Information System Security Analyst
Planate Management Group (PMG) is a Service-Disabled Veteran-Owned Small Business (SDVOSB) with headquarters in Alexandria, Virginia, and Orlando, Florida. Our technical support centers extend across Southeast Asia and East Africa, enabling us to provide comprehensive program management and facilities engineering services worldwide. As a trusted small business partner, Planate specializes in planning, design, infrastructure management, technical consulting, engineering, and construction management services. We proudly support the missions of the U.S. Department of Defense (DOD) and its branches—Army, Air Force, Navy, and Marine Corps—along with various U.S. federal agencies, delivering exceptional service across the globe.
We are looking for an experienced Information System Security Analyst to join our team in Florida. This role involves applying Information System (IS) security principles, practices, and procedures under the Risk Management Framework (RMF) to ensure compliance with security regulations such as NIST, CNSSI, CMMC, and NISPOM for classified information systems. You will manage the program's security efforts and represent the program to the sponsor's security organization. The ideal candidate will be a strong advocate for integrating security into all stages of the program lifecycle and will oversee the implementation and sustainment of security controls throughout the program.
Note: The salary listed is not the final offer and will be determined based on the candidate's qualifications and experience.
Responsibilities:
- Develop and maintain documentation related to information security, ensuring it aligns with the relevant security frameworks and standards.
- Implement, monitor, and maintain security controls across all systems, ensuring they are effective in mitigating risks.
- Advise development teams on integrating security requirements into system design, implementation, and maintenance processes.
- Manage relationships with hardware and software vendors to ensure compliance with security requirements and provide guidance on securing products.
- Achieve and maintain Authorization to Operate (ATO) for classified information systems, ensuring they meet regulatory compliance requirements.
- Coordinate and collaborate with the sponsor’s security organization and corporate security teams to ensure seamless communication and compliance.
- Oversee the Continuous Monitoring program to track, assess, and report security posture of systems and resolve any identified vulnerabilities.
- Provide security-related training and guidance to program management and staff to promote a security-aware culture within the organization.
- Ensure personal eligibility for security clearance and support the security clearance process for other program personnel.
- Perform risk assessments, manage risk, and support ongoing security efforts throughout the system lifecycle, addressing security vulnerabilities and ensuring continuous compliance.
Qualifications:
- Bachelor’s degree in Computer Science, Information Systems, Cybersecurity, or related field (Master’s degree preferred).
- Minimum of 3 years of experience in cybersecurity, with at least 1 year in a supervisory role (preferred).
- Active Secret clearance (preferred).
- IAM Level III certification in accordance with DoD 8570.01M, or CompTIA Security+ certification.
- High-level security or IT certification with practical experience in security management.
- In-depth knowledge of NIST 700/800 series, CNSSI 1253, NISPOM Chapter 8, CMMC, and related publications.
- Familiarity with the RMF process and experience in drafting RMF documentation.
- Experience in performing risk assessments and risk management for information systems (cloud, subscription-based, and on-premise).
- Practical experience implementing and monitoring technical, administrative, and operational security controls.
- Proven success managing classified information systems and working within established security frameworks.
- Strong organizational skills, with the ability to prioritize tasks and meet deadlines.
- Familiarity with CMMC 2.0, STIGs, NIST CVEs, IAVAs, Compliance Checker (SCC), and Cloud Security concepts.
- Strong writing skills and experience in collaborative teamwork.
- Must lawfully reside in the United States and be eligible for employment (Planate does not sponsor visas or work permits).