Job Closed
This listing is no longer active.
GovCIO is a service-disabled-veteran-owned small business (SDVOSB) that offers technology services to improve business performance for government organizations.
Cyber Security Associate (Remote)
Location
United States
Posted
69 days ago
Salary
$70K - $80K / year
Seniority
Mid Level
Job Description
Cyber Security Associate (Remote)
GovCIO
Overview GovCIO is currently hiring for a Cyber Security Analyst 1 to support foundational cybersecurity and ATO activities, including assisting with documentation, evidence collection, and Continuous Monitoring tasks across VA systems. This position will be a fully remote within the United States position. Responsibilities - Assist in preparing and updating foundational ATO documentation under senior staff guidance (e.g., SSP sections, IRP updates, PTA/PIA drafts, CMP updates). - Support tracking and maintenance of ATO packages in ServiceNow CAM, including uploading artifacts and organizing evidence. - Support Continuous Monitoring tasks using ServiceNow CAM, updating dashboards with supervision. - Help coordinate routine security vulnerability scanning requests and compile scan outputs for review. - Participate as a note‑taker or supporting analyst during tabletop and functional IRP/ISCP/DRP exercises. - Assist with gathering data for POA&M updates and maintain documentation libraries. - Conduct initial reviews of security findings and escalate issues to senior analysts. - Help with administrative tasks related to audit preparation, evidence gathering, and compliance reporting. - Collaborate with cross‑functional teams by collecting information needed for engineering, privacy, or security reviews. - Learn and apply fundamental cybersecurity frameworks, VA security processes, and best practices. Qualifications Required Skills and Experience: - Bachelor's degree in Computer Science, Cyber Security, Information Systems, or similar; OR equivalent experience or certifications. - 0–2 years of cybersecurity experience (internship, entry-level role, or coursework projects acceptable). - Familiarity with RMF, NIST SP 800-53 security controls, creating and updating artifacts and FISMA security documents, control implementation details, and Plan of Action and Milestones (POA&M). - Basic understanding of vulnerability scanning tools, ATO processes, or GRC workflows. - Foundational understanding of security concepts such as risk, compliance, configuration management, and incident response. - Willingness to learn VA GRC tools such as eMASS and ServiceNow CAM. - Strong attention to detail and documentation skills. - Effective verbal and written communication skills. Clearance Requirement: Suitability/Public Trust - Eligibility Requirements: Candidates must be U.S. citizens or permanent residents and have resided in the United States for a minimum of three (3) years. Preferred Skills and Experience - Experience with Jira, Confluence, and Microsoft 365. - Exposure to federal cybersecurity programs a plus. - Entry-level certifications: Security+, CAP (in progress), or similar. - Interest in AI‑assisted GRC tooling and automation. Regulation Knowledge - FISMA, FedRAMP (conceptual understanding) - NIST SP 800‑53 (awareness level) - NIST SP 800‑37 RMF basics - VA Directive 6500 (introduction to concepts) Company Overview GovCIO is a team of transformers--people who are passionate about transforming government IT. Every day, we make a positive impact by delivering innovative IT services and solutions that improve how government agencies operate and serve our citizens.But we can't do it alone. We need great people to help us do great things - for our customers, our culture, and our ability to attract other great people. We are changing the face of government IT and building a workforce that fuels this mission. Are you ready to be a transformer? What You Can Expect Interview & Hiring Process If you are selected to move forward through the process, here’s what you can expect: - During the Interview Process - Virtual video interview conducted via video with the hiring manager and/or team - Camera must be on - A valid photo ID must be presented during each interview - During the Hiring Process - Enhanced Biometrics ID verification screening - Background check, to include: - Criminal history (past 7 years) - Verification of your highest level of education - Verification of your employment history (past 7 years), based on information provided in your application Employee Perks At GovCIO, we consistently hear that meaningful work and a collaborative team environment are two of the top reasons our employees enjoy working here. In addition, our employees have access to a range of perks and benefits to support their personal and professional well-being, beyond the standard company offered health benefits, including: - Employee Assistance Program (EAP) - Corporate Discounts - Learning & Development platform, to include certification preparation content - Training, Education and Certification Assistance* - Referral Bonus Program - Internal Mobility Program - Pet Insurance - Flexible Work Environment *Available to full-time employees Our employees’ unique talents and contributions are the driving force behind our success in supporting our customers, which ultimately fuels the success of our company. Join us and be a part of a culture that invests in its people and prioritizes continuous enhancement of the employee experience. We are an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, gender, gender identity or expression, sexual orientation, national origin, disability, or status as a protected veteran. EOE, including disability/vets. Posted Pay Range The posted pay range, if referenced, reflects the range expected for this position at the commencement of employment, however, base pay offered may vary depending on multiple individualized factors, including market location, job-related knowledge, skills, education, experience, and internal equity. The total compensation package for this position may also include other compensation elements, to be discussed during the hiring process. If hired, employee will be in an “at-will position” and the GovCIO reserves the right to modify base salary (as well as any other discretionary payment or compensation program) at any time, including for reasons related to individual performance, GovCIO or individual department/team performance, and market factors. Posted Salary Range USD $70,000.00 - USD $80,000.00 /Yr.
Related Guides
Related Categories
Related Job Pages
More Security Analyst Jobs
Senior Info Security Analyst
UPSUPS is committed to providing a workplace free of discrimination, harassment, and retaliation.
Before you apply to a job, select your language preference from the options available at the top right of this page. Explore your next opportunity at a Fortune Global 500 organization. Envision innovative possibilities, experience our rewarding culture, and work with talented teams that help you become better every day. We know what it takes to lead UPS into tomorrow—people with a unique combination of skill + passion. If you have the qualities and drive to lead yourself or teams, there are roles ready to cultivate your skills and take you to the next level. Job Description: SENIOR INFORMATION SECURITY ANALYST The Sr. Information Security Analyst on the Information Security Identity Access Governance (Info Sec IAG) will assist in maintaining and building out our identity provisioning and auditing practice. This position is critical to maintaining the integrity, security, and compliance of our IBM z/OS Mainframe environment within IBM Security Server (RACF). This role ensures operational stability, regulatory adherence, and timely support for business-critical systems. This position leads the implementation of new Mainframe hardware cryptographic master keys, ensuring robust encryption capabilities. In addition, the role supports SOX compliance through quarterly DataSet audits and UPS control reviews for application access. Serving as the primary authority for encryption operations in our Mahwah data center, this resource also manages the digital certificate lifecycle, guaranteeing alignment with corporate security standards and regulatory requirements. Responsibilities: - Performs incident management, team mailbox support, daily requests received in SailPoint which includes MFA assignment, Dataset, CICS, Generic IDs and DB2 new group requests. - Completes IIQ SailPoint post processing for elevated RACF group connections. - Handles support issues and carries a support phone during the allocated week. - Reports and performs access reviews such as DataSet Quarterly audits, SOX relates audits for UPS controls for application access. - Monitors and completes any manual jobs. - Installs and provide life cycle management support for digital certificates. - Performs encryption functions using pervasive and crypto keys. - Performs master key entry for new z/OS boxes as well as rotates master keys in ICSF. Qualifications: - Experience completing end to end Mainframe projects. - Minimal Mainframe requirements include knowledge and experience using IBM Security Server (RACF), IBM z/OS mainframe environments, TN3270 interfaces (i.e. QWS3270), 3270 session monitors (i.e. TPX), TSO, ISPF. - TKE utility experience and ICSF key management experience is a must. - Pluses include additional knowledge and experience of Mainframe auditing as well as using any of the following: Stig Viewer, Vanguard Administrator, IBM zSecure Audit for RACF, REXX, JCL. - Minimal Windows requirements include knowledge and experience using MS Office products and Planview. - Excellent written and verbal communication skills - Bachelor’s Degree or International equivalent in Computer Science or a related field preferred Other Criteria - Job Grade: 20H - Work Location: This is a remote position but candidates will be required to report to the Mahwah, NJ, Parsippany, NJ or Alpharetta, GA location occasionally Pay Range: Our compensation reflects the cost of labor across several US geographic markets. The base pay for this position ranges from $90,840.00/year to $168,360.00/year. Pay is based on several factors including but not limited to, market location and may vary depending on job-related knowledge, skills, and education/training and a candidate’s work experience. Hired applicants are offered annual short-term and/or long-term incentive compensation programs, subject to applicable eligibility requirements. Payments under these annual programs are not guaranteed and are dependent upon a variety of factors including, but not limited to, individual performance, business unit performance, and/or the company’s performance. The company offers the following benefits for this position, subject to applicable eligibility requirements. Medical/prescription drug coverage, Dental coverage, Vision coverage, Flexible Spending Account, Health Savings Account, Dependent Care Flexible Spending Account, Basic and Supplemental Life Insurance & Accidental Death and Dismemberment, Disability Income Protection Plan, Employee Assistance Program, 401(k) retirement program, Vacation, Paid Holidays and Personal time, Paid Sick and Family and Medical Leave time as required by law, and Discounted Employee Stock Purchase Program. Employee Type: Permanent UPS is committed to providing a workplace free of discrimination, harassment, and retaliation. Other Criteria: UPS is an equal opportunity employer. UPS does not discriminate on the basis of race/color/religion/sex/national origin/veteran/disability/age/sexual orientation/gender identity or any other characteristic protected by law. Basic Qualifications: Must be a U.S. Citizen or National of the U.S., an alien lawfully admitted for permanent residence, or an alien authorized to work in the U.S. for this employer.
• Help Tenchi clients understand our product features and best practices for reducing cyber risk in cloud environments, ensuring the successful adoption of our product integrated into the client's third-party risk management process. • Perform routine operations to meet our clients' requests, generating insights to guide future automation of these operations. • Diagnose product-related issues and work with the technical support and engineering teams to resolve client issues efficiently. • Monitor the health of client environments and collaborate with them to drive product adoption. • Work with the product team by providing customer feedback and offering insights for product improvements and enhancements. • Proactively engage with clients to identify their needs, concerns, and areas for improvement, assisting them in achieving their cybersecurity objectives. • Track and report key metrics such as client satisfaction, product usage, and retention. • Assist in the creation and maintenance of client-facing resources, such as FAQs, product documentation, and best practice guides. • Experience with Python programming and task automation is a plus. • Experience building and maintaining QuickSight, PowerBI, and other analytics dashboards is a plus.
• Join our team as a Cybersecurity Analyst, where you'll play a critical role in assessing and analyzing cybersecurity documentation for client information systems. • You'll apply your scripting skills to develop and improve automations that streamline our assessment processes. • Your work will align with FISMA, NIST RMF for Federal Civilian Agencies, RMF for DoD IT, FedRAMP, and departmental standards, with a primary focus on FedRAMP. • Engage directly with clients through verbal communication to perform interviews for assessments, understand their needs, and provide effective solutions. • Conduct comprehensive assessments by analyzing cybersecurity documentation and performing evidence collection, interviews, and tests to evaluate compliance with relevant standards such as FISMA, NIST RMF, and FedRAMP. • Creating scripts and/or utilizing scripts to automate repetitive tasks and improve the efficiency of security assessments, reporting, and evidence collection. • Conduct system and network vulnerability scanning and analysis using tools such as Nessus/ACAS, SCC, and DISA STIGs/STIG Viewer. • Prepare clear and accurate reports and documentation, with an emphasis on creating scripts to automate analysis and report generation. • Work independently or as part of a client delivery team in a fast-paced, deadline-driven, remote environment. • Travel up to 25% for client engagements as required.
Security Compliance Analyst – Intern
EnsonoEnsono is an information technology and services company on a mission to help technology leaders transform their businesses by becoming a “catalyst for change
• Support Ensono’s internal audit and security control framework initiatives. • Document the Audit Process for All Ensono Audits. • Identify AI Opportunities for Internal Audit and develop solutions. • Review and update Ensono Security Control Framework (ESCF) with test procedures.




