D
Decision Point Security, Inc.
Posted 46 days agoVerified live 8h ago

Cybersecurity Compliance Analyst

Brief overview

Remote
$87k–$143k/yrStated range
3+ yrsMinimum
Clearance requiredU.S. government
Risk Management Framework (RMF) ComplianceNIST SP 800-53NIST SP 800-37eMASSDISA STIGs/SRGsVulnerability AssessmentACAS/Tenable Security CenterSCAP Compliance Checker (SCC)Cloud Architecture Security AWSCloud Architecture Security AzureCloud Architecture Security GCPDoD Cloud Computing SRGDoD Secret Security ClearanceTechnical Risk CommunicationWritten and Oral Communication

About the company

D
Decision Point Security, Inc.dpsec.io

Decision Point team has over 20 years combined experience delivering solutions based on sound research principals and critical thinking.

Job description

Summary

Decision Point Security, Inc. delivers cybersecurity and security assessment solutions for critical defense infrastructure and weapon systems. The Cybersecurity Compliance Analyst supports RMF compliance for defense cloud architectures by conducting NIST control assessments, managing eMASS documentation, reviewing vulnerabilities and architectures, and advising engineering teams on secure-by-design safeguards.

Responsibilities

  • Aid the Security Control Assessor (SCA) in the RMF process by performing Security Assessments, writing Security Assessment Reports (SAR), drafting authorization memorandums, reviewing Security Relevant Change (SRC) requests, and conducting determination briefs
  • Manage RMF documentation within eMASS, validating artifacts, coordinating plans, and maintaining compliance across all RMF control families
  • Conduct comprehensive security control assessments (SCA) on complex defense cloud environments in accordance with NIST SP 800-37 and NIST SP 800-53
  • Ensure compliance with DISA STIGs/SRGs, FISMA requirements, and the DoD Cloud Computing SRG across system lifecycles
  • Execute and review vulnerability scans utilizing tools such as ACAS/Tenable Security Center and SCAP Compliance Checker (SCC)
  • Review system architectures, network diagrams, and data flows to identify vulnerabilities and translate compliance requirements into actionable technical safeguards for engineering teams
  • Perform continuous monitoring tasks required to maintain accurate system records and ensure ongoing authorization

Skills

  • 3-5+ years of experience in cybersecurity, information assurance, or RMF compliance within the Department of Defense (DoD) / Department of War (DoW) or Defense Industrial Base (DIB)
  • DoDD 8570/8140 IAM or IAT Level II/III professional certification (e.g., Security+, CISSP, SecurityX)
  • Deep, hands-on experience utilizing eMASS for RMF artifact management, POA&M tracking, ATO package development, reviewing control compliance, or reviewing POA&M updates
  • Strong proficiency with NIST SP 800-53, DISA STIGs, and vulnerability assessment tools (ACAS/Nessus, SCAP)
  • Experience assessing cloud architectures (AWS, Azure, GCP, etc) and understanding the DoD Cloud Computing SRG
  • Exceptional ability to articulate complex security risks and deliver practical recommendations to both technical engineers and non-technical leadership
  • Active DoD Secret (or higher) security clearance
  • U.S. Citizenship
  • Remote within the United States with 10-20% travel
  • Previous experience as an Information Systems Security Officer (ISSO), Security Control Assessor (SCA), or RMF Information System Security Manager (ISSM)
  • Familiarity with container orchestration (Kubernetes/docker) and securing CI/CD pipelines
  • Understanding of security engineering principles applied to Artificial Intelligence (AI) threat modeling and data pipeline security
  • Experience supporting secure system development by reviewing A&A artifacts such as Ports, Protocols, and Services (PPS) and Hardware/Software inventories

Qualifications

Must Haves

  • 3-5+ years of experience in cybersecurity, information assurance, or RMF compliance within the Department of Defense (DoD) / Department of War (DoW) or Defense Industrial Base (DIB)
  • DoDD 8570/8140 IAM or IAT Level II/III professional certification (e.g., Security+, CISSP, SecurityX)
  • Deep, hands-on experience utilizing eMASS for RMF artifact management, POA&M tracking, ATO package development, reviewing control compliance, or reviewing POA&M updates
  • Strong proficiency with NIST SP 800-53, DISA STIGs, and vulnerability assessment tools (ACAS/Nessus, SCAP)
  • Experience assessing cloud architectures (AWS, Azure, GCP, etc) and understanding the DoD Cloud Computing SRG
  • Exceptional ability to articulate complex security risks and deliver practical recommendations to both technical engineers and non-technical leadership
  • Active DoD Secret (or higher) security clearance
  • U.S. Citizenship
  • Remote within the United States with 10-20% travel

Nice to Haves

  • Previous experience as an Information Systems Security Officer (ISSO), Security Control Assessor (SCA), or RMF Information System Security Manager (ISSM)
  • Familiarity with container orchestration (Kubernetes/docker) and securing CI/CD pipelines
  • Understanding of security engineering principles applied to Artificial Intelligence (AI) threat modeling and data pipeline security
  • Experience supporting secure system development by reviewing A&A artifacts such as Ports, Protocols, and Services (PPS) and Hardware/Software inventories

Benefits

  • Generous 401(k) contribution, matching not required
  • Company Paid Health Insurance
  • Company Paid Dental insurance
  • Company Paid Vision Insurance
  • Company Paid Life Insurance
  • Paid Training
  • Home Office Stipend
  • Paid Time Off
  • Remote within the United States

More jobs like this