SAIC Senior A&A Analyst Job in Vienna, Virginia

Senior A&A Analyst (Job Number:429858)


SAIC is hiring a Senior A&A Analyst in Vienna, VA

Job Description:

This role will lead assessment and authorization (A&A) efforts under the NIST Risk Management Framework (RMF) on behalf of a federal civilian agency as a contractor.

The role will manage a team that conducts cybersecurity analysis in preparation for A&A reviewing and validation of all associated cybersecurity documentation and technical controls.

This individual will supervise and manage the development of the System Security Plans (SSP), Contingency Plans, Business Impact Analyses, POA&Ms, SARs (Security Assessment Report), and SAPs (Security Assessment Plan).

This position covers all cybersecurity aspects including, but not limited to, identifying risks, validating the mitigation of plans of action, analyzing system designs, and assisting with A&A issues that may prevent a system from receiving authorization. It supports the implementation of RMF by developing documentation and updating policies, procedures, and processes as assigned.

Responsibilities and Duties:

  • Manage day-to-day A&A support activities

  • Develop and deliver an A&A program and associated training to improve consistency and quality

  • Build strong relationships with clients and internal departments to understand the IT security challenges and opportunities

  • Able to work with PMs to manage small to large sized projects - managing scope, schedule, resources, risks/issues, and cost

  • Support the creation of A&A management best practices, tools, and ways to drive A&A completion on schedule

  • Identify key stakeholders in A&A efforts and ensure system documentation reflects current system security configurations to include hardware and software components, data flow, interconnections, and ports, protocols, and services, etc.

  • Identify potential risks associated with system configurations and advise on mitigation strategies

  • Lead A&A status meetings and facilitate moving systems toward a successful A&A effort

  • Estimate Level of Effort (LOE) involved in performing A&A activities

  • Develop and implement detailed test plans and review findings from self-assessments to determine readiness for independent validation and verification (IV&V) assessment

  • Assist customer program offices in interpreting and applying mitigation strategies

  • Conduct IV&V assessments and analyze test results for accuracy, compliance, and adherence to Federal cybersecurity requirements

  • Conduct thorough reviews of all vulnerabilities, architecture, and defense in depth strategies and report findings in a plan of action and milestones (POA&M) document

  • Document residual risks and provide the cybersecurity risk analysis and mitigation determination results

  • Produce risk assessment artifacts describing initial risks during system development and residual risks identified during IV&V

  • Maintain cybersecurity policy and processes as assigned

  • Able to analyze, interpret, and apply Federal cybersecurity guidance to customer needs

  • Communicate the security posture of systems through designated reporting mechanism

  • Advise and mentor other team members in cybersecurity and provide initial quality assurance / peer review of RMF system packages


Required Skills:

  • Strong leadership skills, with the ability to lead a diverse team; must have excellent oral and written communication skills across all levels and the ability to write comprehensive reports and senior level documentation skills

  • Strong focus on collaboration, team building, and excellent customer service skills

  • Demonstrated skills running effective meetings and getting buy-in and participation from executive leaders

  • Able to quickly adapt to changing environment and deadlines to provide a consistent level of service

  • Effectiveness working diplomatically across teams with varying objectives

  • Microsoft Office (Word, Excel, Visio, PowerPoint, MS Project), MS SharePoint

  • Well-versed in NIST publications, specifically RMF and NIST controls

  • Subject Matter Expert dealing with defense-in-depth, and other information security and assurance principles and associated supporting technologies

  • Must demonstrate proficiency in the following areas: multi-tasking, organizational skills; critical thinking; and the ability to work quickly, efficiently and accurately in a dynamic and fluid environment

  • Ability to work both independently and as a member of a team

Additional Skills:

  • Experience working with Security engineering to review Nessus Vulnerability / Tripwire compliance scans

  • Experience performing on-site cybersecurity assessments using Standards such as CIS Benchmarks, DISA STIGS, etc.

  • Broad technical experience related to IT operations, networks, OS's, and system administration

Required Qualifications:

  • CISSP Certification

  • Experience as a team lead and performing A&A's

  • Understanding of NIST Special Publication including NIST SP 800-53 and other standards

  • Understanding of FISMA, NIST RMF, and other IT Security standards

Education and Experience:

  • Bachelor's Degree in IT, Cyber Security, Computer Science, or related field preferred and 9-10+ years of experience

  • 6-10+ years of demonstrated experience in Cybersecurity policy, procedures, and processes, including RMF and NIST 800-53 and A&A's

Preferred Qualifications:

  • Master’s Degree or higher

  • Experience working as an audit liaison with third-party and internal auditors for IT-related audits is strongly desired

US Citizenship Required

Must have the ability to obtain a Public Trust Clearance prior to starting work

SAIC Overview:SAIC is a premier technology integrator providing full life cycle services and solutions in the technical, engineering, intelligence, and enterprise information technology markets. SAIC is Redefining Ingenuity through its deep customer and domain knowledge to enable the delivery of systems engineering and integration offerings for large, complex projects. SAIC has approximately 15,000 employees are driven by integrity and mission focus to serve customers in the U.S. federal government. Headquartered in Reston, Virginia, SAIC has annual revenues of approximately $4.5 billion. For more information, visit

EOE AA M/F/Vet/Disability

Job Posting: Aug 11, 2017, 7:41:42 PM

Primary Location: United States-VA-VIENNA

Clearance Level Must Currently Possess: None

Clearance Level Must Be Able to Obtain: Public Trust

Potential for Teleworking: No

Travel: Yes, 10% of the time

Shift: Day Job

Schedule: Full-time