Intermediate II System Security/Information Assurance AnalystThe Intermediate II System Security/Information Assurance Analyst supports cybersecurity, vulnerability assessment, penetration testing, threat analysis, and information assurance activities for National Airspace System (NAS) systems and subsystems. The position supports the identification, analysis, and mitigation of cybersecurity threats and vulnerabilities and may support both unclassified and classified environments.
Responsibilities include:- Support vulnerability assessments and penetration testing activities, including the planning, execution, analysis, and documentation of testing results.
- Assist with the design, planning, and execution of cybersecurity exercises and penetration testing scenarios, including development of exercise timelines, event injections, and anticipated response activities.
- Utilize cybersecurity and penetration testing tools to identify vulnerabilities, evaluate system security, and support threat analysis.
- Develop and utilize Python scripts and other automation tools to support cybersecurity testing, vulnerability analysis, data processing, threat analysis, and repetitive security tasks.
- Analyze actual or attempted cybersecurity incursions to identify potential sources, methods, impacts, and associated risks.
- Identify potential information security threats and recommend appropriate mitigation measures and corrective actions.
- Analyze and prioritize security enhancements, remediation activities, and system security upgrades based on identified vulnerabilities and threats.
- Support the development, implementation, and maintenance of security policies, procedures, and controls for NAS systems and subsystems.
- Support efforts to protect sensitive, proprietary, and Government information and information systems from unauthorized access, disclosure, modification, or loss.
- Support the development, maintenance, and use of threat modeling databases, cybersecurity tools, and related security artifacts.
- Participate in cybersecurity working groups, technical reviews, assessments, and other security-related activities as assigned.
- Prepare and maintain technical documentation associated with vulnerability assessments, penetration testing, threat analysis, mitigation recommendations, and cybersecurity exercises.
Minimum Qualifications:- Bachelor's Degree in Science and/or Engineering
- Minimum of 3 years performing vulnerability assessments, penetration testing, cybersecurity analysis, information assurance, or related cybersecurity activities.
- Working knowledge of cybersecurity vulnerabilities, threats, attack methods, and mitigation techniques.
- Experience with Python programming/scripting, including the ability to develop or modify scripts to support cybersecurity testing, automation, data analysis, or related technical activities.
- Ability to analyze technical information and clearly document findings, risks, and recommended corrective actions.
Preferred Qualifications:- Experience using vulnerability assessment, penetration testing, or offensive security tools such as Metasploit, Nmap, Nessus, Kali Linux, Cobalt Strike, Core Impact, or similar tools.
- Experience using Python to automate cybersecurity tasks, interact with security tools/APIs, analyze security-related data, or develop testing utilities.
- Experience with code analysis, malware analysis, incident analysis, and/or data breach investigations.
- Experience developing or supporting cybersecurity exercise scenarios, timelines, and detailed event injection plans.
- Knowledge of cybersecurity threat modeling methodologies, databases, and tools.
- Experience supporting cybersecurity activities within Government, aviation, NAS, or other mission-critical environments.
We invest in them, and our generous benefits package, which includes medical, dental, matched 401k contributions, Life/Disability, Tuition Reimbursement, PTO/federal holidays, seeks to attract and retain the most qualified workforce. Our success depends on that.