Senior Information Assurance / Cyber Analyst

Concept Plus
United States
3 months ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
5 years minimum
Working hours
Regular working hours
Job source

Tech stack

Agile Methodology Amazon Web Services Cyber Security Data Centers Multi-Factor Authentication Federal Information Processing Standards (FIPS) Identity and Access Management Information Security Management Security Software SonarQube Systems Architecture Tripwire
+8 more
SC Clearance Information Technology Nessus Checkmarx Devsecops Static Application Security Testing Vulnerability Analysis Dynamic Application Security Testing

Job description

Concept Plus is seeking a highly experienced Senior Information Assurance (IA) Cyber Analyst to join our team supporting a critical Air Force program. The program’s systems are deployed across classified and unclassified environments, hosted in both DISA data centers and the cloud.

The successful candidate will be responsible for supporting the government Information System Security Manager (ISSM) in maintaining the system’s cybersecurity posture in accordance with DoD and Air Force policies.

You will be responsible for preparing and maintaining the Risk Management Framework (RMF) package, conducting continuous monitoring, and working closely with technical teams to ensure security is integrated throughout the entire system’s lifecycle. This role is pivotal in supporting the system’s Authority to Operate (ATO) and ensuring robust security from development through production.

What you’ll do

  • Support the ISSM by preparing and maintaining the system’s RMF package throughout its lifecycle using the eMASS tool.
  • Develop, maintain, and update all required RMF documentation (SSP, SAR, POA&Ms, ISCM Plan, etc.).
  • Conduct continuous monitoring, analyze vulnerability scan results, and track the remediation of vulnerabilities by applying DISA STIGs and IAVM-directed patches.
  • Coordinate security engineering input into system designs and the implementation of security controls.
  • Analyze results from SAST/DAST security scans (e.g., SonarQube, Checkmarx) and collaborate with the development team on remediation.
  • Track and respond to cybersecurity incidents, ensuring timely reporting and effective recovery efforts.
  • Ensure compliance with security requirements such as two-factor authentication, data-at-rest encryption, and FIPS standards.
  • Document and report on cybersecurity performance, contributing to artifacts like the Software Cybersecurity Release Report
  • Act as a primary cybersecurity subject matter expert, providing guidance and support to the ISSM and program leadership.
  • Participating in Agile/DevSecOps development cycles, ensuring security is integrated from concept to deployment.
  • Review and validate system architecture, configuration changes, and release plans for security impacts.
  • Prepare for and participate in security assessments, audits, and inspections.
  • Liaise with external security stakeholders and accrediting authorities as directed.

Requirements

Do you have experience in Vulnerability scanning?, Do you have a Bachelor’s degree?, * US Citizenship Required

  • Ability to obtain and/or maintain a Secret Clearance
  • DoD 8140 intermediate certification or DoD 8570 IAM Level II certifications or higher
  • Bachelor’s degree in Cybersecurity, Information Technology, or a related field.
  • Must meet DoD 8140 (formerly 8570) IAM Level II certification requirements (e.g., CISSP, CISM, CASP+ CE).
  • 5-7 years of experience in Federal and DoD cybersecurity compliance.
  • Expert knowledge of DoD/Air Force cybersecurity mandates, including RMF, DISA STIGs, and the IAVM process.
  • Hands-on proficiency with cybersecurity tools such as eMASS, Nessus, SonarQube, and/or Checkmarx.
  • Strong understanding of NIST 800-53 security controls.

Preferred Qualifications

  • Experience in a U.S. Air Force program environment.
  • Knowledge of specific Air Force policies such as AFMAN 17-1301 and 17-1303.
  • Hands-on experience with additional security tools like Trivy or Dependency Track.
  • Experience securing systems in an AWS GovCloud environment.
  • Experience working in an Agile development environment.

Benefits & conditions

Pulled from the full job description

  • Tuition reimbursement
  • Paid time off
  • Vision insurance
  • Dental insurance
  • Life insurance
  • Paid holidays, We offer competitive pay, comprehensive health, dental, and vision insurance, paid life insurance, paid time off, 11 paid holidays, performance bonuses, tuition reimbursement, unlimited training, and the opportunity to thrive in a collaborative, flexible, and innovative environment.

About the company

Concept Plus is a mission-focused technology solutions provider that transforms IT concepts into impactful solutions for federal agencies. Headquartered in Fairfax, VA, we bring the agility, responsiveness, and customer intimacy of a small business combined with the quality and infrastructure of a larger firm.

Recognized as an award-winning Oracle partner, we have delivered innovative solutions across Defense, Intelligence, Civilian, Health IT, and Tribal sectors. Our highly certified experts build systems that drive efficiency, accelerate modernization, and ensure mission outcomes with certainty.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on indeed.com

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

1:15 min

Key lessons learned from implementing automated mobile DevSecOps

Moataz Nabil Moataz Nabil · LIVE

1:45 min

Transitioning from software development to security roles

Stefania Chaplin · WWC 2022

2:07 min

Integrating security practices for devsecops adoption

Nevelina Aleksandrova · LIVE

2:09 min

Shifting security left using the DevSecOps approach

Aarno Aukia · LIVE

2:07 min

Summarizing critical actions for organizational cybersecurity compliance readiness

Matthew Brady Matthew Brady · WWC Europe 2026

2:57 min

Securing sensitive defense infrastructure with dual-vendor cloud strategies

Boris Hecker Boris Hecker +3 · WWC 2025

Videos

See all

Related articles

See all