Information Security Analyst Senior
General Dynamics Information Technology · Hawaii, United States · Yesterday
$94k–$113k/yrFull-time
About the role
Check out this great opportunity to join one of GDIT’s fastest long-standing growing programs!
Responsibilities
- Performs Cybersecurity activities (formally known as IA - Information Assurance) for a large Program;
- Collaborates with government Program staff, USAF, and other government agencies to assist in the creation, dissemination, direction, and auditing of program policy, standards, and operating procedures.
- Utilizes available resources to conduct Cybersecurity activities, and reports to senior GDIT and government personnel on overall program security posture.
- Conducts network and system audits for vulnerabilities using Security Technical Implementation Guides (STIGs), ACAS vulnerability scanner, and DISA SCAP to mitigate those findings for Linux, Windows, and associated network operating systems.
- Creates, tracks, and reviews Plan of Action and Milestones (POA&Ms) and conducts solution identification to assist in problem remediation and resolution.
- Communicates tactical and strategic threat information to Government leaders, Cybersecurity-Ops and A&A staff to assist them in making cyber risk decisions and to mitigate threats.
- Carries out DoW Risk Management Framework (RMF) in accordance with DoW 8510 to ascertain information systems' security posture by utilizing security control validation activities and coordinating security testing.
- Maintains the Security Authorization status, including system documentation of multiple DoW classified networks and interconnected systems.
- Collaborates with OUSDI, USAF, DISA, USN, and other organizations in support of audits and inspections and provides all necessary documentation as required for SAVs, ST&Es, and CCRI.
- Evaluates firewall change requests and assesses organizational risk.
- Performs Security Impact Analysis based on organizational requirements.
- Communicates alerts to agencies regarding intrusions and compromises to their network infrastructure, applications and operating systems.
- Affords assistance with implementation of counter-measures or mitigating controls.
- Ensures the integrity and protection of networks, systems, and applications by technical enforcement of organizational security policies, through monitoring of vulnerability scanning devices.
- Performs periodic and on-demand system audits and vulnerability assessments, including user accounts, application access, file system and integrity scans to determine compliance.
- Provides guidance and work leadership to less-experienced technical staff members.
- Maintains current knowledge of relevant technology as assigned.
- Participates in special projects as required.
Qualifications
- 5+ years of experience.
- BA/BS or the equivalent combination of education, technical training, or work/military experience.
- IAM Level II Certification (CISSP, CASP, CISM, GSLC, or CCIS).
- Must possess and maintain a Top Secret/SCI Security Clearance.
Preferred Qualifications
- The ability to lead and set priorities on multiple projects/tasks at once and operate in a dynamic, fast-paced team-oriented environment.
- Depending on job assignment, additional specific certifications may be required.