Junior Cyber Security Policy Analyst

Alexandria, VA

At Criterion Systems, we developed a different kind of business—a company whose real value is a reputation for excellence built upon the collective skills, talents, perspectives, and backgrounds of its people. By accepting a position with Criterion Systems, you will join a group of professionals with a collaborative mindset where we share ideas and foster professional development to accomplish our goals. In addition to our great culture, we also offer competitive compensation and benefit packages, company-sponsored team building events, and advancement opportunities. To find out more about how Criterion can help you take your career to the next level please visit our website: www.criterion-sys.com.

The National Science Foundation Cyber Security and Privacy (CS&P) Services contract team supports a layered, defense-in-depth cyber security environment that provides successive cyber security controls for approximately 2,500 employees at the Alexandria, Virginia Headquarters and additional employees at other locations. The CS&P Services Team is responsible for a comprehensive, agency-wide Cyber Security Program that encompasses all aspects of cyber security. Strategic objectives for the CS&P Services contract are:  data loss prevention; improve network and system security; risk based management; security incident management; and cyber security training and awareness.

Criterion Systems is looking to hire a Junior Cyber Security Policy Analyst to support our customer onsite in Alexandria.

This position is one of two Assessment and Authorization (A&A) team members responsible to assess the client's compliance with National Institute of Standards and Technology (NIST) Special Publications (SP) guidance.
Serve as POC for A&A efforts and complete required documentation (e.g., FIPS-199 Standards for Security Categorization of Federal Information and Information Systems, Privacy Impact Analysis (PIA), Privacy Threshold Analysis (PTA), System Security Plans (SSPs), Security Assessment Reports (SARs), etc.)
Perform Risk Assessments (RAs), Security Assessments, and develop Authority to Operate (ATO) Letters when required Perform the A&A lifecycle for the customer’s applications, including those hosted at third-party locations and in cloud services
Develop guidelines and procedures for conducting system-level evaluations of federal information systems and networks
Ensure IT systems have all cybersecurity controls in place and that all controls function properly in accordance with NIST 800-53A Revision 4
Evaluate FedRAMP packages, including System Security Plans, Security Assessment Reports, POA&Ms, and other relevant security documentation for cloud service providers
Assist with external and internal audits such as FISMA, Financial Statement Audit and OMB A-123 Management’s Responsibility for Enterprise Risk Management and Internal Control, for designated systems
Advise the customer on new standards and make recommendations on new cybersecurity technologies to improve efficiencies


  • Degree in Computer Science or 4 years of experience to use in lieu of degree
  • Three (3+) years of experience with NIST and/or RMF
  • US Citizenship is required
  • Eligible for a NACI/Public Trust clearance


  • Security + Certification
  • Certified Authorization Professional (CAP)
  • Expertise and experience with the Department of Justice (DoJ) Cyber Security Assessment and Management (CSAM) tool
  • A + Certification
  • Network + Certification
  • Certified Ethical Hacker
  • Certified Information System Security Professional (CISSP)
  • Certified Information System Auditor (CISA)

Criterion Systems is committed to hiring and retaining a diverse workforce. We are proud to be an Equal Opportunity/Affirmative Action Employer, making decisions without regard to race, color, religion, creed, sex, sexual orientation, gender identity, marital status, national origin, age, veteran status, disability, or any other protected class. For our complete EEO/AA and Pay Transparency statement, please visit https://criterion-sys.com/careers.



Criterion offers comprehensive health benefits including medical, dental, vision, life and disability insurance. Most of our plans are available at no cost for employee only coverage.

Time Off

Employees begin accruing PTO at 15 days per year and acquire more based on seniority. In addition to PTO, Criterion provides 10 holidays and bereavement, military, jury duty, and family medical leave.


  • Roth and Traditional 401(k) Plans with company matching contributions
  • Health Care and Dependent Care Flexible Spending Accounts
  • Health Savings Accounts
  • Commuter Benefits


All employees are eligible to use up to $3,000 annually for approved professional development, including trainings, memberships, seminars, and degree programs.

Employee Testimonials

Pets of Criterion

We love our furry friends!

Equal Employment Opportunity and Affirmative Action Employer

Criterion Systems, Inc. is committed to equal employment opportunity and non-discrimination at all levels of our organization. We believe in treating all applicants and employees fairly and make decisions without regard to an individual’s protected status: race/ethnicity, color, national origin, ancestry, sex/gender, gender identity/expression, sexual orientation, marital/parental status, pregnancy/childbirth or related conditions, religion, creed, age, disability, genetic information, veteran status, or any other protected status.

Know Your Rights

Applicants have rights under Federal Employment Laws: Family and Medical Leave Act | Equal Employment Opportunity | Employee Polygraph Protection Act. Criterion participates in E-Verify. Review Right to Work information.

Need an Accommodation?

Criterion is committed to Equal Employment Opportunity and providing reasonable accommodations to applicants with physical and/or mental disabilities. If you are interested in applying for a position with Criterion and need special assistance or an accommodation to apply, please send an email with your request to recruiting@criterion-sys.com or call us at 703-942-5800. Determination on requests for reasonable accommodation are made on a case-by-case basis.