Cyber Security Analyst Level II
Quantum Sky · Warner Robins, GA · 3 wk ago
Information Technology$75k–$85k/yrFull-time
Quantum Sky is searching for a Cyber Security Analyst Level II to support the Air Force Reserve Command (AFRC) Information Technology (IT) Services on a complex, multi-year contract. This role will provide Cyber Security/CORA support and Subject Matter Expertise (SME) for both NIPR and SIPR networks for AFRC host bases.
Responsibilities
- Provide Subject Matter Expertise (SME) for process oversight in implementing/executing STIGS using automated and manual tools provided by DISA (e.g., Security Content Automation Protocol – SCAP).
- Train system administrators (SA) on STIG processes as needed.
- Track STIG compliance and quarterly updates for all servers and infrastructure devices; identify discrepancies to system administrators and A6 CORA Lead.
- Work with Communications Focal Point to obtain quarterly STIGS random sampling (minimum 10%) of physical and virtual workstations. Review checklists for compliance, report findings of incomplete STIGS, and set suspense dates for completion.
- Provide SME for process oversight in POAMs for Enterprise Mission Assurance Support Service (eMASS), DISPATCH, and STIGS for CORA.
- Manage POAM program for assigned base/location by working with SAs to ensure POAMs for all open findings from STIGS and vulnerability scans are created and updated every 30 calendar days until remediation is complete.
- Review and notify SAs, their immediate supervisors, and the A6 CORA Lead for any incomplete or non-submitted POAMs.
- Provide monthly status of open POAMs based on severity level (CAT I (Critical/High), CAT II (Medium), and CAT III (Low)).
- Provide SME on ESS reports; download and analyze weekly posted reports, including:
- Data Loss Prevention (DLP) Violations
- Enhanced Reports
- Outdated Product Report
- Rogues Subnet Coverage
- Notify the office of responsibility SA of open findings and suspense SAs to identify devices for exemption (e.g., printers, non-OS systems). Use designated template for list of exempted devices and submit to 561st Network Operations Squadron (NOS) Client Security via Remedy Ticket or designated ticketing system.
- Work with the office of responsibility to identify two systems within each populated subnet range to apply Rogue Sensor Detectors (RSD). Submit identified systems via designated ticketing system to 561 NOS Client Security.
- Monitor and download weekly reports for status on open findings.
- Serve as functional lead for cybersecurity applications used to manage/monitor cyber compliance status, configuration, and indicators of compromise.
- Provide the following additional support:
- Identify monthly summary of fix actions (punch list) required to meet CORA standards and guidelines.
- Integrate Command Cyber 365 Flight Plan guide with all required components.
- Report monthly on compliance status from assigned bases.
- Manage/report on implementation of policies established by Command Cyber Analysts.
- Manage 38 CORA/HSO reports for assigned bases or equivalent.
- Configure and tailor policies to address specific needs and intricacies of assigned bases.
- Develop Master Software List (MSL) for assigned base(s).
Requirements
- Recommend 3+ years of experience in cybersecurity or related fields.
- Knowledge of the limitations and capabilities of computer systems and technology; operational support of networks, operating systems, Internet technologies, databases, and security infrastructure.
- Familiarity with cybersecurity and information security controls, practices, procedures, and regulations.
- Understanding of incident response program practices and procedures.
- Bachelor’s degree in Information Technology, Cybersecurity, Computer Science, Data Science, or Software Engineering (typically required).
- DoD-approved certifications such as GCIH (GIAC Certified Incident Handler), CEH (Certified Ethical Hacker), Security+, PenTest+, or CySA+.
- Active DoD Secret level clearance.
- Minimal travel required (less than 10%).
Skills & Knowledge
- Proficiency in network security architecture and application vulnerabilities.
- Ability to conduct vulnerability scans and utilize penetration testing tools.
- Knowledge of network analysis tools and techniques.
Pay
The salary range for this position is typically between $75,000 and $85,000. Compensation is based on education, experience, certifications, and other requirements and may fall outside the stated range.
Benefits
- Health, dental, and vision insurance.
- 401(k) match.
- Paid Time Off (PTO).
- Short-Term Disability (STD), Long-Term Disability (LTD), and Life Insurance.
- Referral bonuses.
- Professional development reimbursement.
- Parental leave.