Senior Cyber Software Analyst
a.i. solutions · Huntsville, AL · 2 days ago
On-siteInformation Technology$119k–$144k/yrFull-time
About the role
a.i. solutions is seeking a highly-motivated Cyber Software Analyst to support the Reagan Test Site (RTS) Engineering and Technical Services (RETS) Program in Huntsville, AL.
Essential Functions
- Perform technical engineering support and research in the area of Software Assurance to include the analysis of software source code and binary executable files.
- Perform senior cyber assurance analyst tasks in support of the RTS Government ISSM, Cyber Assurance staff and other senior management in areas of National Institute of Standards and Technology (NIST) Risk Management Framework (RMF), DoD, Army Regulations, Incident Response, Risk Assessment, Software Assurance and related Cyber Assurance disciplines.
- Provide detailed reports of identified issues and work with customer cybersecurity office and software development personnel to analyze and identify mitigations.
- Conduct research on emerging software assurance tools and provide detailed reports on tool capabilities and applicability to the client's software assurance requirements as needed.
- Examine potential security violations to determine if policy has been breached and respond in accordance with the Incident Response Plan.
- Support, monitor, test and troubleshoot hardware and software Cyber Assurance problems pertaining to the network environment.
- Cyber Assurance training and workshops, vulnerability scanning as required by the risk assessment process, incident detection and response, and other configuration management functions in support of RTS.
Required Skills
- Proficiency in tools such as Fortify, Checkmarx, or SonarQube to analyze source code for "CWEs" (Common Weakness Enumerations).
- Adept at performing Vulnerability Research and tracking the CVE database to ensure no outdated components are being used in RTS systems.
- Able to draft and manage standard operation procedures (SOPS).
- Demonstrated understanding of the NIST SP 800-53 and 800-161 controls required for federal information systems.
- Understanding RMF and how Software Assurance feeds into the larger ATO process.
- Strong Ability to validate and verify SW STIGs.
- Exceptional ability to perform risk assessments, analyze technical vulnerabilities, and explain their potential impacts to the RTS mission systems.
- Skilled at analyzing false positives and associated mitigations to weed out "noise" so the developers can focus on the real threats / true positives.
Required Experience
- Bachelor’s Degree in Computer Science, Cybersecurity, or a related field; or an equivalent combination of education and experience.
- Ten (10) years or more of relevant experience including: Three (3) or more years in specialized Cybersecurity/Software Assurance.
- Mastery of SAST/DAST/SCA tools (e.g., Fortify, Checkmarx, SonarQube, or Snyk) and the ability to tune them to reduce false positives.
- Thorough understanding of NIST SP 800-53/800-161 and how SwA artifacts support the RMF/ATO process.
- Must meet DoD 8140.03 IAM/IAT Level II or III requirements (e.g., Security+, CISSP, or CSSLP).
- CISSP preferred.
- Exceptional ability to communicate security risks and remediation strategies to both developers and non-technical mission stakeholders.
Additional Eligibility Qualifications
- Must be able to obtain and maintain a DoD Secret Security Clearance with the ability to obtain a Top Secret, which requires U.S. citizenship.
- The flexibility to work occasional non-duty hours or on weekends to support specific projects or mission requirements.
Benefits
- Salary ranges from $119,000 to $144,000 depending on relevant experience and qualifications.
- View Our Benefits Offerings
- Paid Time Off and Holidays
- 401k Safe Harbor Plan, we contribute on Day #1
- Company Paid Life/AD&DTuition Assistance
- Wellness plans that reward wellbeing & work life harmony
- Equal Opportunity Employer/Protected Veterans/Individuals with Disabilities