Cyber Security Analyst, Intermediate

Savannah River National Laboratory

$80K — $95K *
Aiken, SC 29803In-Person
Information Technology
Less than 5 years of experience
Job Overview by Ladders

Qualifications

  • Bachelor's degree in relevant field with 2-4 years of experience.
  • Proficient in security architectures, encryption, firewalls, and IDS/IPS.
  • Experienced in vulnerability assessment and penetration testing.
  • Knowledge of air-gapped network challenges and secure coding practices.
  • DoD 8570 compliant certification (CISSP, CASP) required.
  • Excellent communication, attention to detail, and problem-solving skills.
  • US Citizenship required for security clearance.

Responsibilities

  • Design and implement secure environments in air-gapped systems using RMF, NIST, and ISO 27001.
  • Enforce security controls and ensure compliance with guidelines like STIGs and SRGs.
  • Develop and maintain documentation for security requirements and authorization activities.
  • Assess security threats, respond to incidents, and research remediation options.
  • Collaborate with IT professionals and stakeholders to align security practices with operational needs.

Benefits

  • Opportunity to work in a cutting-edge research environment.
  • Dynamic team culture focused on growth and solving critical national problems.
  • Access to advanced security technologies and frameworks.
  • Prospects for working across multiple federal customers.
Full Job Description
Job Description

Savannah River National Laboratory is seeking to hire a Cyber Security Analyst. The Analyst is responsible for designing, implementing, and maintaining robust security controls within a highly sensitive and air-gapped enterprise environment. This role is critical in safeguarding the integrity, confidentiality, and availability of information systems by ensuring that security measures are effectively integrated throughout the system development lifecycle (SDLC). The ISSE will work within an air-gapped environment, meaning the systems are physically or logically isolated from unsecured networks, including the internet.

Responsibilities

  • Security Architecture and Design: Design, develop, and implement secure environments within the air-gapped enterprise, applying relevant security frameworks like RMF, NIST, and ISO 27001. Develop strategies for complex security challenges unique to air-gapped systems and enforce secure relations for data transfer.
  • Security Control Implementation and Maintenance: Implement and enforce security controls to protect sensitive information. Ensure compliance with security guidelines like STIGs and SRGs. Configure and troubleshoot security infrastructure, including specialized systems for air-gapped operations. Perform and review technical security assessments.
  • Compliance and Authorization: Develop security requirements and maintain detailed documentation such as SSPs. Prepare and review authorization documentation according to regulations. Support authorization activities and participate in security audits.
  • Incident Response and Risk Management: Assess and mitigate system security threats and risks. Respond to and investigate security incidents, implementing procedures considering air-gapped constraints. Research remediation options for vulnerabilities.
  • Collaboration and Communication: Work closely with other IT professionals to ensure secure practices. Collaborate with stakeholders to align security initiatives with operational needs. Provide expert support and communicate effectively on security matters.


Qualifications

Minimum Qualifications:
  • Bachelor's degree in a relevant field of study and 2-4 years of relevant work experience.
  • Technical Skills:Understanding of security architectures, encryption, firewalls, and IDS/IPS. Expertise in vulnerability assessment and penetration testing. Knowledge of network security protocols and secure coding practices. Familiarity with cloud security principles (if applicable). Proficiency with security tools like SIEM and endpoint protection, including Splunk and Elastic SIEM. Experience applying STIGs. Strong understanding of risk management and the challenges of air-gapped networks.
  • Certifications: DoD 8570 compliance with [Specify IASAE Level] certification (e.g., CISSP, CASP).
  • Soft Skills: Excellent communication and interpersonal skills. Strong attention to detail and adaptability. Ability to multi-task and identify non-compliance solutions.
  • Experience with security frameworks like JSIG, NIST SP 800 Series, and CNSSI 1253.
  • For ability to obtain and maintain a security clearance, US Citizenship is Legally Required


Preferred Qualifications:
  • Cloud Service Provider Associate Certification
  • Experience with containerization and zero-trust architectures.
  • Splunk or Tenable Certifications.
  • Experience with SECOPS administrative processes.
  • Active DOE Clearance


About the Team

Chief Information Office (CIO) team supports SRNL in achieving mission and business goals of this National Laboratory. Our team provides digital solutions along with virtual infrastructure. Dynamic team providing growth opportunity to support cutting edge research and development and solve nation state problems. Ability to work across multiple federal customers. Solutions range from commercial off the shelf and custom written including cloud based solutions.

Similar Jobs

More Jobs at Savannah River National Laboratory

More Information Technology Jobs

Find similar Cyber Security Analyst, Intermediate jobs: