Information Security Analyst

CALIBRE Systems Inc.
Weymouth, MA, United States
23 days ago
Apply on www.wayup.com
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
5 years minimum
Compensation
$89,000.0 - $110,000.0
Working hours
Regular working hours
Job source

Tech stack

Software System Penetration Testing Cloud Computing Security Cyber Security Information Systems Databases Disaster Recovery Zero Trust Network Access Security Information and Event Management Software Vulnerability Management Information Technology Network Server Vulnerability Analysis

Job description

CALIBRE Systems, Inc., an employee-owned mission focused solutions and digital transformation company, is looking for a highly qualified Journeyman Information Security Analyst to support a DoD client with enterprise cybersecurity for a large program serving military families. This position will be hybrid with some required meetings in Alexandria, VA. The role combines cybersecurity operations, compliance, vulnerability management, incident response, and Risk Management Framework (RMF) activities for Department of Defense cloud and information systems. The analyst will help maintain compliance with DoD, DISA, U.S. Cyber Command, MC&FP, NIST RMF, Zero Trust, STIG/SRG, ACAS, and eMASS requirements while supporting the attainment and sustainment of Government-issued Authorizations to Operate (ATOs). An active TOP Secret clearance is required for this role. Salary range for this position is $89k-$110k, · Support RMF documentation, security control implementation, assessment activities, and ATO sustainment using the DoD enterprise eMASS platform. · Conduct weekly DISA STIG/SRG and ACAS vulnerability assessments, assist with remediation tracking, and prepare raw scan outputs, weekly threat reports, and ACAS roll-up reports. · Maintain and update Plans of Action and Milestones (POA&Ms), collect evidence of completion, and coordinate validation with ISSM, ISSO, and Security Control Assessment teams. · Monitor cybersecurity resources, SIEM-integrated logs, anomaly indicators, account aging, compliance status, WAF/NGFW activity, and GovCloud logs; escalate abnormal findings within required timelines. · Support daily review of the DC3 Vulnerability Disclosure Program portal and assist with creation and mitigation of associated POA&Ms. · Assist with vulnerability assessments and penetration testing for new or modified applications, servers, databases, and infrastructure components before deployment. · Support incident reporting, documentation, and coordination with the Incident Response Team and Tier 2 Cybersecurity Service Provider. · Contribute to weekly cybersecurity activity reporting, including compliance status, vulnerability assessments, incident management, and risk metrics. · Support contingency planning, disaster recovery exercises, SOP audits, and cybersecurity exercise activities as directed. · Access SIPRNet and attend classified briefings at the Government facility in Alexandria, Virginia, as required.

Requirements

· Working knowledge of NIST RMF, eMASS, DISA STIGs/SRGs, ACAS, POA&Ms, and DoD cybersecurity policies. · Ability to analyze vulnerability data, document findings, support risk mitigation, and communicate technical information to Government stakeholders. · Familiarity with cloud security monitoring, SIEM tools, incident response processes, and compliance reporting. Desired Skills and Qualifications: · Master’s degree in Information Technology, Cybersecurity, Information Assurance, or a related field. · DoD 8570/8140-aligned certification such as Security+ CE, CySA+, or equivalent · Experience supporting DoD agencies with cybersecurity, information assurance, vulnerability management, or RMF activities. · Active Top Secret clearance · Experience with eMASS or other compliance tracking platforms. · Familiarity with cloud security controls and cloud-based compliance requirements. · Understanding of Zero Trust principles and cybersecurity modernization strategies. Required Experience · Bachelor’s degree in Information Technology, Cybersecurity, Information Assurance, or a related field. · Active Secret security clearance. · 5+ years of experience in cybersecurity, RMF support, compliance, or information assurance. · Experience supporting Federal agencies with cybersecurity, information assurance, vulnerability management, or RMF activities.

  • Qualifications · Working knowledge of NIST RMF, eMASS, DISA STIGs/SRGs, ACAS, POA&Ms, and DoD cybersecurity policies. · Ability to analyze vulnerability data, document findings, support risk mitigation, and communicate technical information to Government stakeholders. · Familiarity with cloud security monitoring, SIEM tools, incident response processes, and compliance reporting. Desired Skills and Qualifications: · Master’s degree in Information Technology, Cybersecurity, Information Assurance, or a related field. · DoD 8570/8140-aligned certification such as Security+ CE, CySA+, or equivalent · Experience supporting DoD agencies with cybersecurity, information assurance, vulnerability management, or RMF activities. · Active Top Secret clearance · Experience with eMASS or other compliance tracking platforms. · Familiarity with cloud security controls and cloud-based compliance requirements. · Understanding of Zero Trust principles and cybersecurity modernization strategies.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.wayup.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

1:45 min

Transitioning from software development to security roles

Stefania Chaplin · World Congress 2022

3:04 min

Database evolution and the funding behind vector databases

Erik Bamberg · LIVE

4:11 min

Introduction to cloud-native application developer security

Micah Silverman · World Congress 2022

3:50 min

Queues in TCP stacks and continuous network connections

Clemens Vasters Clemens Vasters · World Congress 2022

5:03 min

Navigating new cybersecurity compliance frameworks and laws

Kurt Eder · LIVE

4:01 min

Managing application isolation via pluggable database models

Wei Hu Wei Hu · World Congress 2022

Videos

See all

Related articles

See all