At phia we hire talented and passionate people who are focused on collaborative, meaningful work, providing technical and operational subject matter expertise and support services to our partners and clients. phia is seeking an experienced Machine Learning Security Operations (MLSecOps) Analyst to provide Security Testing and Evaluation (ST&E) services for a Federal cybersecurity program. In this position, you will play an integral role in supporting the delivery and operation of advanced cyber capabilities vital to our national security interests. This role is expected to be hybrid with onsite reporting required in Arlington, VA; frequency to be determined. Although this role is contingent upon a contract award, we are engaging with exceptional candidates now.
What You'll Do
Conduct research and maintain expertise on MLSecOps concepts, methodologies, models, government policies, industry best practices, and relevant open-source and commercial implementations.
Identify areas where Machine Learning (ML) capabilities can be applied to Security Test & Evaluation, internal penetration testing, proactive vulnerability assessment and discovery, risk assessment and the development of security controls, and validation of applied security controls.
Develop and implement validation mechanisms to assess the viability and effectiveness of the generated remediation tasks in mitigating the identified issues.
Implement and follow the Risk Management Framework (RMF) process, conducting comprehensive security control assessments for internal systems, including cloud-based environments.
Develop and analyze Security Assessment Reports (SARs) by NIST SP 800-53, NIST SP 800-37, and FIPS standards.
Conduct vulnerability analysis, manage Plan of Action and Milestones (POA&M), and provide security impact reviews for change requests, ensuring compliance with relevant federal regulations.
Collaborate with government stakeholders, system owners, and security professionals to evaluate security readiness across various cybersecurity functions.
Perform continuous monitoring activities, including annual assessments and reporting for Information Security Vulnerability Management (ISVM) and related programs.
Support on-site and remote assessments for information systems, verifying adherence to cloud security standards and infrastructure hardening requirements.
Develop and employ tailored test plans and procedures, utilizing various tools and custom scripts in alignment with NIST guidelines.
Conduct manual testing, vulnerability scans, and penetration testing in compliance with FISMA requirements and other applicable standards.
Implement Offensive Security Operations (OffSecOps) practices, including automated deployment and testing of various targets, while maintaining compliance with federal security regulations.
Perform Assessment & Authorization (A&A) activities, Identity Governance (IG) audits, vulnerability management reporting, and compliance validations in collaboration with relevant stakeholders.
Education + Requirements
Bachelor’s degree with 7 years’ relevant IT/Cybersecurity experience; or 11 years’ relevant experience.
Expertise in security compliance and risk management frameworks (e.g., NIST 800-53A, FISMA), including conducting assessments and developing risk analysis and mitigation strategies.
Proficient in vulnerability scanning, configuration, and patch management, with experience addressing complex system vulnerabilities.
Skilled in creating and maintaining security authorization documentation, ATO packages, and compliance records, with the ability to effectively present technical findings and mitigation plans to diverse audiences.
Experienced in coordinating across teams (e.g., Privacy, Information Governance), supporting audits, and delivering risk briefings.
Adept at communicating security requirements within development cycles and aligning with stakeholder expectations.
Preferred Experience and Knowledge
Familiarity and working experience with machine learning security operations (MLSecOps) or security development operations DevSecOps methodology.
Security Clearance
Active Secret clearance is required
DHS Suitability (EOD)
Desired Certifications (one or more)
Security+
CompTIA Advanced Security Practitioner (CASP)
Certified Information Systems Auditor (CISA)
Certified in Governance, Risk, and Compliance (CGRC)
Certified Authorization Professional (CAP)
GIAC Security Essentials Certification (GSEC)
Cybersecurity Analyst+ (CySA+)
#LI-LC1 Who You Are A proactive problem solver that appreciates the challenges of working in a fast-paced, dynamic environment.Intellectually curious with a genuine desire to learn and advance your career.An effective communicator, both verbally and in writing.Customer service-oriented and mission-focused.Critical thinker with excellent problem-solving skillsIf your experience and qualifications aren’t a match for this position, you will remain in our database for consideration for future opportunities that may be a better fit. Who We Arephia, LLC is a Northern Virginia-based, small business established in 2011 with a focus on Cyber Intelligence, Cyber Security/Defense, Intrusion Analysis & Incident Response, Cyber Architecture & Capability Analysis, Cyber Policy & Strategy, and Information Assurance/Security. we proudly support various agencies and offices within the Department of Defense (DoD), Federal government, and private/commercial entities.phia values work-life balance and offers the following benefits to full-time employees: Comprehensive medical insurance to include dental and visionShort Term & Long-Term Disability 401k Retirement Savings Plan with Company MatchTuition and Professional Development Assistance Flex Spending Accounts (FSA) phia does not discriminate on the basis of race, sex, color, religion, age, national origin, marital status, disability, veteran status, genetic information, sexual orientation, gender identity, or any other reason prohibited by law in the provision of employment opportunities and benefits. Please be aware job applicants have rights under federal employment laws. You can find more information about The Family Medical Leave Act (FMLA), Know Your Rights (EEO), and Employee Polygraph Protection Act (EPPA) on The U.S. Department of Labor (DOL)’s website HERE. Frequently Asked Questions - United States Department of Labor