We use cookies. Find out more about it here. By continuing to browse this site you are agreeing to our use of cookies.
#alert
Back to search results

Information Security Analyst

Cherokee Federal
401(k)
United States, D.C., Washington
Apr 10, 2025

As an Information Security Analyst at Cherokee Nation Systems Solutions (CNSS) in Washington, DC, you will play a pivotal role in ensuring the security and functionality of system platforms. You will collaborate with upper management to determine acceptable levels of risk for enterprise computing platforms.

Must be able to obtain a Public Trust, US Citizenship required per our government client and DHS suitability

Compensation & Benefits:

Estimated Starting Salary Range for Information Security Analyst: Starting $95,000

Pay commensurate with experience.

Full time benefits include Medical, Dental, Vision, 401K, and other possible benefits as provided. Benefits are subject to change with or without notice.

Information Security Analyst Responsibilities Include:



  • Provide Information Technology General Controls (ITGC) testing to develop and execute software test plans to identify procedural issues related to software configurations resulting in financial risk.
  • Assist stakeholders in designing, implementing, and effectively operating IT controls and processes that protect financial data.
  • Support in performing IT Benchmarking tasks which are used to demonstrate through testing that a sufficiently strong IT internal control environment for CFO Systems (internal and external) is designed and operated effectively that will lead to a downgrade of the IT deficiencies.
  • Assist in the development of a strategy that will enable the Benchmarks in consideration of available resources within the organization. Additional support is required to perform an initial A-123 ITGC assessment scoping each Fiscal Year (FY) based on the organization strategy.
  • Establish plans of action and milestones (POA&M) or Remediation Work Plans for all identified deficiencies within required timeframes per DHS 4300A and OCISO guidance.
  • Conduct Test of Design (TOD) for the IT program used for internal controls, over Financial Systems. Includes but not limited to evaluating the design of a control to determine whether the control should sufficiently address the corresponding control requirement and objective as well as relevant standards and regulations such as NIST 800-53, Rev. 5 and DHS Sensitive Systems Policy Directive 4300A.
  • Conduct Test of Effectiveness (TOE) for the IT program used for internal controls, over Financial Systems. Includes but not limited to evaluating the operating effectiveness of a control to determine whether the control is correctly implemented and operated as designed.
  • Provide support to ad-hoc IT Assessments to include but not limited to critical IT controls (CIC), Financial and related financial system ATOs, Accounting Treatment Manual Assessment and Testing (ATM), etc.
  • Collaborate with cross-functional teams to integrate security requirements into system planning, fieldwork, and reporting.
  • Work general supervision, relying on experience and judgment to plan and accomplish goals, while demonstrating a wide degree of creativity and latitude in problem-solving.
  • Report to a manager or head of a unit/department, providing regular updates on security initiatives, risks, and mitigation strategies.
  • Performs other job-related duties as assigned.


Information Security Analyst Experience, Education, Skills, Abilities requested:



  • Minimum education includes a bachelor's degree in a business field, systems engineering, computers, or other related fields, required
  • Minimum experience includes having two (2) years of government IT financial or system testing, including one year of federal internal controls ITGC experience, required
  • Knowledge of Federal and Department of Homeland Security (DHS) policies and guidance, OMB A-123 attachment R-4300A, DISA STIGS, DHS hardening guidance, DHS Control Evaluation Matrix (CEM) framework, DHS CEM Testing and POA&M management, required
  • Strong communication and interpersonal skills, with the ability to collaborate effectively with senior management, technical teams, and stakeholders.
  • Ability to work independently and prioritize tasks in a fast-paced environment.
  • Must be able to obtain a Public Trust, US Citizenship required per our government client and DHS suitability
  • Must pass pre-employment qualifications of Cherokee Federal.
  • Schedule is M-F days
  • 100% on-site
  • No travel expected


Company Information:

Cherokee Nation System Solutions (CNSS) is a part of Cherokee Federal - the division of tribally owned federal contracting companies owned by Cherokee Nation Businesses. As a trusted partner for more than 60 federal clients, Cherokee Federal LLCs are focused on building a brighter future, solving complex challenges, and serving the government's mission with compassion and heart. To learn more about CNSS, visit cherokee-federal.com.

#CherokeeFederal #LI-SB1

Cherokee Federal is a military-friendly employer. Veterans and active military transitioning to civilian status are encouraged to apply.

Similar Job Titles:



  1. IT Security Analyst
  2. Information Assurance Analyst
  3. IT Risk Analyst
  4. Security Compliance Analyst


Keywords:



  1. IT General Controls (ITGC)
  2. IT Accessor
  3. Compliance Testing
  4. Security Controls
  5. Internal Audit


Legal Disclaimer:

All qualified applicants will receive consideration for employment without regard to protected veteran status, disability or any other status protected under applicable federal, state or local law.

Many of our job openings require access to government buildings or military installations. Candidates must pass pre-employment qualifications of Cherokee Federal.

Applied = 0

(web-77f7f6d758-swlff)