
Information Security Analyst Subject Matter Expert (Hybrid)
Share job link
Title:
Information Security Analyst Subject Matter Expert (Hybrid)Belong. Connect. Grow. with KBR!
Around here, we define the future.
We are a company of innovators, thinkers, creators, explorers, volunteers, and dreamers. But we all share one goal: to improve the world responsibly and safely.
THIS POSITION IS CONTINGENT UPON CONTRACT AWARD
KBR is hiring a full-time Information Security Analyst - Subject Matter Expert (SME) supporting the Administrative Office of the US Courts and is contingent upon successful contract award.
This onsite position is located at the Thurgood Marshall Federal Judiciary Building in Washington DC and has the option of an approved telework/hybrid work schedule.
The core work hours dedicated to KBR and our direct customer are 8 am Est to 5 pm Est. No travel is expected with this position.
The Administrative Office of the US Courts Chief Operating Officer (COO) Information Security & Validation Staff (ISVS) is responsible for governing, overseeing, developing, strengthening, and maintaining the information security posture within COO Offices to meet and exceed enterprise security standards. Their mission is to proactively ensure the integrity, confidentiality, and availability of critical judiciary information assets through a comprehensive, rigorous security approach via our governance, risk management, and compliance (GRC) program.
The Information Security Analyst SME will be responsible for enhancing cybersecurity for its customers including cybersecurity systems support, cybersecurity compliance, and cybersecurity risk management for the COO comprehensive IT system portfolio.
Primary Responsibilities:
- Prepare Information Systems: Carry out activities at various levels to help manage security and privacy risks using the JISF and NIST RMF.
- Categorize Information Systems: Determine the adverse impact to Judiciary operations and assets, individuals, other organizations, and the Nation.
- Select Security Controls: Select, tailor, and document the controls necessary to protect the information system and organization.
- Implement Security Controls: Implement the government-approved security controls specified in the Security Plan.
- Assess Security Controls: Determine if the controls selected for implementation are operating as intended and producing the desired outcome.
- Authorize Information System: Provide accountability by requiring a government senior management official to determine if the security and privacy risk is acceptable.
- Monitor Security Controls: Maintain ongoing situational awareness about the security and privacy posture of the information system in compliance with NIST SP 800-53 Rev. 5, NIST SP 800-37 Rev. 2, and CSF 2.0.
- Common Control Identification: Identify, document, and publish Judiciary-wide common controls available for inheritance by Judicial systems.
- Mission or Business Focus: Identify and document the missions, business functions, and mission/business processes that the system is intended to support.
- System Stakeholders: Identify stakeholders who have an interest in the design, development, implementation, assessment, operation, maintenance, or disposal of the system.
- Asset Identification: Identify assets that require protection.
- Authorization Boundary: Determine the authorization boundary of the system.
- Information Types: Identify the types of information to be processed, stored, and transmitted by the system.
- Information Life Cycle: Identify and understand all stages of the information life cycle for each information type processed, stored, or transmitted by the system.
- Risk Assessment—System: Conduct a system-level risk assessment and update the risk assessment results as needed
- Produce and perform quality review of InfoSec Governance, Risk and Compliance (GRC) product deliverables.
Required Qualifications
- Ability to obtain a Public Trust Suitability Determination: Medium Risk Level 2
- Six (6) to ten (10) years of IT system security experience including five years of specialized InfoSec Governance, Risk and Compliance (GRC) experience of which two years were direct supervisory experience.
- Possess in-depth knowledge of applying, selecting and testing the NIST 800-53 Rev 4 or 5 security controls.
- Possess in-depth knowledge of NIST 800-37 Risk Management Framework.
- Excellent customer-handling and verbal/written communication with teamwork emphasis
- Strong analytical skills and attention to detail.
- Ability to handle and prioritize multiple tasks and deadlines
- Ability to explain technical details and issues clearly to non-technical individuals and be able to explain problems clearly and concisely
- Experience with the full Software Development Life Cycle (SDLC)
Education: Bachelor's degree in information technology or related field; preferably a master’s degree
Desired Skills:
- Experience using Cybersecurity Assessment and Management (CSAM) Global Risk Compliance tool
- Experience using Splunk and Nessus VSS vulnerability scan software
- Information security certifications (CISSP, etc.)
The candidate must be able to obtain and maintain a national agency check and background investigation after hire to obtain a badge for facility access and user accounts.
Basic Compensation:
$132,400 - $198,600
This pay range is applicable to the DC area only.
The offered rate will be based on contract affordability and the selected candidate’s working location, knowledge, skills, abilities and/or experience, and in consideration of internal parity.
Additional Compensation:
KBR may offer bonuses, commissions, or other forms of compensation to certain job titles or levels, per internal policy or contractual designation. Additional compensation may be in the form of sign on bonus, relocation benefits, short term incentives, long term incentives, or discretionary payments for exceptional performance.
KBR Benefits
KBR offers a selection of competitive lifestyle benefits which could include 401K plan with company match, medical, dental, vision, life insurance, AD&D, flexible spending account, disability, paid time off, or flexible work schedule. We support career advancement through professional training and development.
Click here to learn more: KBR Benefits | KBR
Belong, Connect and Grow at KBR
At KBR, we are passionate about our people and our Zero Harm culture. These inform all that we do and are at the heart of our commitment to, and ongoing journey toward being a People First company. That commitment is central to our team of team’s philosophy and fosters an environment where everyone can Belong, Connect and Grow. We Deliver – Together.
KBR is an equal opportunity employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, disability, sex, sexual orientation, gender identity or expression, age, national origin, veteran status, genetic information, union status and/or beliefs, or any other characteristic protected by federal, state, or local law.
Get notified for similar jobs
Success!
Successfully subscribed for similar jobs
Failure!
Get tailored job recommendations based on your interests.

Profile recommendations
Similar Jobs
-
Senior Information Security Analyst (Hybrid)
Location Washington, District of Columbia Category Support Services Job Type Full time Job Id R2105279 Posted Date 04/21/2025
Prepare Information Systems: Carry out activities at various levels to help manage security and privacy risks using the JISF and NIST RMF. Authorize Information System: Provide accountability by requi...
-
Information System Security Officer (ISSO)
Location Chantilly, Virginia Category Support Services Job Type Full time Job Id R2095450 Posted Date 01/28/2025
We are looking for a skilled professional to safeguard critical information assets, ensuring compliance with security standards and regulations. Your expertise in risk management and collaboration will be vital in shaping innovative solutions that protect national security and support intelligence-gathering missions. Join us to make a meaningful impact!
-
Senior Information System Security Officer (ISSO)
Location Chantilly, Virginia Category Support Services Job Type Full time Job Id R2097599 Posted Date 03/26/2025
The ISSO is responsible for developing and implementing strategies to safeguard the organization's critical information assets, ensuring compliance with relevant security policies, standards, and regu...
-
Senior Information System Security Officer (ISSO)
Location Chantilly, Virginia Category Support Services Job Type Full time Job Id R2105090 Posted Date 04/16/2025
The ISSO is responsible for developing and implementing strategies to safeguard the organization's critical information assets, ensuring compliance with relevant security policies, standards, and regu...
-
Information System Security Engineering (ISSE)
Category Support Services Job Type Full time Job Id R2105561 Posted Date 04/24/2025
Collaborate on design efforts, provide security engineering, and lead the engineering of RMF BOE artifacts of a large-scale enterprise Information Technology (IT) program. Work collaboratively with Sy...
-
Information System Security Officer (ISSO)
Location Bethesda, Maryland Category Support Services Job Type Full time Job Id R2102677 Posted Date 02/28/2025
Join a dynamic team dedicated to safeguarding critical information assets and enhancing national security. Leverage your expertise in risk management, compliance, and cybersecurity to design robust defense systems, while fostering collaboration and innovation in a supportive environment that values growth and a commitment to excellence.
-
Information System Security Manager (ISSM)
Location Bethesda, Maryland Category Support Services Job Type Full time Job Id R2102653 Posted Date 02/28/2025
Are you looking for an opportunity to lead cybersecurity efforts and safeguard national security? Join a dynamic team where you'll provide critical risk management support, conduct security assessments, and develop compliance documentation, all while fostering innovation and collaboration in a mission-driven environment.
-
Information System Security Officer - Intermediate
Location Fort Meade, Maryland Category Support Services Job Type Full time Job Id R2105097 Posted Date 05/06/2025
Develop and implement information security policies, procedures, and guidelines in accordance with industry best practices, regulatory requirements, and required government policy (e. Collaborate with...
-
Information System Security Engineer - TS/SCI
Location Chantilly, Virginia Category Support Services Job Type Full time Job Id R2092682 Posted Date 01/30/2025
Identify additional security requirements, based on RMF or as the result of security issues that put the customer’s systems at risk. Experience in security systems engineering involving various comput...

Job seekers also viewed