Cybersecurity Analyst (Risk Management Framework) - TS/SCI w/ Polygraph

General Dynamics Information Technology, Inc.

$127K — $172K *
Technical Services
5 - 7 years of experience
Job Overview by Ladders

Qualifications

  • Active TS/SCI clearance with Polygraph required
  • 6+ years of experience in Information Assurance and IT systems
  • Bachelor's Degree in a related technical discipline or equivalent experience
  • 3+ years of IC RMF A&A experience
  • Familiarity with NIST 800-53 security controls
  • Hands-on experience with the Xacta application
  • Excellent communication and technical writing skills

Responsibilities

  • Serve as an Information System Security Officer (ISSO) for IC cyber systems
  • Document briefings on system status and ensure compliance with RMF processes
  • Provide justification for security control implementations as per regulatory standards
  • Draft System Security Plans (SSP) and System Security Test Plans (SSTP)
  • Conduct self-assessments and analyze security controls
  • Assist with formal risk assessments and document findings
  • Research remediation options for identified system vulnerabilities

Benefits

  • Flexible work weeks and a variety of paid time off plans
  • Comprehensive medical, dental, and vision plan options
  • 401(k) with company match
  • Short and long-term disability insurance
  • Life and accident insurance options
  • Regular review of benefits to ensure competitiveness
Full Job Description
Type of Requisition:
Regular

Clearance Level Must Currently Possess:
Top Secret/SCI

Clearance Level Must Be Able to Obtain:
Top Secret SCI + Polygraph

Public Trust/Other Required:
None

Job Family:
Cyber and IT Risk Management

Job Qualifications:

Skills:
Information Assurance, Information Systems, Information Technology (IT)
Certifications:
None
Experience:
6 + years of related experience
US Citizenship Required:
Yes

Job Description:

In this role, a typical day may include:

  • Acting as an appointed Information System Security Officer (ISSO) for IC cyber systems being developed by the engineering team
  • Reporting, documenting, and briefing the status of systems under development, while assuring their successful and timely progression through the clients' Risk Management Framework (RMF) to the satisfaction of the appointed Information System Security Manager (ISSM), and/or Senior Government leadership
  • Providing clear justification satisfying all applicable security control implementation as specified by the IC, AO, or NIST-800-53, rev 4 rev 5
  • Authoring System Security Plans (SSP) and System Security Test Plans (SSTP)
  • Conducting self-assessments of all systems under development
  • Analyzing security controls and the impacts the changes would have on the environment
  • Preparing for and assisting with formal risk assessments conducted by the AO's designated Security Control Assessors (SCA) while acting as a member of the security assessment test team
  • Ensuring the remediation of any findings assigned to engineering as documented in the Security Assessment Report (SAR) and its Plan of Actions and Milestones (PO&AM)
  • Documenting and defending reasoning when waivers are sought, or non-standard remediation solutions are requested for specific security controls
  • Assisting with the transition of systems granted an ATO to the Operations branch and the assignment of an operations ISSO
  • Researching remediation options for vulnerabilities identified for systems under development or already in production under an ATO


What you'll need:
  • Active TS/SCI with Polygraph
  • Must meet DoD 8570 IAT Level II requirements including one of the following: Security+ CE, CND, SSCP, GSEC, GICSP, CySA+, or CCNA Security
  • Bachelor's Degree in a related technical discipline +6 years' experience or the equivalent combination of education, technical certification or training, or work/military experience
  • Minimum of 3-years IC (SCI) RMF Assessment and Authorization (A&A) experience and the ability to describe the differences between collateral and SCI authorization requirements as they apply to DoW and IC instructions and guidelines
  • Ability to speak to the intent of all NIST 800-53 security controls
  • Minimum 1-year hands on experience with the Xacta application
  • Excellent oral and technical writing skills
  • Ability to work both independently and as a member of a team


The likely salary range for this position is $127,500 - $172,500. This is not, however, a guarantee of compensation or salary. Rather, salary will be set based on experience, geographic location and possibly contractual requirements and could fall outside of this range.

Scheduled Weekly Hours:
40

Travel Required:
None

Telecommuting Options:
Onsite

Work Location:
USA MD Annapolis Junction

Additional Work Locations:
USA VA Sterling

Total Rewards at GDIT:
Our benefits package for all US-based employees includes a variety of medical plan options, some with Health Savings Accounts, dental plan options, a vision plan, and a 401(k) plan offering the ability to contribute both pre and post-tax dollars up to the IRS annual limits and receive a company match. To encourage work/life balance, GDIT offers employees full flex work weeks where possible and a variety of paid time off plans, including vacation, sick and personal time, holidays, paid parental, military, bereavement and jury duty leave. To ensure our employees are able to protect their income, other offerings such as short and long-term disability benefits, life, accidental death and dismemberment, personal accident, critical illness and business travel and accident insurance are provided or available. We regularly review our Total Rewards package to ensure our offerings are competitive and reflect what our employees have told us they value most.

Our Identity Verification Process:
As part of the hiring process, we will ask you to complete an identity verification process that leverages advanced biometrics and artificial intelligence to ensure authenticity and protect against identity fraud. You are expected to be on camera during virtual interviews. We reserve the right to take your picture to verify your identity and prevent fraud. By proceeding, you authorize the collection, processing, and use of your biometric data for identity verification and security purposes.

Join our Talent Community to stay up to date on our career opportunities and events at
gdit.com/tc.

Similar Jobs

More Jobs at General Dynamics Information Technology, Inc.

More Technical Services Jobs

Find similar Cybersecurity Analyst (Risk Management Framework) - TS/SCI w/ Polygraph jobs: