Evaluate corrective action plans, system security plans, and technical inquiries against NIST security requirements to ensure federal data protection. Prepare clear compliance determinations and provide cybersecurity guidance for planned changes while maintaining accurate records in the case management system.
Requirements overview
Requires one to three years of experience in cybersecurity compliance or a related information security role, along with a working knowledge of NIST SP 800-53. Candidates must possess strong technical writing skills and the ability to obtain a Minimum Background Investigation (MBI) for federal government work.
Founded in 2012, APTNEXUS is a premier provider of IT Services with a specialization in cybersecurity governance, risk, and compliance solutions for both information and operational technologies. Our focus on IT combined with our specialization in cybersecurity ensures that our services seamlessly integrate into your mission and business processes while also reducing organizational risk.
Our core competency is building teams of highly skilled, certified, and cleared professionals that specialize in all aspects of IT and cybersecurity. Our teams have successfully completed engagements for customers spanning multiple industries, including the IRS, US Trade and Development Agency, Washington Headquarters Services, The International Monetary Fund, MUFG Union Bank, KPMG, United Bank, and Cognizant. This wide ranging experience is what enables our professionals to tailor custom solutions, unique to your agency’s mission, that enhance and protect your business processes and the systems that support them.
Whether IT or OT, we get ‘it’. Your customers will continue to want ‘it’ now and from anywhere. Therefore, your technology and its associated threat landscape will evolve. Let us help you continue focusing on innovative ways to meet your customer's needs while we optimize your IT and eliminate your cybersecurity risk.
Security & SafetyTechnologyGovernment & Public SectorConsulting
Description
Clearance:
Ability to obtain and maintain a Minimum Background Investigation (MBI) for our Department of Treasury customer. Candidates must reside in, and perform all work from, the continental United States or its outlying territories.
Location:
Remote (United States)
Work Schedule:
Full-time, remote. Must be available during core business hours (Eastern Time) to support stakeholder calls and submission deadlines. Occasional travel may be required.
Salary Range:
$65,000 to $75,000 annually, commensurate with experience
Position Overview:
AptNexus is seeking a Cybersecurity Compliance Analyst I to support a cybersecurity compliance program for our Department of Treasury customer. The program oversees the protection of sensitive federal data held by federal, state, and local government organizations, which submit corrective action plans, system security plans, technical inquiries, and change notifications for review. In this role, you will evaluate these submissions against security requirements tailored from NIST SP 800-53, working under the guidance of senior analysts, and deliver clear, well-supported compliance determinations. The ideal candidate is a detail-oriented self-starter who can manage a steady volume of reviews with consistency and precision.
Duties/Responsibilities:
Evaluate corrective action plans and POA&Ms submitted by partner organizations, including supporting evidence such as screenshots, audit logs, and policy documents, and determine whether each finding is open or closed.
Recommend follow-on actions required to close open findings, and address questions and statements raised in partner organization responses.
Review system security plans and related compliance submissions against applicable NIST controls, identify compliance status, and articulate applicable requirements.
Prepare written responses to technical inquiries on topics such as multifactor authentication, cloud configuration, and control implementation, and participate in follow-up calls as needed.
Evaluate advance notifications of planned changes, such as cloud adoption, contractor access, and test environments, and provide written cybersecurity guidance.
Request clarification or additional documentation from partner organizations when submissions are incomplete, and track responses to closure.
Track assigned reviews, due dates, and turnaround to meet customer deadlines.
Use and help maintain standardized templates and Excel-based tools, including VBA macros, that support consistent and efficient reviews.
Maintain complete and accurate records of all correspondence and documentation in the customer’s case management system.
Comply with all customer security, privacy, and records management requirements, using only Government-furnished equipment and approved systems.
Required Skills
One to three years of experience in cybersecurity compliance, audit, assessment, or a related information security role. Recent graduates with relevant internship or academic project experience are encouraged to apply.
Demonstrated experience, whether professional, internship, or academic, identifying and applying information security or cybersecurity requirements.
Working knowledge of NIST SP 800-53 and the NIST Risk Management Framework, including how security controls are implemented and evidenced.
Ability to read technical evidence, such as configuration screenshots, audit logs, and policy documents, and judge whether a control requirement has been met.
Familiarity with common technologies that drive compliance questions, including cloud services, multifactor authentication, encryption, operating systems, and network devices.
Strong technical writing skills, with the ability to produce clear, consistent, and well-supported written determinations.
Proficiency with Microsoft Word and Excel; experience with VBA macros is preferred.
Detail-oriented self-starter who takes ownership of assignments, manages competing priorities, and drives work to completion with minimal supervision.
Preferred Certifications (not required):
CompTIA Security+ CE
CompTIA Cybersecurity Analyst (CySA+)
Systems Security Certified Practitioner (SSCP)
GIAC Security Essentials Certification (GSEC)
Certified in Governance, Risk and Compliance (CGRC, formerly CAP)
Strong written and verbal communication skills, with a professional and courteous approach to partner organizations and customer personnel.
Sound professional judgment, objectivity, and integrity in handling sensitive information.
Must meet federal eligibility requirements for a position of public trust, including U.S. citizenship or lawful permanent residency, federal tax compliance, Selective Service registration (if applicable), a credit check, and fingerprinting.
Must complete customer-required security awareness training upon onboarding and annually thereafter.
Education Requirement:
Associate’s degree or higher from a minimum two-year information technology or cybersecurity program at an accredited college or university. Candidates with a high school diploma and one of the certifications listed above will also be considered. A bachelor’s degree in information technology, cybersecurity, information systems, or a related field is preferred.
AptNexus is an Equal Opportunity Employer. Qualified applicants will receive consideration for employment without regard to race, color, religion, sex, national origin, sexual orientation, gender identity, disability or protected veteran status.