Cybersecurity Analyst II
XSITE LLC · San Diego, CA · 5 days ago
On-siteInformation TechnologyFull-time
Responsibilities
- Prepare, develop, and maintain Risk Management Framework artifacts, packages, and deliverables supporting system validation and Authorization to Operate activities
- Support Assessment and Authorization documentation planning, development, and maintenance
- Perform risk and vulnerability assessments across network, system, and application environments
- Cookordinate day-to-day cybersecurity activities with program technical leads to identify cyber risks, interpret applicable policies, and develop mitigation plans
- Maintain RMF documentation for system baseline variants that have achieved ATO
- Develop and deliver cybersecurity status updates and presentations to senior stakeholders
- Analyze expected system, mission, and workload impacts related to cybersecurity findings and control implementation
- Work independently to identify issues, develop solutions, communicate results, and lead client task execution from inception through completion
Requirements
- Minimum of 4 years of experience in cybersecurity, engineering, test and evaluation, Assessment and Authorization, or a related field
- Bachelor’s degree from an accredited university in a technical, engineering, cybersecurity, computer science, information technology, management, or related discipline
- Active TS/SCI clearance with no Foreign Exception
- Minimum of 4 years of experience working with information technology systems for a DoD or government agency
- Minimum of 3 years of experience leading Navy RMF projects, including A&A activities for systems up to the TS/SCI level
- Experience preparing, developing, and maintaining RMF artifacts, packages, and deliverables
- Experience implementing security controls and policies
- Experience performing cybersecurity compliance testing using industry-standard tools
- Experience performing vulnerability analysis and remediation for networks, systems, and communications protocols
- Experience using eMASS, including Security Plan development and hands-on package processing through workflows
- Experience assisting with security policy development, evaluating assessment documentation, and developing written security risks, mitigations, and recommendations
- Experience with operating systems, platforms, and technologies such as Windows, Linux, networking, virtualization, or containers
- Experience developing and maintaining system artifacts such as Boundary Diagrams and Data Flow Diagrams
- Strong verbal and written communication skills
- Ability to work independently, identify problems, develop analysis and solutions, and communicate results to technical and non-technical audiences
Qualifications
- DoD 8140 qualified, including relevant education, training, and certification; equivalent to former DoD 8570 IAT Level II at a minimum
- Experience with DoD Security Technical Implementation Guides and Evaluate-STIG
- Experience with cybersecurity tools such as ACAS
- Experience integrating security into DevSecOps pipelines
- Experience implementing automation methodologies and processes
- Experience deploying, implementing, maintaining, and integrating cybersecurity tools and applications aligned to the current threat landscape
- Experience analyzing cybersecurity risks and opportunities at tactical and strategic levels
- Experience with network engineering functions involving Windows, Linux, virtual operating systems, security tools, platforms, and technologies
- Experience with network and web application firewalls, web proxies, intrusion prevention systems, vulnerability scanners, and penetration testing tools
- Experience developing and maintaining cyber schedule, performance, and quality metrics within the systems development lifecycle or acquisition lifecycle
- Experience with Navy initiatives and PMW 160 systems, including CANES, PAS, ACS, or ADNS
- Master’s degree in engineering, computer science, cybersecurity, or an equivalent technical discipline
- Familiarity with OCF platforms