Information Security Analyst
Current• Categorize information systems, determine and assign the high watermark • Organize and participate in KOMs with clients to comprehend system nuances and ready the assessment groundwork• Prepare the project team for security control assessment in alignment with Security Assessment Plan (SAP) schedule• Initiate documentation requests from clients, including configuration management plan, account management plan, disaster recovery plan etc. • Collaborate with stakeholders for both pre and post Assessment and Authorization (A&A) activities• Select security controls, discerning common controls, hybrid and system specific controls• Conduct security control tailoring and scoping to tailor the security measures appropriately • Guide clients in the implementation of security controls and offer expert advise• Review and update security controls implementation descriptions for accuracy and relevance• Create and update Security Assessment Report (SAR) and Plan of Actions and Milestones (POA&M)• Scrutinize artifacts and provide constructive feedback to client on how to address and remediate findings• Conduct vulnerability scans using Nessus Security Center and present comprehensive vulnerability reports to clients• Compile comprehensive security Authorization Packages for Authorizing Official to make informed, risk-based decisions for granting Authorizations to Operate (ATO).• Collaborate with Assessor and project team throughout Information Security Continuous Monitoring (ISCM) processes• Develop Privacy threshold analysis (PTA) and Privacy impact Assessment (PIA) for comprehensive privacy evaluations