1

Fips Certification Analyst Jobs in Virginia (NOW HIRING)

Knowledge of risk management standards, CNSSP 1253, FIPS 140-2, 199, 200, and NIST SP 800-37, 800 ... certifications, security clearance level, contract requirements, geographic location, and internal ...

Knowledge of risk management standards, CNSSP 1253, FIPS 140-2, 199, 200, and NIST SP 800-37, 800 ... certifications, security clearance level, contract requirements, geographic location, and internal ...

Senior Cybersecurity Analyst

Leesburg, VA · On-site

$101K - $130K/yr

  • Medical

  • Dental

  • Vision

  • Life

  • Retirement

  • PTO

Working knowledge of NIST SP 800-53, NIST SP 800-53A, NIST SP 800-37 (RMF), and FIPS-199 ... Additional certifications (CEH, GPEN, CAP) preferred but not required Preferred Qualifications

next page

Showing results 1-20

Fips Certification Analyst information

What are some common challenges faced by FIPS Certification Analysts during the certification process?

FIPS Certification Analysts often encounter challenges such as keeping up with evolving cryptographic standards, coordinating documentation with engineering teams, and managing tight project timelines. Navigating complex technical requirements from NIST and ensuring all security modules meet rigorous testing standards can be demanding. Effective communication and organizational skills are essential, as analysts frequently collaborate with multiple stakeholders, including developers, testers, and external auditors, to ensure compliance and resolve issues promptly.

What are the key skills and qualifications needed to thrive as a FIPS Certification Analyst?

To thrive as a FIPS Certification Analyst, you need a solid understanding of cryptographic standards, information security, and regulatory compliance, often supported by a degree in computer science or cybersecurity. Familiarity with NIST standards, FIPS 140-2/140-3 validation processes, and related tools like Cryptographic Module Validation Program (CMVP) documentation systems is crucial. Strong analytical skills, attention to detail, and effective written communication set top analysts apart when preparing certification documentation and liaising with stakeholders. These competencies are essential to ensure secure, compliant cryptographic implementations and successful certification outcomes.

What is a FIPS Certification Analyst?

FIPS Certification Analysts are professionals who specialize in ensuring that products, systems, or processes comply with the Federal Information Processing Standards (FIPS), which are U.S. government standards for data security and interoperability. They support organizations in preparing for FIPS certification by interpreting technical requirements, testing cryptographic modules, and coordinating with certification bodies. Their work helps organizations meet regulatory requirements for handling sensitive government data, especially in industries such as IT, cybersecurity, and defense.

What is the difference between Fips Certification Analyst vs Fips Compliance Specialist?

AspectFips Certification AnalystFips Compliance Specialist
Required CredentialsCertifications in cybersecurity, compliance, or related fields; knowledge of FIPS standardsCertifications in compliance, security, or auditing; familiarity with FIPS requirements
Work EnvironmentTypically in IT, cybersecurity, or government agencies; focus on certification processesOften in compliance departments; focus on regulatory adherence and audits
Employer & Industry UsageUsed by government agencies, tech firms, and security organizationsCommon in regulated industries like finance, healthcare, and government

The Fips Certification Analyst primarily focuses on obtaining and maintaining FIPS certifications, ensuring products meet federal standards. In contrast, the Fips Compliance Specialist concentrates on ongoing compliance and regulatory adherence related to FIPS standards. Both roles require similar certifications and work environments but differ in their core responsibilities—certification versus compliance management.

What are popular job titles related to Fips Certification Analyst jobs in Virginia?

For Fips Certification Analyst jobs in Virginia, the most frequently searched job titles are:

What job categories do people searching Fips Certification Analyst jobs in Virginia look for?

The top searched job categories for Fips Certification Analyst jobs in Virginia are:

What cities in Virginia are hiring for Fips Certification Analyst jobs?

Cities in Virginia with the most Fips Certification Analyst job openings:

Infographic showing various Fips Certification Analyst job openings in Virginia as of August 2026, with employment types broken down into 2% As Needed, 76% Full Time, 16% Part Time, and 6% Contract. Highlights an 96% Physical, 1% Hybrid, and 3% Remote job distribution.

RMF Cyber Security Analyst - 306210

Delaware Nation Industries

Virginia Beach, VA • On-site

Full-time

Re-posted 28 days ago


Job description

Delaware Nation Industries is supporting the Naval Surface Warfare Center Dahlgren Division Dam Neck Activity (NSWCDD DNA). We are providing enterprise management and technical support of the Naval Surface Warfare Center Dahlgren Division Dam Neck Activity (NSWC DD DNA) by providing assistance in policy, procedures, seat refresh, engineering/technical solutions, ordering to Next Generation Enterprise Network (NGEN) and the Naval Networking Environment (NNE) strategy.

Job Summary:   The RMF Analyst will assist in developing RMF accreditation packages and assist in maintaining Authorization to Operate (ATO) certifications for networked systems and applications used by the organization. The RMF Analyst will assist in the development of information system documentation and the provision of a designated set of common controls for the authorization package, including the executive summary, system security plan, privacy plan, security control assessment, privacy control assessment, and any relevant plans of action and milestones. This system certification documentation must comply with DoD and Civilian Agency policy focused on NIST 800-37, NIST 800-53 rev 4.

Responsibilities:

  • Monitor and assess existing Information Security Management and Security Technical Architecture, regulations, and controls (FIPS, NIST, DISN Connection Process Guide(CPG), Navy RMF Process Guide (RPG), Navy Testing Guidance)
  • Assess proposed Information Security Management and Security Technical Architecture, regulations, and controls (FIPS, NIST, DISN CPG, Navy RPG, Navy Testing Guidance)
  • Maintain regular meetings/notes and informal dialog with RDT&E CORE/LAB managers and ISSOs to keep them abreast of upcoming Information System Security Manager (ISSM) requirements and to gather specifics on their capability and core support requirements and trends
  • Maintain records in the Enterprise Mission Assurance Support Service (eMASS)
  • Evaluating technical testing from Assured Compliance Assessment Solution (ACAS) scans, Evaluate STIG, eMASSter), and Security Technical Implementation Guide Viewer tool using FMATS or other NAVSEA or DoD-approved toolset.
  • Monitor security access, passwords, badges, log-ins, to keep a site or system safe
  • Use firewalls and information security standards to keep their organization secure
  • Perform security assessments, vulnerability testing and risk analysis
  • Conduct security audits internal and external
  • Identify the cause of security breaches

Requirements

  • DoD Top Secret Security Clearance
  • 5+ Years of Experience in Cyber Security
  • Cyber Security Workforce level IAM II/III CASP,CISM, or CISSP required
  • Bachelor Degree or Equivalent Work Experience
  • Familiarity with NIST IT Security Special Publication (SP) 800 Series with emphasis on NIST SP 800-37 and NIST SP 800-53 rev 4/5
  • Forensics analysis familiarity
  • Experienced STIG reviewer
  • Microsoft Visio and Microsoft Project user

Desired:

  • Navy Qualified Validator (NQV) Level II
  • Familiarity with ACAS, RedSeal, and Carbon Black
  • Familiarity with the Vulnerability Remediation Asset Manager (VRAM) web tool
  • Familiarity with the Continuous Monitoring and Risk Scoring (CMRS) web tool