
51 - 200 employees
💼 Consulting
🎖️ Defense
🏥 Healthcare
Consulting • Defense • Healthcare
SHR Consulting Group is an IT consulting firm that provides innovative information technology services to address the evolving challenges faced by government IT customers. With a focus on modernization, they offer a range of services including cloud services, cybersecurity, data analytics, and software development. SHR is committed to delivering superior service backed by industry certifications and a strong emphasis on the professional development of their employees.
🔥 0 minutes ago
⚔️ Virginia – Remote
💵 $115k - $145k / year
⏰ Full Time
🟡 Mid-level
🟠 Senior
🔐 Security Analyst
👻 Ghost score 1%
Improve your chances of getting an interview by checking your resume score before you apply.

51 - 200 employees
💼 Consulting
🎖️ Defense
🏥 Healthcare
Consulting • Defense • Healthcare
SHR Consulting Group is an IT consulting firm that provides innovative information technology services to address the evolving challenges faced by government IT customers. With a focus on modernization, they offer a range of services including cloud services, cybersecurity, data analytics, and software development. SHR is committed to delivering superior service backed by industry certifications and a strong emphasis on the professional development of their employees.
• Support implementation and ongoing execution of the NIST Risk Management Framework and DHS/FEMA security policies and procedures • Develop, maintain, and update System Security Plans, Security Assessment Reports, Plans of Action and Milestones, Contingency Plans, Configuration Management Plans, and related authorization artifacts • Support Assessment and Authorization activities for FEMA systems, applications, and cloud environments • Maintain security documentation and evidence in applicable DHS/FEMA governance, risk, and compliance systems • Conduct and document security control assessments and support implementation and validation of NIST SP 800-53 controls • Track cybersecurity findings, vulnerabilities, POA&Ms, remediation activities, and risk acceptance through closure • Review vulnerability scanning and security monitoring results from Tenable/Nessus, CrowdStrike, Elastic, and other approved security platforms • Coordinate with system administrators, cloud engineers, DevSecOps teams, application teams, and system owners to remediate vulnerabilities and configuration deficiencies • Support continuous monitoring, including recurring security control reviews, vulnerability management, configuration compliance, and required reporting • Review proposed system and infrastructure changes for cybersecurity impacts and ensure security requirements are incorporated throughout the system lifecycle • Support compliance with DHS security directives, FEMA policies, FISMA, FedRAMP, NIST guidance, and federal cybersecurity requirements • Assist with incident response, security investigations, audit requests, and cybersecurity reporting • Participate in security reviews, technical meetings, change management activities, and coordination with FEMA cybersecurity stakeholders • Identify cybersecurity risks and provide recommendations for mitigation, remediation, or risk management • Maintain audit-ready security documentation and supporting evidence
• Bachelor's degree in Cybersecurity, Information Technology, Computer Science, Information Systems, or a related discipline; relevant experience may be considered in lieu of a degree • 5+ years of cybersecurity or information assurance experience, preferably supporting federal government environments • Experience supporting RMF, A&A, security control implementation, continuous monitoring, vulnerability management, and POA&M management • Working knowledge of NIST SP 800-53, NIST SP 800-37, FISMA, FedRAMP, and federal cybersecurity requirements • Experience developing and maintaining cybersecurity authorization and compliance documentation • Familiarity with enterprise and cloud environments, including AWS and/or Microsoft Azure • Strong written and verbal communication skills with technical and non-technical stakeholders • U.S. Citizenship • Ability to obtain and maintain required DHS/FEMA suitability and security clearance/access requirements • Priority given to FEMA Public Trust Clearance or DHS Public Trust within the last 3 years, or active/current Public Trust • Preferred: Previous experience supporting FEMA, DHS, or another federal civilian agency • Preferred: Experience securing AWS GovCloud and/or Azure Government environments • Preferred: Experience with vulnerability management, SIEM, endpoint security, and continuous monitoring technologies • Preferred: Experience working with Agile and DevSecOps engineering teams • Preferred: Familiarity with Zero Trust architecture and federal cloud security requirements • Preferred: One or more relevant certifications, such as CISSP, CAP/CGRC, Security+, CISM, CCSP, or equivalent cybersecurity certification
• Competitive salary commensurate with experience and clearance level • Comprehensive medical, dental, and vision coverage • 401(k) with company contribution • Paid time off • Eleven federal holidays • Certification reimbursement and training • Life and disability insurance • Long-term career growth on stable, multi-year programs
Apply Now🕒 Yesterday
Senior IT Security Analyst strengthening UBC’s Azure and on-premises cybersecurity program. Managing vulnerabilities, threat intelligence, security monitoring, and incident response.
🕒 Yesterday
Senior IT Security Analyst strengthening UBC’s Azure and on-premises cybersecurity program. Managing vulnerabilities, threat intelligence, security monitoring, compliance, and incident response.
🕒 Yesterday
Senior Security Analyst monitoring threats and managing incident response for CompassMSP’s managed security service clients. Deploying security tools and strengthening client environments.
🕒 Yesterday
IAM Epic Security Analyst II managing identity access, compliance, and Epic security systems at Sharp HealthCare. Supporting provisioning, audits, RBAC, incidents, and security projects.
🕒 Yesterday
Cyber Security Analyst protecting Cigna Healthcare systems, networks, and data. Monitoring defenses, investigating incidents, and strengthening security controls and policies.