Core One
Security Analyst
McLean, VA · Junior
No sponsorship$53k-$800kDetected 71 days ago
TypeScriptAWSGCPAzureCloud PlatformsCybersecurityMicrosoft SentinelIncident ResponseZero TrustCompTIA
About the role
- Core One is a team-oriented, dynamic, and growing company that values exceptional performance!
- The ideal candidate brings deep expertise in NIST frameworks, FedRAMP authorization processes, continuous monitoring (ConMon), and ATO lifecycle management, along with the ability to operate in classified or high-security environments.
Responsibilities
- Lead and support FedRAMP Moderate/High and IC ATO authorization processes
- Develop, review, and maintain security documentation: System Security Plans (SSP), Security Assessment Reports (SAR), Plan of Action & Milestones (POA&M)
- Implement and manage RMF lifecycle activities (Categorize → Monitor)
- Track and manage POA&M remediation activities
- Support incident response and forensic analysis
- Implement identity and access controls
- Support 3PAO assessments and audits
- Provide security guidance during system design and change management
Requirements
- Bachelor's degree or higher in Cybersecurity, IT, or related field and 5+ years' experience in Cybersecurity in federal or IC environments
- OR Masters and 3+ years of experience in Cybersecurity in federal or IC environments
- Strong Knowledge of NIST RMF (800-37), NIST 800-53 controls, and FedRAMP requirements
- Experience in the following tools: NIST 800-53, RMF, FedRAMP, ICD 503, ServiceNow GRC, Splunk, Azure Sentinel, Nessus, ACAS, AWS GovCloud, Azure Government, GCP, SCAP, STIG Viewer
- Active TS/SCI with Polygraph
Skills
- Support automation of compliance and reporting workflows
- Act as liaison between Engineering teams, ISSOs / ISSMs, and Compliance and audit teams
- Mentor junior analysts and support team development
- Promote a culture of security-first engineering and compliance excellence
- Contribute to security governance and policy development
- Experience with cloud-native security tools
- Knowledge of Zero Trust Architecture
- Experience with cross-domain solutions
- Experience with ICD 503
- Familiarity with DevSecOps pipelines in regulated environments
- Ensure compliance with NIST SP 800-53 / 800-37 RMF, FedRAMP baselines, ICD 503
- Perform risk assessments, control assessments, and gap analyses
Compensation
- We offer a competitive total compensation package that sets us apart from our competition.
Apply directly at Core One →Create a free account for alerts like thisView Core One immigration profile
This listing is sourced directly from Core One's careers page and normalized into a canonical job model.