yandex
appian
Страна
США
+500% приглашений

Откликайтесь
на вакансии с ИИ

Ускорим процесс поиска работы
LeadВ офисеПолная занятость

Principal Security Analyst (Top Secret)

Оценка ИИ

Позиция в стабильной публичной компании с сильной корпоративной культурой и отличным пакетом льгот. Высокий балл обусловлен стратегической важностью роли и работой с передовыми облачными технологиями, несмотря на строгие требования к присутствию в офисе.


Вакансия из Quick Offer Global, списка международных компаний
Пожаловаться

Сложность вакансии

ЛегкоСложно
Оценка ИИ

Высокая сложность обусловлена требованием действующего допуска к секретной службе (Top Secret) и готовности работать в SCIF. Роль требует глубоких знаний специфических федеральных стандартов США (NIST RMF, FedRAMP) и опыта работы с облачными архитектурами.

Анализ зарплаты

Медиана175 000 $
Рынок150 000 $ – 210 000 $
Оценка ИИ

Предлагаемая роль Principal уровня в районе Вашингтона (McLean, VA) с допуском Top Secret обычно оплачивается выше среднего по рынку из-за дефицита квалифицированных кадров с такими допусками. Указанный диапазон отражает рыночные реалии для экспертов по GRC и FedRAMP.

Сопроводительное письмо

I am writing to express my strong interest in the Principal Security Analyst position at Appian. With extensive experience in the NIST Risk Management Framework (RMF) and a proven track record of driving FedRAMP and ATO authorizations, I am confident in my ability to lead complex security initiatives for your federal customers. My background as a systems administrator, combined with a deep focus on GRC principles, allows me to not only assess security but also architect robust, secure solutions on AWS and Azure platforms.

Throughout my career, I have successfully managed the development of System Security Packages (SSPs) and mentored junior analysts to ensure team excellence. Holding an active Top Secret clearance and having a readiness to work in SCIF environments, I am prepared to hit the ground running and contribute to Appian’s mission of delivering high-quality process automation. I am particularly drawn to Appian’s culture of in-person collaboration in McLean and look forward to the opportunity to bring my technical expertise and leadership to your Customer Success team.

+250% к просмотрам

Составьте идеальное письмо к вакансии с ИИ-агентом

Составьте идеальное письмо к вакансии с ИИ-агентом

Откликнитесь в appian уже сейчас

Присоединяйтесь к Appian, чтобы возглавить критически важные проекты в сфере кибербезопасности для федеральных заказчиков США!

Описание вакансии

Here at Appian, our values of Intensity and Excellence define who we are. We set high standards and live up to them, ensuring that everything we do is done with care and quality. We approach every challenge with ambition and commitment, holding ourselves and each other accountable to achieve the best results. When you join Appian, you’ll be part of a passionate team dedicated to accomplishing hard things, together.

The Principal GRC Security Analyst at Appian will play a key role in advising and assisting federal customers in designing, implementing, and maintaining secure Appian-based solutions. This position requires a strong understanding of cybersecurity principles, the government's IT security authorization process, and experience with the NIST Risk Management Framework (RMF) and Authority to Operate (ATO) processes. The Senior Analyst will leverage their experience to guide customers through the security authorization process, contribute to the development of secure architectures, and mentor junior team members. This role involves working with cloud platforms such as Amazon Web Services (AWS) and Microsoft Azure in the context of government managed services.

This role is based at our HQ in McLean, VA. Appian was built on a culture of in-person collaboration, which we believe is a key driver of our mission to be the best. Employees hired for this position are expected to be in the office 4 - 5 days per week to foster that culture, ensure we thrive through shared ideas and teamwork, and maximize opportunities to connect with the exceptional people across Appian. While working in-person with customers is our main priority, we also believe the office environment enables more opportunities to celebrate wins, collaborate effectively, and build strong relationships across teams.

Responsibilities:

  • Leading and Applying RMF Processes: Independently manage and execute the RMF steps, including system categorization, security control selection, implementation guidance, assessment support, authorization package development, and continuous monitoring for Appian-based solutions.
  • Driving ATO and FedRAMP Authorization: Take ownership of the preparation and management of Authorization to Operate (ATO) packages and lead the FedRAMP authorization process for federal customers, ensuring compliance with federal security standards.
  • Designing Secure Solutions: Architect secure end-to-end solutions for federal customers leveraging cloud platforms like AWS and Microsoft Azure, applying security best practices and federal requirements.
  • Mentoring Junior Analysts: Provide guidance and mentorship to junior security analysts, sharing your knowledge and experience in GRC and cybersecurity.
  • Collaborating with Customers and Internal Teams: Partner directly with federal customers and Appian’s Customer Success team to understand their security requirements and provide expert guidance on implementing cybersecurity strategies . Collaborate with senior cyber advisors to refine security approaches.
  • Contributing to Security Authorization Strategies: Play a significant role in developing and implementing comprehensive cybersecurity strategies for Appian deployments within federal environment.
  • Maintaining Knowledge of Federal Policies: Stay current with the latest federal cybersecurity policies, standards (including FedRAMP), and best practices to ensure ongoing compliance and effective security authorization support.
  • Contributing to System Security Packages (SSPs): Lead the development and maintenance of System Security Packages (SSPs) in accordance with RMF requirements.

Qualifications:

  • Bachelor’s degree in any Engineering discipline, Computer Science, Mathematics, Information Technology, or similar work.
  • An Active Government Clearance (Top Secret and above, without any limitations) is required.
  • Ability and interest to maintain an Active TS:SCI Clearance (CI or FSP), with the ability and willingness to perform work within cleared facilities (SCIF work is required).
  • Approximately 5+ years of experience as an IT systems administrator building, maintaining, scripting, patching, & managing hosts, databases, and interconnected Cloud services with significant experience in a security-focused role and a strong understanding of GRC principles.
  • Demonstrated experience in navigating the NIST Risk Management Framework (RMF) and Authority to Operate (ATO) processes.
  • Proven ability to contribute to the development of System Security Packages (SSPs).
  • Experience with cloud platforms such as Amazon Web Services (AWS) and Microsoft Azure, with a focus on security best practices for cloud environments.
  • Passion for cybersecurity and a strong desire to architect secure solutions for federal customers.
  • Strong communication and interpersonal skills, with the ability to effectively advise and guide customers.

#LI-KC1

Tools and Resources

  • Training and Development: During onboarding, we focus on equipping new hires with the skills and knowledge for success through department-specific training. Continuous learning is a central focus at Appian, with dedicated mentorship and the First-Friend program being widely utilized resources for new hires.
  • Growth Opportunities: Appian provides a diverse array of growth and development opportunities, including our leadership program tailored for new and aspiring managers, a comprehensive library of specialized department training through Appian University, skills based training, and tuition reimbursement for those aiming to advance their education. This commitment ensures that employees have access to a holistic range of development opportunities.
  • Community: We’ll immerse you into our community rooted in respect starting on day one. Appian fosters inclusivity through our 8 employee-led affinity groups. These groups help employees build stronger internal and external networks by planning social, educational, and outreach activities to connect with Appianites and larger initiatives throughout the company.

Benefits

Appian offers a comprehensive benefits package designed to support your health, wellbeing, and financial future. Benefits may include health coverage, Employee Assistance Program (EAP) with free mental health support, life and disability insurance, an Employee Stock Purchase Program (ESPP), a retirement/pension plan, wellness dollars, tuition reimbursement, family-forming benefits and more. Benefits vary by country—please ask your Talent Acquisition contact for details specific to the location you are applying to.

About Appian

Appian provides process automation technology. We automate complex processes in large enterprises and governments. Our platform is known for its unique reliability and scale. We’ve been automating processes for 25 years and understand enterprise operations like no one else. For more information, visit appian.com. [Nasdaq: APPN]

Follow Appian: LinkedIn, Youtube, Instagram, Facebook

Appian is an equal opportunity employer that strives to attract and retain the best talent. All qualified applicants will receive consideration for employment without regard to any characteristic protected by applicable federal, state, or local law.

Appian provides reasonable accommodations to applicants in accordance with all applicable laws. If you need a reasonable accommodation for any part of the employment process, please contact us by email at ReasonableAccommodations@appian.com. Please note that only inquiries concerning a request for reasonable accommodation will be responded to from this email address.

Appian's Applicant & Candidate Privacy Notice

+400% к собеседованиям

Создайте идеальное резюме с помощью ИИ-агента

Создайте идеальное резюме с помощью ИИ-агента

Навыки

  • AWS
  • FedRAMP
  • Microsoft Azure
  • Information Security
  • Cloud Security
  • Risk Management Framework
  • GRC
  • NIST RMF
  • Top Secret Clearance
  • System Security Plan

Возможные вопросы на собеседовании

Проверка практического опыта работы с основным фреймворком, указанным в требованиях.

Опишите ваш опыт управления всеми этапами жизненного цикла NIST RMF для крупной федеральной системы.

Оценка навыков работы с облачной безопасностью в контексте государственных требований.

С какими основными трудностями вы сталкивались при получении FedRAMP авторизации для решений на базе AWS или Azure?

Проверка способности проектировать безопасные системы, а не только проверять соответствие.

Как вы подходите к проектированию архитектуры безопасности для облачного решения, чтобы минимизировать риски на этапе аудита ATO?

Оценка лидерских качеств и способности развивать команду.

Расскажите о случае, когда вы менторили младшего аналитика: как вы помогали ему освоить сложные процессы GRC?

Проверка готовности к специфическим условиям работы.

Учитывая требование работы в SCIF, как вы организуете свою работу и взаимодействие с командой в условиях ограниченного доступа к внешним сетям?

Похожие вакансии

Navio
от 300 000 ₽

Ведущий специалист по безопасности приложений (AppSec)

LeadГибридРоссия
AppSec · SAST · SCA · ASOC · AntiDDoS · WAF · Kubernetes · Cloud Infrastructure · Linux · Jira · GitLab · Artifactory · Network Security
+13 навыков
Т-Банк
от 430 000 ₽

Red Team Lead

LeadВ офисеРоссия
Red Teaming · Offensive Security · Python · Go · C++ · PowerShell · Linux · Windows · Active Directory · MITRE ATT&CK · SIEM · EDR · WAF · Threat Intelligence · Purple Teaming · PKI · Cryptography
+17 навыков
netskope
147 000 $ – 299 500 $

Principal Engineer, Cloud Firewall

LeadУдалённоСША
C++ · TCP/IP · SSL/TLS · Firewall · IPS/IDS · Wireshark · TCPDump · GTest · PyTest · Ansible · Kubernetes · SQL · NoSQL · CI/CD · Jenkins · Distributed Systems
+16 навыков
Atom group
4 000 $ – 5 000 $

Senior Information Security (ИБ)

SeniorУдалённоБеларусь
Information Security · DevSecOps · SDLC · Risk Management · Security Policy · DevOps
+6 навыков
iherb
177 000 $ – 225 000 $

Principal Application Security Engineer

LeadУдалённоСША
Python · C++ · .NET · JavaScript · Node.js · Java · AWS · Docker · SAST · DAST · SCA · Threat Modeling · Cryptography · API Design · Microservices · Cloudflare · OWASP Top 10
+17 навыков
SDOdev
380 000 ₽ – 500 000 ₽

Senior Android Security / Reverse Engineer (HTTPS Traffic, Google Services)

SeniorУдалённоРоссия
Android · iOS · TCP/IP · HTTPS · Cryptography · MITM · Frida · Objection · Apktool · Jadx · Hopper · Smali · Hermes · Swift · Dart · Objective-C · C++ · Reverse Engineering · Cybersecurity
+19 навыков
более 1000 офферов получено
4.9

1000+ офферов получено

Устали искать работу? Мы найдём её за вас

Quick Offer улучшит ваше резюме, подберёт лучшие вакансии и откликнется за вас. Результат — в 3 раза больше приглашений на собеседования и никакой рутины!

appian
Страна
США