Demo

Information Systems Security Analyst

CTAC
Falls, VA Full Time
POSTED ON 12/26/2025
AVAILABLE BEFORE 2/25/2026

Job Details

Description:

CTAC is seeking an experienced Information Systems Security Analyst to support a federal program focused on achieving and sustaining an Authority to Operate (ATO) for a complex, multi-tenant AWS cloud environment. This role is a key member of CTACs federal delivery team and is responsible for executing Risk Management Framework (RMF) activities across the full NIST lifecycle, with a strong emphasis on control validation, documentation, evidence development, and assessor engagement.

The ideal candidate will bring deep hands-on experience supporting federal ATOs, implementing NIST SP 800-53 controls, managing POA&Ms, and working directly with cloud engineers, architects, and Authorizing Officials to remediate security gaps and maintain continuous authorization readiness. This position requires a balance of technical security expertise, disciplined documentation, and the ability to operate effectively in a fast-paced, sprint-based delivery model.

Key Responsibilities

*

Execute and support the full NIST Risk Management Framework (RMF) lifecycle (Categorize, Select, Implement, Assess, Authorize, Monitor) for ORNLs AWS multi-tenant platform.

*

Perform control-by-control gap analysis against NIST SP 800-53, identifying incomplete, partially implemented, or undocumented controls.

*

Develop, update, and maintain RMF artifacts, including:

*

System Security Plan (SSP)

*

Control implementation narratives

*

POA&M

*

Continuous Monitoring documentation

*

Objective evidence mappings

*

Partner closely with cloud architects and engineers to validate technical control implementations and support remediation activities within AWS.

*

Support assessment and authorization activities, including direct engagement with assessors, auditors, and ORNL security stakeholders.

*

Track, document, and manage risks, findings, and remediation activities in accordance with federal RMF expectations.

*

Ensure security documentation accurately reflects the operational state of the environment and remains audit-ready throughout the engagement.

*

Support the use of governance, risk, and compliance (GRC) tools (e.g., eMASS, Kion, or equivalent) to manage controls, evidence, and reporting.

*

Contribute to sprint planning and execution by aligning RMF activities with engineering and documentation deliverables.

*

Assist in the development or refinement of security policies, procedures, and standards where gaps exist.

*

Provide subject matter expertise on federal security requirements, best practices, and emerging guidance relevant to cloud-hosted systems



Requirements:

*

Bachelors degree in Information Security, Cybersecurity, Information Technology, or a related discipline (or equivalent experience).

*

10 years of progressive experience in cybersecurity, information assurance, or RMF-focused security roles supporting federal systems.

*

Demonstrated hands-on experience supporting ATO packages for federal cloud or hybrid environments.

*

Deep working knowledge of:

*

NIST SP 800-53

*

NIST SP 800-37

*

FISMA requirements

*

Federal A&A processes

*

Strong experience developing and maintaining SSPs, POA&Ms, and RMF evidence.

*

Experience working with cloud (Amazon Web Services) security environments, including validation of technical control implementations.

*

Ability to clearly document complex technical and compliance concepts for both technical and non-technical audiences.

*

Proven ability to collaborate across engineering, security, and program management teams.
Strong analytical, organizational, and communication skills.

*

Ability to obtain and maintain a Public Trust (or higher) clearance.

Preferred Qualifications

*

Masters degree in Cybersecurity, Information Systems, or a related field.

*

Active CISSP and/or CISM certification.

*

Experience supporting multi-tenant cloud platforms and control inheritance models.

*

Familiarity with Infrastructure as Code (IaC) concepts and how automation supports compliance.

*

Experience supporting federal research, scientific, or mission-driven environments.

*

Prior experience working in agile or sprint-based delivery models for RMF execution.

CTAC is an equal opportunity employer. Qualified applicants will receive consideration for employment without regard to race, color, religion, sex, age, sexual orientation, gender identity, national origin, disability, or protected veteran status. VEVRAA Federal Contractor
Employers have access to artificial intelligence language tools (“AI”) that help generate and enhance job descriptions and AI may have been used to create this description. The position description has been reviewed for accuracy and Dice believes it to correctly reflect the job opportunity.

Salary.com Estimation for Information Systems Security Analyst in Falls, VA
$115,981 to $136,597
If your compensation planning software is too rigid to deploy winning incentive strategies, it’s time to find an adaptable solution. Compensation Planning
Enhance your organization's compensation strategy with salary data sets that HR and team managers can use to pay your staff right. Surveys & Data Sets

What is the career path for a Information Systems Security Analyst?

Sign up to receive alerts about other jobs on the Information Systems Security Analyst career path by checking the boxes next to the positions that interest you.
Income Estimation: 
$70,462 - $84,818
Income Estimation: 
$77,991 - $108,747
Income Estimation: 
$87,093 - $107,335
Income Estimation: 
$140,233 - $181,029
Income Estimation: 
$161,209 - $233,553
Income Estimation: 
$164,835 - $201,088
Income Estimation: 
$102,189 - $143,024
Income Estimation: 
$135,994 - $168,063
Income Estimation: 
$161,209 - $233,553
View Core, Job Family, and Industry Job Skills and Competency Data for more than 15,000 Job Titles Skills Library

Not the job you're looking for? Here are some other Information Systems Security Analyst jobs in the Falls, VA area that may be a better fit.

  • Information Systems Solutions, Inc. Suitland, MD
  • Description Information Systems Solutions (ISS) is looking for a mid-level ISSE supporting the Office of Naval Intelligence. The Information Systems Securi... more
  • 26 Days Ago

  • Data Systems Analysts, Inc. Fairfax, VA
  • DSA is hiring a Senior Information Security Analyst. This is a full-time position supporting a customer in the DC Metro area with a HYBRID Schedule. This p... more
  • 19 Days Ago

AI Assistant is available now!

Feel free to start your new journey!