Cyber Security Analyst Level II
QUANTUM SKY LLC
Warner Robins, GA, United States
6 days ago
- Discuss this with your agent
- Open in Claude
- Open in ChatGPT
Role details
Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Experienced
Experience required
3 years minimum
Working hours
Regular working hours
Job source
Tech stack
Software System Penetration Testing
Network Analysis
Cyber Security
Databases
Information Leak Prevention
Issue Tracking Systems
Internet Protocol
Subnetting
Network Security
Comptia Pentest+ CE
SAS (Software)
Security Content Automation Protocol
+4 more
Software Engineering
Computer Network Operations
Information Technology
Vulnerability Analysis
Job description
- Will provide Subject Matter Expertise (SME) for process oversight in implementing/executing STIGS using automated and manual tools provided by DISA (ex. Security Content Automation Protocol - SCAP).
- Will provide training to system administrators (SA) on STIG process as needed.
- Track STIG compliance and quarterly updates for all servers and infrastructure devices and identify discrepancies to system administrators and A6 CORA Lead.
- Works with Communications Focal Point to obtain quarterly STIGS random sampling (min ten percent (10%)) of physical and virtual workstations.
- Review checklist for compliance and report findings of incomplete STIGS and set a suspense date for completion.
- Will provide Subject Matter Expertise (SME) for process oversight in POAMs for Enterprise Mission Assurance Support Service (eMASS), DISPATCH, and STIGS for CORA.
- Manages POAM program for assigned base\location by working with SAs to ensure a POAMs for all open findings from STIGS and vulnerability scans are created and updated every thirty (30) calendar days until remediation is complete.
- Review and notify SAs and their immediate supervisor as well as the A6 CORA Lead for any incomplete or non-submitted POAMs.
- Provide monthly status of open POAM status based on severity level (CAT I (Critical/High), CAT II (Medium) and CAT III (Low)
- Will provide Subject Matter Expertise (SME) on ESS reports and will be responsible for downloading and analyzing weekly posted reports.
-
Reports: o Data Loss Prevention (DLP) Violations o Enhanced Reports o Outdated Product Report o Rogues o Subnet Coverage
- Notify the office of responsibility SA of open findings and suspense SAs to identify devices for exemption (ex. Printers, non-OS systems). Use designated template for list of exempted devices.
- Submit exempted device list to 561st Network Operations Squadron (NOS) Client Security via Remedy Ticket or designated ticketing system.
- Work with office of responsibility to identify which two (2) systems within each populated subnet range will have Rogue Sensor Detectors (RSD) applied. Submit identified systems via designated ticketing system to 561 NOS Client Security.
- Monitor and download weekly reports for status on open findings.
- Serve as functional lead for cybersecurity applications used to manage / monitor cyber compliance status, configuration and indicators of compromise
- Base Analysts will provide the following support in addition to STIGs, POAMs, and ESS compliance:
- Identify monthly summary of fix actions (i.e. punch list) required to meet CORA standards and guidelines.
- Integrate Command Cyber 365 Flight Plan guide with all required components.
- Report monthly on compliance status from assigned bases.
- Manage / report om implementation of policies established by Command Cyber Analysts
- Manage 38 CORA/HSO reports for assigned bases or equivalent
- Configure and tailor policies to address specific needs and intracacies of assigned bases.
- Develop Master Software List (MSL) for assigned base(s).
Requirements
Required:
- Recommend 3+ years of experience
- Knowledge of the limitations and capabilities of computer systems and technology; operational support of networks, operating systems, Internet technologies, databases, and security infrastructure; cybersecurity and information security controls, practices, procedures, and regulations; and incident response program practices and procedures.
- Education: Bachelor’s degree in Information Technology, Cybersecurity, Computer Science, Data Science, or Software Engineering is typically required.
- Certifications (DoD Approved): Common certifications for this role include GCIH (GIAC Certified Incident Handler), CEH (Certified Ethical Hacker), Security+, and others like PenTest+ or CySA+.
- Skills & Knowledge:
- Proficiency in network security architecture and application vulnerabilities.
- Ability to conduct vulnerability scans and utilize penetration testing tools.
- Knowledge of network analysis tools and techniques.
Clearance:
- Active DoD Secret level clearance
Travel Required:
- Minimal, less than 10%
Apply for this position
This job is hosted externally. Click below to view the full posting and apply.
Apply on www.clearancejobs.comGood distractions
Talks and stories from around this role — technically off-topic, practically not.
Moments
Explore playlistsVideos
See allRelated articles
See all
LM
Luis Minvielle
about 2 years ago
CH
Chris Heilmann
Dev Digest 134 - Where pixels sing?
almost 2 years ago
LM
Luis Minvielle
7 Cloud Computing Trends Coming in 2025 for Developers
over 2 years ago
LM
Luis Minvielle
Where to Find Entry-Level Software Engineering Jobs
over 2 years ago
KD
Krissy Davis
Best Paying Jobs in Technology
about 3 years ago
LM
Luis Minvielle
Is Software Engineering Over-Saturated?
over 2 years ago