Serco

Cybersecurity Analyst - ISSM- Tinker AFB, OK

Serco$100K — $120K *
Aerospace & Defense
8 - 10 years of experience
Job Overview by Ladders

Qualifications

  • Active DoD Top Secret security clearance with SCI eligibility.
  • SAP/SAR eligibility.
  • Bachelor's degree with 8 years Cybersecurity experience or Associate's degree with 10 years experience.
  • DoD 8570 IAM Level III certification or equivalent.
  • Experience with RMF ATO Process and mixed Windows/Linux environments.

Responsibilities

  • Lead implementation and enforcement of DoD and NIST Cybersecurity policies.
  • Update system documentation from NIST 800-53 r4 to r5.
  • Manage RMF lifecycle activities and oversee ATO submissions.
  • Conduct audits and compliance reviews for cybersecurity.
  • Act as primary Cybersecurity liaison and mentor team members.

Benefits

  • Medical, dental, and vision insurance.
  • Robust vacation and sick leave benefits.
  • 401(k) plan with employer matching.
  • Tuition reimbursement program.
  • Life insurance and disability coverage.
Full Job Description
Position Description & Qualifications

Serco is seeking an Cybersecurity Analyst /Information System Security Manager (ISSM) supporting the 76th Software Maintenance Group at Tinker AFB, OK. The ISSM will serve as the senior security authority and Cybersecurity SME for assigned information systems, ensuring compliance with DoD Cybersecurity requirements, managing system ATO, and guiding technical teams in the protection of classified environments.

In this role, you will:
  • Lead the implementation, management, and enforcement of DoD, Air Force, and NIST Cybersecurity policies.
  • Responsible for updating all documentation from NIST 800-53 r4 to NIST 800-53 r5
  • Serve as the primary authority for RMF lifecycle activities including categorization, control selection, validation, continuous monitoring, and ATO package submission.
  • Manage and maintain system security documentation including SSPs, SCTMs, POA&Ms, Incident Response Plans, and Contingency Plans within eMASS.
  • Conduct cybersecurity inspections, audits, and compliance reviews.
  • Provide expert guidance to system owners, administrators, and engineers.
  • Oversee vulnerability and patch management activities including ACAS scans, system alerts, and patch mitigations.
  • Work with Configuration Management to help direct change processes and security impact analyses.
  • Monitor security posture across hybrid Windows and Linux environments.
  • Ensure continuity with incident response, backup and recovery response.
  • Team player | Provide technical cybersecurity mentorship to team members
  • Act as the primary Cybersecurity liaison to government stakeholders and leadership.
  • Provide oversight and direction to administrators, engineers, and technicians.
  • Present system status, vulnerabilities, and POA&M progress.


To be successful in this role, you will have:
  • An active DoD Top Secret security clearance with SCI eligibility.
  • SAP/SAR eligibilty.
  • A Bachelor's degree and 8 years of Cybersecurity experience (or equivalent).
    • OR an Associate's degree and 10 years of Cybersecurity experience.
  • DoD 8570 IAM Level III certification (CISSP, CISM, GSLC, etc.) or DoD 8140 Cybersecurity ISSM - Intermediate qualifications
  • Active CAPM certification or obtain within 12 months of hire
  • RMF ATO Process experience.
  • Experience in mixed Windows/Linux enterprise environments.
  • The ability to travel up to 10%.

Additional desired experience and skills:
  • ISSM/ISSO experience with PaaS or shared-service offering.
  • Hands-on experience securing cloud environments such as Microsoft Azure commercial and/or Azure Gov.
  • Experience authorizing hybrid architectures spanning commercial and/or gov cloud and on-premises infrastructure, including boundary definition and interconnection documentation for hybrid systems.
  • Working knowledge of container platforms such as Kubernetes, and container image hardening, scanning, and registry governance.
  • Experience applying RMF to CI/CD pipelines, including control assessment of pipeline components, build integrity, artifact provenance, and automated gate enforcement.
  • Familiarity with Infrastructure as Code (IaC) and Configuration as Code (CaC), such as Terraform, ARM/Bicep, and Ansible, including how IaC affects configuration management, baseline drift, and change control under an existing authorization.
  • Understanding of how to sustain an authorization boundary under Continuous Integration and Continuous Delivery (CI/CD), including control inheritance, security impact analysis at deployment velocity, and evidence generation as a pipeline artifact rather than a manual collection effort.
  • Experience supporting systems operating at multiple classification levels, including management of separate authorization boundaries and data handling requirements across levels.
  • Familiarity with Cross Domain Solutions (CDS), NCDSMO, and data transfer flow validation.
  • Hands-on experience operating and managing ACAS/Tenable, including scan configuration, credentialed scanning, and false-positive adjudication.
  • Practical experience with SCAP/STIG workflow to include benchmark selection, STIG Viewer/Evaluate-STIG checklist production, and translating findings into POA&M entries.
  • Proficiency in eMASS, including package build, control response authoring, artifact management and workflow submission.
  • Experience with supply chain risk management (SCRM) as applied to software dependencies, third-party libraries, and container base images (SBOM familiarity ideal).
  • Working knowledge of ITAR/export control requirements and their impact on personnel access, data residency, and administrative access to cloud environments
  • Proficiency with Atlassian Suite toolset (Jira, Confluence, Bitbucket).
  • Familiarity with Agile development methodologies (Scrum, Kanban, etc..), including experience decomposing security and compliance requirements into user stories, participating in sprint events, and embedding security acceptance criteria into defined task completions.

Pay Transparency

Our Total Rewards package includes competitive pay, performance-based incentives, and benefits that promote well-being and work-life balance-so you can thrive both professionally and personally. Eligible employees also gain access to a wide range of benefits from comprehensive health coverage and health savings accounts to retirement plans, life and disability insurance, and time-off programs that support work-life balance. Program availability may vary based on factors such as contract type, location, hire date, and applicable collective bargaining agreements.

Salary range: The range for this position can be found at the top of this posting. This range is provided as a general guideline and represents a good faith estimate across all experience levels. Actual base salary will be determined by a variety of factors, including but not limited to, the scope of the role, relevant experience, job-related knowledge, education and training, key skills, and geographic market considerations. For roles available in multiple states, the range may vary to reflect differences in local labor markets. In addition to base salary, eligible positions may include other forms of compensation such as annual bonuses or long-term incentive opportunities.Benefits - Comprehensible benefits for full-time employees (part-time employees receive a limited package tailored to their role):

  • Medical, dental, and vision insurance
  • Robust vacation and sick leave benefits, and flexible work arrangements where permitted by role or contract
  • 401(k) plan that includes employer matching funds
  • Tuition reimbursement program
  • Life insurance and disability coverage
  • Optional coverages that can be purchased, including pet insurance, home and auto insurance, additional life and accident insurance, critical illness insurance, group legal, ID theft protection
  • Birth, adoption, parental leave benefits
  • Employee Assistance Plan


To review all Serco benefits please visit: https://careers.serco-na.com/us/en/about-us.

Serco complies with all applicable state and local leave laws, including providing time off under the Colorado Healthy Families and Workplaces Act for eligible Colorado residents, in alignment with our policies and benefit plans. The application window for this position is for no more than 60 days. We encourage candidates to apply promptly after the posting date, as the position may close earlier if filled or if the application volume exceeds expectations. Please submit applications exclusively through Serco's external (or internal) career site. If an applicant has any concerns with job posting compliance, please send an email to: [email protected].

About Serco

Serco Group plc is a British company providing public services. It is listed on the London Stock Exchange and is a constituent of the FTSE 250 Index. The company has four divisions: Health, Justice and Immigration, Transport, and Defence, and operates across the UK and Europe, North America, Asia Pacific and the Middle East. Serco primarily provides public services to governments, including the operation of prisons and hospitals, defence and aerospace services, and transport services. The company also provides IT and consultancy services to the public sector. Serco has been involved in a number of controversies, including allegations of overcharging the UK government and mismanagement of contracts.
Learn more about Serco
Size
50,000 employees
Industry
Founded
1988

Similar Jobs

More Jobs at Serco

More Aerospace & Defense Jobs

Find similar Cybersecurity Analyst - ISSM- Tinker AFB, OK jobs: