Senior Cybersecurity Analyst

OCH Technologies LLC

$110K — $130K *
Information Technology
8 - 10 years of experience
Job Overview by Ladders

Qualifications

  • Bachelor's degree in Cybersecurity, Computer Science, Information Technology, Engineering, Mathematics, or Physics.
  • 8+ years of experience in security or vulnerability assessments in federal or critical infrastructure environments.
  • Recent assessment experience (last 3 years) required.
  • Knowledge of NIST SP 800-53, NIST SP 800-53A, NIST SP 800-37 (RMF), and FIPS-199.
  • Proficiency with vulnerability scanning tools like Nessus, WebInspect, nMap.

Responsibilities

  • Execute independent risk assessments on NAS and Mission Support systems using NIST assessment methods.
  • Lead on-site assessment events, coordinating with facility personnel and system owners.
  • Conduct vulnerability scans using approved tools like Nessus and WebInspect.
  • Develop System Security Assessment Reports (SARs) documenting findings and risk levels.
  • Create actionable Plans of Action and Milestones (POAMs) for mitigation steps.
  • Perform regression assessments to check remediation of previously identified vulnerabilities.
  • Collect and analyze necessary system and security documentation.

Benefits

  • Opportunity for on-site work at key FAA hubs in Oklahoma City, Atlantic City, or Washington, DC.
  • Potential for travel to various FAA facilities nationwide for assessments.
  • Experience with key federal cybersecurity compliance standards and assessment frameworks.
  • Direct involvement with the FAA and access to critical infrastructure cybersecurity.
  • Collaboration with other experienced professionals in the field.
Full Job Description
OCH Technologies is seeking a Senior Cybersecurity Analyst to execute independent risk assessments and vulnerability assessments at FAA facilities. Candidate should be based at one of three FAA hub locations (Oklahoma City, Atlantic City, or DC) where major NAS programs and equipment reside, with travel to other FAA sites for assessment events. The candidate will own assigned systems, run assessments from kickoff through artifact collection through SAR delivery, and lead on-site test events.

This position supports a proposal effort and is contingent upon award, customer approval, and successful onboarding requirements.

Location

On site: FAA hub locations- Mike Monroney Aeronautical Center (MMAC) Oklahoma City, OK OR William J. Hughes Technical Center (WJHTC) Egg Harbor, NJ OR Air Traffic Control System Command Center (ATCSCC) Washington, DC.

This position has the potential to travel up to 40% to other FAA facilities nationwide for assessment events.

Core Responsibilities & Duties
  • Execute independent risk assessments on NAS and Mission Support systems using the three NIST 800-53A assessment methods (Examine, Interview, Test).
  • Lead on-site assessment events at FAA facilities nationwide. Coordinate with facility personnel, system owners, and ACG to execute assessments on schedule.
  • Conduct vulnerability scanning using tools including Nessus, WebInspect, AppDetective Pro, nMap, and other FAA-approved tools.
  • Develop System Security Assessment Reports (SARs) documenting findings, risk levels, and recommended mitigations.
  • Develop draft Plans of Action and Milestones (POAMs) with clear, actionable remediation steps.
  • Perform regression assessments to validate that previously identified vulnerabilities have been remediated.
  • Collect and analyze system configuration files, security documentation, and other artifacts required for assessment.
  • Conduct interviews with system administrators, system owners, and other personnel as part of the assessment methodology.
  • Support the Security Assessment Lead in maintaining the Integrated Master Test Schedule and coordinating resource assignments.
  • Maintain proficiency with current assessment tools and techniques. Participate in cross-training during periods between scheduled assessments.

Responsibilities may evolve over time to support team and organizational goals but will remain consistent with the overall scope of the role.

Requirements

Minimum Qualifications

Education

Bachelor's degree in Cybersecurity, Computer Science, Information Technology, Engineering, Mathematics, or Physics from an accredited institution

Experience
  • A minimum of eight (8)+ years of hands-on experience conducting security assessments or vulnerability assessments in federal or critical infrastructure environments. At least 2 years of relevant experience must be recent (performed within the last 3 years).
  • Working knowledge of NIST SP 800-53, NIST SP 800-53A, NIST SP 800-37 (RMF), and FIPS-199.
  • Proficiency with vulnerability scanning tools (Nessus, WebInspect, nMap, or equivalents).
  • Experience developing SARs, POAMs, or equivalent assessment documentation.

Security Clearance Requirement

Candidate must have the ability to obtain and maintain a Public Trust

Certifications

At least one of the following risk assessment certifications required : CISSP, GCED (GIAC Certified Enterprise Defender), CASP (CompTIA Advanced Security Practitioner), or CISA (Certified Information Systems Auditor). Additional certifications (CEH, GPEN, CAP) preferred but not required

Preferred Qualifications
  • Prior experience assessing NAS systems or working at FAA facilities.
  • Experience with CIS Benchmarks and automated compliance scanning.
  • Experience assessing cloud environments (FedRAMP, AWS GovCloud, Azure Government).
  • Familiarity with operational technology (OT) or industrial control system (ICS) security.
  • Cloud security posture tools (Prowler, ScoutSuite) for assessing AWS GovCloud and Azure Government environments.
  • OpenSCAP or SCAP Compliance Checker for automated compliance validation against CIS Benchmarks and NIST baselines.
  • Elastic/ELK or Splunk for log-based assessment analysis and continuous monitoring data review.
  • AI-assisted documentation analysis tools for accelerating NIST 800-53 control gap identification across system security plans and configuration artifacts.

Other Required Skills and Abilities
  • Ability and willingness to lead test events on-site independently, not just participate as a team member.
  • Strong interpersonal skills for conducting interviews and coordinating with FAA facility personnel who have competing operational priorities.
  • Ability to work in lab and operational environments with appropriate care for safety-critical systems.


Similar Jobs

More Jobs at OCH Technologies LLC

  • Senior Full Stack Developer
    $120K — $135K *
    Egg Harbor Township, NJ 08234 (Atlantic County)
    Aerospace & Defense
    In-Person
  • Security Assessment Lead
    $100K — $130K *
    Fort Washington, MD 20744 (Prince Georges County)
    Information Technology
    In-Person
  • Security Assessment Lead
    $100K — $130K *
    Oklahoma City, OK 73160 (Cleveland County)
    Information Technology
    In-Person
  • Program Manager
    $100K — $130K *
    Fort Washington, MD 20744 (Prince Georges County)
    Aerospace & Defense
    In-Person
  • Program Manager
    $100K — $130K *
    Herndon, VA 20171 (Fairfax County)
    Aerospace & Defense
    In-Person

More Information Technology Jobs

Find similar Senior Cybersecurity Analyst jobs: