TIAG Logo

TIAG

Cybersecurity Analyst

Posted 15 Days Ago
In-Office or Remote
Hiring Remotely in 20814, Bethesda, MD
80K-90K Annually
Entry level
In-Office or Remote
Hiring Remotely in 20814, Bethesda, MD
80K-90K Annually
Entry level
Modernize DoD RMF and ATO packages for Google Cloud, Google Workspace, and ServiceNow GCC-High environments. Conduct gap analyses, develop SSPs, SARs, POA&Ms, and continuous monitoring plans, validate Rev. 5 control narratives, map evidence in ServiceNow GRC, evaluate FedRAMP inheritance, and document organizational risk and authorization decisions.
The summary above was generated by AI

TIAG is hiring Cyber Security Analyst to support our team at the Uniform Services University of Health Sciences (USUHS) in Bethesda, MD. The Cyber Analyst will support the modernization of the Authorization to Operate (ATO) packages for enterprise platforms, specifically targeting Google Cloud, Google Workspace, and ServiceNow GCC-High instances.

This role focuses on transitioning system environments from legacy NIST SP 800-53 Revision 3 documentation and existing DISA eMASS baselines to completely modernized, organizationally tailored NIST SP 800-53 Revision 5 and DoD Impact Level 4 (IL-4) authorization packages. 

Key Responsibilities

  • Provide comprehensive support across the full RMF lifecycle, driving the ATO modernization process from initial gap analysis through final package validation and closeout recommendations. 
  • Create and modernize complete RMF authorization packages, which must include the System Security Plan (SSP), Security Assessment Report (SAR), Plan of Action and Milestones (POA&M), and Continuous Monitoring Plan. 
  • Draft and refine implementation-specific control narratives (answering controls) to ensure they accurately reflect the system's actual configuration, directly replacing generic baseline statements. 
  • Develop, document, and manage POA&Ms for any control gaps identified during technical discovery that require future remediation. 
  • Prepare all required fields, supporting documentation, artifacts, and attachments to support eMASS readiness and Government upload. 
  • Upload and map artifacts, technical evidence, control responsibilities, and POA&M information to individual Control Objectives within the ServiceNow GRC Policy and Compliance module. 
  • Evaluate Cloud Service Provider FedRAMP packages to determine control inheritance, tailoring the baseline to reflect local Agency implementation, shared responsibilities, and DoD IL-4 requirements. 
  • Perform 100% Human-in-the-Loop (HitL) validation on all AI-assisted technical content to ensure narratives accurately address Rev 5 controls and contain no unsupported technical statements. 
  • Document organizational tuning decisions in coordination with system stakeholders, capturing risk acceptances, organizational overrides, compensatory mitigations, and tool-specific authorizations. 
     
Qualifications

Required Experience:

  • Active DoD Secret clearance required.
  • DoD 8140/8570 IAT Level II or IAM Level I certification required (e.g., Security+ CE, CAP/CGRC, SSCP). Note: IAM Level II (e.g., CASP+, CISM) is highly preferred.
  • 2+ years of relevant cybersecurity and information assurance experience, with hands-on exposure to writing control narratives, tracking POAMs, and supporting the RMF ATO process.
  • Ability to collaborate seamlessly with a specialized technical team, supporting the efforts of the Senior Cloud Security Engineer, Senior ISSE, and Senior ServiceNow GRC Specialist.
  • Familiarity with the Risk Management Framework (RMF), NIST SP 800-53 Revision 5, and DoD Cloud Computing Security Requirements Guide IL-4.
  • Hands-on experience preparing artifacts and required fields using an RMF repository (e.g., eMASS, Xacta, CSAM).
  • Familiarity with ServiceNow GRC or similar platforms, with an understanding of mapping granular evidence to Control Objectives rather than bulk document uploads.
  • Technical ability to understand actual system realities and translate them into accurate control narratives, moving beyond generic baseline statements.
  • Active DoD Secret clearance required.
  • Strong technical validation skills to ensure control narratives align with actual system realities rather than generic baseline statements. 

TIAG is an equal opportunity employer and federal contractor or subcontractor.  Consequently, the parties agree that, as applicable, they will abide by the requirements of 41 CFR 60-1.4(a), 41 CFR 60-300.5(a), and 41 CFR 60-741.5(a)  and employment decisions shall be based solely on merit and without regard disability, or protected veteran status, or any other characteristic protected by local, state, or federal laws, rules, or regulations. TIAG takes proactive steps to employ and advance in employment qualified individuals without regard to disability or protected veteran status.  The parties also agree that, as applicable, they will abide by the requirements and may be subject and required to take action pursuant to the following laws and accompanying regulations:

The Vietnam Era Veterans Readjustment Assistance Act of 1974, as amended (and its implementing regulations at 41 C.F.R. 60-300);
Section 503 of the Rehabilitation Act of 1973, as amended (and its implementing regulations at 41 C.F.R 60-741); and 
Executive Order 13496 (and its implementing regulations at 29 C.F.R. part 471, Appendix A to Subpart A).

Similar Jobs

15 Days Ago
Remote
United States
Mid level
Mid level
Healthtech • Information Technology
Protect internal and client environments through security operations, incident response, vulnerability management, risk assessments, security monitoring, audits, and continuous improvement. The role investigates alerts and incidents, maintains security controls, supports firewall and cloud security, manages awareness training, develops documentation, and communicates risks and mitigation strategies to stakeholders. This fully remote position supports healthcare organizations in strengthening their cybersecurity posture.
Top Skills: Active DirectoryCloud PlatformsEndpoint ProtectionFirewallsGroup PolicyIds/IpsMulti-Factor AuthenticationNetworkingSIEMVulnerability Management Platforms
Yesterday
Remote
United States
103K-140K Annually
Senior level
103K-140K Annually
Senior level
Healthtech • Biotech
Investigates and responds to high-severity cybersecurity incidents across identification, containment, eradication, recovery, and lessons learned. Performs endpoint, network, and cloud forensics; malware analysis; threat hunting; and root-cause assessments. Documents findings, presents reports, collaborates with technical and business teams, improves detection content and response playbooks, and supports automation and AI capabilities within the incident response program.
Top Skills: Behavioral AnalyticsCloud ForensicsDetection EngineeringEndpoint Detection And Response (Edr)Endpoint ForensicsIncident Response PlaybooksMalware AnalysisNetwork ForensicsSplunkThreat HuntingThreat Intelligence
26 Days Ago
Remote
United States
100K-112K Annually
Senior level
100K-112K Annually
Senior level
Information Technology
Supports cybersecurity planning, assessments, implementation, compliance, and continuous monitoring for Air Force infrastructure modernization. Coordinates RMF activities, DISA STIG validation, NIST control analysis, vulnerability remediation, POA&M development, eMASS documentation, accreditation packages, and cybersecurity reviews. The role validates controls throughout deployment and operational transition, collaborates with ISSMs and engineering teams, and requires active Secret clearance, DoD IAM/IAT certification, and 35% travel.
Top Skills: Acas/TenableCloud OneCnapComsecCross Domain SolutionsDisa StigsEmassHaipeMicrosoft DefenderMicrosoft SentinelNist Sp 800-207Nist Sp 800-53PkiRisk Management Framework (Rmf)ScapSIEMZero Trust

What you need to know about the Austin Tech Scene

Austin has a diverse and thriving tech ecosystem thanks to home-grown companies like Dell and major campuses for IBM, AMD and Apple. The state’s flagship university, the University of Texas at Austin, is known for its engineering school, and the city is known for its annual South by Southwest tech and media conference. Austin’s tech scene spans many verticals, but it’s particularly known for hardware, including semiconductors, as well as AI, biotechnology and cloud computing. And its food and music scene, low taxes and favorable climate has made the city a destination for tech workers from across the country.

Key Facts About Austin Tech

  • Number of Tech Workers: 180,500; 13.7% of overall workforce (2024 CompTIA survey)
  • Major Tech Employers: Dell, IBM, AMD, Apple, Alphabet
  • Key Industries: Artificial intelligence, hardware, cloud computing, software, healthtech
  • Funding Landscape: $4.5 billion in VC funding in 2024 (Pitchbook)
  • Notable Investors: Live Oak Ventures, Austin Ventures, Hinge Capital, Gigafund, KdT Ventures, Next Coast Ventures, Silverton Partners
  • Research Centers and Universities: University of Texas, Southwestern University, Texas State University, Center for Complex Quantum Systems, Oden Institute for Computational Engineering and Sciences, Texas Advanced Computing Center

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account