Senior Security Analyst (A&A)/Assessor - NIST at ITC Federal in US-MD-Gaithersburg
- Company: ITC Federal
- Location: US-MD-Gaithersburg
- Posted: Sep 24, 2026
- Type: Full-Time
- Experience: 8+ years
Overview
ITC Federal, LLC (ITC) connects technology advancements in automation and AI, customer experience, and financial services to solve government mission challenges, enabling smoother operational efficiency and bolstering national security. We leverage the latest technology innovations and proven approa…
Job description
- ITC Federal, LLC (ITC) connects technology advancements in automation and AI, customer experience, and financial services to solve government mission challenges, enabling smoother operational efficiency and bolstering national security. We leverage the latest technology innovations and proven approaches to better serve the mission and support the DHS, DOJ, and DoW workforce, customers, and programs, regardless of scale or complexity. ITC is located in Fairfax, VA and offers outstanding compensation and benefits plan and a challenging and rewarding professional work environment.
- Senior Security Analyst will be focused on Security Assessment & Authorization (A&A) of systems for the National Institute of Standards and Technology (NIST). The Senior Security An alyst is expected to be capable of lending subject matter expertise while performing A&A activities. The Senior Security Analyst will demonstrate a strong knowledge of Security Requirement Analysis, Security Architecture , Enterprise Security Program Assessment, evaluating Vulnerability Assessment results and perform other duties as required.
Responsibilities
- Conducting A&A activities for NIST systems working individually or as part of a team.
- Work with NIST staff to provide technical and policy driven solutions to remediate or mitigate identified risks.
- Support system personnel with remediation plans for A&A findings.
- Provide guidance to Information System Security Officers (ISSO) on system documentation.
- Coordinate/conduct vulnerability scans and analyze results.
- Complete Security Assessment Reports involving both technical and policy related aspects of the assessment.
- Review and update A&A packages based on management feedback.
Requirements
- 5 - 8 years of experience implementing the NIST 800 Series Special Publications.
- Conducting IT assessor activities based on the NIST Risk Management Framework, to include the interviewing, examining and testing of related control sets; the review and/or updates of core system documents- System Security Plans, Contingency Plans, Privacy Threshold Assessments, hardware and software inventories, and system diagrams.
- Performing Security Test and Evaluation and developing Security Assessment Reports for NIST senior management.
- Delivering risk and vulnerability briefings confidently to management and government customers.
- Experience working with vulnerability data, writing Assessment Reports, POA&Ms and Risk Acceptance justifications
- Knowledge of the formation and implementation of IT security policies to ensure confidentiality, integrity and availability of information systems.
- Strong technical oral, writing and customer service skills as you will regularly interact with NIST colleagues and senior managers.
- Ability to successfully pass a National Agency Check with Local Agency Check (NACLC)
- Prior federal or GOVCON experience
- Cloud Experience (AWS or Azure)
- Active Certified Information Systems Security Professional (CISSP), Certified Information Security Manager (CISM), Certified Information Security Auditor (CISA) or comparable certification
- Advanced Degree in computer science or related field or related experience
- Direct experience with NIST or other academic environments.
- Expertise with COTS based security tools (i.e. RSA Archer, CSAM, Tenable, WebInspect, AppDetective) used to establish security baselines and assess continuing compliance.
Skills
Required
- NIST 800 Series Special Publications
- NIST Risk Management Framework
- Security Test and Evaluation
- Vulnerability scanning and analysis
- IT security policies
- Technical oral and written communication
- Customer service skills
Preferred
- Prior federal or GOVCON experience
- Cloud Experience (AWS or Azure)