IT Business Analyst/Project Manager

Posted Yesterday
Washington, DC, USA
In-Office
125K-130K Annually
Mid level
Information Technology • Software
The Role
Manages High Value Asset cybersecurity compliance for Department of State systems, including FISMA reporting, assessments, vulnerability remediation, penetration testing, configuration management, and cybersecurity dashboard monitoring. Analyzes current information systems and databases, gathers stakeholder requirements, documents processes and architecture, and develops modernization recommendations and roadmaps. Supports requirements development, user acceptance testing, implementation, change management, training, and coordination with IT offices, vendors, and external stakeholders.
Summary Generated by Built In

The Office of International Visitors and U.S. Speaker Program (OIV) within the Bureau of Educational and Cultural Affairs (ECA), Professional Exchanges, Office of International Visitors (ECA/PE/V) in Washington, DC, needs to hire a full-time IT Business Analyst/Project Manager to support the Office of International Visitors and U.S. Speaker Program (OIV).

The incumbent will serve as an IT Business Analyst/Project Manager in the U.S. Department of State's (DOS) Bureau of Educational and Cultural Affairs (ECA) under the authority of the Fulbright-Hays Act of 1961 as amended and the Smith-Mundt Act of 1948.  The International Visitor Leadership Program (IVLP) is a professional exchange program that strengthens bilateral and multilateral relations, which advance U.S. positions on global issues.  The position has two primary areas of responsibility: (1) fulfilling High Value Asset (HVA) compliance requirements for IVLP data, currently in the International Visitor Leadership Program Resource Center (IVRC) platform, and (2) conducting a comprehensive analysis and modernization of the office's current information systems and databases. Incumbent will serve under the direction of a Division/Branch Chief to support the IVLP mission and enhance operational efficiency.

The IT Business Analyst/Project Manager will serve in the Office of International Visitors and U.S. Speaker Program at the U.S. Department of State's Bureau of Educational and Cultural Affairs.  The incumbent will be responsible for ensuring compliance with federal HVA requirements and conducting comprehensive analysis and modernization of the office's information technology systems and databases.

The IT Business Analyst/Project Manager position is responsible for managing HVA compliance activities and conducting information systems analysis and modernization.  The incumbent will have broad, independent responsibilities and authority to ensure successful fulfillment of all HVA requirements and provide strategic recommendations for technology improvements.

Job Duties:

HVA System Management and Compliance:

  • Provide updated high value asset (HVA) system information during quarterly and annual data calls as required by the Department's HVA Oversight Program
  • Ensure that the HVA Security Control Overlay for the IVRC system (or a subsequent platform) is implemented
  • Ensure that the IVRC system (or a subsequent platform) meets Department Continuous Diagnostics and Mitigation (CDM) requirements
  • Maintain ongoing authorization of the IVRC system (or a subsequent platform)
  • Coordinate and participate in annual penetration testing for the IVRC system (or a subsequent platform)
  • Participate in tri-annual HVA assessments as required by BOD 18-02

BOD 18-02 Data Call Management:

  • Respond to the annual BOD 18-02 Data Call questionnaire in early May to validate that IVRC (or a subsequent platform) continues to meet HVA criteria
  • Collaborate with the HVA Oversight Team to successfully complete and submit all required data call responses
  • Provide responses to additional requests for information from the HVA Oversight Team as needed
  • Update Point of Contact (POC) lists for all bureau HVA stakeholders on a quarterly basis and/or upon any role changes

HVA Assessment Coordination:

  • Coordinate with the HVA Oversight Team regarding assigned assessment quarters and scheduling for system assessments
  • Participate in HVA Assessment Kick-Off Meetings 15 days prior to the start of assessments
  • Gather, review, and provide HVA technical documentation as requested
  • Participate in all assessment meetings including Technical Exchange Meetings (TEMs), penetration testing activities, and out briefs
  • Respond to assessment artifacts and documentation requests in a timely manner

Vulnerability Remediation and Reporting:

  • Create POA&Ms in ArchAngel for all open HVA assessment findings
  • Develop and submit remediation plans for all high, major, and critical findings if full remediation cannot be completed within 30 days of the final assessment report
  • Ensure remediation plans are signed by bureau leadership
  • Provide remediation plan updates to the HVA Oversight Team every 30 days until findings have been remediated
  • Provide evidence of Independent Verification & Validation (IV&V) confirmation of finding remediation

FISMA Metrics Reporting:

  • Respond to quarterly Federal Information Security Modernization Act (FISMA) Data Calls to ensure the Department meets FISMA requirements for HVA systems
  • Provide accurate and timely responses to HVA-specific FISMA metrics 20-25 days before quarterly due dates
  • Respond to audit clarification questions and requests for additional information regarding FISMA metrics

Critical Software Management:

  • Ensure current system critical hardware and software are documented and maintained in ArchAngel
  • Ensure the Configuration Management Database (CMDB) is updated with the latest critical software at least quarterly
  • Ensure security tools are updated with system current assets at least quarterly or when major changes arise
  • Identify and inventory all critical software in use within the IVRC system
  • Manage supply chain risks, including maintaining a Software Bill of Materials (SBOM)

HVA Cybersecurity Dashboard Monitoring:

  • Review HVA Cybersecurity Dashboards (Legacy and Next Gen) weekly to monitor system performance
  • Notify appropriate POCs to resolve data issues prior to the end of each quarter
  • Submit update requests to data owners prior to quarterly cut-off dates for changes to be reflected in final quarterly scorecard reporting
  • Attend stakeholder information sessions as required
  • Respond to HVA and Extended Support License Data Calls

Current Systems Analysis:

  • Conduct comprehensive inventory and analysis of all information systems and databases currently used by the Office of International Visitors and U.S. Speaker Program
  • Document how current systems interact with each other, including data flows, integration points, and dependencies
  • Map business processes to existing technology solutions to identify gaps and inefficiencies
  • Analyze user workflows and identify pain points in current system usage
  • Document technical architecture, including hardware, software, network configurations, and security controls

Needs Assessment and Strategic Recommendations:

  • Conduct interviews with program officers, branch and division chiefs, and other OIV staff to understand business requirements
  • Identify challenges and limitations of the current system setup
  • Evaluate data management practices, including data quality, accessibility, and security
  • Analyze reporting capabilities and identify gaps in business intelligence and analytics
  • Develop comprehensive needs assessment report documenting findings and recommendations
  • Identify key requirements and capabilities the office should prioritize when modernizing current systems
  • Develop roadmap for system modernization initiatives

Stakeholder Engagement:

  • Facilitate meetings and working sessions with OIV staff to gather requirements and feedback
  • Collaborate with relevant Department of State IT offices, including the Bureau of Diplomatic Technology (DT)
  • Coordinate with external stakeholders including National Program Agencies and Community Based Members as needed

Documentation and Reporting:

  • Prepare detailed technical documentation of current systems and modernization plan
  • Create visual diagrams and flowcharts to illustrate system architectures and processes
  • Develop user guides and training materials as needed
  • Prepare oral and written reports on systems analysis findings and recommendations
  • Maintain project documentation in accordance with Department standards

Future System Development Support:

  • Participate in requirements gathering sessions for system modernization
  • Develop detailed functional and technical requirements documents
  • Create user stories and use cases to support system design
  • Work with software developers and vendors to implement new systems
  • Conduct user acceptance testing and quality assurance activities
  • Develop implementation and change management plans
  • Provide training and support during system transitions

Requirements
  • Bachelor's degree in Information Technology, Computer Science, Information Systems, Cybersecurity, Business Administration, or related field
  • A minimum of three (3) years of professional work experience in IT project management, business analysis, cybersecurity compliance, or related field
  • Knowledge of cybersecurity principles, risk management, and security control implementation
  • Experience with business process analysis, requirements gathering, and IT modernization
  • Strong analytical and problem-solving skills with ability to analyze complex systems and processes
  • Excellent written and oral communication skills, including ability to prepare technical documentation and present to variety of audiences
  • Demonstrated ability to manage multiple priorities and meet deadlines
  • Experience working with databases and information systems
  • Proficiency with Microsoft Office Suite (Word, Excel, PowerPoint, Visio) and project management tools
  • Ability to work independently with minimal supervision and as part of a team
  • Ability to be in office 5 days a week
  • Maintain a Secret Security Clearance

Preferred:

  • Master's degree in Information Technology, Cybersecurity, Business Administration, or related field
  • Professional certifications such as PMP (Project Management Professional), CISSP (Certified Information Systems Security Professional), CISM (Certified Information Security Manager), or similar
  • Experience working with U.S. Department of State systems and IT security requirements
  • Experience with HVA programs, BOD 18-02 compliance, or CISA assessment processes
  • Familiarity with international exchange programs or public diplomacy initiatives

Benefits

Benefits Include:

  • Covers 100% of employee benefit premiums, including Medical (PPO or HDHP Option), Vision, Dental
  • Matching 401K
  • Short- and Long-Term Disability
  • Pet Insurance
  • Professional Development/Education Reimbursement
  • Parking and Transit Benefits for NY, NJ, ATL, and DC Metro areas

Other Duties:

Please note this job description is not designed to cover or contain a comprehensive listing of activities, duties or responsibilities that are required of the employee for this job. Duties, responsibilities and activities may change at any time with or without notice.

Salary Compensation: $125,000-$130,000

Equal Opportunity Employer / Individuals with Disabilities / Protected Veterans

Skills Required

  • Bachelor's degree in Information Technology, Computer Science, Information Systems, Cybersecurity, Business Administration, or a related field
  • At least three years of professional experience in IT project management, business analysis, cybersecurity compliance, or a related field
  • Knowledge of cybersecurity principles, risk management, and security control implementation
  • Experience with business process analysis, requirements gathering, and IT modernization
  • Strong analytical and problem-solving skills for analyzing complex systems and processes
  • Excellent written and oral communication skills, including technical documentation and presentations
  • Ability to manage multiple priorities and meet deadlines
  • Experience working with databases and information systems
  • Proficiency with Microsoft Office Suite, including Word, Excel, PowerPoint, and Visio, and project management tools
  • Ability to work independently with minimal supervision and as part of a team
  • Ability to work in the office five days per week
  • Maintain a Secret Security Clearance
  • Master's degree in Information Technology, Cybersecurity, Business Administration, or a related field
  • Professional certification such as PMP, CISSP, CISM, or similar
  • Experience with U.S. Department of State systems and IT security requirements
  • Experience with HVA programs, BOD 18-02 compliance, or CISA assessment processes
  • Familiarity with international exchange programs or public diplomacy initiatives
Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
HQ: Oklahoma City, OK
300 Employees
Year Founded: 2015

What We Do

DNI (Delaware Nation Industries) is the parent organization for all Information Technology focused businesses owned by the Delaware Nation. Founded in 2014 DNI was created to support the rapid growth of the tribe’s first 8(a) technology firm, Indigenous Technologies, LLC. In 2011 Indigenous Technologies began several teaming partnerships with CSI, LLC. and was awarded 4 prime contracts with federal customers as a result of this arrangement. This partnership continued through the Fall of 2014 when DNI purchased CSI adding its capabilities and past performance to the growing Tribal IT Services division. As a result of this strategic acquisition by the Delaware Nation, CSI became the second Tribally owned technology focused LLC in the Delaware Nation portfolio. The third company under DNI operations is CreativeIT, LLC. CreativeIT is being built with an eye to the future and is focused on developing core competencies which supplement the strong capabilities of its sister organizations. DNI continues to build a strong team of companies, providing an all-inclusive suite of Information Technology services and capabilities to our clients.

Similar Jobs

Jellyfish Logo Jellyfish

Senior Data Engineer

Big Data • Cloud • Productivity • Software • Database • Analytics • Automation
Remote or Hybrid
United States
225 Employees
165K-235K Annually

CrowdStrike Logo CrowdStrike

Sr. Intrusion Analyst, OverWatch (Remote)

Cloud • Computer Vision • Information Technology • Sales • Security • Cybersecurity
Remote or Hybrid
5 Locations
11000 Employees
125K-180K Annually

CrowdStrike Logo CrowdStrike

Operations Manager

Cloud • Computer Vision • Information Technology • Sales • Security • Cybersecurity
Remote or Hybrid
USA
11000 Employees
100K-155K Annually

CrowdStrike Logo CrowdStrike

Specialist, AIDR (Remote)

Cloud • Computer Vision • Information Technology • Sales • Security • Cybersecurity
Remote or Hybrid
DC, USA
11000 Employees
130K-175K Annually

Similar Companies Hiring

Onshore Thumbnail
Artificial Intelligence • Fintech • Software • Financial Services
New York, New York
60 Employees
Revel.io Thumbnail
Aerospace • Hardware • Robotics • Software
US
50 Employees
Blee Thumbnail
Artificial Intelligence • Marketing Tech • Software • Productivity
US
15 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account