Assessment & Authorization (A&A) Analyst
Hybrid Remote • Bethesda, MD • Health & Civil Division
Job Type
Full-time
Description

Salary: $60,000 - $71,000/year


Work location: Hybrid, 1-2 days per week on-site in Bethesda, MD.


The A&A Analyst will map NIH's FISMA systems to the Zero Trust controls they can inherit and help make Zero Trust assessable inside NIH's A&A process under the NIH Governance, Risk & Compliance (GRC) Zero Trust Architecture (ZTA) Support Services task order for the NIH Office of the Chief Information Officer (OCIO).

  • Pull the CSAM inventory and map the control set of each of NIH's 72 FISMA-registered systems against the Centrally Provided Services Matrix. Identify inherited, hybrid, and uncovered controls for the Inherited Controls Mapping and Remediation Roadmap.
  • Score residual gaps by FIPS 199 impact, data sensitivity, and internet exposure.
  • Build the ZTA Overlay mappings and evidence expectations, tagging each control as central, hybrid, or system-specific. Support the CSAM import and the three-system pilot.
  • Maintain records in the shared NIH ZTA control library.
  • Develop package templates (SSP, SAP/SAR, POA&M) and continuous-monitoring cadences (SP 800-137) for the three authorization tiers.
  • Keep the IC-inheritable controls content current on the OCIO ZTA Wiki, and answer control questions routed from the ZTA help desk.

Tools & Technology Environment: CSAM (primary), Xacta, RSA/SGRC Archer, ServiceNow; Excel and Power BI; Confluence/SharePoint and the OCIO ZTA Wiki.

Requirements
  • US Citizenship required
  • 4+ years of RMF/A&A experience in a federal environment
  • Working knowledge of NIST SP 800-37 Rev 2, 800-53 Rev 5, 800-53A, and FISMA.
  • Hands-on POA&M management and experience with CSAM or a comparable GRC tool.
  • Bachelor's degree
  • Security+ or CAP/CGRC certification.

Clearance Requirement: Ability to obtain and maintain a Public Trust.


Desired Qualifications:

  • HHS or NIH A&A experience in CSAM.
  • Common-control and inheritance modeling; experience with Zero Trust control mapping.
  • FedRAMP experience; CGRC or CISA certification.


The salary range for this position depends upon multiple factors including location, the individual's knowledge, skills, competencies, and experience, and contract-specific budget constraints and organizational requirements.
Gunnison Consulting Group's total compensation package also includes bonus and profit-sharing opportunities, depending on company and employee performance. Available employee benefits include:

  • 3 weeks of Personal Leave your first year
  • 11 paid Holidays each year
  • 5 days of Flexible Time Off each year for approved training or certifications (self-study is ineligible)
  • 401(k) company match at 50% up to 10% of your salary
  • Medical, Dental and Vision Insurance
  • Life and Disability Insurance
  • Public Transportation Subsidies
  • Certifications and Training Allowance - Up to $5,000/year!

Why Join Gunnison?

  • Gunnison takes on ambitious projects. We target fun, challenging work that requires creative thinking and innovation.
  • Quality is our top priority.
  • Gunnison employee benefits meet or exceed what other companies in the Washington, D.C. metropolitan area offer.
  • There is a great sense of camaraderie at Gunnison. This is an atmosphere we will maintain as we continue to grow.
  • We are growing rapidly and the opportunity for individual professional growth with Gunnison is outstanding.
  • We hire for careers at Gunnison, not to fill a position.

Equal Opportunity/Affirmative Action Employer. Must be eligible for employment in the United States. We are unable to sponsor candidates at this time.
In 1994 Gunnison began serving the greater Washington, D.C. metro area, focused on tackling our customers' most ambitious technology projects. By creating a culture dedicated to enabling our customers and employees to achieve more than they ever thought they could, the company has thrived for over 25 years.

Salary Description
$60,000 - $71,000/year