Core One

Core One

Security Analyst

McLean, VA · Junior

No sponsorship$53k-$800kDetected 71 days ago
TypeScriptAWSGCPAzureCloud PlatformsCybersecurityMicrosoft SentinelIncident ResponseZero TrustCompTIA

About the role

  • Core One is a team-oriented, dynamic, and growing company that values exceptional performance!
  • The ideal candidate brings deep expertise in NIST frameworks, FedRAMP authorization processes, continuous monitoring (ConMon), and ATO lifecycle management, along with the ability to operate in classified or high-security environments.

Responsibilities

  • Lead and support FedRAMP Moderate/High and IC ATO authorization processes
  • Develop, review, and maintain security documentation: System Security Plans (SSP), Security Assessment Reports (SAR), Plan of Action & Milestones (POA&M)
  • Implement and manage RMF lifecycle activities (Categorize → Monitor)
  • Track and manage POA&M remediation activities
  • Support incident response and forensic analysis
  • Implement identity and access controls
  • Support 3PAO assessments and audits
  • Provide security guidance during system design and change management

Requirements

  • Bachelor's degree or higher in Cybersecurity, IT, or related field and 5+ years' experience in Cybersecurity in federal or IC environments
  • OR Masters and 3+ years of experience in Cybersecurity in federal or IC environments
  • Strong Knowledge of NIST RMF (800-37), NIST 800-53 controls, and FedRAMP requirements
  • Experience in the following tools: NIST 800-53, RMF, FedRAMP, ICD 503, ServiceNow GRC, Splunk, Azure Sentinel, Nessus, ACAS, AWS GovCloud, Azure Government, GCP, SCAP, STIG Viewer
  • Active TS/SCI with Polygraph

Skills

  • Support automation of compliance and reporting workflows
  • Act as liaison between Engineering teams, ISSOs / ISSMs, and Compliance and audit teams
  • Mentor junior analysts and support team development
  • Promote a culture of security-first engineering and compliance excellence
  • Contribute to security governance and policy development
  • Experience with cloud-native security tools
  • Knowledge of Zero Trust Architecture
  • Experience with cross-domain solutions
  • Experience with ICD 503
  • Familiarity with DevSecOps pipelines in regulated environments
  • Ensure compliance with NIST SP 800-53 / 800-37 RMF, FedRAMP baselines, ICD 503
  • Perform risk assessments, control assessments, and gap analyses

Compensation

  • We offer a competitive total compensation package that sets us apart from our competition.

This listing is sourced directly from Core One's careers page and normalized into a canonical job model.