Cybersecurity Analyst
Edgewater Federal Solutions, Inc. District of Columbia, United States · $190K–$200K/yr
Information Technology & Services · 501-1,000 employees
Applying here? Try the free cover letter tool — paste this posting and your résumé, no account needed.
About the role
The Cybersecurity Analyst leads RMF life-cycle activities, including system categorization, control validation, and continuous monitoring to maintain Authority to Operate (ATO). They also coordinate with engineering teams to implement security controls and support internal and external audits through evidence collection and risk assessment.
What they look for
Requirements
Candidates must have an active Top Secret clearance and 3–5 years of experience in cybersecurity, specifically with RMF and federal compliance. A bachelor's degree in IT or a related field is preferred, along with strong technical writing and communication skills.
Benefits
Full description
Overview
The Cybersecurity Analyst supports day-to-day operations with strong experience in the NIST Risk Management Framework (RMF) to also support the security authorization, compliance, and continuous monitoring of federal information systems. This role provides technical guidance to management, system owners, and engineering teams on cybersecurity risk, control implementation, and authorization activities. In this position, the Cybersecurity Analyst will develop and maintain RMF documentation, conduct risk and vulnerability assessments, support security control assessments, and help systems obtain and maintain an Authority to Operate (ATO). The position requires knowledge of FISMA, NIST publications, federal cybersecurity policies, and agency-specific guidance, along with sound judgment, strong technical writing, and the ability to translate requirements into actionable security practices.
Work Location: Washington, DC
Work Arrangement: Onsite
Clearance: Must have an active Top Secret clearance and able to obtain a SCI
Responsibilities
- Lead RMF life-cycle activities, including system categorization, control selection and validation, assessments, authorization, and continuous monitoring.
- Develop and maintain RMF documentation, including SSPs, SAPs/SARs, POA&Ms, risk assessments, PIAs, and continuous monitoring artifacts.
- Conduct risk assessments, control gap analyses, and vulnerability reviews; evaluate impact and recommend risk-based remediation.
- Coordinate with system owners, network engineers, and administrators to implement and document NIST SP 800-53 controls and support daily operations.
- Support the ATO process by preparing authorization packages, tracking findings, coordinating assessor requests, and briefing stakeholders on residual risk and remediation.
- Monitor compliance with FISMA, NIST, agency policies, and contractual cybersecurity requirements.
- Support internal and external audits through evidence collection, control mapping, interviews, and corrective action tracking.
- Analyze vulnerability scans, security tool outputs, and operational data to identify trends, validate control effectiveness, and support continuous diagnostics and mitigation.
- Provide cybersecurity guidance and training to system owners, administrators, and users on requirements, secure practices, and documentation.
- Develop cybersecurity policies, procedures, standards, and governance processes to strengthen compliance and risk management.
Qualifications
- Bachelor’s degree in IT, Computer Science, or a related field preferred; equivalent combination of education, certifications, and relevant experience will be considered.
- Active Top Secret Clearance with ability to obtain a SCI.
- 3–5 years of Cybersecurity experience supporting RMF, compliance, assessments, or ISSO functions in federal or regulated environments.
- Knowledge of NIST SP 800-37/53, FISMA, FIPS 199/200, and related federal guidance.
- Knowledge of DISA CCIs and NIST SP 800-53 mapping.
- Experience maintaining RMF documentation, authorization packages, and continuous monitoring.
- Ability to assess risk, interpret scans, prioritize remediation, and communicate technical risk.
- Familiarity with vulnerability management, SIEM, endpoint security, CDM, and eMASS or similar platforms preferred.
- Strong technical writing, documentation, presentation, audit, and executive reporting skills.
- Ability to work independently, prioritize tasks, and collaborate across teams.
Preferred Qualifications (must have at least 2):
- CompTIA Security+ CE
- ISC2 CGRC
- CompTIA CySA+
- CISSP or CISM
- DoD Manual 8140.3
- IAT Level II
Benefits:
- Competitive salary: $190,000 -200,000
- Paid Time Off & Holiday Pay
- Medical Insurance
- Dental Insurance
- Vision Insurance
- Disability, Life Insurance, and AD&D
- Flexible Spending Accounts
- Pre-Tax 401K and/or After-Tax Roth IRA (with employer matching contribution)
- Tuition and Technical Training Reimbursement
- Exercise Reimbursement
- Employee Assistance Program
- Collaborative and dynamic work environment
Physical Demands: The physical demands described here are representative of those that must be met by an employee to successfully perform the essential functions of this job. Reasonable accommodations may be made to enable individuals with disabilities to perform the essential functions.
- While performing the duties of this job, the employee may be regularly required to stand, sit, talk, hear, reach, stoop, kneel, and use hands and fingers to operate a computer, telephone, keyboard, and standard office equipment.
- Specific vision abilities required by this job include close vision requirements due to computer work.
- The employee must occasionally lift and/or move up to fifteen (15) pounds.
- Fine hand manipulation (keyboarding).
Working at Edgewater Federal Solutions:
Edgewater Federal Solutions is a privately held government contracting firm located in Frederick, MD. The company was founded in 2002 with the vision of being highly recognized and admired for supporting customer missions through employee empowerment, exceptional services, and timely delivery. Edgewater Federal Solutions is ISO 9001, 20000-1, 270001 certified, appraised at CMMI Level 3 Maturity for Development and Services, and has been named in the Top Workplaces in the Greater Washington Area Companies since 2018.
Edgewater Federal Solutions is an Equal Opportunity Employer. It has been and continues to be our policy to provide equal employment to all employees and applicants for employment without regard to race, color, religion, gender, national origin, age, disability, marital status, veteran status and/or other status protected by applicable law. #LI-HH1
Similar roles
-
Cybersecurity Analyst
Kahana & Feld LLP New York, New York, United States
-
(LPS) Senior Cybersecurity Consultant
Lenovo Hong Kong, Hong Kong Island, Hong Kong S.A.R.
-
Cybersecurity Analyst
Valiant Solutions, LLC Dayton, Ohio, United States
-
Sr. Security Engineer - GRC APAC Fintech & Financial Services
SpaceXAI Tokyo, Japan
-
Security Engineer, Modern Workplace Technology, Security Services Remote
BCD Pune, Maharashtra, India
-
Graduate Application Security Analyst
NextGen Sydney, New South Wales, Australia