Noblis logo
Noblis
Posted 2 days agoVerified live 11h ago

Information System Security Compliance Analyst (Multiple Levels)

Brief overview

Remote
UndergradOr in progress
$79k–$123k/yrStated range
9+ yrsMinimum
2 H-1B approvalsDept. of Labor
Cybersecurity ComplianceNIST Risk Management Framework (RMF)NIST SP 800-53 Security ControlsPOA&M ManagementAuthorization Package DocumentationContinuous MonitoringVulnerability ManagementRisk ManagementSecurity Control AssessmentMicrosoft OfficeFAA Public Trust ClearanceWritten and Verbal Communication

Visa sponsorship history

2 years sponsoring, last filed FY2025

Data powered by U.S. Department of Labor. This does not guarantee sponsorship for this specific role.
2H-1B approved
100%approval rate
1new H-1B hires
$90,000median wage / yr
H-1B Petition ApprovalsVisas USCIS actually granted: the strongest sign the company sponsors.
20241
20251
LCA Certified ApplicationsAn early filing step, not a visa approval: it signals intent, not confirmed sponsorship.
20241
Top sponsored roles
Data Engineer

Job description

Summary

Noblis delivers scientific, management, and engineering expertise to support critical federal missions. The Information System Security Compliance Analyst manages security authorization and continuous monitoring activities for federal information systems, ensuring compliance with NIST and federal cybersecurity requirements. The role develops authorization documentation, tracks POA&M remediation, assesses security controls, and communicates risks and compliance status to stakeholders.

Responsibilities

  • Manage the security authorization lifecycle for one or more information systems in accordance with Federal Risk Management Framework (RMF) requirements
  • Coordinate activities required to obtain and maintain Authorization to Operate (ATO) approvals
  • Assess and track implementation of NIST SP 800-53 security controls and associated compliance requirements
  • Develop, review, update, and maintain authorization package documentation, including:
  • System Security Plans (SSPs)
  • Security Assessment Reports (SARs)
  • Plan of Action and Milestones (POA&Ms)
  • Risk Assessments
  • Continuous Monitoring documentation
  • Security-related policies and procedures
  • Manage POA&M activities by tracking findings, monitoring remediation progress, validating corrective actions, and supporting closure efforts
  • Provide technical guidance and compliance recommendations to system owners, engineers, administrators, and security stakeholders to facilitate POA&M remediation and closure
  • Coordinate with technical teams to gather evidence supporting security control implementation and compliance requirements
  • Review vulnerability scan results, assessment findings, and security documentation to identify compliance gaps and areas requiring remediation
  • Support continuous monitoring activities by tracking security posture, compliance status, and ongoing control effectiveness
  • Participate in security assessments, audits, and compliance reviews conducted by internal and external stakeholders
  • Assist in the development of risk mitigation strategies and recommendations for addressing identified security weaknesses
  • Track authorization milestones, compliance deadlines, and remediation activities to ensure timely completion
  • Communicate compliance status, risks, findings, and recommendations to both technical and non-technical stakeholders
  • Support audits and reporting activities related to Federal cybersecurity requirements and organizational security programs

Skills

  • * Experience supporting cybersecurity compliance, security authorization, risk management, or information security programs
  • * Experience working with the NIST Risk Management Framework (RMF)
  • * Subject matter expertise with NIST SP 800-53 security controls and Federal cybersecurity compliance requirements
  • * Experience supporting the development, maintenance, or review of authorization package documentation, including SSPs, SARs, POA&Ms, and Risk Assessments
  • * Understanding of the Authorization to Operate (ATO) process and continuous monitoring requirements
  • * Experience tracking and managing POA&M findings through remediation and closure
  • * Ability to review technical security information and translate findings into compliance documentation and actionable recommendations
  • * Understanding of cybersecurity principles, security controls, vulnerability management, and risk management concepts
  • * Strong organizational skills with the ability to manage multiple systems, priorities, and compliance activities simultaneously
  • * Strong written and verbal communication skills, including the ability to develop and review formal security documentation
  • * Proficiency with Microsoft Office applications, particularly Excel, Word, and PowerPoint
  • * U.S. Citizen or Green Card Permanent Resident with a minimum of three (3) years of U.S. residency
  • * Ability to obtain and maintain an FAA Public Trust
  • * Bachelor's degree in Cybersecurity, Information Technology, Telecommunications, or a related field
  • * 9+ years of experience in cybersecurity or network security roles
  • * A High School degree with a total of 15 years of experience in cybersecurity or network security roles
  • * Masters degree with a total of 6 years of experience in cybersecurity or network security roles
  • * Bachelor's degree in Cybersecurity, Information Technology, Telecommunications, or a related field
  • * 12+ years of experience in cybersecurity or network security roles
  • * A High School degree with a total of 16 years of experience in cybersecurity or network security roles
  • * An Associates Degre with a total of 14 years of experience in cybersecurity or network security roles
  • * Masters degree with a total of 9 years of experience in cybersecurity or network security roles
  • * Masters degree in Cybersecurity, Information Technology, Telecommunications, or a related field
  • * 16+ years of experience in cybersecurity or network security roles
  • * A Bachelors degree with a total of 19 years of experience in cybersecurity or network security roles
  • * Experience serving as an Information System Security Officer (ISSO), Security Control Assessor (SCA), Information System Security Manager (ISSM), or similar cybersecurity compliance role
  • * Experience managing authorization packages for multiple systems simultaneously
  • * Strong knowledge of NIST SP 800-53 Rev. 5, NIST RMF, FISMA, and related Federal cybersecurity requirements
  • * Experience developing, reviewing, and maintaining SSPs, SARs, POA&Ms, Risk Assessments, Contingency Plans, and other authorization artifacts
  • * Experience conducting control assessments, compliance reviews, and security documentation audits
  • * Ability to interpret technical findings from vulnerability scans, configuration assessments, and security reviews to support risk-based decision-making
  • * Experience providing technical guidance to engineering and operations teams to support corrective actions and POA&M closure
  • * Familiarity with continuous monitoring programs and ongoing authorization requirements
  • * Experience working with vulnerability management tools, compliance dashboards, and governance, risk, and compliance (GRC) platforms
  • * Knowledge of cloud security compliance, Zero Trust Architecture, and modern Federal cybersecurity initiatives
  • * Industry certifications such as:
  • + CISSP
  • + CAP (Certified Authorization Professional)
  • + Security+
  • + CISM
  • + GSLC
  • + CGRC
  • + or equivalent certifications
  • * Strong written, verbal, analytical, and interpersonal communication skills, with the ability to interact effectively with technical teams, auditors, system owners, and government stakeholders
  • * Experience supporting federal government programs, preferably within the FAA, Department of Transportation, or other civilian federal agencies
  • * FAA or transportation sector experience preferred

Qualifications

Must Haves

  • * Experience supporting cybersecurity compliance, security authorization, risk management, or information security programs
  • * Experience working with the NIST Risk Management Framework (RMF)
  • * Subject matter expertise with NIST SP 800-53 security controls and Federal cybersecurity compliance requirements
  • * Experience supporting the development, maintenance, or review of authorization package documentation, including SSPs, SARs, POA&Ms, and Risk Assessments
  • * Understanding of the Authorization to Operate (ATO) process and continuous monitoring requirements
  • * Experience tracking and managing POA&M findings through remediation and closure
  • * Ability to review technical security information and translate findings into compliance documentation and actionable recommendations
  • * Understanding of cybersecurity principles, security controls, vulnerability management, and risk management concepts
  • * Strong organizational skills with the ability to manage multiple systems, priorities, and compliance activities simultaneously
  • * Strong written and verbal communication skills, including the ability to develop and review formal security documentation
  • * Proficiency with Microsoft Office applications, particularly Excel, Word, and PowerPoint
  • * U.S. Citizen or Green Card Permanent Resident with a minimum of three (3) years of U.S. residency
  • * Ability to obtain and maintain an FAA Public Trust
  • * Bachelor's degree in Cybersecurity, Information Technology, Telecommunications, or a related field
  • * 9+ years of experience in cybersecurity or network security roles
  • * A High School degree with a total of 15 years of experience in cybersecurity or network security roles
  • * Masters degree with a total of 6 years of experience in cybersecurity or network security roles
  • * Bachelor's degree in Cybersecurity, Information Technology, Telecommunications, or a related field
  • * 12+ years of experience in cybersecurity or network security roles
  • * A High School degree with a total of 16 years of experience in cybersecurity or network security roles
  • * An Associates Degre with a total of 14 years of experience in cybersecurity or network security roles
  • * Masters degree with a total of 9 years of experience in cybersecurity or network security roles
  • * Masters degree in Cybersecurity, Information Technology, Telecommunications, or a related field
  • * 16+ years of experience in cybersecurity or network security roles
  • * A Bachelors degree with a total of 19 years of experience in cybersecurity or network security roles
  • * Experience serving as an Information System Security Officer (ISSO), Security Control Assessor (SCA), Information System Security Manager (ISSM), or similar cybersecurity compliance role
  • * Experience managing authorization packages for multiple systems simultaneously
  • * Strong knowledge of NIST SP 800-53 Rev. 5, NIST RMF, FISMA, and related Federal cybersecurity requirements
  • * Experience developing, reviewing, and maintaining SSPs, SARs, POA&Ms, Risk Assessments, Contingency Plans, and other authorization artifacts
  • * Experience conducting control assessments, compliance reviews, and security documentation audits
  • * Ability to interpret technical findings from vulnerability scans, configuration assessments, and security reviews to support risk-based decision-making
  • * Experience providing technical guidance to engineering and operations teams to support corrective actions and POA&M closure
  • * Familiarity with continuous monitoring programs and ongoing authorization requirements
  • * Experience working with vulnerability management tools, compliance dashboards, and governance, risk, and compliance (GRC) platforms
  • * Knowledge of cloud security compliance, Zero Trust Architecture, and modern Federal cybersecurity initiatives
  • * Industry certifications such as:
  • + CISSP
  • + CAP (Certified Authorization Professional)
  • + Security+
  • + CISM
  • + GSLC
  • + CGRC
  • + or equivalent certifications
  • * Strong written, verbal, analytical, and interpersonal communication skills, with the ability to interact effectively with technical teams, auditors, system owners, and government stakeholders

Nice to Haves

  • * Experience supporting federal government programs, preferably within the FAA, Department of Transportation, or other civilian federal agencies
  • * FAA or transportation sector experience preferred

Benefits

  • Health benefits
  • Life benefits
  • Disability benefits
  • Financial benefits
  • Retirement benefits
  • Paid leave
  • Professional development
  • Tuition assistance
  • Work-life programs
  • Award programs acknowledge employees for exceptional performance and superior demonstration of our service standards.
  • Full-time and part-time employees working at least 20 hours a week on a regular basis are eligible to participate in our benefit programs.
  • Remote/hybrid status is subject to change based on Noblis and/or government requirements.

More jobs like this