- 01-Feb-2021 to Until Filled (EST)
- Herndon, VA, USA
- Full Time
- TS/SCI with CI Poly
Title: Computer Systems Security Analyst
Location: Herndon, VA
Clearance: TS/SCI w/CI polygraph
Responsibilities:
- Design and implement safety measures and controls
- Monitor network activity to identify vulnerable points and address privacy breaches and malware threats
- Support the Assessment and Authorization (A&A) processes and IA documentation for multiple analytic and mission systems across all CLINs
- Generate and maintain the complete security Body of Evidence (BoE) while leading the A&A activities according to the Risk Management Framework (RMF) processes (ICD 503, CNSSI-1253, NIST 800-37, NIST 800-53, etc.) for all multiple information systems
- Analyze existing security systems and make recommendations for changes or improvements
- Prepare reports and action plans in the event that a security breech does occur
- Monitor the network and provide early warning of abnormalities or problems
- Communicate the system status and keep users informed of downtime or changes to the system
- Provide system updates and write code fixes
- Work closely with software developers and architects to understand security requirements
- Guide the application developers on security policy, identifying security requirements, providing technical guidance for the satisfaction of requirements
- Create and manage the plan of action and milestones (POA&Ms), and working with project managers and engineers to develop schedules and engineering actions that mitigate open findings
- Support the continuous monitoring of operational systems; experience monitoring and auditing operational systems for proper use
Requirements:
- Bachelor's degree required with 9+ years of experience supporting Assessment and Authorization (A&A) and information assurance processes and documentation using RMF
- Knowledge of current security risks and protocols
- Excellent analytic and problem-solving skills
- Experience with RMF and Xacta
- Experience working with AWS/Google cloud-hosted information systems or applications a plus
- Knowledge of Redhat or CentOS Linux operating systems, and experience working in a DevSecOps environment and tool chain desired
- Willingness to work on-call in the event of a security breech or other emergency
- DoD Approved 8570 baseline certification such as Sec+ required
- Current active TS/SCI clearance with a CI polygraph
Equal Opportunity Employer/Veterans/Disabled
