Jobs · Information Technology · Colorado

Cybersecurity Analyst / Information Systems Security Officer (ISSO)

KBR Careers · Colorado Springs, CO · 1 wk ago
Information Technology$90k–$105k/yrFull-time

About the role

KBR is seeking a Cybersecurity Analyst / Information Systems Security Officer (ISSO) to join our team at Peterson SFB in Colorado Springs, CO. An active TS/SCI clearance is required.

Responsibilities

  • Perform activities to convert accreditation packages from DoDRMF Rev. 4 to Rev. 5
  • Compile and track vulnerabilities and mitigation results in quantifying program effectiveness, creating and maintaining vulnerability management policies, procedures and training
  • Apply security policies to meet security objectives of the system
  • Apply updates, patches, and security technical implementation while maintaining control system performance and availability requirements
  • Establish and maintain security configuration baseline for the control system(s), including IT components, interconnections, and interfaces
  • Implement Risk Management Framework (RMF) Assessment requirements for control systems, and document/maintain records for them
  • Maintain knowledge of the function and security of control system and IT technologies with which the control systems interface
  • Support risk assessments by reviewing and documenting the implementation status of security requirements of control systems
  • Mitigate/correct security deficiencies identified during security/certification testing and/or recommend risk acceptance for the appropriate senior leader or authorized representative
  • Provide input to the Risk Management Framework process activities and related documentation (e.g., system life-cycle support plans, concept of operations, operational procedures, and maintenance training materials)
  • Reviewing and defining requirements for information security solutions, controls compliance and policy development
  • Organizing network-based scans to identify possible network security attacks and host-based scans to identify vulnerabilities in workstations, servers and other network hosts determining critical security flaws and figuring out how to fix them
  • Conduct audits and assessments focused on uncover vulnerabilities in the networks through scanning tools
  • Assist in improving and automating existing vulnerability management lifecycle including but not limited to data ingestion & normalization, compliance metrics and detections on assets
  • Assist in partnering with tools and technology teams to troubleshoot, develop, select, implement, and automate appropriate security solutions to keep system data protected from internal and external threats
  • Assist in providing support and resolution for scanning and vulnerability remediation reporting issues
  • Avoidance of known vulnerabilities and system compliance
  • Stay current with vulnerability information across all the products in the AVAC environment
  • Work as part of an integrated team to develop and maintain RMF body of evidence documentation using Enterprise Mission Assurance Support Service (eMASS), XACTA or equivalent products
  • Develop and execute security control assessment procedures to verify conformance with control requirements as part of ongoing continuous monitoring and authorization assessment activities
  • Ensure all security-related vulnerabilities and deficiencies are documented in the Plan of Action and Milestones (POA&M) for each system
  • Maintain repositories of all body of evidence documentation for systems under your purview
  • Advise ISSM of compliance issues, findings and status related to the system packages

Requirements

  • Active TS/SCI clearance required
  • DoD Directive (DoDD) 8140.01 certification, Security+
  • 2+ years of related experience
  • Working knowledge of DoDRMF Rev.4 and/or 5, cyber technologies, NIST standards and DISA STIG governance
  • Experience in the Agile Lifecycle to include, requirements, design, development, implementation, deployment and remediation
  • Excellent technical document preparation and verbal communication skills are required
  • Strong working knowledge of Confidentiality, Integrity, and Availability (CIA) concepts such as patch management, multi-factor authentication, host-based security, intrusion detection, security event management and defense-in-depth
  • Strong analytical skills for known vulnerabilities and system compliance
  • Effective interpersonal skills are required with a demonstrated ability to support complex organizational relationships

Qualifications

  • Bachelor’s Degree (IT or Cybersecurity related) or equivalent related experience
  • GSEC, SCNP, SSCP, CISSP or higher
  • Experience with RMF controls, eMASS or XACTA, risk assessment, Plan of Actions and Milestones (POAMs), policy and plans documentation, Information Assurance Vulnerability Management (IAVM) and vulnerability assessment for mission systems

Skills

  • Strong analytical skills for known vulnerabilities and system compliance
  • Effective interpersonal skills are required with a demonstrated ability to support complex organizational relationships

Benefits

KBR offers a selection of competitive lifestyle benefits which could include 401K plan with company match, medical, dental, vision, life insurance, AD&D, flexible spending account, disability, paid time off, or flexible work schedule. We support career advancement through professional training and development.

Pay

The offered rate will be based on the selected candidate’s knowledge, skills, abilities and/or experience and in consideration of internal parity. Other Compensation KBR may offer bonuses, commissions, or other forms of compensation to certain job titles or levels, per internal policy or contractual designation.

Schedule

Standard Compensation For Colorado only, the salary range for this position is approximately $90,000 - $105,000. The offered rate will be based on the selected candidate’s knowledge, skills, abilities and/or experience and in consideration of internal parity.

Similar jobs