DescriptionCyber Security AnalystSalary Range $100,000 - $125,000We are seeking a Cyber Security Analyst to support Department of Defense (DoD) cybersecurity and Risk Management Framework (RMF) activities.
This position will work with other cybersecurity personnel, system owners, engineers, and government stakeholders to support RMF documentation, security control implementation, system authorization, vulnerability management, and continuous monitoring activities.
The position is primarily onsite with limited work-from-home flexibility, based on mission and customer requirements. An active DoD Secret clearance is required.
Key Responsibilities- Support DoD RMF activities throughout the system lifecycle.
- Develop and maintain SSPs, POA&Ms, security control implementation statements, assessment evidence, and other authorization artifacts.
- Enter, update, and maintain RMF documentation in eMASS.
- Assist with system categorization, security control implementation, assessment, authorization, and continuous monitoring.
- Review and document compliance with applicable NIST security controls and DISA STIGs.
- Assist with vulnerability analysis, remediation tracking, and POA&M management.
- Collect and organize cybersecurity evidence supporting security control assessments and ATO activities.
- Support ACAS/Tenable vulnerability scanning and analysis, as applicable.
- Participate in cybersecurity assessments, audits, inspections, and authorization reviews.
- Coordinate with ISSMs, ISSOs, System Owners, engineers, Security Control Assessors, and other cybersecurity stakeholders.
- Identify cybersecurity issues and escalate complex technical or compliance matters to senior team members.
- Support configuration management and system change reviews for cybersecurity impact.
- Maintain accurate and complete cybersecurity documentation.
RequirementsRequired Qualifications- Active DoD Secret security clearance.
- CISSP certification or equivalent.
- Bachelor's degree in Cybersecurity, Information Technology, Computer Science, Engineering, or related discipline, or an equivalent combination of education and relevant experience as permitted by contract requirements.
- Approximately 5 years of cybersecurity, information assurance, information security, systems administration, or related experience.
• Candidate must meet applicable
DoD 8140 Cyber Workforce Qualification Program requirements for the assigned work role and proficiency level.
• Relevant certifications or qualification pathways may include CISSP, CISA, CAP/CGRC, or other DoD-approved education, training, experience, or certification options applicable to the designated work role.
- Working knowledge of the DoD Risk Management Framework (RMF).
- Familiarity with NIST SP 800-37, NIST SP 800-53/53A, DISA STIGs, POA&Ms, vulnerability management, and ATO processes.
- Ability to develop clear and accurate technical documentation.
- Strong analytical, organizational, written, and verbal communication skills.
Preferred Qualifications- Experience supporting DoD information systems or cybersecurity programs.
- Hands-on experience with eMASS.
- Experience developing or maintaining RMF authorization packages.
- Familiarity with ACAS/Tenable, DISA STIG Viewer, SCAP tools, and vulnerability management.
- Experience supporting classified information systems.
- Familiarity with SSPs, POA&Ms, security control implementation statements, and continuous monitoring.