Jobs · Information Technology · Pennsylvania

Cyber Information Assurance Analyst

On-siteInformation Technology$69k–$132k/yrFull-time

We are searching for a Cyber Information Assurance Analyst to join the Risk Management Department in the Applied Research Laboratory (ARL) at Penn State. The CIAA evaluates system and network environments to implement effective cybersecurity programs and determines security controls and policies based on best practices, regulations, and contractual requirements.

About the role

The Applied Research Laboratory (ARL) leverages modeling and simulation expertise and other resources to deliver prototypes, demonstrations, and accelerated transitions of emerging research and technologies vital to national security needs. ARL is an authorized DoD SkillBridge partner and welcomes all transitioning military members to apply.

ARL's purpose is to research and develop innovative solutions to challenging scientific, engineering, and technology problems in support of the Navy, the Department of Defense (DoD), and the Intelligence Community (IC).

Employment with the University will require successful completion of background check(s) in accordance with University policies. Employees must be eligible to obtain a government security clearance, participate in the ARL drug testing program, and comply with electronic and physical monitoring requirements applicable to federal contractors. ARL operates in a secure information environment involving Unclassified, Controlled Unclassified Information (CUI), and Classified information. You must be a U.S. citizen to apply.

Responsibilities

  • Conduct risk assessments and provide recommendations for system, network, and application design, implementation, and operation of departmental systems
  • Conduct vulnerability assessments of departmental systems and networks to identify deviations from acceptable configurations or policies
  • Meet with stakeholders regularly to assess needs and requirements at a departmental level
  • Monitor the corrective actions of departmental system audits; draft documentation of Plan of Action and Milestones (POAM) for review
  • Obtain certification and accreditation for departmental systems through the creation of process documentation support; may assist with unit or University-wide process documentation
  • Participate in the establishment of program control processes to ensure risk mitigation
  • Perform periodic audits of departmental systems under general supervision
  • Participate in the implementation of required policies, procedures, and configurations; make recommendations for improvements
  • Participate in the preparation of requirements and procedures for forensic preservation
  • Research and stay current on industry best practices

Additional responsibilities for higher-level positions include:

  • Lead risk assessments and provide recommendations for system, network, and application design, implementation, and operation of unit-wide systems
  • Lead vulnerability assessments of unit-wide systems and networks to identify deviations from acceptable configurations or policies; conduct assessments of non-standard systems
  • Monitor the corrective actions of unit-wide system audits; develop and manage Plan of Action and Milestones (POAM)
  • Meet with stakeholders regularly to assess needs and requirements at a unit-wide level
  • Obtain certification and accreditation through the creation of process documentation; develop unit or University-wide process documentation
  • Establish program control processes to ensure risk mitigation
  • Perform periodic audits of systems
  • Implement required policies, procedures, and configurations; make recommendations for improvements
  • Develop requirements and procedures for forensic preservation
  • Assist in the development of policy, process, and standards of Cyber Incident Response Team (CIRT) program and participate in CIRT activities as needed
  • Assist in the development and delivery of information security training material
  • Interface with external entities including law enforcement and intelligence/government agencies
  • Provide guidance to lower-level Analysts

Requirements

  • Windows and Linux
  • OSCI/CD pipeline
  • Review of hardware and software vulnerabilities
  • DoD Risk Management Framework (RMF)
  • Understand and enforce policies and procedures within classified space
  • Previous success with collaborations in a multi-disciplinary, team-oriented culture
  • Assured Compliance Assessment Solution (ACAS) and Security Technical Implementation Guide (STIG)
  • Ability to multitask multiple programs
  • Security+, CAP, GSEC or equivalent certification
  • Active security clearance, at the Top-Secret level and possession of or eligible for SCI level

Preferred Qualifications

  • Development and maintenance of Security Assessment Plans, Risk Assessment Reports, and POAMs
  • Containerized environments
  • Gitlab and Ansible
  • JIRA and Confluence
  • Vulnerability scanning tools (ACAS, OpenSCAP, Trivy, Grype, etc.)
  • Bachelor's degree in Information Technology, Cybersecurity or related field

Education & Experience

Cyber Security Information Analyst (ARL) - Intermediate Professional:

  • Bachelor's Degree
  • 1+ years of relevant experience; or an equivalent combination of education and experience accepted

Cyber Security Information Analyst (ARL) - Professional:

  • Bachelor's Degree
  • No prior relevant work experience required; previous relevant work experience accepted in lieu of education

Schedule

Your working location will be fully on-site in State College, PA, but options exist for hybrid of on-site/work from home based on project-dependent ability. Travel is expected to be at 50% of the time to surrounding areas.

Pay

The salary range for this position, including all possible grades, is $68,604.00 - $132,204.00.

Benefits

Penn State provides a competitive benefits package for full-time employees designed to support both personal and professional well-being. Benefits include:

  • Comprehensive medical, dental, and vision coverage
  • Robust retirement plans
  • Substantial paid time off which includes holidays, vacation, and sick time
  • Generous 75% tuition discount, available to employees as well as eligible spouses and children

Similar jobs

Cyber Information Assurance Analyst

The Applied Research Laboratory at Penn State UniversityReston, VA· 6 mo ago
Information Technology$69k–$132k/yrapply on psu.wd1.myworkdayjobs.com