Cybersecurity Information Security Assessor
GDIT is seeking a Cybersecurity Information Assurance (IA)/Security Assessor to provide support on our Defense Enterprise Office Solution (DEOS) Cloud Service Offering contract. This position is a combination of remote (20%) and hybrid onsite (80%) support at either Chantilly, VA or Fort Meade, MD. US citizenship is required.
About the role
Provide cybersecurity support and guidance for overall confidentiality, availability, and integrity of capabilities in Microsoft (MS) Azure environments. This role works closely with the Cybersecurity Lead, as well as other areas supporting the customer (e.g., Threat Hunting, Engineering, Operations) and represents the customer in various briefings and meetings with senior leadership.
Responsibilities
- Participate in risk assessment during the Accreditation and Authorization process.
- Design, develop, test, implement, and integrate IA architecture, system, or system components.
- Participate in information systems (IS) risk assessments and design security countermeasures to mitigate identified risks.
- Ensure the architecture and design of Department of War (DoW) IS are functional and secure.
- Design and develop IA or IA-enabled products, interface specifications, and approaches to secure the environment.
- Utilize experience and judgment to plan and accomplish the organization's security-related goals.
- Support system or network designs that encompass multiple boundaries, including those with differing data protection/classification requirements.
- Report IA issues with separate reporting to senior management for network operational requirements.
- Provide support services for protecting the Department of Defense Information Network (DoDIN) from cyber threats using cybersecurity systems, Techniques, Tactics, and Procedures (TTP), and information sharing with DoW, Department of Homeland Security (DHS), and other federal agencies.
- Support cyber threat hunt initiatives to search for signs of malicious activities or security vulnerabilities within an organization’s network and/or digital infrastructure.
- Support cybersecurity operations, including incident detection, triage, and response.
- Analyze logs, network traffic, and endpoint telemetry to identify suspicious activity.
- Conduct thorough investigations of security incidents and provide high-quality reports on findings and mitigation strategies.
Requirements
- Bachelor’s Degree.
- Current 8570 IAT Level II certification (Security+ CE, CCNA Security, CySA+, GICSP, GSEC, or SSCP).
- Active Top Secret security clearance with ability to obtain SCI.
- 5+ years of related experience.
- 3+ years’ experience supporting MS Azure in a large-scale environment.
- Expert knowledge of commonly used cybersecurity systems, including DoW Host Based Security System (HBSS), Assured Compliance Assessment Solution (ACAS), Continuous Monitoring and Risk Scoring (CMRS), Joint Incident Management System (JIMS), and Enterprise Mission Assurance Support Service (eMASS).
- Experience in cybersecurity program policies and implementation for DoW Impact Level 6 (IL6) and Impact Level 7 (IL7).
- Expert knowledge implementing heightened security controls for sensitive systems (e.g., Access Control [AC], Physical and Environmental Protection [PE], IA, Audit and Accountability [AU], and Personal Security [PS]).
- Experience in Cyber Network Defense (CND).
Skills
- Cyber Defense
- Cybersecurity Operations
- Information Assurance
- Information Systems
- Network Defense
Desired Qualifications
- IAT Level III certification (CISSP, CASP CE, CCNP, CISA).
- Experience with Azure Sentinel, Lighthouse, and Defender Advanced Threat Protection (ATP).
- Hands-on experience with MS Sentinel (Azure Sentinel), including:
- Creating, tuning, and maintaining analytics rules, workbooks, and dashboards.
- Writing advanced Kusto Query Language (KQL) queries for detection, threat hunting, and reporting.
- Building and maintaining playbooks/automation (e.g., Logic Apps) to orchestrate response.
- Integrating Sentinel with diverse data sources (on-prem, cloud, and third-party security tools).
- Hands-on threat hunting experience, including:
- Conducting proactive, hypothesis-driven threat hunts across endpoints, networks, cloud, and identity.
- Using threat intelligence and MITRE ATT&CK to guide hunting and improve detection coverage.
- Analyzing logs, network traffic, and endpoint telemetry to identify and investigate suspicious activity.
- Experience with commercial cloud services (e.g., Amazon Web Services [AWS], Azure, Google Cloud Platform [GCP]).
- Experience with Agile software development.
- Ability to thrive in a highly collaborative, fast-paced, growth-focused environment.
- Provide guidance and direction to other professionals, acting in a consulting and/or advisory capacity.
- Coordinate resolution of highly complex problems and tasks, with the ability to meet and operate under deadlines.
Benefits
- Comprehensive medical, dental, and vision plan options, some with Health Savings Accounts.
- 401(k) plan with company match (pre- and post-tax contributions up to IRS annual limits).
- Paid time off, including vacation, sick, personal time, holidays, parental leave, military leave, bereavement, and jury duty.
- Short- and long-term disability benefits, life insurance, accidental death and dismemberment, personal accident, critical illness, and business travel and accident insurance.
- AI-powered career tool for identifying career steps and learning opportunities.
- Internal mobility team focused on career growth support.
Pay
The likely salary range for this position is $127,500 - $172,500, based on experience, geographic location, and contractual requirements.
Schedule
- Scheduled weekly hours: 40
- Travel required: Less than 10%
- Telecommuting options: Hybrid (20% remote, 80% onsite)
- Work locations: USA VA Chantilly or USA MD Fort Meade