Cyber Security Analyst- ISSO

Scientific Research Corporation
North Charleston, SC, United States
about 1 month ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
5 years minimum
Working hours
Regular working hours
Job source

Tech stack

Xacta Microsoft Windows Antivirus Softwares Apache HTTP Server Apache Tomcat Unix Configuration Management Cyber Security Information Systems Linux Elasticsearch VMware ESX Servers
+17 more
Web Servers Network Topologies Internet Information Services (IIS) Networking Hardware WildFly (JBoss AS) PostgreSQL MariaDB Microsoft SQL Server MongoDB MySQL Nginx Red Hat Enterprise Linux Security Content Automation Protocol SQL Databases Data Streaming Nessus Splunk

Job description

  • Developing and updating assessment and authorization documentation (Body of Evidence) for management and continuous monitoring of information systems
  • Performing ongoing compliance assessments using tools, such as Assured Compliance Assessment Solution (ACAS), Secure Content Automation Protocol (SCAP), and Trellix Virus Scan Enterprise while reviewing, documenting, and maintaining all results
  • Verifying patches and virus definitions to the systems using existing automated tools
  • Adhering to pre-defined configuration management and change management policies and procedures for authorizing software prior to its implementation on systems
  • Performing security audits using to track multiple events including any signs of inappropriate or unusual activity, intrusion events, data transfers, etc.
  • Performing security assessments of NCS Family of Systems in accordance with NIST, Navy, NSA, and NAVINTEL IA guidance
  • Working with system engineers to take corrective action to resolve identified problems
  • Performing Site Based Security Assessments (SBSAs) of systems and recommending authorization to the Designated Authorizing Official (DAO) as a certified trusted agent
  • Reporting security incidents in accordance with the Command Incident Response Plan (CIRP)
  • Ensuring systems are operated, used, maintained, and disposed of in accordance with all applicable security policies and practices

Requirements

  • Must possess an active Top Secret/SCI clearance
  • 5-8 years of cybersecurity experience
  • Must currently hold a DoD 8140-compliant IAT II certification (Security+CE with appropriate CE/OS certificate), or be able to obtain within six months
  • CE/OS certificate may include Windows or Linux
  • Experience with System Security Plans (SSPs), POA-Ms, ACAS/Nessus, SCAP, and DISA STIGs
  • Experience with Risk Management Framework (RMF) processes
  • Have developed communication skills and the ability to express thoughts and ideas clearly and concisely
  • Must be a team player, dedicated to program support, capable of multitasking and working several complex and diverse tasks with simultaneous, or near simultaneous, deadlines
  • Be a self-starter who is accountable and requires minimal direction and supervision
  • Be open to new and innovative ideas
  • Must be able to be appointed ISSO for NCS systems within 6 months of employment

Desired Skills:

  • Extensive training or experience with Windows and UNIX based information systems standards with a working knowledge of networking devices
  • Knowledge of configuration of various SQL databases, including MS SQL, PostgreSQL, MongoDB, MariaDB, MySQL, and Elasticsearch
  • Knowledge of web servers, including Apache Web Server, Apache Tomcat, Red Hat JBOSS, nginx, and MS IIS
  • Knowledge of VMWare ESXi
  • Knowledge of data flows and the ability to work up readable network topology and data flow diagrams
  • Experience with NAVINTEL IA and NSA enterprise services: continuous monitoring
  • Experience with the following systems/platforms/tools: XACTA, XACTA 360 (preferred), eMASS, HBSS, ACAS, Nessus, and SPLUNK

Clearance Information: SRC IS A CONTRACTOR FOR THE U.S. GOVERNMENT, THIS POSITION WILL REQUIRE U.S. CITIZENSHIP AS WELL AS, A U.S. GOVERNMENT SECURITY CLEARANCE AT THE TOP SECRET / SCI LEVEL Travel Requirements:

  • Minimal travel maybe required 10%

Benefits & conditions

Pulled from the full job description

  • Tuition reimbursement
  • Health insurance
  • 401(k) matching
  • Paid time off
  • Vision insurance
  • Dental insurance
  • Life insurance, SRC offers a generous benefit package, including medical, dental, and vision plans, 401(k) with a company match, life insurance, vacation and sick paid time off accruals with amounts increasing based on role and years of service, 11 paid holidays, tuition reimbursement, and a work environment that encourages excellence and more. For positions requiring a security clearance, selected applicants will be subject to a government security investigation and must meet eligibility requirements for access to classified information.

About the company

Scientific Research Corporation is an advanced information technology and engineering company that provides innovative products and services to government and private industry, as well as independent institutions. At the core of our capabilities is a seasoned team of highly skilled engineers and scientists with multidisciplinary backgrounds. This team is challenged daily to provide cutting edge technology solutions to our clients.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.indeed.com

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

2:03 min

Microsoft integrating native Unix coreutils into Windows environments

Chris Heilmann +2 · LIVE

7:28 min

Constructing a new Docker layer from scratch

Oliver Seitz Oliver Seitz · WWC Europe 2026

4:01 min

Finding personal fulfillment in the cybersecurity industry

LIVE

2:04 min

Defining timestamps and the international standard format

Denny Biasiolli Denny Biasiolli · Europe 2026 Virtual

1:45 min

Transitioning from software development to security roles

Stefania Chaplin · WWC 2022

5:02 min

Manual port forwarding configuration using network address translation

Oliver Seitz Oliver Seitz · WWC 2025

Videos

See all

Related articles

See all