Summary
WINTrio LLC delivers technical and professional services, including cybersecurity and IT modernization solutions, to federal and commercial customers. The company is seeking an experienced Security Analyst to support USDA information systems by developing and maintaining RMF, Assessment & Authorization, and Authority to Operate documentation and packages. The role also involves coordinating with federal stakeholders, reviewing compliance artifacts, and supporting NIST and agency security requirements.
Responsibilities
- Collect, review, and update system information
- Create and maintain system records in Cybersecurity Assessment and Management System (CSAM)
- Develop/update and upload Privacy Threshold Analyses (PTAs)
- Perform and document system security categorization
- Develop/update Privacy Impact Assessments (PIAs)
- Develop/update E-Authentication Risk Assessments
- Maintain system identification information and system/technical narratives within CSAM
- Identify common and inherited security controls
- Develop and maintain compliance descriptions for security controls
- Support security-control tailoring
- Develop compensating controls where required
- Develop/update:
- Contingency Plans (CP)
- CP test, training, and exercise documentation
- System of Records Notices (SORN)
- Configuration Management Plans (CMP)
- Incident Response Plans (IRP)
- Business Impact Assessments (BIA)
- Interconnection Security Agreements (ISA)
- Finalize System Security Plan (SSP) compliance descriptions
- Finalize Contingency Plans
- Finalize CMPs, IRPs, and Disaster Recovery Plans where applicable
- Review RMF packages for completeness and readiness
- Assist USDA REE stakeholders in resolving findings and updating documentation during concurrence review
Skills
- U.S. Citizenship required
- Working knowledge of:
- NIST Risk Management Framework
- FIPS PUB 199
- NIST SP 800-53 Rev. 4/5
- NIST SP 800-37 Rev. 2
- NIST SP 800-171 Rev. 2
- NIST SP 800-47 Rev. 1
- Experience developing security-control implementation/compliance descriptions
- Experience developing Federal security and authorization documentation such as SSPs, CPs, CMPs, IRPs, BIAs, PIAs, ISAs, and related RMF artifacts
- Experience using CSAM or a comparable Federal governance, risk, and compliance/RMF system
- Experience completing all aspects of the NIST RMF process
- Ability to work collaboratively with system owners, ISSOs/ISSMs, technical teams, privacy personnel, and Government security stakeholders
- Strong technical writing, documentation, analytical, and quality-assurance skills
- Must be able to satisfy applicable background investigation/Public Trust, HSPD-12, PIV, and facility/system access requirements
- Previous experience supporting USDA RMF programs
- Working knowledge of:
- USDA Risk Management Framework 2.0
- USDA Six-Step RMF Process
- USDA Departmental Regulation 3540-003, Security Assessment and Authorization
- USDA POA&M procedures
- Hands-on experience with the USDA CSAM instance
- Previous USDA or other Federal civilian agency cybersecurity experience
- Experience obtaining ATOs for FedRAMP products, platforms, or solutions
- Experience supporting FISMA-regulated Federal systems
- Prior participation in similar Federal RMF/A&A projects
Qualifications
Must Haves
- U.S. Citizenship required
- Working knowledge of:
- NIST Risk Management Framework
- FIPS PUB 199
- NIST SP 800-53 Rev. 4/5
- NIST SP 800-37 Rev. 2
- NIST SP 800-171 Rev. 2
- NIST SP 800-47 Rev. 1
- Experience developing security-control implementation/compliance descriptions
- Experience developing Federal security and authorization documentation such as SSPs, CPs, CMPs, IRPs, BIAs, PIAs, ISAs, and related RMF artifacts
- Experience using CSAM or a comparable Federal governance, risk, and compliance/RMF system
- Experience completing all aspects of the NIST RMF process
- Ability to work collaboratively with system owners, ISSOs/ISSMs, technical teams, privacy personnel, and Government security stakeholders
- Strong technical writing, documentation, analytical, and quality-assurance skills
- Must be able to satisfy applicable background investigation/Public Trust, HSPD-12, PIV, and facility/system access requirements
Nice to Haves
- Previous experience supporting USDA RMF programs
- Working knowledge of:
- USDA Risk Management Framework 2.0
- USDA Six-Step RMF Process
- USDA Departmental Regulation 3540-003, Security Assessment and Authorization
- USDA POA&M procedures
- Hands-on experience with the USDA CSAM instance
- Previous USDA or other Federal civilian agency cybersecurity experience
- Experience obtaining ATOs for FedRAMP products, platforms, or solutions
- Experience supporting FISMA-regulated Federal systems
- Prior participation in similar Federal RMF/A&A projects
Benefits
- Healthcare, Medical, Dental, and Vision
- FSA and HSA options
- 401(k) Retirement Plan
- Annual Bonus and Profit Sharing Opportunities
- Paid Time Off
- Employee Assistance Program
- Life and Disability Insurance