Information Security Analyst Principal
information securitycybersecurityRisk ManagementSecurity ArchitectureZero TrustNIST SP 800-53Network SecurityCISSPCISA
About the Role
This position is listed on behalf of a partner company, who manages all applications and next steps. Our partner is looking for a Information Security Analyst Principal based in the United States. This is a senior cybersecurity role focused on protecting critical information systems within a federal healthcare environment. You’ll provide expert guidance across security architecture, infrastructure, risk management, compliance, and secure system development. The position combines hands-on security implementation with strategic advisory responsibilities and close collaboration with technical and customer teams. You’ll assess systems and development changes, recommend appropriate controls, and help address security risks and remediation priorities. The role also requires staying ahead of emerging security requirements, including Zero Trust and Software Bill of Materials (SBOM) practices. You’ll serve as a key connection between internal technology teams and customer security organizations, translating complex security requirements into practical solutions. This fully remote opportunity is well suited to an experienced security professional who enjoys working on mission-critical systems and solving complex cybersecurity challenges. This position is listed on behalf of a partner company, who manages all applications and next steps. Our partner is looking for a Information Security Analyst Principal based in the United States. This is a senior cybersecurity role focused on protecting critical information systems within a federal healthcare environment. You’ll provide expert guidance across security architecture, infrastructure, risk management, compliance, and secure system development. The position combines hands-on security implementation with strategic advisory responsibilities and close collaboration with technical and customer teams. You’ll assess systems and development changes, recommend appropriate controls, and help address security risks and remediation priorities. The role also requires staying ahead of emerging security requirements, including Zero Trust and Software Bill of Materials (SBOM) practices. You’ll serve as a key connection between internal technology teams and customer security organizations, translating complex security requirements into practical solutions. This fully remote opportunity is well suited to an experienced security professional who enjoys working on mission-critical systems and solving complex cybersecurity challenges. Accountabilities: Provide senior-level information security support for federal healthcare systems and associated technology environments. Support the current security infrastructure while helping define future security programs, architectures, and implementation strategies. Contribute to the design and implementation of firewalls and other security technologies and controls. Analyze information systems to ensure appropriate security functions and protections are incorporated into system architecture and design. Participate in software and system development processes by advising developers and conducting security impact assessments for proposed changes. Recommend and assist with the implementation of security countermeasures, mitigating controls, and risk-reduction strategies. Provide guidance on the development and maintenance of security documentation, including Standard Operating Procedures, System Security Plans, security manuals, and related materials. Manage responses, remediation activities, and tracking for Plans of Action and Milestones (POA&Ms) associated with supported government systems. Monitor evolving cybersecurity requirements and emerging technologies, including Zero Trust, SBOM, and other relevant security frameworks and practices. Assess and communicate the potential impact of new security requirements to technical and leadership stakeholders. Maintain current knowledge of relevant information security technologies, practices, policies, and industry developments. Serve as a key liaison between internal delivery teams and customer security organizations, ensuring clear communication and alignment. Support security-related special projects and initiatives as required. Contribute to security monitoring, implementation, and ongoing improvement of information assurance practices. Help ensure systems and processes align with applicable federal security policies, standards, and risk-management requirements. Requirements: Bachelor’s degree in Information Technology, Cybersecurity, Computer Science, or a related technical discipline with 10 years of relevant experience; alternatively, a Master’s degree with 8 years of experience or a Ph.D./Doctorate with 6 years of relevant experience. At least 10 years of related professional experience in information security, cybersecurity, IT security services, or IT system security. Demonstrated experience with information security implementation, monitoring, and security support. Expert-level knowledge of data security administration principles, methods, and techniques. Broad knowledge of information assurance practices, security tools, and enterprise security concepts. Strong understanding of network configuration, security monitoring, and network protection technologies. Familiarity with domain structures, user authentication mechanisms, and digital signatures. Working knowledge of federal information security policies and standards, including FIPS 199, FIPS 200, and NIST SP 800-53. Familiarity with Agile software development lifecycle methodologies and the ability to integrate security considerations into development processes. Ability to conduct security impact assessments and recommend appropriate controls or countermeasures. Strong technical communication and documentation skills, with the ability to explain complex security issues to both technical and non-technical stakeholders. CISSP, CISA, or another relevant professional security certification is required or strongly preferred. Experience with electronic healthcare technologies and operations is an advantage. Familiarity with source code control and version-management tools is a plus. Knowledge of VistA electronic health records or the Resource and Patient Management System (RPMS) is desirable. Familiarity with the Department of Health and Human Services Enterprise Performance Life Cycle (EPLC) is an advantage. Ability to obtain and maintain the required Public Trust clearance through an Indian Health Service background investigation. No U.S. citizenship requirement is specified for this position. Ability to work independently in a fully remote environment while collaborating effectively with distributed technical and customer teams. Benefits: Annual salary range of approximately $110,500–$149,500 , depending on experience, geographic location, and applicable contractual requirements. Fully remote work arrangement from anywhere in the United States. Full-flex work week designed to support flexibility and personal priorities. Core working hours from Monday through Friday, 9:00 AM–3:00 PM ET . 401(k) retirement plan with company matching. Comprehensive medical plan options, including plans with Health Savings Accounts. Dental and vision insurance options. Paid vacation, sick, and personal leave, with eligible new employees typically receiving 15 days of paid leave per calendar year. 10 paid holidays per year, subject to applicable employment terms. Paid parental, military, bereavement, and jury-duty leave. Paid Family Leave of up to 160 hours during a rolling 12-month period for eligible employees. Short- and long-term disability coverage. Life insurance, accidental death and dismemberment, personal accident, critical illness, and business travel and accident insurance options. Paid education and professional certification opportunities. Internal career mobility and professional growth support. Exposure to advanced cybersecurity, cloud, AI, and other emerging technologies. Opportunity to contribute to mission-critical technology and healthcare initiatives with meaningful public-sector impact. Standard full-time schedule of 40 hours per week . Limited travel requirement of less than 10% . How Jobgether works: We use an AI-powered matching process to ensure your application is reviewed quickly, objectively, and fairly against the role's core requirements. Our system identifies the top-fitting candidates, and this shortlist is then shared directly with the hiring company. The final decision and next steps (interviews, assessments) are managed by their internal team. We appreciate your interest and wish you the best! Why Apply Through Jobgether? Data Privacy Notice: By submitting your application, you acknowledge that Jobgether will process your personal data to evaluate your candidacy and share relevant information with the hiring employer. This processing is based on legitimate interest and pre-contractual measures under applicable data protection laws (including GDPR). You may exercise your rights (access, rectification, erasure, objection) at any time. #LI-CL1
You'll be redirected to Jobgether's application page
Job Details
Salary
$111K–$150K
Location
United States
Job type
Full-time
Category
Cybersecurity
Experience
10 years
Posted
Today
Job Highlights
- $111K–$150K salary
- 10 years level role
- 100% Remote — open to candidates in United States
About Jobgether
This job is hosted by Jobgether. Clicking Apply opens their site.
Remote Work Style
Mixed
Mix of flexible and scheduled meetings
Your Match
See how well your skills line up with this role, and what you're missing.
AI Cover Letter
Generate a cover letter tailored to this job from your profile.