Information Security Analyst, Information Assurance / RMF

Nationwide IT Services
Alexandria, VA
Information Security Analyst, Information Assurance/RMF
Active Secret Required
Hybrid schedule
CISSP, CAP, or CISM certification required

Nationwide IT Services, NIS, is seeking an Information Security Analyst/Information Assurance/RMF for the following potential opportunity.

Core Responsibilities:
  • Support the execution of the full cybersecurity and RMF lifecycle for DoD and Federal systems, with emphasis on security control implementation, assessment, authorization, and continuous monitoring activities.
  • Perform vulnerability scanning and compliance validation, including, but not limited to, ACAS scanning, STIG assessments, SCAP validation, and configuration compliance checks.
  • Analyze vulnerability scan results, identify false positives, assess risk severity, and support remediation planning in coordination with engineering and operations teams.
  • Track, document, and manage remediation activities and Plans of Action and Milestones (POA&Ms) through closure, ensuring alignment with mandated timelines and risk tolerance.
  • Support RMF authorization activities, including initial ATOs, ATO renewals, significant change packages, and continuous authorization (cATO) efforts.
  • Support and execute Information Security Continuous Monitoring (ISCM) activities, including vulnerability trend analysis, control effectiveness validation, configuration drift monitoring, and security posture reporting.
  • Support the implementation and monitoring of Zero Trust security principles at a system level, including identity awareness, least privilege access, and continuous validation of users, devices, and workloads.
  • Prepare, review, and maintain cybersecurity and authorization artifacts in eMASS, including, but not limited to:
    • System Security Plans (SSPs)
    • Security Assessment Reports (SARs)
    • Plans of Action and Milestones (POA&Ms)
    • Control implementation narratives and supporting evidence packages
  • Conduct security control assessments and support independent verification and validation activities.
  • Assist with the implementation and maintenance of security controls aligned with NIST SP 800-53 and DoD cybersecurity requirements.
  • Coordinate with system owners, cybersecurity engineers, and program leadership to communicate security findings, risks, and remediation status.
  • Support cybersecurity audits, inspections, and Cyber Operational Readiness Assessments (CORA), ensuring accurate documentation and evidence traceability.
  • Assist in maintaining compliance with applicable cybersecurity policies, including FISMA, DoD RMF, DoD Zero Trust guidance, and the DoD Cloud Computing Security Requirements Guide (CC SRG).
Qualifications:
  • Active Secret clearance required.
  • Five or more years of experience in information security, information assurance, or cybersecurity operations, with experience supporting RMF-based programs.
  • Hands-on experience performing vulnerability scanning and compliance assessments using tools such as ACAS, STIG Viewer, and SCAP Compliance Checker.
  • Experience supporting RMF documentation and authorization packages, including SSPs, SARs, and POA&Ms.
  • Working knowledge of NIST SP 800-53, NIST RMF, and DoD cybersecurity policies.
  • Experience using eMASS to support RMF lifecycle activities and track authorization artifacts.
  • Familiarity with cloud security concepts and environments such as AWS GovCloud or Microsoft Azure Government.
  • One or more cybersecurity certifications required, including CISSP, CCSP, CISM, and CASP+ ( Renamed SecurityX)

Preferred Qualification:

  • Bachelor’s degree in Cybersecurity, Information Systems, Computer Science, or a related field.
About Nationwide IT Services
NIS is an IT and Management consulting company that is a CVE-verified Service-Disabled Veteran- Owned Small Business. Our mission is to deliver value-added services to our customers, leveraging technology, people, and industry best practices to implement innovative solutions through our trusted employees and team members.

Our benefits package includes medical, dental, and vision insurance, life and disability insurance, 401(k) plan with employer match, paid holidays, PTO (sick/vacation), commuter benefits, employee assistance program (EAP), and educational reimbursement, along with Pet Insurance.

Nationwide IT Services, Inc. provides equal employment opportunities (EEO) to all qualified applicants regardless of race, color, religion, sex, national origin, sexual orientation, gender identity, genetics, disability, or protected veteran status. for the following potential opportunity.

Core Responsibilities:
  • Support the execution of the full cybersecurity and RMF lifecycle for DoD and Federal systems, with emphasis on security control implementation, assessment, authorization, and continuous monitoring activities.
  • Perform vulnerability scanning and compliance validation, including, but not limited to, ACAS scanning, STIG assessments, SCAP validation, and configuration compliance checks.
  • Analyze vulnerability scan results, identify false positives, assess risk severity, and support remediation planning in coordination with engineering and operations teams.
  • Track, document, and manage remediation activities and Plans of Action and Milestones (POA&Ms) through closure, ensuring alignment with mandated timelines and risk tolerance.
  • Support RMF authorization activities, including initial ATOs, ATO renewals, significant change packages, and continuous authorization (cATO) efforts.
  • Support and execute Information Security Continuous Monitoring (ISCM) activities, including vulnerability trend analysis, control effectiveness validation, configuration drift monitoring, and security posture reporting.
  • Support the implementation and monitoring of Zero Trust security principles at a system level, including identity awareness, least privilege access, and continuous validation of users, devices, and workloads.
  • Prepare, review, and maintain cybersecurity and authorization artifacts in eMASS, including, but not limited to:
    • System Security Plans (SSPs)
    • Security Assessment Reports (SARs)
    • Plans of Action and Milestones (POA&Ms)
    • Control implementation narratives and supporting evidence packages
  • Conduct security control assessments and support independent verification and validation activities.
  • Assist with the implementation and maintenance of security controls aligned with NIST SP 800-53 and DoD cybersecurity requirements.
  • Coordinate with system owners, cybersecurity engineers, and program leadership to communicate security findings, risks, and remediation status.
  • Support cybersecurity audits, inspections, and Cyber Operational Readiness Assessments (CORA), ensuring accurate documentation and evidence traceability.
  • Assist in maintaining compliance with applicable cybersecurity policies, including FISMA, DoD RMF, DoD Zero Trust guidance, and the DoD Cloud Computing Security Requirements Guide (CC SRG).
Qualifications:
  • Active Secret clearance required.
  • Bachelor’s degree in Cybersecurity, Information Systems, Computer Science, or a related field.
  • Five or more years of experience in information security, information assurance, or cybersecurity operations, with experience supporting RMF-based programs.
  • Hands-on experience performing vulnerability scanning and compliance assessments using tools such as ACAS, STIG Viewer, and SCAP Compliance Checker.
  • Experience supporting RMF documentation and authorization packages, including SSPs, SARs, and POA&Ms.
  • Working knowledge of NIST SP 800-53, NIST RMF, and DoD cybersecurity policies.
  • Experience using eMASS to support RMF lifecycle activities and track authorization artifacts.
  • Familiarity with cloud security concepts and environments such as AWS GovCloud or Microsoft Azure Government.
  • One or more cybersecurity certifications required, including CISSP, CCSP, CISM, and CASP+ ( Renamed SecurityX)
About Nationwide IT Services
NIS is an IT and Management consulting company that is a CVE-verified Service-Disabled Veteran- Owned Small Business. Our mission is to deliver value-added services to our customers, leveraging technology, people, and industry best practices to implement innovative solutions through our trusted employees and team members.

Our benefits package includes medical, dental, and vision insurance, life and disability insurance, 401(k) plan with employer match, paid holidays, PTO (sick/vacation), commuter benefits, employee assistance program (EAP), and educational reimbursement, along with Pet Insurance.

Nationwide IT Services, Inc. provides equal employment opportunities (EEO) to all qualified applicants regardless of race, color, religion, sex, national origin, sexual orientation, gender identity, genetics, disability, or protected veteran status.

Posted 2026-01-16

Recommended Jobs

Associate Veterinarian

The VET Recruiter
Fairfax County, VA

Associate Veterinarian – Fairfax County, VA #2294 Do you have a particular passion you want to dive into or skill you want to acquire? We want to help you develop it when you join our close-knit …

View Details
Posted 2026-01-07

SAP NS2 AI Consultant

SAP
Herndon, VA

We help the world run better At SAP, we keep it simple: you bring your best to us, and we'll bring out the best in you. We're builders touching over 20 industries and 80% of global commerce, and w…

View Details
Posted 2025-10-23

Commercial HVAC Service Technician

AIR Control Concepts
Norfolk, VA

Job Title : Commercial HVAC Service Technician Job Location : Norfolk, VA Operating Company: Hobbs & Associates FLSA Status: Non-Exempt About: The Commercial HVAC Service Technicia…

View Details
Posted 2026-01-09

THREE DevOps Senior Developers (AWS, Docker, Kubernetes, CICD, Automation, Groovy DSL, Jenkins, Ansible, Maven) in McLean, VA

DBA Web Technologies
McLean, VA

THREE DevOps Senior Developers (AWS, Docker, Kubernetes, CICD, Automation, Groovy DSL, Jenkins, Ansible, Maven) in McLean, VA AWS, CD, CI, Docker, Jenkins, Kubernetes Location: Virginia Job Functi…

View Details
Posted 2026-01-29

Hardwood Lumber Sales Representative

Woodgrain
Independence, VA

Hardwood Lumber Sales Representative Woodgrain is looking for an experienced  Hardwood Lumber Sales Representative for our Independence, VA and Elkin, NC sawmills to join our team!   About Woo…

View Details
Posted 2025-07-24

Signals Intelligence SME (SIGINT SME)

Peraton
McLean, VA

Program Overview About The Role Peraton is seeking experienced Signals Intelligence SMEs (SIGINT SME) to join our talented team of technical and business experts providing key operational a…

View Details
Posted 2026-01-21

Prog Admin Manager III

Virginia Department of Transportation
Colonial Heights, VA

Job Identification 11513 Job Category Program Administration Posting Date 01/30/2026, 08:19 PM Locations Richmond District Office Apply Before 02/14/2026, 04:59 AM Job Schedule Full …

View Details
Posted 2026-01-28

Master HVAC Tech

Sterling, VA

Job Title: Master HVAC Tech Category:  Construction Description: 10+ year HVAC install tech with CFC certification and Class-A interior experience Location  Sterling , VA Minimum Experie…

View Details
Posted 2026-01-29

Architect Engineering Mgr II

Virginia Department of Transportation
Wytheville, VA

Job Identification 11538 Job Category Architecture and Engineering Services Posting Date 01/15/2026, 07:04 PM Locations BRISTOL DISTRICT OFFICE Job Schedule Full time State Role Titl…

View Details
Posted 2026-01-21

Pet Bather (HAMPTON)

PetSmart
Hampton, VA

PetSmart does Anything for Pets JOIN OUR TEAM! Pet Bather About Life at PetSmart At PetSmart, Anything for Pets begins with our people. Every associate plays a vital role in creating meaningful…

View Details
Posted 2026-02-03