Demo

Information Security Analyst 3

C-HIT
Columbia, MD Full Time
POSTED ON 6/16/2026
AVAILABLE BEFORE 8/16/2026

Job Description: The Information Security Officer (ISO) will work closely with Project and Technical management to plan, design and implement Dynamic Application Security Testing (DAST) and/or Static Application Security Testing (SAST) security methodologies into the technical solution of a program within the Centers for Medicare and Medicaid Services (CMS). The ISO will be responsible for assuring all CMS security and privacy considerations and requirements are assessed, addressed and documented for the given application, designing the solution so that it passes the required Annual Security Assessment Testing (within CMS referred to ACT or Adaptive Capabilities Testing) and maintains the system Authority to Operate (ATO).  

The primary responsibilities of the position include but are not limited to:

· Promote a professional work ethic with the ability to meet commitments, scheduled timelines and take ownership of problems.

· Lead, support and document all security incident response activities.

· Perform annual security assessment audits (such as ACT, PenTest, etc.).

· Perform Web Application Penetration and Continuous Diagnostic Monitoring (CDM) testing.

· Mitigate and/or address the security specific vulnerabilities and document via Plan of Action and Milestones (POA&M).

· Support ad hoc security requests from the customer and program management.

· Conduct security impact assessments for new or existing architecture changes.

Required Skills:

· 3 years of experience with NIST and Federal security documentation.

· Active CISSP or equivalent security related certification.

· Capable of obtaining Level Five: Public Trust security clearance.

· Proven experience with FISCAM and FedRAMP requirements.

· Experience writing and maintaining security related documents, including the System Security Plan (SSP), Contingency Plan and Test (CP), Information System Risk Assessment (ISRA), Security Assessment Plan/Report (SAP/SAR) and the Privacy Impact Assessment (PIA).

· Ability to resolve complex support issues by leveraging user forums, support forums, or opening support cases with vendors and following them to closure. Strong ability to find mitigation and alternative approaches.

· Knowledge of current as well as emerging security threats.

· Understanding of and experience with Agile Development and DevSecOps/DevOps.

· Proven experience with Cloud Technologies (AWS)

· Proven experience with Microsoft Office Tools (Outlook, Word, Excel, PowerPoint).

Desired Skills and Certifications:

· Working experience within CMS including with CMS Information Systems Security and Privacy Policy (IS2P2), NIST 800-53, NIST 800-63, CMS Acceptable Risk Safeguards (ARS), CMS Risk Management Handbook (RMH) and CMS Federal Information Security Management Act (FISMA) Controls Tracking System (CFACTS).

· Proven experience with Security tools such as Burp, SonarQube, AWS Security Tools

· Proven experience with networking concepts, such as, DHCP, DNS, VLANs, Routing and VPNs

Salary & Benefits Information: 

  • The actual salary offer will carefully consider a wide range of factors, including your skills, qualifications, experience, and location. 
  • C-HIT offers Healthcare Benefits, Remote Working Options, Paid Time Off, PTO cash-out, Training/Certification opportunities, Healthcare Savings Account & Flexible Savings Account, Paid Life Insurance, Short-term & Long-term Disability, 401K Match, Employee Assistance Program, Paid Holidays, and much more perks and Voluntary benefits! 
  • Employees of C-HIT shall, as an enduring obligation throughout their term of employment, adhere to all information security requirements as documented in company policies and procedures. 

C-HIT, a CMMI Maturity Level 5 company, focuses on delivering information technology and professional services to Federal and State agencies. 

“C-HIT is an EOE, including disability and veterans”

Salary.com Estimation for Information Security Analyst 3 in Columbia, MD
$106,119 to $127,636
If your compensation planning software is too rigid to deploy winning incentive strategies, it’s time to find an adaptable solution. Compensation Planning
Enhance your organization's compensation strategy with salary data sets that HR and team managers can use to pay your staff right. Surveys & Data Sets

What is the career path for a Information Security Analyst 3?

Sign up to receive alerts about other jobs on the Information Security Analyst 3 career path by checking the boxes next to the positions that interest you.
Income Estimation: 
$112,673 - $137,290
Income Estimation: 
$139,945 - $168,577
Income Estimation: 
$140,233 - $181,029
Income Estimation: 
$161,209 - $233,553
Income Estimation: 
$140,233 - $181,029
Income Estimation: 
$164,835 - $201,088
Income Estimation: 
$135,994 - $168,063
Income Estimation: 
$161,209 - $233,553
Income Estimation: 
$70,462 - $84,818
Income Estimation: 
$77,991 - $108,747
Income Estimation: 
$87,093 - $107,335
Income Estimation: 
$140,233 - $181,029
Income Estimation: 
$161,209 - $233,553
Income Estimation: 
$87,093 - $107,335
Income Estimation: 
$111,725 - $147,313
Income Estimation: 
$112,673 - $137,290
Income Estimation: 
$140,233 - $181,029
Income Estimation: 
$161,209 - $233,553
Income Estimation: 
$112,673 - $137,290
Income Estimation: 
$139,945 - $168,577
Income Estimation: 
$140,233 - $181,029
Income Estimation: 
$161,209 - $233,553
Employees: Get a Salary Increase
View Core, Job Family, and Industry Job Skills and Competency Data for more than 15,000 Job Titles Skills Library

Job openings at C-HIT

  • C-HIT Columbia, MD
  • Job Summary: Full Stack Developer is responsible for designing, developing, testing, and maintaining front-end and back-end components of enterprise applic... more
  • 10 Days Ago

  • C-HIT Columbia, MD
  • Job Summary Business Analyst / Scrum Master facilitates Agile Scrum processes while also serving as a liaison between business stakeholders and technical t... more
  • 10 Days Ago

  • C-HIT Columbia, MD
  • Job Summary MuleSoft Developer/Admin (API Integration Specialist) is responsible for designing, developing, deploying, and supporting APIs and integrations... more
  • 10 Days Ago

  • C-HIT Columbia, MD
  • Position Overview Operations Lead is responsible for overseeing day‑to‑day operational activities, ensuring smooth execution of business processes, team co... more
  • 10 Days Ago


Not the job you're looking for? Here are some other Information Security Analyst 3 jobs in the Columbia, MD area that may be a better fit.

  • DLA Piper Baltimore, MD
  • DLA Piper is, at its core, bold, exceptional, collaborative and supportive. Our people are the backbone, heart and soul of our firm. Wherever you are in yo... more
  • 2 Days Ago

  • Sigma Defense Belcamp, MD
  • Sigma Defense is currently seeking an Information Security Analyst to work in support of the Army for the Network Modernization & Mission Network Technical... more
  • 3 Days Ago

AI Assistant is available now!

Feel free to start your new journey!