Cybersecurity Analyst / ISSO

Lever, Inc.
Stafford, VA, United States
about 2 months ago
Apply on jobs.lever.co
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Experienced
Experience required
4 years minimum
Working hours
Regular working hours
Job source

Tech stack

Microsoft Windows Artificial Intelligence Cisco PIX Cisco IOS Cyber Security Identity and Access Management Network Security Machine Learning Red Hat Enterprise Linux Zero Trust Network Access Systems Architecture Speech Recognition
+5 more
SC Clearance Cyber Warfare Scap Compliance Checker Data Pipelines Plan of Action and Milestones

Job description

This role requires a strategic understanding of how emerging technologies (like A.I.) and high-level USMC Cyber Directives impact the acquisition lifecycle and overall enterprise risk posture.

What Your Day-To-Day Looks Like (Position Responsibilities):

Leading cybersecurity risk management efforts across enterprise systems by assessing AI and machine learning capabilities, overseeing RMF authorization activities, managing POA&M remediation strategies, and ensuring compliance with DoD cybersecurity directives and NIST standards. Responsibilities include evaluating system architectures through a zero-trust lens, interpreting and implementing Cyber Tasking Orders, validating security controls and STIG compliance, developing cybersecurity policies and continuous monitoring strategies, and providing technical leadership to maintain secure, mission-ready environments.

Requirements

  • A.I. Risk & Architecture: Experience assessing the risk of Artificial Intelligence (A.I.) and Machine Learning (ML) capabilities, including familiarity with emerging DoD A.I. security guidelines, data pipeline security, and assessing A.I. toolsets within the authorization boundary.
  • DoD/ DoW Cyber Directives: Proven capability to interpret, analyze, and direct programmatic responses to MFCC (Marine Forces Cyber Command) and DCDC (Department of Defense Cyber Defense Command) TaskOrds, Cyber Tasking Orders (CTOs), and other organizational directives, policies, and messages governing cyber / IT.
  • Strategic POA&M Management: Expert-level creation, management, and strategic burn-down of complex Plan of Action and Milestones (POA&Ms) across multiple enterprise systems, ensuring alignment with USMC continuous monitoring timelines / requirements.
  • CND Oversight: Advanced understanding of Computer Network Defense (CND) architectures, including zero-trust principles, network boundary defense, and threat intelligence integration.
  • RMF Leadership: Deep expertise navigating eMASS and leading systems through the complete Risk Management Framework (RMF) Assess and Authorize (A&A) lifecycles and workflows.
  • Deep understanding of NIST SP 800-53 security controls, CNSSI 1253, NIST SP 800-161 & NIST SP 800-162, and DoDI 8510.01.
  • Experience drafting organizational cybersecurity policies, Incident Response Plans, and Continuous Monitoring Strategies.
  • Advanced proficiency using the DISA STIG Viewer, executing SCAP Compliance Checker (SCC), using eMASSter, and manually validating STIG/SRG requirements on diverse operating systems (Windows, Red Hat Linux, Cisco IOS, Cisco ASA).
  • Expert level understanding of applying zero-trust methodologies to system design and tracking implementation throughout the system life-cycle., * Experience Level: 4-8 years of progressive experience in DoD cybersecurity, information assurance, or Computer Network Defense (CND).
  • Security Clearance: Active Secret clearance
  • DoD 8140/8570.01-M Baseline Certification: IAM Level II or III (e.g., CISSP, CISM, CAP/CGRC) AND highly recommended to hold a CSSP Auditor/Manager baseline.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on jobs.lever.co
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

1:45 min

Transitioning from software development to security roles

Stefania Chaplin · World Congress 2022

2:58 min

Adapting the STRIDE threat model for MCP deployments

Jose Manuel Ortega Jose Manuel Ortega · Europe 2026 Virtual

3:22 min

Transitioning from software engineering to security roles

Anna Oliveira · Coffee With Developers

Videos

See all

Related articles

See all