Senior Cybersecurity Analyst
About the role
OCH Technologies is seeking a Senior Cybersecurity Analyst to execute independent risk assessments and vulnerability assessments at FAA facilities. The position is contingent upon award, customer approval, and successful onboarding requirements.
Responsibilities
- Execute independent risk assessments on NAS and Mission Support systems using the three NIST 800-53A assessment methods (Examine, Interview, Test).
- Lead on-site assessment events at FAA facilities nationwide.
- Cook with facility personnel, system owners, and ACG to execute assessments on schedule.
- Conduct vulnerability scanning using tools including Nessus, WebInspect, AppDetective Pro, nMap, and other FAA-approved tools.
- Develop System Security Assessment Reports (SARs) documenting findings, risk levels, and recommended mitigations.
- Develop draft Plans of Action and Milestones (POAMs) with clear, actionable remediation steps.
- Perform regression assessments to validate that previously identified vulnerabilities have been remediated.
- Collect and analyze system configuration files, security documentation, and other artifacts required for assessment.
- Conduct interviews with system administrators, system owners, and other personnel as part of the assessment methodology.
- Support the Security Assessment Lead in maintaining the Integrated Master Test Schedule and coordinating resource assignments.
- Maintain proficiency with current assessment tools and techniques.
- Participate in cross-training during periods between scheduled assessments.
Requirements
- Minimum Qualifications: Bachelor's degree in Cybersecurity, Computer Science, Information Technology, Engineering, Mathematics, or Physics from an accredited institution; 8+ years of hands-on experience conducting security assessments or vulnerability assessments in federal or critical infrastructure environments; at least 2 years of relevant experience must be recent; working knowledge of NIST SP 800-53, NIST SP 800-53A, NIST SP 800-37 (RMF), and FIPS-199; proficiency with vulnerability scanning tools (Nessus, WebInspect, nMap, or equivalents); experience developing SARs, POAMs, or equivalent assessment documentation.
- Security Clearance Requirement: Candidate must have the ability to obtain and maintain a Public Trust certification.
- Preferred Qualifications: Prior experience assessing NAS systems or working at FAA facilities; experience with CIS Benchmarks and automated compliance scanning; experience assessing cloud environments (FedRAMP, AWS GovCloud, Azure Government); familiarity with operational technology (OT) or industrial control system (ICS) security; cloud security posture tools (Prowler, ScoutSuite) for assessing AWS GovCloud and Azure Government environments; OpenSCAP or SCAP Compliance Checker for automated compliance validation against CIS Benchmarks and NIST baselines; Elastic/ELK or Splunk for log-based assessment analysis and continuous monitoring data review; AI-assisted documentation analysis tools for accelerating NIST 800-53 control gap identification across system security plans and configuration artifacts.
Skills
- Ability and willingness to lead test events on-site independently, not just participate as a team member.
- Strong interpersonal skills for conducting interviews and coordinating with FAA facility personnel who have competing operational priorities.
- Ability to work in lab and operational environments with appropriate care for safety-critical systems.
Benefits
At OCH, we offer a comprehensive benefits package designed to support your wellbeing and work-life balance, including:
- Paid time off and Holidays
- Medical, Dental, and Vision Insurance
- Paid Parental Leave
- Short-term disability, long-term disability, and life insurance - Employer Paid!
- 401(k)
- Additional Voluntary Life Insurance
- Tuition Reimbursement & More!
About Us
At OCH, we are more than just a government contracting firm; we are innovators and leaders in providing cutting-edge IT services and cybersecurity solutions. Driven by a set of fundamental values, we excel in creating secure, efficient, and forward-thinking solutions that empower the government agencies we work with. Our commitment to maintaining the highest standards of integrity, adapting swiftly to new challenges, and focusing on the people we serve ensures that we consistently exceed expectations and lead the industry in innovation and reliability.
Why Join Us?
Join a team that values creativity and initiative, offering a platform to transform the landscape of government IT services. Here, your work is not just a career—it's a mission. Embrace the opportunity to grow, innovate, and excel alongside industry leaders who are as passionate about technology as they are about making a difference. Plus, we offer a comprehensive benefits package designed to support your wellbeing and work-life balance, including:
- Paid time off and Holidays
- Medical, Dental, and Vision Insurance
- Paid Parental Leave
- Short-term disability, long-term disability, and life insurance - Employer Paid!
- 401(k)
- Additional Voluntary Life Insurance
- Tuition Reimbursement & More!