Jr. Information Security Analyst
About the position
The Junior Information Security Analyst will assist in conducting security control assessments, collecting evidence, and supporting compliance reporting for IRS systems under FISMA requirements. This role involves hands-on support for vulnerability scanning, control validation, and POA&M tracking using tools like ServiceNow and Qmulos. The analyst will contribute to assessments of cloud platforms (PaaS, SaaS, IaaS), pipeline security in CI/CD environments, and help develop metrics and dashboards for quarterly reporting.
Responsibilities
- Conducting security control assessments
- Collecting evidence
- Supporting compliance reporting for IRS systems under FISMA requirements
- Hands-on support for vulnerability scanning
- Control validation
- POA&M tracking using tools like ServiceNow and Qmulos
- Contributing to assessments of cloud platforms (PaaS, SaaS, IaaS)
- Pipeline security in CI/CD environments
- Help develop metrics and dashboards for quarterly reporting
Requirements
- 1 to 3 years of relevant professional experience in information security, cyber risk management, network defense, or cybersecurity operations
- Knowledge of FISMA, NIST Special Publications, OMB, Risk Management Framework (RMF), and ISCM Plan development
- IT security knowledge with professional certifications from ISC2, ISA, PMI, CompTIA, or SANS Institute
- Knowledge and experience with technology risk assessments covering Webservices, network appliances, and software
- Knowledge and experience with cloud systems, CSPs, and FedRAMP requirements
- IRS Moderate Risk Public Trust (Background Investigation required)
- Bachelor's degree in Cybersecurity, Information Systems, Computer Science, or related field
Nice-to-haves
- Security+ CE certification required
- Higher-level certifications (e.g., CISSP, CISM, CEH, CAP) preferred and may substitute for additional years of experience
- Knowledge of the IRS infrastructure, technologies, and general support systems
- Knowledge and experience with the IRS Enterprise Lifecycle and OneSDLC
- Knowledge of System Interconnections including VPN and other encryption technologies
- Knowledge of IRS Business Units and IT enterprise processes
- Knowledge/experience with Qmulos Q-Compliance, SharePoint, Scanning tools, ServiceNow GRC, SPLUNK
- Knowledge and experience with security architecture principles and system modeling
- Experience with end-user troubleshooting for access and permission issues in GRC workflows
Benefits
- Health, dental, and vision insurance
- 401(k) retirement plan
- Paid time off (PTO) and holidays
- Group Term Life and Accidental Death and Dismemberment Insurance
- Voluntary Term Life Insurance
- Short and Long-term disability insurance