A Cyber Security Manager or Administrator monitors, controls, and maintains systems that protect the security of large databases, including databases with customer information and patient files. Manages and administers the examination of client computer systems, identification of weak points in security, development and implementation of new systems, and monitoring and response to security issues.
Job Requirements Alexandria, VA Dept of Homeland Security Polygraph Unspecified Career Level not specified Salary not specified Join Premium to unlock estimated salaries Job Description SHR Consulting Group, LLC is a small business delivering enterprise IT, cybersecurity, and program management services to the Department of Defense and federal civilian agencies. We support mission-critical infrastructure at the Pentagon and across the National Capital Region, and we invest in our people through competitive compensation, professional certification support, and long-term career growth on stable, multi-year programs. We are seeking a Cybersecurity Analyst / Information System Security Officer (ISSO) to provide cybersecurity, risk management, compliance, and continuous monitoring support for Federal Emergency Management Agency (FEMA) information systems and cloud environments. The ISSO works with FEMA system owners, Information System Security Managers (ISSMs), technical teams, and cybersecurity stakeholders to maintain system security posture and compliance with
DHS/FEMA
cybersecurity requirements, FISMA, and the NIST Risk Management Framework (RMF). Key Responsibilities Support implementation and ongoing execution of the NIST Risk Management Framework (RMF) and
DHS/FEMA
security policies and procedures. Develop, maintain, and update system security documentation, including System Security Plans (SSPs), Security Assessment Reports (SARs), Plans of Action and Milestones (POA&Ms), Contingency Plans, Configuration Management Plans, and related authorization artifacts. Support Assessment and Authorization (A&A) activities for FEMA systems, applications, and cloud environments. Maintain security documentation and evidence within applicable
DHS/FEMA
governance, risk, and compliance (GRC) systems. Conduct and document security control assessments and support implementation and validation of
NIST SP 800-53
security and privacy controls. Track cybersecurity findings, vulnerabilities, POA&Ms, remediation activities, and risk acceptance through closure. Review vulnerability scanning and security monitoring results from tools such as Tenable/Nessus, CrowdStrike, Elastic, and other DHS/FEMA-approved security platforms. Coordinate with system administrators, cloud engineers, DevSecOps teams, application teams, and system owners to remediate vulnerabilities and configuration deficiencies. Support continuous monitoring, including recurring security control reviews, vulnerability management, configuration compliance, and required reporting. Review proposed system and infrastructure changes to identify cybersecurity impacts and ensure security requirements are incorporated throughout the system lifecycle. Support compliance with applicable DHS security directives, FEMA policies, FISMA, Fed
RAMP, NIST
guidance, and federal cybersecurity requirements. Assist with incident response activities, security investigations, audit requests, and cybersecurity reporting as required. Participate in security reviews, technical meetings, change management activities, and coordination with FEMA cybersecurity stakeholders. Identify cybersecurity risks and provide practical recommendations for mitigation, remediation, or risk management. Maintain audit-ready security documentation and supporting evidence. Minimum Qualifications Bachelor's degree in Cybersecurity, Information Technology, Computer Science, Information Systems, or a related discipline; relevant experience may be considered in lieu of a degree. 5+ years of cybersecurity or information assurance experience, preferably supporting federal government environments. Demonstrated experience supporting RMF, A&A, security control implementation, continuous monitoring, vulnerability management, and POA&M management. Working knowledge of
NIST SP 800-53, NIST SP
800-37, FISMA, FedRAMP, and federal cybersecurity requirements. Experience developing and maintaining cybersecurity authorization and compliance documentation. Familiarity with enterprise and cloud environments, including AWS and/or Microsoft Azure. Strong written and verbal communication skills with the ability to work effectively with technical and non-technical stakeholders. Preferred Qualifications Previous experience supporting FEMA, DHS, or another federal civilian agency. Experience securing AWS GovCloud and/or Azure Government environments. Experience with vulnerability management, SIEM, endpoint security, and continuous monitoring technologies. Experience working with Agile and DevSecOps engineering teams. Familiarity with Zero Trust architecture and federal cloud security requirements. One or more relevant certifications, such as CISSP, CAP/CGRC, Security+, CISM, CCSP, or equivalent cybersecurity certification. Desired Attributes Strong attention to detail and ability to maintain accurate, audit-ready security documentation. Ability to manage multiple systems, security requirements, findings, and deadlines simultaneously. Proactive approach to identifying and resolving cybersecurity risks. Ability to translate federal cybersecurity requirements into actionable requirements for engineering and operations teams. Strong collaboration skills and ability to work across cybersecurity, engineering, program management, and Government stakeholder organizations. Clearance Requirements U.S. Citizenship. Ability to obtain and maintain required
DHS/FEMA
suitability and security clearance/access requirements. Priority will be given to FEMA Public Trust Clearance or DHS Public Trust within the last 3 years, or to active/current Public Trust. Benefits Competitive salary commensurate with experience and clearance level Comprehensive medical, dental, and vision coverage. 401(k) with company contribution. Paid time off and eleven federal holidays. Certification reimbursement and training Life and disability insurance. SHR Consulting Group, LLC is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability, or protected veteran status.