Information Security AnalystCompany: Sugpiat Defense
Program: Missile Defense Agency (MDA)
Employment Type: Full-Time
Position OverviewSugpiat Defense is seeking an experienced
Information Security Analyst to support the Missile Defense Agency (MDA) in Colorado Springs, Colorado. The selected candidate will assist in protecting mission-critical information systems by implementing cybersecurity policies, supporting Risk Management Framework (RMF) activities, monitoring system security posture, and ensuring compliance with Department of Defense (DoD) cybersecurity requirements.
The ideal candidate is detail-oriented, possesses strong analytical and problem-solving skills, and has experience supporting cybersecurity operations within a DoD environment. This role works closely with Information System Security Managers (ISSMs), engineers, system administrators, and government personnel to maintain the security and compliance of MDA information systems.
Essential Duties and Responsibilities- Support the implementation and maintenance of cybersecurity requirements for classified and unclassified information systems.
- Assist with Risk Management Framework (RMF) activities throughout the system lifecycle.
- Maintain and update RMF documentation, including System Security Plans (SSPs), Security Assessment Reports (SARs), Plans of Action and Milestones (POA&Ms), and supporting artifacts.
- Perform continuous monitoring activities to ensure compliance with DoD cybersecurity requirements.
- Review vulnerability scan results, document findings, and coordinate remediation efforts with technical teams.
- Support implementation and validation of DISA Security Technical Implementation Guides (STIGs).
- Assist with Assessment and Authorization (A&A) activities to maintain system Authority to Operate (ATO).
- Monitor system security posture and report cybersecurity risks and compliance issues.
- Support security audits, inspections, and cybersecurity assessments.
- Assist with investigating and documenting cybersecurity incidents in accordance with established procedures.
- Review proposed system changes to identify potential security impacts.
- Collaborate with engineers, system administrators, and government stakeholders to ensure cybersecurity requirements are incorporated into system operations.
- Prepare reports, metrics, and status updates related to cybersecurity compliance and continuous monitoring.
- Stay current on DoD cybersecurity policies, emerging threats, and industry best practices.
Required Qualifications- Bachelor's degree in Cybersecurity, Information Technology, Computer Science, Information Assurance, or a related field.
- Minimum of 3-5 years of experience supporting information assurance or cybersecurity programs, preferably within the Department of Defense.
- Experience supporting the DoD Risk Management Framework (RMF).
- Working knowledge of:
- NIST SP 800-53
- NIST SP 800-37
- DoD RMF
- DISA STIGs
- Vulnerability management
- Security compliance and continuous monitoring
- Experience with Enterprise Mission Assurance Support Service (eMASS) or similar RMF tools.
- Familiarity with Windows and Linux operating systems, Active Directory, and basic networking concepts.
- Strong analytical, organizational, written, and verbal communication skills.
- Ability to work independently while contributing effectively within a collaborative team environment.
Preferred Qualifications- Experience supporting the Missile Defense Agency (MDA) or another DoD organization.
- Experience using ACAS, SCAP Compliance Checker, or other DoD cybersecurity assessment tools.
- Familiarity with cybersecurity engineering principles and secure system development practices.
- Experience supporting classified information systems.
- Knowledge of Zero Trust concepts and current DoD cybersecurity initiatives.
CertificationsOne or more of the following certifications is preferred:
- Security+
- CySA+
- CASP+
- CISSP (Associate or full certification)
- CAP
Certification must meet applicable DoD 8570/8140 requirements for the assigned position.
Security Clearance- Active TopSecret with SCI eligibility security clearance required.