Full-Time

Senior Mlsecops Analyst

Posted on 2/21/2025

phia

phia

11-50 employees

Provides cybersecurity solutions for government agencies

No salary listed

Senior, Expert

Arlington, VA, USA

This role is hybrid with onsite reporting required in Arlington, VA; frequency to be determined.

US Top Secret Clearance Required

Category
Applied Machine Learning
AI & Machine Learning
Required Skills
Machine Learning
Risk Management
Requirements
  • Bachelor’s degree with 7 years’ relevant IT/Cybersecurity experience; or 11 years’ relevant experience.
  • Expertise in security compliance and risk management frameworks (e.g., NIST 800-53A, FISMA), including conducting assessments and developing risk analysis and mitigation strategies.
  • Proficient in vulnerability scanning, configuration, and patch management, with experience addressing complex system vulnerabilities.
  • Skilled in creating and maintaining security authorization documentation, ATO packages, and compliance records, with the ability to effectively present technical findings and mitigation plans to diverse audiences.
  • Experienced in coordinating across teams (e.g., Privacy, Information Governance), supporting audits, and delivering risk briefings.
  • Adept at communicating security requirements within development cycles and aligning with stakeholder expectations.
Responsibilities
  • Conduct research and maintain expertise on MLSecOps concepts, methodologies, models, government policies, industry best practices, and relevant open-source and commercial implementations.
  • Identify areas where Machine Learning (ML) capabilities can be applied to Security Test & Evaluation, internal penetration testing, proactive vulnerability assessment and discovery, risk assessment and the development of security controls, and validation of applied security controls.
  • Develop and implement validation mechanisms to assess the viability and effectiveness of the generated remediation tasks in mitigating the identified issues.
  • Implement and follow the Risk Management Framework (RMF) process, conducting comprehensive security control assessments for internal systems, including cloud-based environments.
  • Develop and analyze Security Assessment Reports (SARs) by NIST SP 800-53, NIST SP 800-37, and FIPS standards.
  • Conduct vulnerability analysis, manage Plan of Action and Milestones (POA&M), and provide security impact reviews for change requests, ensuring compliance with relevant federal regulations.
  • Collaborate with government stakeholders, system owners, and security professionals to evaluate security readiness across various cybersecurity functions.
  • Perform continuous monitoring activities, including annual assessments and reporting for Information Security Vulnerability Management (ISVM) and related programs.
  • Support on-site and remote assessments for information systems, verifying adherence to cloud security standards and infrastructure hardening requirements.
  • Develop and employ tailored test plans and procedures, utilizing various tools and custom scripts in alignment with NIST guidelines.
  • Conduct manual testing, vulnerability scans, and penetration testing in compliance with FISMA requirements and other applicable standards.
  • Implement Offensive Security Operations (OffSecOps) practices, including automated deployment and testing of various targets, while maintaining compliance with federal security regulations.
  • Perform Assessment & Authorization (A&A) activities, Identity Governance (IG) audits, vulnerability management reporting, and compliance validations in collaboration with relevant stakeholders.
Desired Qualifications
  • Familiarity and working experience with machine learning security operations (MLSecOps) or security development operations DevSecOps methodology.

phia LLC specializes in delivering tailored cyber assessments, proactive cybersecurity operations, security engineering, and advisory services, leveraging threat intelligence, operational realities, and industry best practices to counter advanced cyber threats for mission-critical teams within various government agencies. The company's main product focuses on providing sophisticated cyber solutions through intelligence-driven approaches and industry standards, utilizing a variety of frameworks informed by threat intelligence and operational realities.

Company Size

11-50

Company Stage

N/A

Total Funding

N/A

Headquarters

Louisville, Kentucky

Founded

2011

Simplify Jobs

Simplify's Take

What believers are saying

  • Growing demand for zero-trust models boosts Phia's market potential.
  • AI-driven threat detection is increasingly sought after by businesses.
  • Healthcare sector expansion offers new opportunities for Phia's services.

What critics are saying

  • AI in cyber attacks requires Phia to constantly adapt its defenses.
  • Quantum computing challenges current encryption methods, demanding innovation.
  • Shortage of skilled professionals may impact Phia's service delivery.

What makes phia unique

  • Phia offers a comprehensive suite of cybersecurity and intelligence services.
  • The company specializes in zero-trust security models for remote work environments.
  • Phia is advancing in AI-driven threat detection and response systems.

Help us improve and share your feedback! Did you find this helpful?

Benefits

Health Insurance

Dental Insurance

Vision Insurance

Short Term & Long-Term Disability

401(k) Retirement Plan

401(k) Company Match

Tuition and Professional Development Assistance

Flex Spending Accounts (FSA)

INACTIVE