Systems Security Analyst

MAGNUS MANAGEMENT GROUP, LLC
Santa Rita, United States
3 days ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience required
1 year minimum
Working hours
Regular working hours
Job source

Tech stack

Configuration Management Information Systems Security Engineering Professional Log Analysis Security Content Automation Protocol Software Vulnerability Management SC Clearance Plan of Action and Milestones

Job description

Position Overview We are seeking a Systems Security Analyst to support our client. You will help protect the confidentiality, integrity, and availability of Facility-Related Control Systems by leading security engineering, Risk Management Framework (RMF), vulnerability management, continuous monitoring, and incident response activities. This is a mission-essential, hands-on role for a security professional who can work independently, coordinate across technical and government stakeholders, and turn complex compliance requirements into operational results., Drive the end-to-end RMF lifecycle (Steps 1-6) in accordance with current Department of the Navy and NAVFAC Echelon II guidance; verify artifacts for completeness, quality, and compliance and maintain accurate eMASS packages. Achieve, maintain, and track Authorities to Operate (ATOs) for FRCS; support annual security reviews and prepare Memorandums for Record for approved baseline changes. Develop and maintain security policies, standard operating procedures, and implementation plans mapped to applicable NIST SP 800-53 control families and tailored to the FRCS environment. Execute vulnerability and compliance assessments using approved DoN tools such as ACAS, SCAP, and Evaluate STIG; complete manual STIG/SRG validations and maintain .ckl/.cklb checklists. Prepare Security Center and eMASSter reports for eMASS integration and ensure vulnerability results are accurately uploaded and maintained in VRAM. Sustain system-level continuous monitoring through recurring scans, audit-log analysis, remediation tracking, mitigation, and quarterly POA&M updates. Coordinate and support on-site RMF Step 4 validation, including evidence collection and collaboration with system owners and independent validators. Serve as a technical representative and/or Configuration Management Officer on the Configuration Control Board, providing security-impact analyses and risk assessments for proposed FRCS baseline changes. Support cyber incident response as a member of the MAR Cyber Emergency Response Team, including participation in an on-call rotation and preparation of operational logs and after-action reports. Provide bi-weekly RMF status reports to the ISSM, maintain project records in Maximo and/or eProjects, and contribute to monthly status reporting.

Requirements

Must be a US Citizen Must hold Secret Clearance Minimum of five years of RMF experience, including at least one year of specialized experience supporting FRCS RMF and cybersecurity engineering activities At least one current qualifying certification: CCSP, Cloud+, GICSP, GISF, GSEC, or Security+, RCCE Level 1, CISSO, CISSP-ISSEP, CySA+, FITSP-O, GCLD, GCSA, GSNA.

Benefits & conditions

401(k) Dental insurance Health insurance Paid time off Vision insurance

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.wayup.com

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

2:59 min

Why existing security and device management tools fail

Marcus Wermuth Marcus Wermuth · WWC Europe 2026

2:07 min

Technical components of internal developer platforms

Christian Strack · LIVE

11:18 min

Addressing audience questions on security and microservice architectures

Reinhard Kugler · LIVE

3:22 min

Transitioning from software engineering to security roles

Anna Oliveira · Coffee With Developers

1:02 min

Applying an ETL methodology to infrastructure configuration management

Axel Barbier · WWC 2023

3:48 min

Leveraging multi-agent systems for autonomous software testing

Ondřej Gróf Ondřej Gróf · WWC Europe 2026

Videos

See all

Related articles

See all