Information Security Analyst

Sanmina-SCI

$80K — $95K *
Information Technology
Less than 5 years of experience
Job Overview by Ladders

Qualifications

  • Active DoD Secret clearance required
  • Bachelor's Degree in IT, Cybersecurity, Computer Science, or related field, or equivalent experience
  • 3+ years in ISSO or cybersecurity compliance roles
  • Experience with DoD/DCSA accreditation and SSP development
  • Deep understanding of RMF and eMASS
  • Current CompTIA Security+ or equivalent certification
  • Technical skills in Nessus, Splunk, and Windows administration

Responsibilities

  • Develop and update System Security Plans and authorization artifacts
  • Implement and validate RMF controls in eMASS
  • Conduct weekly security audits and log reviews
  • Perform vulnerability scanning and manage remediation
  • Enforce Security Technical Implementation Guides across systems
  • Manage and track Plans of Action and Milestones
  • Provide tier 2/3 technical support and troubleshooting

Benefits

  • Opportunities for professional development and training
  • Access to advanced cybersecurity tools and technologies
  • Dynamic and collaborative work environment
  • Engagement with national security initiatives
  • Potential for career growth within the organization
Full Job Description
Information System Security Officer (ISSO) / System Administrator

Job Purpose

The Information System Security Officer (ISSO) / System Administrator serves as the primary cybersecurity and compliance lead for the organization, ensuring systems adhere to Risk Management Framework (RMF) and Defense Counterintelligence and Security Agency (DCSA) security requirements. This role is primarily focused on strategic cybersecurity alignment, system accreditation, continuous monitoring, and risk management, while also providing operational system administration support and maintenance for desktop and standalone computing environments.

Key Responsibilities

Cybersecurity & Compliance (Primary)
• Develop, maintain, and update System Security Plans (SSPs) and associated authorization artifacts for standalone and networked systems.
• Ensure RMF security controls are properly implemented, validated, and loaded into the Enterprise Mission Assurance Support Service (eMASS).
• Perform weekly security audits and log reviews using Splunk Enterprise or native monitoring tools as required by DCSA; execute corrective actions as needed.
• Conduct vulnerability scanning and management using Tenable Nessus, coordinating patching and remediation strategies.
• Apply, enforce, and verify Security Technical Implementation Guides (STIGs) across operating systems and applications.
• Create, track, and manage Plans of Action and Milestones (POA&Ms) through resolution.

System Administration & Operations (Secondary)
• Perform system administration functions, including user account management and access controls on standalone computers.
• Provide tier 2/3 technical support, computer setup, hardware/software troubleshooting, and root-cause resolution.
• Configure and administer Group Policy Objects (GPOs) to enforce security configurations and user policies.
• Execute regular system backups, disaster recovery tests, and routine operating system updates.
• Assist in maintaining virtual machine (VM) environments.

Qualifications & Requirements
• Clearance: Active DoD Secret clearance.
• Education: Bachelor's Degree in Information Technology, Cybersecurity, Computer Science, or a related field (or equivalent work experience).
• Experience:
o 3+ years of dedicated experience acting as an ISSO or in a direct cybersecurity compliance role.
o Demonstrated experience with DoD or DCSA accreditation processes and SSP development.
o Deep understanding and hands-on experience with the Risk Management
Framework (RMF) and eMASS.
o Proficiency in tracking and resolving POA&Ms.
• Certification: Current CompTIA Security+ (or equivalent DoD 8140/8570 IAT II / IAM I baseline certification).
• Core Technical Skills:
o Experience using Nessus / Security Center for vulnerability scanning.
o Working knowledge of audit log review platforms like Splunk Enterprise.
o Working knowledge of Windows desktop administration, Group Policies, and standalone computer environment.

Preferred Qualifications
• Hands-on experience performing dual ISSO and System Administrator duties in a classified or sensitive environment.
• Current Windows Operating System certification.
• Experience with virtual machine configuration and backup management platforms.

Similar Jobs

More Jobs at Sanmina-SCI

More Information Technology Jobs

Find similar Information Security Analyst jobs: