Security Analyst

Posted Yesterday
Be an Early Applicant
McLean, VA, USA
In-Office
150K-200K Annually
Senior level
Security • Cybersecurity
The Role
Support FedRAMP and IC ATO processes, RMF lifecycle, continuous monitoring, risk and control assessments, POA&M remediation, security documentation, incident response, vulnerability analysis, audit support, cloud security, and liaison with SOC, engineering, and compliance teams.
Summary Generated by Built In

Join our team at Core One! Our mission is to be at the forefront of devising analytical, operational and technical solutions to our Nation's most complex national security challenges. In order to achieve our mission, Core One values people first! We are committed to recruiting, nurturing, and retaining top talent! We offer a competitive total compensation package that sets us apart from our competition. Core One is a team-oriented, dynamic, and growing company that values exceptional performance!

Clearance Required: Active TS/SCI with Polygraph

Summary

We are seeking a Security Analyst to support cybersecurity operations, compliance, and risk management for FedRAMP-authorized and Intelligence Community (IC) systems. This role is responsible for ensuring systems meet stringent federal security requirements while enabling secure, scalable, and compliant cloud and on-premises solutions.

The ideal candidate brings deep expertise in NIST frameworks, FedRAMP authorization processes, continuous monitoring (ConMon), and ATO lifecycle management, along with the ability to operate in classified or high-security environments.

Key Responsibilities

  • Lead and support FedRAMP Moderate/High and IC ATO authorization processes
  • Develop, review, and maintain security documentation: System Security Plans (SSP), Security Assessment Reports (SAR), Plan of Action & Milestones (POA&M)
  • Ensure compliance with NIST SP 800-53 / 800-37 RMF, FedRAMP baselines, ICD 503
  • Perform risk assessments, control assessments, and gap analyses
  • Implement and manage RMF lifecycle activities (Categorize → Monitor)
  • Track and manage POA&M remediation activities
  • Facilitate security control inheritance and shared responsibility models
  • Execute continuous monitoring strategies and reporting
  • Analyze security posture using Vulnerability scans and Configuration compliance
  • Produce monthly/quarterly ConMon deliverables
  • Monitor and analyze security events and alerts
  • Support incident response and forensic analysis
  • Coordinate with SOC teams and stakeholders for threat mitigation
  • Conduct root cause analysis and lessons learned
  • Secure cloud environments aligned with FedRAMP controls
  • Implement identity and access controls
  • Support 3PAO assessments and audits
  • Prepare evidence artifacts for FedRAMP JAB/Agency ATO reviews and Inspector General (IG) audits
  • Coordinate with internal/external auditors
  • Utilize security tools for monitoring and compliance: Splunk, Sentinel, Vulnerability management tools, ServiceNow
  • Support automation of compliance and reporting workflows
  • Act as liaison between Engineering teams, ISSOs / ISSMs, and Compliance and audit teams
  • Provide security guidance during system design and change management
  • Mentor junior analysts and support team development
  • Promote a culture of security-first engineering and compliance excellence
  • Contribute to security governance and policy development

Qualifications 

  • Active TS/SCI with Polygraph
  • Bachelor's degree or higher in Cybersecurity, IT, or related field and 5+ years' experience in Cybersecurity in federal or IC environments
  • OR Masters and 3+ years of experience in Cybersecurity in federal or IC environments
  • Strong Knowledge of NIST RMF (800-37), NIST 800-53 controls, and FedRAMP requirements
  • At least one of the following certifications: CISM or CISA, CompTIA Security+ (baseline), Certified Authorization Professional (CAP), CCSP (cloud security)
  • Experience in the following tools: NIST 800-53, RMF, FedRAMP, ICD 503, ServiceNow GRC, Splunk, Azure Sentinel, Nessus, ACAS, AWS GovCloud, Azure Government, GCP, SCAP, STIG Viewer

Desired Qualifications

  • Experience with cloud-native security tools
  • Knowledge of Zero Trust Architecture
  • Experience with cross-domain solutions
  • Experience with ICD 503
  • Familiarity with DevSecOps pipelines in regulated environments

Salary Range: $150,000 - $200,000

The pay range reflected above is a general guideline for this position and labor category and is not a guarantee of a specific salary or offer. Final compensation is determined based on factors including, but not limited to, relevant experience, education, certifications, security clearance level, contract requirements, geographic location, and internal pay equity, and may reflect market data specific to the awarded contract.


Core One is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, gender identity, sexual orientation, national origin, or protected veteran status and will not be discriminated against on the basis of disability.

__PRESENT

__PRESENT__PRESENT__PRESENT__PRESENT__PRESENT__PRESENT

Skills Required

  • Active TS/SCI with Polygraph
  • Bachelor's degree in Cybersecurity, IT, or related field plus 5+ years' cybersecurity experience in federal/IC environments OR Master's degree plus 3+ years' experience
  • Strong knowledge of NIST RMF (800-37), NIST SP 800-53 controls, and FedRAMP requirements
  • At least one certification: CISM or CISA, CompTIA Security+ (baseline), Certified Authorization Professional (CAP), or CCSP
  • Experience with ServiceNow GRC, Splunk, Azure Sentinel, Nessus, ACAS, AWS GovCloud, Azure Government, GCP, SCAP, and STIG Viewer
  • Experience leading FedRAMP Moderate/High and IC ATO authorization processes, ConMon, POA&M management, 3PAO assessments, and audits
  • Experience with incident response, forensic analysis, vulnerability scanning, configuration compliance, and coordinating with SOC teams
Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
HQ: Sterling, VA
61 Employees

What We Do

Our mission is to be at the forefront of devising analytical, operational and technical solutions to the most complex national security challenges by delivering superior advice, building trusted partnerships, and augmenting the capabilities of our clients.

Similar Jobs

Capital One Logo Capital One

Principal Associate, Security Intelligence Analyst, Protective Intelligence Global Workplace Services

Fintech • Machine Learning • Payments • Software • Financial Services
Hybrid
3 Locations
55000 Employees
99K-136K Annually

Northrop Grumman Logo Northrop Grumman

Industrial Security Analyst

Aerospace • Logistics • Security • Software • Cybersecurity
In-Office
Chantilly, VA, USA
85636 Employees
76K-114K Annually

Accenture Federal Services Logo Accenture Federal Services

Government Security Personnel Analyst

Artificial Intelligence • Information Technology • Consulting • Cybersecurity
In-Office
Arlington, VA, USA
17634 Employees
64K-109K Annually
In-Office
6 Locations
13446 Employees
94K-131K Annually

Similar Companies Hiring

Credal.ai Thumbnail
Software • Security • Productivity • Machine Learning • Artificial Intelligence
Brooklyn, NY
Milestone Systems Thumbnail
Artificial Intelligence • Security • Software • Analytics • Big Data Analytics
Lake Oswego, OR
1500 Employees
NODA AI Thumbnail
Artificial Intelligence • Information Technology • Software • Cybersecurity
Sydney, AU
54 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account