SonicJobs Logo
Left arrow iconBack to search

Senior Information Security Analyst

Wood River Federal
Posted 2 days ago, valid for a month
Location

Lackland AFB, TX, US

Salary

Competitive

Contract type

Full Time

By applying, a Sonicjobs account will be created for you. Sonicjobs's Privacy Policy and Terms & Conditions will apply.

SonicJobs' Terms & Conditions and Privacy Policy also apply.

Sonic Summary

info
  • The Senior Information Security Analyst is a seasoned cybersecurity professional tasked with safeguarding an organization's information systems' confidentiality, integrity, and availability.
  • This role requires a minimum of seven years of progressive experience in information security, with at least three years in a hands-on ISSO position managing the RMF/ATO process for DoD systems.
  • Key responsibilities include leading risk management efforts, conducting vulnerability assessments, and ensuring compliance with security policies and regulations.
  • Candidates must possess a current CompTIA Security+ CE certification and demonstrate expert knowledge of RMF and NIST standards, with advanced certifications being highly desirable.
  • The salary for this position is competitive, reflecting the level of expertise required and the critical nature of the role in maintaining cybersecurity.

Labor Category Description:


The Senior Information Security Analyst is a highly experienced cybersecurity professional
responsible for ensuring the confidentiality, integrity, and availability of an organization's
information systems. This role serves as a subject matter expert on all matters of operational
cybersecurity, leading efforts to secure systems, manage risks, and ensure compliance with all
governing policies and regulations. The Senior Analyst is responsible for implementing and
managing the security posture of assigned systems throughout their lifecycle, from initial
authorization to decommissioning. This individual works with system owners, administrators,
and users to enforce security controls, respond to threats, and maintain the formal Authority to
Operate (ATO).
Typical Task List:


Risk Management Framework (RMF) and Compliance:
- Lead the development, maintenance, and submission of all
documentation required to achieve and maintain the system's ATO
under the RMF process.
- Develop and maintain key security artifacts, including the System
Security Plan (SSP), Contingency Plan, and Incident Response Plan.
- Conduct periodic reviews of security controls to ensure ongoing
compliance and prepare the system for security assessments and
audits.


Vulnerability Management and Remediation:
- Perform regular vulnerability scanning of systems and networks using
approved tools (e.g., ACAS/Nessus).
- Analyze scan results, prioritize vulnerabilities based on severity and
mission impact, and coordinate with system administrators to ensure
timely remediation.
- Track and report on remediation progress, and develop Plans of Action
and Milestones (POA&Ms) for vulnerabilities that cannot be
immediately fixed.


Security Operations and Monitoring:
- Monitor security logs and alerts from various sources (e.g., SIEM,
firewalls, endpoint security tools) to identify, analyze, and respond to
suspicious activity.
- Serve as a key player in the security incident response process,
including identifying the source of a threat, containing the impact, and
leading eradication and recovery efforts.
- Conduct regular audits of user accounts and system access logs to
detect and report unauthorized activity.


Policy and Guidance:
- Develop, implement, and enforce information security policies,
procedures, and guidelines based on DoD, DAF, and NIST standards.
- Provide expert cybersecurity guidance and consultation to system
owners, developers, and administrators to ensure security is integrated
into all phases of the system lifecycle ("security by design").
- Promote security awareness by providing training and guidance to all
system users.


Minimum Qualifications / Requirements
Experience:
- A minimum of seven (7) years of progressive experience in an
information security, cybersecurity, or Information Assurance (IA)
role.
- At least three (3) years of direct, hands-on experience serving as an
Information Systems Security Officer (ISSO) or a similar role with
responsibility for managing the RMF/ATO process for DoD systems.

Certifications (Baseline):
- Must possess a current CompTIA Security+ CE certification (or
higher) to meet DoD 8140 requirements for IAT Level II.


Certifications (ISSO Environment - Desired):
- Advanced certifications demonstrating subject matter expertise are
highly desired, such as:
CASP+ CE
CISM (Certified Information Security Manager)


Security Clearance:
Must be eligible to obtain and hold a DoW security clearance


Technical Skills:
- Expert-level knowledge of the Risk Management Framework (RMF)
and NIST Special Publications (e.g., SP 800-53, SP 800-37).
- Proficiency with vulnerability scanning tools such as ACAS/Nessus.
- Strong understanding of network security, operating system hardening
(Windows/Linux), and application security principles.

- Experience with Security Information and Event Management (SIEM)
systems and other security monitoring tools.
- Familiarity with DoD Security Technical Implementation Guides
(STIGs) and the STIGing process.




Learn more about this Employer on their Career Site

Apply now in a few quick clicks

By applying, a Sonicjobs account will be created for you. Sonicjobs's Privacy Policy and Terms & Conditions will apply.

SonicJobs' Terms & Conditions and Privacy Policy also apply.