CALIBRE

Information Security Analyst

CALIBRE$80K — $90K *
Information Technology
5 - 7 years of experience
Job Overview by Ladders

Qualifications

  • 5+ years in cybersecurity, RMF support, compliance, or information assurance.
  • Bachelor's degree in Information Technology, Cybersecurity, or a related field.
  • Active Secret security clearance is required.
  • Working knowledge of NIST RMF, eMASS, DISA STIGs/SRGs, and ACAS.
  • Ability to analyze and document vulnerability data and communicate findings to stakeholders.

Responsibilities

  • Support RMF documentation and ATO sustainment using eMASS.
  • Conduct DISA STIG/SRG and ACAS vulnerability assessments.
  • Maintain and update POA&Ms and coordinate validation efforts.
  • Monitor cybersecurity resources and escalate abnormal findings.
  • Assist with vulnerability assessments for new applications and infrastructure.
  • Support incident reporting and coordination with Incident Response Team.
  • Contribute to weekly cybersecurity activity reporting.

Benefits

  • Hybrid work environment with required meetings in Alexandria, VA.
  • Opportunities to work on DoD cloud and information systems.
  • Engagement with Government cybersecurity teams and systems.
  • Access to classified briefings at Government facilities.
Full Job Description
Job Description

This position will be hybrid with some required meetings in Alexandria, VA.

The role combines cybersecurity operations, compliance, vulnerability management, incident response, and Risk Management Framework (RMF) activities for Department of Defense cloud and information systems. The analyst will help maintain compliance with DoD, DISA, U.S. Cyber Command, MC&FP, NIST RMF, Zero Trust, STIG/SRG, ACAS, and eMASS requirements while supporting the attainment and sustainment of Government-issued Authorizations to Operate (ATOs).

An active Secret clearance is required for this role.

Salary range for this position is $80k-$90k

Key Responsibilities:
• Support RMF documentation, security control implementation, assessment activities, and ATO sustainment using the DoD enterprise eMASS platform.
• Conduct weekly DISA STIG/SRG and ACAS vulnerability assessments, assist with remediation tracking, and prepare raw scan outputs, weekly threat reports, and ACAS roll-up reports.
• Maintain and update Plans of Action and Milestones (POA&Ms), collect evidence of completion, and coordinate validation with ISSM, ISSO, and Security Control Assessment teams.
• Monitor cybersecurity resources, SIEM-integrated logs, anomaly indicators, account aging, compliance status, WAF/NGFW activity, and GovCloud logs; escalate abnormal findings within required timelines.
• Support daily review of the DC3 Vulnerability Disclosure Program portal and assist with creation and mitigation of associated POA&Ms.
• Assist with vulnerability assessments and penetration testing for new or modified applications, servers, databases, and infrastructure components before deployment.
• Support incident reporting, documentation, and coordination with the Incident Response Team and Tier 2 Cybersecurity Service Provider.
• Contribute to weekly cybersecurity activity reporting, including compliance status, vulnerability assessments, incident management, and risk metrics.
• Support contingency planning, disaster recovery exercises, SOP audits, and cybersecurity exercise activities as directed.
• Access SIPRNet and attend classified briefings at the Government facility in Alexandria, Virginia, as required.

Required Skills
• Working knowledge of NIST RMF, eMASS, DISA STIGs/SRGs, ACAS, POA&Ms, and DoD cybersecurity policies.
• Ability to analyze vulnerability data, document findings, support risk mitigation, and communicate technical information to Government stakeholders.
• Familiarity with cloud security monitoring, SIEM tools, incident response processes, and compliance reporting.

Desired Skills and Qualifications:
• Master's degree in Information Technology, Cybersecurity, Information Assurance, or a related field.
• DoD 8570/8140-aligned certification such as Security+ CE, CySA+, or equivalent
• Experience supporting DoD agencies with cybersecurity, information assurance, vulnerability management, or RMF activities.
• Active Top Secret clearance
• Experience with eMASS or other compliance tracking platforms.
• Familiarity with cloud security controls and cloud-based compliance requirements.
• Understanding of Zero Trust principles and cybersecurity modernization strategies.

Required Experience
• Bachelor's degree in Information Technology, Cybersecurity, Information Assurance, or a related field.
• Active Secret security clearance.
5+ years of experience in cybersecurity, RMF support, compliance, or information assurance.
• Experience supporting Federal agencies with cybersecurity, information assurance, vulnerability management, or RMF activities.

About CALIBRE

CALIBRE Systems, Inc. provides management consulting and technology services. The Company offers program management, financial management, information technology, engineering, logistics, and training services. CALIBRE Systems serves customers in the United States.
Learn more about CALIBRE
Size
4,000 employees
Industry
Founded
1989

Similar Jobs

More Jobs at CALIBRE

More Information Technology Jobs

Find similar Information Security Analyst jobs: