Cyber Security Analyst I
Scientific Research Corporation · North Charleston, SC · Yesterday
Information TechnologyFull-time
About the role
Scientific Research Corporation is seeking a cybersecurity professional to support configuration management, security update implementation, and compliance activities for U.S. Government systems.
Responsibilities
- Verify configuration management and track security update implementation using existing automated tools.
- Adhere to pre-defined configuration management and change management policies and procedures for authorizing software prior to implementation on systems.
- Ensure systems are operated, used, maintained, and disposed of in accordance with all applicable security policies and practices.
- Perform cybersecurity testing, analysis, and reporting by conducting:
- Assured Compliance Assessment Solution (ACAS) scans
- Security Technical Implementation Guide (STIG) checks
- Port scanning
- Application code review
- Risk Management Framework (RMF) control review
- Plan of Action and Milestone (POAM) tracking
- Provide in-depth analysis on cybersecurity test results, remediation steps, and potential mitigating factors.
- Support the Information System Security Manager (ISSM) and Cybersecurity Lead in meeting all RMF documentation, process, policy, risk assessment, testing, and continuous monitoring requirements per the NIST SP-800 series.
- Provide RMF support for all future and/or new Assessment and Authorization (A-A).
- Maintain security reporting compliance requirements outlined in the System SLCM Strategy.
Requirements
- Must currently hold a DoD 8570-compliant IAT II certification (SSCP or Security+CE with appropriate CE/OS certificate) or be able to obtain within six months.
- CE/OS certificate may include Windows or Linux.
- Experience with eMASS, SSPs, POAMs, ACAS/Nessus, SCAP, Security Checklists, and STIG Viewer.
- Experience with Risk Management Framework (RMF) processes.
- Developed communication skills and the ability to express thoughts and ideas clearly and concisely.
- Capable of multitasking and working several complex and diverse tasks with simultaneous or near-simultaneous deadlines.
- Self-starter who is accountable and requires minimal direction and supervision.
- Open to new and innovative ideas.
- Team player willing to interface with clients and relay information back to the team.
- U.S. citizenship and ability to obtain a U.S. Government security clearance at the Secret level.
Desired Skills
- Experience in a RHEL environment.
- Experience with networking devices.
- Experience with DevSecOps.
- Experience with EvaluateSTIG and/or STIGManager.
- Experience with Virtual Machines (VMware, vSphere).
- Experience with Cisco products (Switches & Routers).
Benefits
- Medical, dental, and vision plans.
- 401(k) with a company match.
- Life insurance.
- Vacation and sick paid time off accruals, increasing based on role and years of service.
- 11 paid holidays.
- Tuition reimbursement.
Filling this position is contingent upon funding. Selected applicants will be subject to a government security investigation and must meet eligibility requirements for access to classified information.