Info. Security Analyst Principal

General Dynamics Information Technology
Hampton, VA, United States
19 days ago
Apply on dejobs.org
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
8 years minimum
Compensation
$108,800.0 - $147,200.0
Working hours
Regular working hours
Job source

Tech stack

Microsoft Windows Software Documentation Cyber Security Information Systems Computer Networks Data Security Linux File Systems Federal Information Processing Standards (FIPS) Security Content Automation Protocol Juniper SC Clearance
+6 more
Splunk Cisco Plan of Action and Milestones Vulnerability Analysis User Accounts Vmware

Job description

Please take this opportunity to join one of GDIT’s fastest long-standing growing programs! US Battlefield Information Collection and Exploitation System eXtended (US BICES-X) is a cutting-edge program supporting DoW intelligence information sharing on current and emerging global threats to mission and coalition partners and emerging nations. With an internationally dispersed team supporting each combatant command, the US BICES-X team is in direct support of the war fighter and their missions. We are seeking a creative and driven professional with a passion for solving real world issues on a cross-functional, fast paced team. You will be part of a dynamic team that is delivering a business-driven Enterprise Network to support BICES Global Enterprise Mission Support Services increasing performance, security, scalability, and stability while reducing costs and complexity resulting in increased supportability., * Performs Cybersecurity activities (formally known as IA - Information Assurance) for a large Program; coordinates with government Program staff, USAF, and other government agencies to assist in the creation, dissemination, direction, and auditing of program policy, standards, and operating procedures.

  • Utilize available resources to conduct Cybersecurity activities, and report to senior GDIT and government personnel on overall program security posture.
  • Conduct network and system audits for vulnerabilities using Security Technical Implementation Guides (STIGs), DISA SCAP, ACAS vulnerability scanner, ESS Policy Auditor to mitigate those findings for Linux, Windows, Cisco, Juniper, VMWare and other associated operating systems.
  • Ability to create, track and review Plan of Action and Milestones (POA&Ms) and conduct solution identification to assist in problem remediation and resolution.
  • Communicate tactical and strategic threat information to Government leaders, Cybersecurity-Ops and A&A (formerly C&A) Staff to assist them in making cyber risk decisions and to mitigate threats.
  • Carries out DoW Risk Management Framework (RMF) in accordance with DoW 8510 to ascertain information systems’ security posture by utilizing security control validation activities and coordinating security testing.
  • Maintain the Security Accreditation status, including system documentation of multiple DoW classified networks and interconnected systems.
  • Coordinates with AFRL, and USAF, and other organizations in support of audits and inspections and provides all necessary documentation as required for SAVs, ST&Es, and CCRI.
  • Evaluate firewall change requests and assess organizational risk.
  • Provides guidance on vulnerability countermeasures or mitigation of non-compliant controls.
  • Ensures the integrity and protection of networks, systems, and applications by technical enforcement of organizational security policies, through monitoring of vulnerability scanning devices.
  • Performs periodic and on-demand system audits and vulnerability assessments, including user accounts, application access and file system to determine compliance.
  • Provides guidance and work leadership to less-experienced technical staff members.
  • Maintains current knowledge of relevant technology as assigned.
  • Participates in special projects as required.

Requirements

ACAS,DISA STIG,RMF,Splunk (Inactive)

Experience:

10 + years of related experience, * 10+ years of experience required (8+ years of experience preferred).

  • Must possess and maintain a Secret clearance.
  • BA/BS degree - may substitute additional years of experience.
  • Comprehensive knowledge of data security administration principles, methods, and techniques.
  • Must meet DOW 8570.01M requirements for IAT Level II (e.g. CASP CE, etc.)
  • Requires understanding of DOW RMF (800-53 Rev 4 and Rev 5)
  • Requires understanding of DoW policies and procedures, including FIPS 199, FIPS 200, NIST 800-53 and other applicable policies., * Ability to acquire and maintain a TS/SCI clearance.
  • The ability to work and set priorities on multiple projects/tasks at once and operate in a dynamic, fast-paced team-oriented environment
  • Depending on job assignment, additional specific certifications may be required
  • The work is typically performed in an office environment, which requires normal safety precautions; work may require some physical effort in the handling of light materials, boxes, or equipment.

Benefits & conditions

The likely salary range for this position is $108,800 - $147,200. This is not, however, a guarantee of compensation or salary. Rather, salary will be set based on experience, geographic location and possibly contractual requirements and could fall outside of this range.

Total Rewards at GDIT:

Our benefits package for all US-based employees includes a variety of medical plan options, some with Health Savings Accounts, dental plan options, a vision plan, and a 401(k) plan offering the ability to contribute both pre and post-tax dollars up to the IRS annual limits and receive a company match. To encourage work/life balance, GDIT offers employees full flex work weeks where possible and a variety of paid time off plans, including vacation, sick and personal time, holidays, paid parental, military, bereavement and jury duty leave. To ensure our employees are able to protect their income, other offerings such as short and long-term disability benefits, life, accidental death and dismemberment, personal accident, critical illness and business travel and accident insurance are provided or available. We regularly review our Total Rewards package to ensure our offerings are competitive and reflect what our employees have told us they value most.

Our Identity Verification Process:

As part of the hiring process, we will ask you to complete an identity verification process that leverages advanced biometrics and artificial intelligence to ensure authenticity and protect against identity fraud. You are expected to be on camera during virtual interviews. We reserve the right to take your picture to verify your identity and prevent fraud. By proceeding, you authorize the collection, processing, and use of your biometric data for identity verification and security purposes.

About the company

We are GDIT. A global technology and professional services company that delivers technology solutions and mission services to every major agency across the U.S. government, defense and intelligence community. Our 26,000 experts extract the power of technology to create immediate value and deliver solutions at the edge of innovation. We operate across 50+ countries worldwide, offering leading mission-ready capabilities in AI, cloud, cyber and software development.

Join our Talent Community to stay up to date on our career opportunities and events at https://gdit.com/tc.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on dejobs.org
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

1:45 min

Transitioning from software development to security roles

Stefania Chaplin · World Congress 2022

1:40 min

Managing containerized infrastructure with Podman Desktop

Cedric Clyburn Cedric Clyburn +1 · World Congress 2025

52 sec

Running persistent Linux environments directly on Windows

Ben Breard Ben Breard · World Congress 2025

1:29 min

Expanding practical knowledge with community sandboxes and resources

Stuart Clark · LIVE

3:22 min

Transitioning from software engineering to security roles

Anna Oliveira · Coffee With Developers

1:41 min

Parallels between cloud and legacy infrastructure lock-ins

Björn Stahl Björn Stahl · World Congress 2024

Videos

See all

Related articles

See all