{"schemaVersion":"jobsearcher.job.v1","id":"eb62f0ba76a5e801f2070fe0","url":"https://jobsearcher.com/jobs/eb62f0ba76a5e801f2070fe0","canonicalUrl":"https://jobsearcher.com/jobs/eb62f0ba76a5e801f2070fe0","title":"Senior Information Security Analyst","description":"All hired employees are expected to have experience with Microsoft Copilot and / or an approved equivalent AI solution.\nDSA is hiring a Senior Information Security Analyst. This is a full-time position supporting a customer in the DC Metro area with a HYBRID Schedule. This position supports the Environmental Protection Agency (EPA). DSA is the Prime and has been working with this customer on this contract for more than 13 years. It is a dynamic team with a passion for supporting Federal programs that serve U.S. citizens.\n\nLocation is Hybrid: Allows the candidate the ability to work onsite at DSA or customer site with potential for telework. DSA work locations include Fairfax, VA.\n\nWork Location is flexible with telework as approved. The ability to work onsite each week is required. Core work hours dedicated to DSA and our direct customers are 8 am est to 5 pm est.\n\nThe Environmental Protection Agency (EPA) Office of Information Security and Privacy (OISP) is responsible for developing and maintaining agency-wide information security and privacy programs; developing and maintaining information security and privacy policies, procedures, and control techniques; training personnel with significant information security responsibilities and assisting senior agency officials with information security and privacy responsibilities.\n\nThe Senior Information Security Analyst will be an integral part of a team responsible for supporting the development and maturation of an Agency-wide information security (InfoSec) program for a large civilian Federal agency. The candidate will serve as a subject matter expert with regards to the Risk Management Framework (RMF) and all associated information security policies and procedures and should possess in-depth knowledge of applying, selecting and testing the NIST family of security controls.\nPrimary Responsibilities:\nAdvising senior-level stakeholders on InfoSec initiatives including compliance, awareness and training, and security operations.\nLeading Independent Validation and Verification (IV&V) efforts on security authorization/ATO packages to ensure compliance with agency requirements.\nLeveraging the existing Governance, Risk, and Compliance (GRC) tool, Telos Xacta (or an alternate like CSAM or RSA Archer), to track and reconcile findings from assessments, audits, and vulnerability scans.\nCoordinating government data calls (FISMA, FMFIA, BDR, etc.) and monthly reports.\nAssessing the effectiveness of the InfoSec and privacy training program and leading the collection, analyzing, and presentation of enterprise-level InfoSec performance metrics.\nManaging InfoSec Program POA&Ms, including advising on remediation efforts.\nWorking closely with senior agency security officials, system owners, information system security officers (ISSOs) and other stakeholders to advise and implement security solutions.\nIdentify opportunities for efficiencies in work process and innovative approaches.\nParticipating in team problem solving efforts and offer ideas to solve client issues.\nConducting relevant research, data analysis, and developing reports.\nPreparing and assisting in the development of policy and procedures.\nImplementing processes and procedures to monitor risk across programs / projects.\nPreparing briefings to the executive team to debrief the results of studies, analyses, and plans.\nAssisting the client leadership in reviewing monthly project progress, documenting issues, and monitoring resolution.\n\nRequired Qualifications:\nAbility to obtain a Public Trust.\nBachelor's degree in information technology or related field and 8 years of relevant IA experience. May substitute security certification (e.g. CISSP) for 2 years of experience.\n3+ years in a leadership role\nStrong data analysis skills.\nExcellent written and verbal communication skills.\nPossess in-depth knowledge of applying, selecting and testing the NIST 800-53 Rev 4 security controls.\nPossess in-depth knowledge of NIST 800-37 Risk Management Framework.\nExperience with a Governance, Risk and Compliance tool (e.g., Xacta, RSA Archer, CSAM or eMASS).\nExcellent attention to detail.\nAbility to handle and prioritize multiple tasks and deadlines.\n\nDesired Qualifications:\nAdvanced level cybersecurity certification (e.g., CompTIA CISM, ISC2 CISSP)\nIn-depth knowledge of applying, selecting and testing the NIST 800-53 Rev 5 security controls\n#DSA209\n#LI-CW1\n\nMany of DSA's positions require the ability to obtain a security clearance. Security clearances may only be granted to U.S. citizens. In addition, applicants who accept a conditional offer of employment may be subject to government security investigation(s) and must meet eligibility requirements for access to classified information. DSA is proud to be an Equal Opportunity Employer. DSA is committed to treating all employees and applicants for employment with respect and dignity and maintaining a workplace that is free from unlawful discrimination. All qualified applicants will receive consideration for employment without regard to race, color, sex, sexual orientation, gender identity, religion, national origin, disability, veteran status, or other legally protected status. DSA requires background checks , where permitted , by law. DSA is an E-Verify Employer.","company":"Data Systems Analysts","rawCompany":"data systems analysts","city":"Washington","state":"DC","isRemote":false,"isActive":false,"createdAt":"2026-07-31T12:02:19.237Z","occupations":[{"code":"15-1212.00","title":"Information Security Analysts","slug":"information-security-analysts"},{"code":"15-1299.05","title":"Information Security Engineers","slug":"information-security-engineers"},{"code":"13-1199.07","title":"Security Management Specialists","slug":"security-management-specialists"}],"industries":[{"code":"541690","title":"Other Scientific and Technical Consulting Services","slug":"other-scientific-and-technical-consulting-services"},{"code":"541512","title":"Computer Systems Design Services","slug":"computer-systems-design-services"},{"code":"921190","title":"Other General Government Support","slug":"other-general-government-support"}],"jobPosting":{"@context":"https://schema.org","@type":"JobPosting","title":"Senior Information Security Analyst","description":"All hired employees are expected to have experience with Microsoft Copilot and / or an approved equivalent AI solution.\nDSA is hiring a Senior Information Security Analyst. This is a full-time position supporting a customer in the DC Metro area with a HYBRID Schedule. This position supports the Environmental Protection Agency (EPA). DSA is the Prime and has been working with this customer on this contract for more than 13 years. It is a dynamic team with a passion for supporting Federal programs that serve U.S. citizens.\n\nLocation is Hybrid: Allows the candidate the ability to work onsite at DSA or customer site with potential for telework. DSA work locations include Fairfax, VA.\n\nWork Location is flexible with telework as approved. The ability to work onsite each week is required. Core work hours dedicated to DSA and our direct customers are 8 am est to 5 pm est.\n\nThe Environmental Protection Agency (EPA) Office of Information Security and Privacy (OISP) is responsible for developing and maintaining agency-wide information security and privacy programs; developing and maintaining information security and privacy policies, procedures, and control techniques; training personnel with significant information security responsibilities and assisting senior agency officials with information security and privacy responsibilities.\n\nThe Senior Information Security Analyst will be an integral part of a team responsible for supporting the development and maturation of an Agency-wide information security (InfoSec) program for a large civilian Federal agency. The candidate will serve as a subject matter expert with regards to the Risk Management Framework (RMF) and all associated information security policies and procedures and should possess in-depth knowledge of applying, selecting and testing the NIST family of security controls.\nPrimary Responsibilities:\nAdvising senior-level stakeholders on InfoSec initiatives including compliance, awareness and training, and security operations.\nLeading Independent Validation and Verification (IV&V) efforts on security authorization/ATO packages to ensure compliance with agency requirements.\nLeveraging the existing Governance, Risk, and Compliance (GRC) tool, Telos Xacta (or an alternate like CSAM or RSA Archer), to track and reconcile findings from assessments, audits, and vulnerability scans.\nCoordinating government data calls (FISMA, FMFIA, BDR, etc.) and monthly reports.\nAssessing the effectiveness of the InfoSec and privacy training program and leading the collection, analyzing, and presentation of enterprise-level InfoSec performance metrics.\nManaging InfoSec Program POA&Ms, including advising on remediation efforts.\nWorking closely with senior agency security officials, system owners, information system security officers (ISSOs) and other stakeholders to advise and implement security solutions.\nIdentify opportunities for efficiencies in work process and innovative approaches.\nParticipating in team problem solving efforts and offer ideas to solve client issues.\nConducting relevant research, data analysis, and developing reports.\nPreparing and assisting in the development of policy and procedures.\nImplementing processes and procedures to monitor risk across programs / projects.\nPreparing briefings to the executive team to debrief the results of studies, analyses, and plans.\nAssisting the client leadership in reviewing monthly project progress, documenting issues, and monitoring resolution.\n\nRequired Qualifications:\nAbility to obtain a Public Trust.\nBachelor's degree in information technology or related field and 8 years of relevant IA experience. May substitute security certification (e.g. CISSP) for 2 years of experience.\n3+ years in a leadership role\nStrong data analysis skills.\nExcellent written and verbal communication skills.\nPossess in-depth knowledge of applying, selecting and testing the NIST 800-53 Rev 4 security controls.\nPossess in-depth knowledge of NIST 800-37 Risk Management Framework.\nExperience with a Governance, Risk and Compliance tool (e.g., Xacta, RSA Archer, CSAM or eMASS).\nExcellent attention to detail.\nAbility to handle and prioritize multiple tasks and deadlines.\n\nDesired Qualifications:\nAdvanced level cybersecurity certification (e.g., CompTIA CISM, ISC2 CISSP)\nIn-depth knowledge of applying, selecting and testing the NIST 800-53 Rev 5 security controls\n#DSA209\n#LI-CW1\n\nMany of DSA's positions require the ability to obtain a security clearance. Security clearances may only be granted to U.S. citizens. In addition, applicants who accept a conditional offer of employment may be subject to government security investigation(s) and must meet eligibility requirements for access to classified information. DSA is proud to be an Equal Opportunity Employer. DSA is committed to treating all employees and applicants for employment with respect and dignity and maintaining a workplace that is free from unlawful discrimination. All qualified applicants will receive consideration for employment without regard to race, color, sex, sexual orientation, gender identity, religion, national origin, disability, veteran status, or other legally protected status. DSA requires background checks , where permitted , by law. DSA is an E-Verify Employer.","datePosted":"2026-07-31T12:02:19.237Z","dateModified":"2026-07-31T12:02:19.237Z","hiringOrganization":{"@type":"Organization","name":"Data Systems Analysts","sameAs":"https://jobsearcher.com"},"jobLocation":{"@type":"Place","address":{"@type":"PostalAddress","addressLocality":"Washington","addressRegion":"DC","addressCountry":"US"}},"identifier":{"@type":"PropertyValue","name":"JobSearcher","value":"eb62f0ba76a5e801f2070fe0"},"url":"https://jobsearcher.com/jobs/eb62f0ba76a5e801f2070fe0"}}