Cybersecurity Analyst - ISSM- Tinker AFB, OK

Serco
Lawton, OK, United States
5 days ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
10 years minimum
Working hours
Regular working hours
Job source

Tech stack

Microsoft Windows Agile Methodology Confluence JIRA Microsoft Azure Configuration Management Cyber Security Information Systems Data Transmissions Linux Identity and Access Management Information Security Management
+19 more
Linux System Administration Platform as a Service (PAAS) Scrum Methodology Software Maintenance Ansible SAP (Applications) Security Content Automation Protocol Data Processing Cloud Platform System Infrastructure as Code (IaC) Containerization Kubernetes Atlassian Tools Bicep Patch Management Bitbucket Hardware Infrastructure Terraform Plan of Action and Milestones

Job description

Serco is seeking an Cybersecurity Analyst / Information System Security Manager (ISSM) supporting the 76th Software Maintenance Group at Tinker AFB, OK. The ISSM will serve as the senior security authority and Cybersecurity SME for assigned information systems, ensuring compliance with DoD Cybersecurity requirements, managing system ATO, and guiding technical teams in the protection of classified environments.

In this role, you will:

  • Lead the implementation, management, and enforcement of DoD, Air Force, and NIST Cybersecurity policies.
  • Responsible for updating all documentation from NIST 800-53 r4 to NIST 800-53 r5
  • Serve as the primary authority for RMF lifecycle activities including categorization, control selection, validation, continuous monitoring, and ATO package submission.
  • Manage and maintain system security documentation including SSPs, SCTMs, POA&Ms, Incident Response Plans, and Contingency Plans within eMASS.
  • Conduct cybersecurity inspections, audits, and compliance reviews.
  • Provide expert guidance to system owners, administrators, and engineers.
  • Oversee vulnerability and patch management activities including ACAS scans, system alerts, and patch mitigations.
  • Work with Configuration Management to help direct change processes and security impact analyses.
  • Monitor security posture across hybrid Windows and Linux environments.
  • Ensure continuity with incident response, backup and recovery response.
  • Team player Provide technical cybersecurity mentorship to team members
  • Act as the primary Cybersecurity liaison to government stakeholders and leadership.
  • Provide oversight and direction to administrators, engineers, and technicians.
  • Present system status, vulnerabilities, and POA&M progress.

Requirements

  • An active DoD Top Secret security clearance with SCI eligibility.
  • SAP/SAR eligibilty.
  • A Bachelor’s degree and 8 years of Cybersecurity experience (or equivalent).
  • OR an Associate’s degree and 10 years of Cybersecurity experience.
  • DoD 8570 IAM Level III certification (CISSP, CISM, GSLC, etc.) or DoD 8140 Cybersecurity ISSM - Intermediate qualifications
  • Active CAPM certification or obtain within 12 months of hire
  • RMF ATO Process experience.
  • Experience in mixed Windows/Linux enterprise environments.
  • The ability to travel up to 10%.

Additional desired experience and skills:

  • ISSM/ISSO experience with PaaS or shared-service offering.
  • Hands-on experience securing cloud environments such as Microsoft Azure commercial and/or Azure Gov.
  • Experience authorizing hybrid architectures spanning commercial and/or gov cloud and on-premises infrastructure, including boundary definition and interconnection documentation for hybrid systems.
  • Working knowledge of container platforms such as Kubernetes, and container image hardening, scanning, and registry governance.
  • Experience applying RMF to CI/CD pipelines, including control assessment of pipeline components, build integrity, artifact provenance, and automated gate enforcement.
  • Familiarity with Infrastructure as Code (IaC) and Configuration as Code (CaC), such as Terraform, ARM/Bicep, and Ansible, including how IaC affects configuration management, baseline drift, and change control under an existing authorization.
  • Understanding of how to sustain an authorization boundary under Continuous Integration and Continuous Delivery (CI/CD), including control inheritance, security impact analysis at deployment velocity, and evidence generation as a pipeline artifact rather than a manual collection effort.
  • Experience supporting systems operating at multiple classification levels, including management of separate authorization boundaries and data handling requirements across levels.
  • Familiarity with Cross Domain Solutions (CDS), NCDSMO, and data transfer flow validation.
  • Hands-on experience operating and managing ACAS/Tenable, including scan configuration, credentialed scanning, and false-positive adjudication.
  • Practical experience with SCAP/STIG workflow to include benchmark selection, STIG Viewer/Evaluate-STIG checklist production, and translating findings into POA&M entries.
  • Proficiency in eMASS, including package build, control response authoring, artifact management and workflow submission.
  • Experience with supply chain risk management (SCRM) as applied to software dependencies, third-party libraries, and container base images (SBOM familiarity ideal).
  • Working knowledge of ITAR/export control requirements and their impact on personnel access, data residency, and administrative access to cloud environments
  • Proficiency with Atlassian Suite toolset (Jira, Confluence, Bitbucket).
  • Familiarity with Agile development methodologies (Scrum, Kanban, etc..), including experience decomposing security and compliance requirements into user stories, participating in sprint events, and embedding security acceptance criteria into defined task completions.

Benefits & conditions

Serco is an equal opportunity employer. We evaluate qualified applicants without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability, veteran status, and other legally protected characteristics.

Pay Transparency

Our Total Rewards package includes competitive pay, performance-based incentives, and benefits that promote well-being and work-life balance-so you can thrive both professionally and personally. Eligible employees also gain access to a wide range of benefits from comprehensive health coverage and health savings accounts to retirement plans, life and disability insurance, and time-off programs that support work-life balance. Program availability may vary based on factors such as contract type, location, hire date, and applicable collective bargaining agreements.

Salary range: The range for this position can be found at the top of this posting. This range is provided as a general guideline and represents a good faith estimate across all experience levels. Actual base salary will be determined by a variety of factors, including but not limited to, the scope of the role, relevant experience, job-related knowledge, education and training, key skills, and geographic market considerations. For roles available in multiple states, the range may vary to reflect differences in local labor markets. In addition to base salary, eligible positions may include other forms of compensation such as annual bonuses or long-term incentive opportunities. Benefits - Comprehensible benefits for full-time employees (part-time employees receive a limited package tailored to their role):

  • Medical, dental, and vision insurance
  • Robust vacation and sick leave benefits, and flexible work arrangements where permitted by role or contract
  • 401(k) plan that includes employer matching funds
  • Tuition reimbursement program
  • Life insurance and disability coverage
  • Optional coverages that can be purchased, including pet insurance, home and auto insurance, additional life and accident insurance, critical illness insurance, group legal, ID theft protection
  • Birth, adoption, parental leave benefits
  • Employee Assistance Plan

About the company

Serco Inc. (Serco) is the Americas division of Serco Group, plc. In North America, Serco’s 9,000+ employees strive to make an impact every day across 100+ sites in the areas of Defense, Citizen Services, and Transportation. We help our clients deliver vital services more efficiently while increasing the satisfaction of their end customers. Serco serves every branch of the U.S. military, numerous U.S. Federal civilian agencies, the Intelligence Community, the Canadian government, state, provincial and local governments, and commercial clients. While your place may look a little different depending on your role, we know you will find yours here. Wherever you work and whatever you do, we invite you to discover your place in our world. Serco is a place you can count on and where you can make an impact because every contribution matters.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on dejobs.org

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

1:45 min

Transitioning from software development to security roles

Stefania Chaplin · WWC 2022

52 sec

Running persistent Linux environments directly on Windows

Ben Breard Ben Breard · WWC 2025

2:56 min

Provisioning a secure container infrastructure with Bicep

Matthias Falkenberg +1 · WWC 2022

3:05 min

Integrating an assistant application with Jira software

Felix Augenstein · LIVE

2:39 min

Experiencing core Linux capabilities for DevOps administration

Michael Cade · LIVE

4:09 min

Selecting infrastructure tools and determining proper abstraction layers

Alayshia Knighten Alayshia Knighten · WWC 2024

Videos

See all

Related articles

See all