability and compliance reports from XACTA, STIGs, ACAS, Prisma, Splunk, Trellix (HBSS), or similar tools.
Solid analytical and problem‑solving skills to identify root causes and recommend practical remediation steps.
Some experience leading or contributing to security initiatives that require coordination across multiple teams.
Ability to collaborate effectively in mixed technical environments and contribute to improving the overall security maturity of supported programs.
Required Qualifications:
Certifications:
Obtain an IAT-III or Maintain IAT Level II Certification in compliance with DoD 8570.01-M and DoD Directive 8140 Cyberspace Workforce Management.
CompTIA Cybersecurity Analyst (SySA+)
CompTIA Security
EC-Council Certified Network Defense CND v3
CCNA Security
Global Industrial Cyber Security Professional (GICSP)
GIAC Security Essentials (GSEC)
Systems Security Certified Practitioner (SSCP)
Education:
Possess a Bachelor’s degree
12 years’ experience in addition to education.
Clearance:
Hold a Top Secret Security Clearance with SCI eligibility.
Ability to Pass CI Poly.
group id: 10299880