Senior Information Security Analyst

Data Systems Analysts
Oakton, VA

DSA is hiring a Senior Information Security Analyst. This is a full-time position supporting a customer in the DC Metro area with a HYBRID Schedule. This position supports the Environmental Protection Agency (EPA). DSA is the Prime and has been working with this customer on this contract for more than 13 years. It is a dynamic team with a passion for supporting Federal programs that serve U.S. citizens.

Location is Hybrid: Allows the candidate the ability to work onsite at DSA or customer site with potential for telework. DSA work locations include Fairfax, VA.

Work Location is flexible with telework as approved. The ability to work onsite each week is required. Core work hours dedicated to DSA and our direct customers are 8 am est to 5 pm est.

The Environmental Protection Agency (EPA) Office of Information Security and Privacy (OISP) is responsible for developing and maintaining agency-wide information security and privacy programs; developing and maintaining information security and privacy policies, procedures, and control techniques; training personnel with significant information security responsibilities and assisting senior agency officials with information security and privacy responsibilities.

The Senior Information Security Analyst will be an integral part of a team responsible for supporting the development and maturation of an Agency-wide information security (InfoSec) program for a large civilian Federal agency. The candidate will serve as a subject matter expert with regards to the Risk Management Framework (RMF) and all associated information security policies and procedures and should possess in-depth knowledge of applying, selecting and testing the NIST family of security controls.

Primary Responsibilities:


  • Advising senior-level stakeholders on InfoSec initiatives including compliance, awareness and training, and security operations.

  • Leading Independent Validation and Verification (IV&V) efforts on security authorization/ATO packages to ensure compliance with agency requirements.

  • Leveraging the existing Governance, Risk, and Compliance (GRC) tool, Telos Xacta (or an alternate like CSAM or RSA Archer), to track and reconcile findings from assessments, audits, and vulnerability scans.

  • Coordinating government data calls (FISMA, FMFIA, BDR, etc.) and monthly reports.

  • Assessing the effectiveness of the InfoSec and privacy training program and leading the collection, analyzing, and presentation of enterprise-level InfoSec performance metrics.

  • Managing InfoSec Program POA&Ms, including advising on remediation efforts.

  • Working closely with senior agency security officials, system owners, information system security officers (ISSOs) and other stakeholders to advise and implement security solutions.

  • Identify opportunities for efficiencies in work process and innovative approaches.

  • Participating in team problem solving efforts and offer ideas to solve client issues.

  • Conducting relevant research, data analysis, and developing reports.

  • Preparing and assisting in the development of policy and procedures.

  • Implementing processes and procedures to monitor risk across programs / projects.

  • Preparing briefings to the executive team to debrief the results of studies, analyses, and plans.

  • Assisting the client leadership in reviewing monthly project progress, documenting issues, and monitoring resolution.


Required Qualifications:


  • Ability to obtain a Public Trust.

  • Bachelor’s degree in information technology or related field and 8 years of relevant IA experience. May substitute security certification (e.g. CISSP) for 2 years of experience.

  • 3+ years in a leadership role

  • Strong data analysis skills.

  • Excellent written and verbal communication skills.

  • Possess in-depth knowledge of applying, selecting and testing the NIST 800-53 Rev 4 security controls.

  • Possess in-depth knowledge of NIST 800-37 Risk Management Framework.

  • Experience with a Governance, Risk and Compliance tool (e.g., Xacta, RSA Archer, CSAM or eMASS).

  • Excellent attention to detail.

  • Ability to handle and prioritize multiple tasks and deadlines.


Desired Qualifications:


  • Advanced level cybersecurity certification (e.g., CompTIA CISM, ISC2 CISSP)

  • In-depth knowledge of applying, selecting and testing the NIST 800-53 Rev 5 security controls

#DSA209

#LI-CW1

Many of DSA's positions require the ability to obtain a security clearance. Security clearances may only be granted to U.S. citizens. In addition, applicants who accept a conditional offer of employment may be subject to government security investigation(s) and must meet eligibility requirements for access to classified information. DSA is proud to be an Equal Opportunity Employer. DSA is committed to treating all employees and applicants for employment with respect and dignity and maintaining a workplace that is free from unlawful discrimination. All qualified applicants will receive consideration for employment without regard to race, color, sex, sexual orientation, gender identity, religion, national origin, disability, veteran status, or other legally protected status. DSA requires background checks , where permitted , by law. DSA is an E-Verify Employer.

Posted 2025-09-12

Recommended Jobs

Pharmacist, Clinical Staff OOJ - 32701

Hatch Global Search
Roanoke, VA

Job Description A clinical staff pharmacist is a healthcare professional who actively collaborates with other medical staff to optimize medication therapy for patients by reviewing prescriptions, …

View Details
Posted 2025-09-29

Space Program Manager, Finance Operations, Regional Portfolio Management (RPM-AMER) GREF

Amazon.com Services LLC
Arlington, VA

DESCRIPTION Work hard, have fun, make history. That's what we do every day at Amazon. As a key leader within Amazon's Global Real Estate & Facilities (GREF) team, the regional Space Program Manage…

View Details
Posted 2025-10-06

Maintenance Coordinator

Real Property Management
Richmond, VA

We are searching for a dedicated and driven Maintenance Coordinator for Real Property Management-Richmond Metro. The Maintenance Coordinator is responsible for managing the business' maintenance div…

View Details
Posted 2025-08-06

Veterinarian - General Practice

Pender Veterinary Center - Manassas
Manassas Park, VA

Pender Veterinary Centre – Manassas is looking for an Associate Veterinarian! ***Competitive Salary, Generous Sign-On and Retention Bonuses, Relocation Available*** We are seeking a compassion…

View Details
Posted 2025-10-21

Customer Service Representative

UniFirst
Winchester, VA

As a CSR, you are responsible for handling inbound/outbound customer inquiries through both phone and e-mail. You will be responsible for providing adequate customer service in a professional manner.…

View Details
Posted 2025-10-07

Action Officer - intermediate

Tenica and Associates
Chantilly, Loudoun County, VA

TENICA is looking to hire action officers, TS/SCI with CI poly.  Job location: Chantilly, VA   Responsibilities:  -          Provide senior executive level support -          Track actions; evalu…

View Details
Posted 2025-08-06

Licensed Veterinary Technician (LVT)

Catoctin Veterinary Clinic
Leesburg, VA

Are you a Licensed Veterinary Technician looking for full-time or part-time work?We are a small animal clinic who has been serving Loudoun County since 1978. We have four veterinarians on staff and s…

View Details
Posted 2025-10-18

Senior Workers Compensation Claim Representative

Travelers
Richmond, VA

Who Are We? Taking care of our customers, our communities and each other. That’s the Travelers Promise. By honoring this commitment, we have maintained our reputation as one of the best property ca…

View Details
Posted 2025-09-30