WINTrio LLC logo
WINTrio LLC
Posted 16 days agoVerified live 14h ago

Security Analyst – Risk Management Framework (RMF) / Assessment & Authorization

Brief overview

Remote
UndergradOr in progress
3+ yrsMinimum
NIST Risk Management Framework (RMF)Assessment and Authorization (A&A)Authority to Operate (ATO)Cybersecurity Assessment and Management System (CSAM)NIST SP 800-53NIST SP 800-37NIST SP 800-171NIST SP 800-47Federal Security and Authorization DocumentationSecurity-Control Implementation and Compliance DescriptionsFedRAMPFISMA

About the company

WINTrio LLC logo
WINTrio LLCwintrio.com

Established in 2014, WINTrio LLC is an SBA 8(a)-certified, HUBZone, and ISO 9001/27001/20000-certified federal IT consulting firm.

Job description

Summary

WINTrio LLC delivers technical and professional services, including cybersecurity and IT modernization solutions, to federal and commercial customers. The company is seeking an experienced Security Analyst to support USDA information systems by developing and maintaining RMF, Assessment & Authorization, and Authority to Operate documentation and packages. The role also involves coordinating with federal stakeholders, reviewing compliance artifacts, and supporting NIST and agency security requirements.

Responsibilities

  • Collect, review, and update system information
  • Create and maintain system records in Cybersecurity Assessment and Management System (CSAM)
  • Develop/update and upload Privacy Threshold Analyses (PTAs)
  • Perform and document system security categorization
  • Develop/update Privacy Impact Assessments (PIAs)
  • Develop/update E-Authentication Risk Assessments
  • Maintain system identification information and system/technical narratives within CSAM
  • Identify common and inherited security controls
  • Develop and maintain compliance descriptions for security controls
  • Support security-control tailoring
  • Develop compensating controls where required
  • Develop/update:
  • Contingency Plans (CP)
  • CP test, training, and exercise documentation
  • System of Records Notices (SORN)
  • Configuration Management Plans (CMP)
  • Incident Response Plans (IRP)
  • Business Impact Assessments (BIA)
  • Interconnection Security Agreements (ISA)
  • Finalize System Security Plan (SSP) compliance descriptions
  • Finalize Contingency Plans
  • Finalize CMPs, IRPs, and Disaster Recovery Plans where applicable
  • Review RMF packages for completeness and readiness
  • Assist USDA REE stakeholders in resolving findings and updating documentation during concurrence review

Skills

  • U.S. Citizenship required
  • Working knowledge of:
  • NIST Risk Management Framework
  • FIPS PUB 199
  • NIST SP 800-53 Rev. 4/5
  • NIST SP 800-37 Rev. 2
  • NIST SP 800-171 Rev. 2
  • NIST SP 800-47 Rev. 1
  • Experience developing security-control implementation/compliance descriptions
  • Experience developing Federal security and authorization documentation such as SSPs, CPs, CMPs, IRPs, BIAs, PIAs, ISAs, and related RMF artifacts
  • Experience using CSAM or a comparable Federal governance, risk, and compliance/RMF system
  • Experience completing all aspects of the NIST RMF process
  • Ability to work collaboratively with system owners, ISSOs/ISSMs, technical teams, privacy personnel, and Government security stakeholders
  • Strong technical writing, documentation, analytical, and quality-assurance skills
  • Must be able to satisfy applicable background investigation/Public Trust, HSPD-12, PIV, and facility/system access requirements
  • Previous experience supporting USDA RMF programs
  • Working knowledge of:
  • USDA Risk Management Framework 2.0
  • USDA Six-Step RMF Process
  • USDA Departmental Regulation 3540-003, Security Assessment and Authorization
  • USDA POA&M procedures
  • Hands-on experience with the USDA CSAM instance
  • Previous USDA or other Federal civilian agency cybersecurity experience
  • Experience obtaining ATOs for FedRAMP products, platforms, or solutions
  • Experience supporting FISMA-regulated Federal systems
  • Prior participation in similar Federal RMF/A&A projects

Qualifications

Must Haves

  • U.S. Citizenship required
  • Working knowledge of:
  • NIST Risk Management Framework
  • FIPS PUB 199
  • NIST SP 800-53 Rev. 4/5
  • NIST SP 800-37 Rev. 2
  • NIST SP 800-171 Rev. 2
  • NIST SP 800-47 Rev. 1
  • Experience developing security-control implementation/compliance descriptions
  • Experience developing Federal security and authorization documentation such as SSPs, CPs, CMPs, IRPs, BIAs, PIAs, ISAs, and related RMF artifacts
  • Experience using CSAM or a comparable Federal governance, risk, and compliance/RMF system
  • Experience completing all aspects of the NIST RMF process
  • Ability to work collaboratively with system owners, ISSOs/ISSMs, technical teams, privacy personnel, and Government security stakeholders
  • Strong technical writing, documentation, analytical, and quality-assurance skills
  • Must be able to satisfy applicable background investigation/Public Trust, HSPD-12, PIV, and facility/system access requirements

Nice to Haves

  • Previous experience supporting USDA RMF programs
  • Working knowledge of:
  • USDA Risk Management Framework 2.0
  • USDA Six-Step RMF Process
  • USDA Departmental Regulation 3540-003, Security Assessment and Authorization
  • USDA POA&M procedures
  • Hands-on experience with the USDA CSAM instance
  • Previous USDA or other Federal civilian agency cybersecurity experience
  • Experience obtaining ATOs for FedRAMP products, platforms, or solutions
  • Experience supporting FISMA-regulated Federal systems
  • Prior participation in similar Federal RMF/A&A projects

Benefits

  • Healthcare, Medical, Dental, and Vision
  • FSA and HSA options
  • 401(k) Retirement Plan
  • Annual Bonus and Profit Sharing Opportunities
  • Paid Time Off
  • Employee Assistance Program
  • Life and Disability Insurance

More jobs like this