Come build, innovate, disrupt, and thrive!
KēSTA I.T is actively seeking a IT Security Analyst for an immediate contract engagement with our government client.
Work Location: This position is Hybrid
Job Description:
We Are Seeking an IT Security Analyst to support enterprise security compliance, governance, and risk management initiatives by developing, maintaining, and validating System Security Plans (SSPs) for new and existing information systems. This role is responsible for collaborating with cross-functional technical and business teams to ensure systems comply with security standards, regulatory requirements, and organizational policies. The ideal candidate will have experience with security governance, NIST security controls, Governance, Risk, and Compliance (GRC) tools, risk assessments, and security documentation, along with strong analytical, communication, and problem-solving skills.
Responsibilities:
· Develop, maintain, and update System Security Plans (SSPs) for new and existing enterprise applications and systems.
· Collaborate with project managers, system owners, security administrators, technical leads, product owners, and business stakeholders to establish and document security processes and controls.
· Support Authority to Operate (ATO) activities and ensure compliance with organizational security accreditation processes.
· Create and maintain security documentation within Governance, Risk, and Compliance (GRC) platforms.
· Coordinate system registration activities and maintain required security documentation throughout the system lifecycle.
· Perform risk assessments and document responses for security control implementation.
· Identify security vulnerabilities and collaborate with technical teams to develop remediation plans.
· Validate security controls to ensure compliance with NIST standards, organizational policies, and applicable regulatory requirements.
· Lead security testing, vulnerability scanning, and system assessment activities.
· Monitor Plans of Action and Milestones (POA&Ms) and Corrective Action Plans (CAPs) to ensure timely remediation of identified risks.
· Coordinate security scanning and assessment activities with internal security teams, project teams, and business stakeholders.
· Lead data classification activities as part of the SSP and ATO processes.
· Collect, review, and validate security artifacts required for compliance assessments and audits.
· Develop recommendations to strengthen system security posture and improve compliance with security standards.
· Maintain technical documentation and provide ongoing support for enterprise security governance initiatives.
Required Skills:
Required Qualifications
· Bachelor's degree in Information Technology, Computer Science, Cybersecurity, Computer Information Systems, Mathematics, or a related field, or an associate degree with qualifying technical coursework and relevant professional experience, or a high school diploma (or equivalent) with qualifying information technology experience, or an industry-recognized IT or Cybersecurity certification.
· 1–3 years of experience in information security, cybersecurity, compliance, governance, risk management, or a related field.
· Knowledge of System Security Plans (SSPs), security governance, and compliance processes.
· Familiarity with Governance, Risk, and Compliance (GRC) tools and security documentation.
· Understanding of NIST security frameworks, security controls, and cybersecurity best practices.
· Experience supporting security assessments, risk assessments, vulnerability management, and compliance initiatives.
· Knowledge of Authority to Operate (ATO), Plans of Action and Milestones (POA&Ms), and Corrective Action Plans (CAPs).
· Experience coordinating with technical teams, business stakeholders, and security personnel to implement security requirements.
· Strong analytical, troubleshooting, and problem-solving skills.
· Excellent written and verbal communication skills with the ability to create clear technical documentation.
· Ability to manage multiple priorities while working independently and collaboratively in a team environment.
Preferred Qualifications
· Experience using Keylight or similar Governance, Risk, and Compliance (GRC) platforms.
· Experience supporting enterprise application security compliance initiatives.
· Knowledge of Secure Application Development Life Cycle (SADLC) practices.
· Experience with vulnerability scanning, security testing, and security accreditation processes.
· Familiarity with data classification methodologies and enterprise security governance.
· Experience working within regulated or large enterprise IT environments.
Available Benefits:
· Medical Benefits (Platinum level plans available)
· Work from home / Hybrid / Onsite options
· PTO
· Holiday Pay
· VTO
· 401K
· Charitable Match
· Training reimbursement
About KēSTA I.T.:
Our name says it all; KēSTA I.T. (Keys-to-I.T.) AND our people are our keys to our success!
KēSTA I.T. is a premier Utah-based technical staffing and consulting services firm. We specialize in temporary and permanent placement of Software, Hardware, Network, Cloud, CRM/ERP, Data, End-User support, Web and Executive / leadership-based positions on a full time and consulting basis.
If you're interested in a role where top performance is rewarded, personal time is valued, and excellence is demanded at every level we want to talk to you today!
Where do you want to go? We've got the keys! ~ KēSTA I.T.