Cyber Security Analyst 4

Keaki Technologies
Kauai County, HI, United States
26 days ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
5 years minimum
Working hours
Regular working hours

Tech stack

Cyber Security Information Systems Identity and Access Management Information Security Management Security Software Security Information and Event Management Privacy Controls SC Clearance Information Technology National Industrial Security Program Operating Manual (NISPOM)

Job description

We are seeking a skilled and detail-oriented Information System Security Officer (ISSO) to support the execution of cybersecurity and risk management activities in accordance with DoD and federal standards. The ISSO will be responsible for implementing the DoDI 8510.01 Risk Management Framework (RMF), supporting Assessment and Authorization (A&A) processes, and ensuring the security posture of information systems., * Execute the DoDI 8510.01 Risk Management Framework (RMF) for DoD Information Systems and assist in implementing DoD Assessment and Authorization (A&A) procedures. Support Assessment & Authorization (A&A) activities in alignment with NIST SP 800-37 and 800-53.

  • Manage and respond to security events and incidents, including triage, remediation, documentation, escalation, and after-action reporting.
  • Participate in cybersecurity-related meetings such as Cyber Security Working Groups, system ATO discussions, and IT/Cyber status updates.
  • Assist in the development and maintenance of comprehensive cybersecurity programs to protect organizational data, systems, and networks.
  • Perform activities related to NIST RMF A&A processes and ensure compliance with policies governing classified and unclassified information systems.
  • Ensure adherence to 32 CFR Part 117 (NISPOM), NIST SP 800-37, and DoDI 8510.01 standards.
  • Provide mentorship and training to employees on cybersecurity concepts, policies, and best practices.
  • Serve as a liaison with government points of contact (POCs) in a mid-level ISSO capacity.
  • Perform other duties and responsibilities as assigned.

Office conditions are varied and includes physical tasks including lifting, pushing or pulling up to 10 pounds. Physical positions will include but not be limited to walking, sitting or standing for extended periods of time, crawling, kneeling, stooping or cramped working places and work requiring repeated or frequent climbing. Environment will include customer contact, extended workdays, an office laboratory environment.

Requirements

This role demands a seasoned cybersecurity professional with deep knowledge of federal security standards, hands-on experience in incident response, and the ability to mentor and guide others in best practices. The analyst will contribute to strategic cybersecurity initiatives, support system accreditation efforts, and ensure continuous monitoring and compliance across both classified and unclassified environments, * Bachelor’s degree in Computer Science or related discipline (Master’s degree preferred)

  • Relevant experience may be substituted for a bachelor’s degree
  • DoD 8570/8140: IAM II, * Ten (10) years of cybersecurity experience, with a strong background in information assurance and system security.
  • Five (5) years of RMF experience, including:
  • Hands-on experience with DoD Authorization to Operate (ATO) compliance and certification processes.
  • Proficiency in creating and modifying RMF packages and artifacts throughout the acquisition lifecycle.
  • Ability to review and generate security documentation such as System Security Plans, POA&Ms, and Security CONOPs.
  • Experience preparing and implementing accreditation and certification requirements, including FISMA and COOP documentation.
  • Experience assisting Information System Owners (ISOs) with system registration, FISMA data calls, RMF documentation, and coordination with Certifying and Designated Approval Authorities.
  • Experience with cybersecurity tools and platforms such as SIEM, ACAS, Trellix (ESS), eMASS, and STIGs.
  • Ability to review threat and vulnerability assessments and analyze risks to information systems and networks.
  • In-depth knowledge of current Government Information Assurance and Cybersecurity policies, regulations, and standards.
  • Strong understanding of NIST SP 800-53 security and privacy controls and their application within RMF processes.

REQUIRED CITIZENSHIP AND CLEARANCE:

  • Must be a U.S. Citizen
  • Secret security clearance is required. (Applicants selected either must currently possess a Secret clearance or will be subject to a government security investigation and must meet eligibility requirements to obtain clearance prior to commencement of employment and maintain a security clearance for access to classified information or Closed/Restricted Areas throughout duration of employment.)

Benefits & conditions

Bering-Alaka`ina Holdings, LLC is a fast-growing government service provider. Employees enjoy competitive salaries. Eligible employees enjoy a 401K plan with company match; medical, dental, disability, and life insurance coverage; tuition reimbursement; paid time off; and 11 paid holidays.

About the company

Bering-Alakaina Holdings, LLC is comprised of industry-recognized government service firms designated as Alaska Native Corporation (ACN)-owned and 8(a) certified businesses and includes Keaki Technologies, LLC; Laulima Government Solutions, LLC; Kūpono Government Services, LLC; Kapili Services, LLC; Po`okela Solutions, LLC; Kīkaha Solutions, LLC; and Pololei Solutions, LLC.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.clearancejobs.com

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

1:45 min

Transitioning from software development to security roles

Stefania Chaplin · WWC 2022

1:13 min

Requirements and licensing plans for GitHub Copilot

lgonta lgonta +1 · WWC 2024

4:11 min

Introduction to cloud-native application developer security

Micah Silverman · WWC 2022

4:01 min

Finding personal fulfillment in the cybersecurity industry

LIVE

1:45 min

Transitioning from API consumers to on-device AI builders

Sasha Denisov Sasha Denisov · WWC Europe 2026

3:44 min

Current industry adoption and future security initiatives

Alexander Allmendinger · LIVE

Videos

See all

Related articles

See all