Cybersecurity Analyst
Position Overview
Ellumen is seeking a Cybersecurity Analyst to support cybersecurity and Risk Management Framework (RMF) activities for Defense Health Agency (DHA) systems and applications. The successful candidate will serve as a key liaison supporting Information System Security Managers (ISSMs), system stakeholders, and site personnel to ensure the security, compliance, and operational integrity of DHA environments.
This role requires expertise in RMF, cybersecurity compliance, continuous monitoring, and accreditation activities across enterprise systems and networks. The Cybersecurity Analyst will evaluate security controls, assess risks, support authorization activities, and provide recommendations to strengthen the security posture of DHA systems, including local and wide area networks, workstations, network devices, and end-user devices.
Key Responsibilities
- Support all phases of the Risk Management Framework (RMF) lifecycle, including system authorization, continuous monitoring, and accreditation activities.
- Develop, implement, and maintain cybersecurity programs, policies, procedures, and security requirements at the organizational and system levels.
- Manage and maintain cybersecurity documentation repositories, including eMASS and related compliance artifacts.
- Coordinate cybersecurity inspections, assessments, audits, testing activities, and continuous monitoring efforts with internal and external stakeholders.
- Provide technical cybersecurity guidance and advisory support to ISSMs, site personnel, and program stakeholders.
- Review security requirements and provide recommendations to project teams and system owners.
- Analyze, review, and provide input on Plans of Action and Milestones (POA&Ms) to support risk mitigation efforts.
- Support the development and implementation of Cybersecurity Control Correlation Identifier (CCI) metrics, policies, and procedures.
- Monitor compliance with DHA and Department of Defense cybersecurity policies, standards, and regulations.
- Identify, document, and report cybersecurity incidents through appropriate reporting channels.
- Provide guidance regarding CMRS tagging, TASKORD requirements, and Information Assurance Vulnerability Management (IAVM) compliance.
- Conduct cybersecurity risk assessments and provide analysis, recommendations, and strategic guidance to Government leadership.
- Collaborate with cross-functional teams to support secure system operations and maintain authorization compliance.
- Perform additional cybersecurity and compliance-related duties as assigned.
Required Qualifications
- Bachelor's degree in Cybersecurity, Information Technology, Computer Science, or a related field. Equivalent combination of education and experience may be considered.
- Minimum of 5 years of experience supporting RMF processes within Department of Defense (DoD) or DHA environments, or equivalent relevant experience.
- Minimum of 5 years of experience supporting DHA systems, programs, or healthcare IT environments, or equivalent relevant experience.
- Active Secret Security Clearance (required).
- Strong knowledge of:
- DoD Risk Management Framework (RMF)
- NIST 800-53 security controls
- eMASS
- Continuous Monitoring (ConMon)
- Security Control Assessments (SCAs)
- Vulnerability management and compliance reporting
- POA&M development and management
- IAVM requirements and remediation processes
Certifications
Candidates must meet DoD 8570/8140 requirements for IAM Level I certification and possess one of the following certifications (or equivalent):
- CompTIA Security+ CE (minimum requirement)
- CAP
- GSLC
- Other DoD-approved IAM Level I certifications
For additional certification requirements, refer to the DoD Approved Baseline Certifications guidance.
Preferred Qualifications
- Experience supporting Defense Health Agency (DHA) enterprise environments.
- Familiarity with military healthcare systems and federal cybersecurity compliance requirements.
- Experience working directly with ISSMs, Authorizing Officials (AOs), and Security Control Assessors (SCAs).
- Strong written and verbal communication skills with the ability to present technical findings to both technical and non-technical audiences.
- Ability to manage multiple priorities in a fast-paced federal environment.
Clearance Requirement
- Active Secret Security Clearance required.
|