Senior FISMA Analyst

Alexandria, VA

At Criterion Systems, we developed a different kind of business—a company whose real value is a reputation for excellence built upon the collective skills, talents, perspectives, and backgrounds of its people. By accepting a position with Criterion Systems, you will join a group of professionals with a collaborative mindset where we share ideas and foster professional development to accomplish our goals. In addition to our great culture, we also offer competitive compensation and benefit packages, company-sponsored team building events, and advancement opportunities. To find out more about how Criterion can help you take your career to the next level please visit our website:

The National Science Foundation Cyber Security and Privacy (CS&P) Services contract team supports a layered, defense-in-depth cyber security environment that provides successive cyber security controls for approximately 2,500 employees at the Alexandria, Virginia Headquarters and additional employees at other locations. The CS&P Services Team is responsible for a comprehensive, agency-wide Cyber Security Program that encompasses all aspects of cyber security. Strategic objectives for the CS&P Services contract are:  data loss prevention; improve network and system security; risk based management; security incident management; and cyber security training and awareness.

Criterion Systems has a position for a Senior FISMA Analyst at a federal client site in Alexandria, Virginia. This position is responsible for leading A&A duties in compliance with guidance from the National Institute of Standards and Technology (NIST), Office of Management and Budget (OMB), General Accountability Office (GAO), and other federal requirements.  This person will utilize the following skills to be successful:

Thought Leadership and Customer Relationship Management
1.Excellent communication skills and the ability to set a communication strategy throughout the program both internally and externally
2.Knowledge of FISMA, A-123, NIST guidance, FedRAMP requirements, and the culture of audit compliance
3.Out-of-the box positive thinking that focuses on solutions and effective cross functional teams
4.Creative and collaborative team player, driven by the end results and executed within a win-win principled approach across a diverse environment of stakeholders and contractors
5.Self-starter capable of planning and executing projects with minimal guidance from federal lead
6.Excellent work ethic with a strong track record that is verifiable

Federal Security Requirements and Program Management
1.In-depth understanding of federal-wide security requirements, e.g. National Institute for Standards and Technology (NIST), Federal Information Security Management Act (FISMA), as well as current threats and security/privacy protection methodologies
2.Proven technical leadership experience managing a staff of SMEs and ability to lead, instruct, or mentor teammates and junior staff
3.Solid project management skills
4.Ability to translate complex technical concepts and strategies into a concise, professional manner and easily understood terms and/or presentations for stakeholders  
5.Extensive understanding of secure IT operations, audit review, stakeholders and the dynamics of conducting an audit

Technical Expertise
1.Expertise in security principles for managing operating systems (UNIX, Windows, network equipment) and databases (Oracle, Sybase, SQL Server)
2.Experience in including security requirements into the Systems Development Life Cycle
3.Experience in the user access life cycle, including background investigation and proper separation at the end of the person's tenure with the organization
4.Experience with PIV and PIV-I implementations, including best practices to reduce operational burden
5.Experience in developing and implementing secure configuration of operating systems and databases, including development of secure baselines from best practices, scanning for configuration deviations, determining best alternative for remediating deviations, and managing the implementation process
6.Experience in managing security vulnerabilities, including setup of a scanning process, assessing criticality of vulnerabilities based on mitigating factors, negotiating remediation activities, and management reporting of vulnerabilities that have not been addressed within agreed service levels
7.Proficiency in researching and tracking new requirements that shape the IT Security industry and drive audit assessments
8.Knowledge of security vendors, current solutions and tools

1.Excellent writing skills and proven experience in developing high quality deliverables (plans, processes and procedures, responses to audit findings, senior management briefs, etc.)
2.High proficiency in MS Office (Visio, PowerPoint, Word, Excel)
3.Solid experience in audit reviews and the dynamics of conducting an audit

Required Qualifications

  • US Citizenship
  • Ability to obtain a public trust
  • Bachelor's degree or four years of work experience may be substituted for degree
  • 10-15 total years of IT, network infrastructure and security
  • 3-5 total years of IT Security audit support

Preferred Qualifications

  • PMP / CISSP or CISM certification, preferred but not required
  • CISA / Certified in the Governance of Enterprise IT (CGEIT) certification are a plus

Criterion Systems is committed to hiring and retaining a diverse workforce. We are proud to be an Equal Opportunity/Affirmative Action Employer, making decisions without regard to race, color, religion, creed, sex, sexual orientation, gender identity, marital status, national origin, age, veteran status, disability, or any other protected class. For our complete EEO/AA and Pay Transparency statement, please visit



Criterion offers comprehensive health benefits including medical, dental, vision, life and disability insurance. Most of our plans are available at no cost for employee only coverage.

Time Off

Employees begin accruing PTO at 15 days per year and acquire more based on seniority. In addition to PTO, Criterion provides 10 holidays and bereavement, military, jury duty, and family medical leave.


  • Roth and Traditional 401(k) Plans with company matching contributions
  • Health Care and Dependent Care Flexible Spending Accounts
  • Health Savings Accounts
  • Commuter Benefits


All employees are eligible to use up to $3,000 annually for approved professional development, including trainings, memberships, seminars, and degree programs.

Employee Testimonials

Pets of Criterion

We love our furry friends!

Equal Employment Opportunity and Affirmative Action Employer

Criterion Systems, Inc. is committed to equal employment opportunity and non-discrimination at all levels of our organization. We believe in treating all applicants and employees fairly and make decisions without regard to an individual’s protected status: race/ethnicity, color, national origin, ancestry, sex/gender, gender identity/expression, sexual orientation, marital/parental status, pregnancy/childbirth or related conditions, religion, creed, age, disability, genetic information, veteran status, or any other protected status.

Know Your Rights

Applicants have rights under Federal Employment Laws: Family and Medical Leave Act | Equal Employment Opportunity | Employee Polygraph Protection Act. Criterion participates in E-Verify. Review Right to Work information.

Need an Accommodation?

Criterion is committed to Equal Employment Opportunity and providing reasonable accommodations to applicants with physical and/or mental disabilities. If you are interested in applying for a position with Criterion and need special assistance or an accommodation to apply, please send an email with your request to or call us at 703-942-5800. Determination on requests for reasonable accommodation are made on a case-by-case basis.