Full-Time

Cybersecurity Policy and Compliance Analyst

Posted on 11/16/2024

Booz Allen

Booz Allen

Consulting in strategy, technology, and engineering

Data & Analytics
Consulting
Government & Public Sector
Cybersecurity
Defense

Compensation Overview

$75.6k - $172kAnnually

Senior

Dahlgren, VA, USA

Requires on-site presence in Dahlgren, VA for five days a week.

US Top Secret Clearance Required

Category
Cybersecurity
IT & Security
Requirements
  • 5+ years of experience with NIST RMF policies, including continuous monitoring, and information system security policies, standards, and procedures
  • Experience with eMASS
  • Knowledge of the DoD RMF process
  • Knowledge of DoD A&A processes and standards
  • Ability to work 5 days a week on-site
  • Secret clearance
  • HS diploma or GED
  • CCNA Security, CySA+, GICSP, GSEC, Security+ CE, or SSCP Certification
  • Experience supporting Navy Commands in the implementation or assessment of cybersecurity controls
  • Knowledge of IA or INFOSEC concepts and requirements
  • Knowledge of vulnerability remediation asset manager (VRAM) activities
  • Possession of excellent verbal and written communication skills
  • Navy Qualified Validator (NQV) Certification
Responsibilities
  • Support the Navy cybersecurity risk assessment team in conducting assessments of cybersecurity risk by evaluating Navy systems.
  • Assist with drafting cybersecurity risk reports to highlight current architecture, mitigations, and cybersecurity risk posture.
  • Analyze, review, and critique assessment and authorization (A&A) documentation in compliance with DoD cybersecurity policy and agency guidance, including DoD 8500 series, CNSS 1253, and NIST special publications.
  • Assess program security compliance, support program briefs, and coordinate and compile program security documentation for various programs.
  • Provide A&A and cybersecurity support, including Risk Management Framework (RMF) for DoD IT, assess compliance with security technical implementation guides (STIGs), review automated scans, conduct security test and evaluation (ST&E), vulnerability assessments, and computer security responses, and create and manage RMF packages using the Enterprise Mission Assurance Support Service (eMASS).
  • Provide results of unresolved discrepancies to the client for inclusion in that system’s IA Plan of Action and Milestones (POA&M).
  • Interact with clients to perform policy and technical audits.
  • Brief client leadership on vulnerabilities in support of the government client and prepare brief slides and summary of findings analyses.

Booz Allen Hamilton provides consulting services focused on strategy, technology, and engineering. The firm works with a variety of clients, including government agencies, corporations, and non-profits, primarily in the defense, intelligence, and civil sectors. Their services help clients tackle complex technical and strategic challenges, utilizing their expertise in areas like cybersecurity, data analytics, and digital transformation. Booz Allen's business model includes long-term contracts and project-based engagements, allowing them to generate revenue while delivering tailored solutions. What sets Booz Allen apart from competitors is their deep industry knowledge combined with advanced technological capabilities, which enables them to effectively address modern threats and optimize client operations. The company aims to foster an inclusive and diverse work environment that encourages innovation and collaboration among its employees.

Company Stage

IPO

Total Funding

$34.6M

Headquarters

McLean, Virginia

Founded

N/A

Simplify Jobs

Simplify's Take

What believers are saying

  • Strategic investments in high-growth areas like AI security and space technology offer employees exposure to innovative and impactful projects.
  • Booz Allen's diversified portfolio across commercial and military sectors provides stability and multiple avenues for career growth.
  • The company's venture capital arm allows for a dynamic work environment where employees can engage with startups and emerging technologies.

What critics are saying

  • The competitive landscape in AI and space technology sectors could pose challenges in maintaining a leading edge.
  • Balancing investments between commercial and military applications may lead to strategic misalignments.

What makes Booz Allen unique

  • Booz Allen's venture capital arm, Booz Allen Ventures, strategically invests in dual-use technologies, setting it apart from traditional consulting firms.
  • Their focus on AI security and space automation through investments in companies like HiddenLayer and Albedo highlights a unique blend of consulting and cutting-edge technology.
  • Booz Allen's involvement in both commercial and military sectors provides a diversified portfolio that leverages dual-use capabilities.

Help us improve and share your feedback! Did you find this helpful?