Information Security Analyst

Cherokee Federal

  • Washington, DC
  • 3 days ago

    Highlights

    Knowledge of Federal and Department of Homeland Security (DHS) policies and guidance, OMB A-123 attachment R-4300A, DISA STIGS, DHS hardening guidance, DHS Control Evaluation Matrix (CEM) framework, DHS CEM Testing and POA&M management . Support in performing IT Benchmarking tasks which are used to demonstrate through testing that a sufficiently strong IT internal control environment for CFO Systems (internal and external) is designed and operated effectively that will lead to a downgrade of the IT deficiencies.

    Numbers & Facts

    LocationWashington, DC

    Description

    Compensation & Benefits:

    Estimated Starting Salary Range for ​Information Security Analyst​: Starting $95,000

    Pay commensurate with experience.

    Full-time benefits include Medical, Dental, Vision, 401K, and other possible benefits as provided.  Benefits are subject to change with or without notice.

     

    ​​Information Security Analyst​ Responsibilities Include:

    • Provide Information Technology General Controls (ITGC) testing to develop and execute software test plans to identify procedural issues related to software configurations resulting in financial risk.

    • Assist stakeholders in designing, implementing, and effectively operating IT controls and processes that protect financial data.

    • Support in performing IT Benchmarking tasks which are used to demonstrate through testing that a sufficiently strong IT internal control environment for CFO Systems (internal and external) is designed and operated effectively that will lead to a downgrade of the IT deficiencies.

    • Assist in the development of a strategy that will enable the Benchmarks in consideration of available resources within the organization. Additional support is required to perform an initial A-123 ITGC assessment scoping each Fiscal Year (FY) based on the organization strategy.

    • Establish plans of action and milestones (POA&M) or Remediation Work Plans for all identified deficiencies within required timeframes per DHS 4300A and OCISO guidance.

    • Conduct Test of Design (TOD) for the IT program used for internal controls, over Financial Systems. Includes but not limited to evaluating the design of a control to determine whether the control should sufficiently address the corresponding control requirement and objective as well as relevant standards and regulations such as NIST 800-53, Rev. 5 and DHS Sensitive Systems Policy Directive 4300A.

    • Conduct Test of Effectiveness (TOE) for the IT program used for internal controls, over Financial Systems. Includes but not limited to evaluating the operating effectiveness of a control to determine whether the control is correctly implemented and operated as designed.

    • Provide support to ad-hoc IT Assessments to include but not limited to critical IT controls (CIC), Financial and related financial system ATOs, Accounting Treatment Manual Assessment and Testing (ATM), etc.

    • Collaborate with cross-functional teams to integrate security requirements into system planning, fieldwork, and reporting.

    • Work general supervision, relying on experience and judgment to plan and accomplish goals, while demonstrating a wide degree of creativity and latitude in problem-solving.

    • Report to a manager or head of a unit/department, providing regular updates on security initiatives, risks, and mitigation strategies.

    • Performs other job-related duties as assigned.

     

    ​​Information Security Analyst​ Experience, Education, Skills, Abilities requested:

    • Minimum education includes a bachelor’s degree in a business field, systems engineering, computers, or other related fields.

    • Minimum experience includes having two (2) years of government IT financial or system testing, including one year of federal internal controls ITGC experience. 

    • Knowledge of Federal and Department of Homeland Security (DHS) policies and guidance, OMB A-123 attachment R-4300A, DISA STIGS, DHS hardening guidance, DHS Control Evaluation Matrix (CEM) framework, DHS CEM Testing and POA&M management

    • Strong communication and interpersonal skills, with the ability to collaborate effectively with senior management, technical teams, and stakeholders.

    • Ability to work independently and prioritize tasks in a fast-paced environment.

    • Must be able to obtain a Public Trust and DHS suitability 

    • Must pass pre-employment qualifications of Cherokee Federal.

     

     

    Company Information:

    ​​Cherokee Nation System Solutions (CNSS)​ is a part of Cherokee Federal – the division of tribally owned federal contracting companies owned by Cherokee Nation Businesses. As a trusted partner for more than 60 federal clients, Cherokee Federal LLCs are focused on building a brighter future, solving complex challenges, and serving the government’s mission with compassion and heart. To learn more about ​CNSS​, visit cherokee-federal.com. 

     

    ​​#CherokeeFederal #LI​

     

    Cherokee Federal is a military friendly employer. Veterans and active military transitioning to civilian status are encouraged to apply.

     
    Similar Job Titles:

    1. IT Security Analyst

    1. Information Assurance Analyst

    1. Cybersecurity Analyst

    1. IT Risk Analyst

    1. Security Compliance Analyst

    Keywords:

    1. IT General Controls (ITGC)

    1. Risk Assessment

    1. Compliance Testing

    1. Security Controls

    1. Internal Audit

     

     

    Legal Disclaimer: Cherokee Federal is an equal opportunity employer. Please visit cherokee-federal.com/careers for information regarding our Affirmative Action and Equal Opportunity Employer Statement, and Accommodation request.

    Similar Jobs

    See more jobs