Information Security Analyst Senior
ExternalFull-timeOn-site1w ago
AuditingComplianceDocumentationIAMLeadershipLess
Prepare for this interview
EliteAI-generated questions, company research, and talking points tailored to this role
Responsibilities
- Strategy & Planning
- Utilize available resources to conduct Cybersecurity activities, and report to senior GDIT and government personnel on overall program security posture.
- Conduct network and system audits for vulnerabilities using Security Technical Implementation Guides (STIGs), ACAS vulnerability scanner, and DISA SCAP to mitigate those findings for Linux, Windows, and associated network operating systems.
- Ability to create, track and review Plan of Action and Milestones (POA&Ms) and conduct solution identification to assist in problem remediation and resolution.
- Communicate tactical and strategic threat information to Government leaders, Cybersecurity-Ops and A&A staff to assist them in making cyber risk decisions and to mitigate threats.
- Carries out DoW Risk Management Framework (RMF) in accordance with DoW 8510 to ascertain information systems' security posture by utilizing security control validation activities and coordinating security testing.
- Maintain the Security Authorization status, including system documentation of multiple DoW classified networks and interconnected systems.
- Coordinates with OUSDI, USAF, DISA, USN, and other organizations in support of audits and inspections and provides all necessary documentation as required for SAVs, ST&Es, and CCRI.
- Evaluate firewall change requests and assess organizational risk.
- Perform Security Impact Analysis based on organizational requirements.
- Communicates alerts to agencies regarding intrusions and compromises to their network infrastructure, applications and operating systems.
- Assists with implementation of counter-measures or mitigating controls
- Ensures the integrity and protection of networks, systems, and applications by technical enforcement of organizational security policies, through monitoring of vulnerability scanning devices.
- Performs periodic and on-demand system audits and vulnerability assessments, including user accounts, application access, file system and integrity scans to determine compliance.
- Provides guidance and work leadership to less-experienced technical staff members.
- Maintains current knowledge of relevant technology as assigned.
- Participates in special projects as required.
- Required Qualifications:
- 5+ years of experience.
- BA/BS or the equivalent combination of education, technical training, or work/military experience.
- IAM Level II Certification (CISSP, CASP, CISM, GSLC, or CCIS)
- Must possess and maintain a Top Secret/SCI Security Clearance.
- Additional specific certifications may be required, depending on job assignment.
- Ability to work in a team-oriented, collaborative environment.
- Requires familiarity with network concepts, user authentication, and digital signatures
- Requires understanding of DOW RMF (800-53 Rev 4 and Rev 5)
- Requires understanding of DoW policies and procedures, including FIPS 199, FIPS 200, NIST 800-53, and other applicable policies.
Requirements
- DISA STIG, Enterprise Mission Assurance Support Service (eMASS), NIST 800-53, Risk Assessments, RMF Certifications:
- None Experience:
- 5 + years of related experience US Citizenship Required:
- Yes
- Job Description:
- The ability to lead and set priorities on multiple projects/tasks at once and operate in a dynamic, fast-paced team-oriented environment.
- Depending on job assignment, additional specific certifications may be required.
- The work is typically performed in an office environment, which requires normal safety precautions; work may require some physical effort in the handling of light materials, boxes or equipment.
- The above-listed job description is not intended to be, nor should it be construed as, exhaustive of all responsibilities, skills, efforts, or working conditions associated with this job. Requests for reasonable accommodations will be considered to
Additional Information
Type of Requisition: Regular Clearance Level Must Currently Possess: Top Secret/SCI Clearance Level Must Be Able to Obtain: Top Secret/SCI Public Trust/Other Required: None Job Family: Cyber and IT Risk Management Job Qualifications:
Your Match
How well this role fits your profile.
Company Intel
What employees say
Worked at General Dynamics IT? Share your experience