System Security Analyst (FedRamp)

Flex Staffing Resources
Herndon, VA

System Security Analyst (FedRAMP/FISMA)

Location Employment Type Work Model
Herndon, VA 20171 Full-Time Employee (FTE) + Benefits Hybrid (4 Days Remote / 1 Day On-Site)
Citizenship Experience Clearance
U.S. Citizenship Required 5+ Years Public Trust

About the Role

Join the team as a Senior System Security Analyst and play a critical role in securing the future of our cloud offerings. You will be the essential link responsible for driving and achieving FedRAMP and FISMA authorizations for new Cloud Products and Third-Party Applications across various cloud environments (including commercial, FedRAMP, and DOD).

This is a technical, hands-on position where you will bridge the gap between our Security, Engineering, Build, and Operations teams. You will gather critical technical control implementation details and translate them into accurate, high-quality security documentation, including System Security Plans (SSPs) . If you are a self-motivated expert who thrives on ensuring continuous compliance, performing in-depth analysis, and making thoughtful security recommendations, this position offers high impact and autonomy.

What You'll Do (Key Responsibilities)

Authorization & Documentation Leadership

  • Lead and support all aspects of the FedRAMP and FISMA authorization process, including preparing Engineering, Build, and Operations teams through training and mock interviews.

  • Serve as the primary liaison for security-related data gathering, working directly with technical teams to accurately document security control implementation in the SSP.

  • Develop, update, and manage essential security documentation, including System Security Plans (SSPs), policies, procedures, and technical implementation language.

  • Conduct thorough Security Impact Analyses for changes to the environment and provide expert, actionable recommendations to senior management.

  • Interpret and communicate the intent of FedRAMP Moderate and FISMA security controls to technical and non-technical stakeholders.

Security Assessment & Monitoring

  • Configure, execute, and perform in-depth analysis of vulnerability scans using industry tools (e.g., Nessus/Security Center, WebInspect).

  • Evaluate vulnerability scan data and control implementation to identify risks and suggest robust remediation strategies.

  • Identify and assess the security posture of cloud systems, including RMF package status, patching compliance, and Cyber Security Vulnerability Assessment (CSVA) mechanisms.

  • Support ongoing activities and effectively respond to customer/Agency inquiries regarding compliance status.

Technical Analysis & Communication

  • Interpret and assess complex technical artifacts, including network diagrams (Visio), logical/physical system diagrams, and data flow diagrams.

  • Utilize tools such as Splunk to execute queries, search, and review data for security impact analysis and continuous monitoring.

  • Prepare and deliver clear, concise written and oral presentations of complex technical material to all levels of IT and business management.

What You'll Bring (Required Qualifications)

  • Experience: Minimum 5 years of experience in Information Technology, with a strong focus on Information Security, Security Engineering, or a related technical discipline.

  • Government Framework Expertise: Proven, hands-on experience with FedRAMP and/or other government authorization processes (e.g., FISMA, DOD), and a deep understanding of the NIST Risk Management Framework (RMF) and NIST 800-53 controls.

  • Vulnerability Management: Direct experience in the execution and detailed analysis of vulnerability scans using industry-standard tools (e.g., Nessus/Security Center, WebInspect).

  • Technical Documentation: Demonstrated ability to document information system specifications and security controls.

  • Communication: Excellent communication skills and the proven ability to work effectively with cross-functional teams (Security, Engineering, and Operations).

  • Education: Bachelor’s Degree in Computer Science, MIS, Information Technology, or equivalent professional experience.

Bonus Points (Desired Skills & Certifications)

  • Cloud Technologies: Experience with major Cloud Service Providers, specifically AWS and Azure .

  • Security Certifications: Professional certifications such as ISC CISSP , ISACA CISM , or equivalent.

  • Security Architecture: Experience in developing, evaluating, and implementing information security architectures, technologies, and best practices.

  • Tooling: Familiarity with Splunk for security data analysis.

Posted 2025-10-28

Recommended Jobs

Early Childhood - Teacher Assistant/Aide

Amazing Childcare and Learning Academy
Hampton, VA

Summary Amazing Childcare and Learning Academy is dedicated to providing high-quality early childhood education with a focus on kindergarten readiness. Our program utilizes a state-approved curr…

View Details
Posted 2025-09-25

HR Specialist & Office Manager - Top Secret Clearance REQUIRED

McLean, VA

Job description: We are looking for a hands-on and people focused HR Specialist & Office Manager to join our Washington DC team. In this role you will be the go-to person for HR processes and of…

View Details
Posted 2025-10-20

Embrace New Beginnings in Beautiful Warrenton, VA!

NurseRecruiter
Warrenton, VA

RN Labor and Delivery job in Warrenton, VA Embrace the opportunity to work as a Registered Nurse in the picturesque town of Warrenton, VA, renowned for its charming historic districts, vibrant arts s…

View Details
Posted 2025-08-19

Senior Software Engineer, Full Stack (Bank Tech)

Capital One
McLean, VA

Senior Software Engineer, Full Stack (Bank Tech) Do you love building and pioneering in the technology space? Do you enjoy solving complex business problems in a fast-paced, collaborative, in…

View Details
Posted 2025-09-23

Lead Data Engineer (AWS, Azure, GCP)

Captech Consulting
Richmond, VA

Company Description CapTech is an award-winning consulting firm that collaborates with clients to achieve what’s possible through the power of technology. At CapTech, we’re passionate about the …

View Details
Posted 2025-10-22

Biomed Technician

Scientific Safety Alliance
Virginia Beach, VA

Biomedical Technician  Location:  Hybrid (Virginia Beach) - 50% Travel Compensation:  up to $33/hour + Bonus + Equity Start Date: ASAP Scientific Safety Alliance Scientific Safety Allia…

View Details
Posted 2025-09-01

Sales Manager

Victory Nissan of Mechanicsville
Mechanicsville, VA

Sales Manager Company Description  Victory Automotive Group is family owned and operated since 1997 with over 50 locations across the United States. We provide the best opportunities for all em…

View Details
Posted 2025-10-29

Warehouse Associate

A-1 DISTRIBUTION INC
Sterling, VA

Job Description Job Description Benefits/Perks Flexible Schedule  Competitive Pay Career Advancement Job Summary We are seeking an energetic and motivated Warehouse Associate to j…

View Details
Posted 2025-07-29