Cybersecurity Requirements Analyst
Professional Level
Engineer 1
Responsibilities
Review system documentation, technical evidence, and assessment results against NIST, FISMA, RMF, FedRAMP, and Zero Trust requirements.
Elicit, document, and maintain cybersecurity requirements for cloud, hybrid, and on-premises systems.
Perform control-gap analyses, maturity assessments, and compliance reviews; identify risks and recommend corrective actions.
Support authorization and assessment activities by preparing security plans, control implementation statements, assessment artifacts, and remediation documentation.
Track findings, evidence requests, Plans of Action and Milestones, and remediation status in eMASS or comparable governance, risk, and compliance tools.
Coordinate with system owners, engineers, cloud teams, and program stakeholders to resolve security requirements and validate corrective actions.
Develop concise assessment reports, risk summaries, and leadership briefings that explain findings, impacts, and recommended next steps.
Requirements
Five or more years of cybersecurity analysis, security requirements, governance, risk, compliance, or security assessment experience.
Working knowledge of the NIST Risk Management Framework, NIST SP 800-53 controls, FISMA, FedRAMP, and authorization to operate processes.
Experience assessing security controls, analyzing evidence, documenting gaps, and tracking Plans of Action and Milestones to closure.
Experience with Zero Trust principles and with cybersecurity requirements for cloud, hybrid, or on-premises environments.
Ability to develop clear security requirements, technical documentation, assessment reports, and stakeholder briefings.
Bachelor's degree in cybersecurity, information systems, information technology, engineering, or a related field, or equivalent relevant experience. A master's degree in a related field is preferred.
Strong analytical, organization, written communication, and collaboration skills.
Salary Range
$62,818—$69,738 USD