Position Description & QualificationsSerco is seeking an
Cybersecurity Analyst /Information System Security Manager (ISSM) supporting the 76th Software Maintenance Group at Tinker AFB, OK. The ISSM will serve as the senior security authority and Cybersecurity SME for assigned information systems, ensuring compliance with DoD Cybersecurity requirements, managing system ATO, and guiding technical teams in the protection of classified environments.
In this role, you will:
- Lead the implementation, management, and enforcement of DoD, Air Force, and NIST Cybersecurity policies.
- Responsible for updating all documentation from NIST 800-53 r4 to NIST 800-53 r5
- Serve as the primary authority for RMF lifecycle activities including categorization, control selection, validation, continuous monitoring, and ATO package submission.
- Manage and maintain system security documentation including SSPs, SCTMs, POA&Ms, Incident Response Plans, and Contingency Plans within eMASS.
- Conduct cybersecurity inspections, audits, and compliance reviews.
- Provide expert guidance to system owners, administrators, and engineers.
- Oversee vulnerability and patch management activities including ACAS scans, system alerts, and patch mitigations.
- Work with Configuration Management to help direct change processes and security impact analyses.
- Monitor security posture across hybrid Windows and Linux environments.
- Ensure continuity with incident response, backup and recovery response.
- Team player | Provide technical cybersecurity mentorship to team members
- Act as the primary Cybersecurity liaison to government stakeholders and leadership.
- Provide oversight and direction to administrators, engineers, and technicians.
- Present system status, vulnerabilities, and POA&M progress.
To be successful in this role, you will have:
- An active DoD Top Secret security clearance with SCI eligibility.
- SAP/SAR eligibilty.
- A Bachelor's degree and 8 years of Cybersecurity experience (or equivalent).
- OR an Associate's degree and 10 years of Cybersecurity experience.
- DoD 8570 IAM Level III certification (CISSP, CISM, GSLC, etc.) or DoD 8140 Cybersecurity ISSM - Intermediate qualifications
- Active CAPM certification or obtain within 12 months of hire
- RMF ATO Process experience.
- Experience in mixed Windows/Linux enterprise environments.
- The ability to travel up to 10%.
Additional desired experience and skills:
- ISSM/ISSO experience with PaaS or shared-service offering.
- Hands-on experience securing cloud environments such as Microsoft Azure commercial and/or Azure Gov.
- Experience authorizing hybrid architectures spanning commercial and/or gov cloud and on-premises infrastructure, including boundary definition and interconnection documentation for hybrid systems.
- Working knowledge of container platforms such as Kubernetes, and container image hardening, scanning, and registry governance.
- Experience applying RMF to CI/CD pipelines, including control assessment of pipeline components, build integrity, artifact provenance, and automated gate enforcement.
- Familiarity with Infrastructure as Code (IaC) and Configuration as Code (CaC), such as Terraform, ARM/Bicep, and Ansible, including how IaC affects configuration management, baseline drift, and change control under an existing authorization.
- Understanding of how to sustain an authorization boundary under Continuous Integration and Continuous Delivery (CI/CD), including control inheritance, security impact analysis at deployment velocity, and evidence generation as a pipeline artifact rather than a manual collection effort.
- Experience supporting systems operating at multiple classification levels, including management of separate authorization boundaries and data handling requirements across levels.
- Familiarity with Cross Domain Solutions (CDS), NCDSMO, and data transfer flow validation.
- Hands-on experience operating and managing ACAS/Tenable, including scan configuration, credentialed scanning, and false-positive adjudication.
- Practical experience with SCAP/STIG workflow to include benchmark selection, STIG Viewer/Evaluate-STIG checklist production, and translating findings into POA&M entries.
- Proficiency in eMASS, including package build, control response authoring, artifact management and workflow submission.
- Experience with supply chain risk management (SCRM) as applied to software dependencies, third-party libraries, and container base images (SBOM familiarity ideal).
- Working knowledge of ITAR/export control requirements and their impact on personnel access, data residency, and administrative access to cloud environments
- Proficiency with Atlassian Suite toolset (Jira, Confluence, Bitbucket).
- Familiarity with Agile development methodologies (Scrum, Kanban, etc..), including experience decomposing security and compliance requirements into user stories, participating in sprint events, and embedding security acceptance criteria into defined task completions.