Cyber Analyst III

General Atomics
Rome, NY, United States
2 days ago
Apply on www.clearancejobs.com
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Working hours
Regular working hours

Tech stack

Amazon Web Services Data Analysis Cloud Computing Cloud Computing Security CompTIA Security+ Information Systems Identity and Access Management Network Security Network Segmentation Cloud Services Security Information and Event Management Software Vulnerability Management
+4 more
Data Logging Cloud Platform System Serverless Computing Vulnerability Analysis

Job description

  • Supports the design, implementation, and operation of secure AWS cloud environments (e.g., AWS GovCloud, DoD IL5), including identity and access management (IAM), network security, encryption, logging/monitoring, and configuration baselines.
  • Implements and maintains security controls for cloud workloads that handle Controlled Unclassified Information (CUI) and/or USG federal information, ensuring alignment with applicable frameworks (e.g., CMMC/NIST 800-171, FedRAMP/FISMA/NIST 800-53), as directed by program requirements.
  • Works with internal compliance leads to map and implement required controls in AWS and other cloud environments; provides technical input for System Security Plans (SSPs), Plans of Action and Milestones (POA&Ms), and related documentation for cloud systems.
  • Supports efforts to achieve and maintain DoD IL5 or equivalent impact levels for cloud workloads, including preparation for assessments, evidence collection, and remediation of findings.
  • Collaborates with USG customers, program security teams, and other stakeholders to understand security requirements for specific tenants and workloads, including when environments transition to USG federal information systems and fall under non-CMMC frameworks.
  • Conducts regular security control assessments and configuration reviews for cloud resources; validates that implemented controls are effective and aligned with approved baselines.
  • Reviews and analyzes security logs, alerts, and reports from cloud-native services (e.g., AWS CloudTrail, GuardDuty, Security Hub, Config) and SIEM platforms to identify potential security and compliance issues in cloud environments.
  • Supports vulnerability management for cloud workloads, including scanning, triage, coordination with engineering teams, and tracking remediation in accordance with applicable requirements and timelines.
  • Contributes to the development, review, and maintenance of cloud security policies, standards, and procedures, including documentation of shared responsibility models and tenant-specific requirements.
  • Prepares and delivers technical and compliance-related information to both technical and non-technical stakeholders, including internal leadership and USG representatives.
  • Maintains the strict confidentiality of sensitive information.
  • Performs other duties as assigned.

We recognize and appreciate the value and contributions of individuals with diverse backgrounds and experiences and welcome all qualified individuals to apply.

Requirements

  • Typically requires a bachelors degree in related field and five or more years of professional computer system security experience or related field. Equivalent professional experience may be substituted in lieu of education.
  • Equivalent professional experience may be substituted in lieu of education.
  • Must demonstrate a complete understanding of computer system security principles, concepts, practices and techniques.
  • Must have experience organizing, planning scheduling, conducting, and managing work assignments to meet project milestones or established completion dates.
  • Must possess the ability to understand new concepts quickly and apply them in an evolving environment while contributing to the development of new processes.
  • Must be customer focused and possess:
  • (1) the ability to identify issues, analyze and interpret data and develop solutions to a variety of complex issues;
  • (2) strong analytical skills, verbal and written communication skills to accurately document, report and present findings;
  • (3) strong interpersonal skills and ability to interface with other professionals; and
  • (4) strong computer skills.
  • Ability to work both independently and in a team environment is essential as is the ability to work extended hours as required.

Desired Skills:

  • Experience supporting DoD contracts and working with Controlled Unclassified Information (CUI).
  • Experience conducting or supporting security audits, assessments, or authorization activities for cloud systems.
  • Familiarity with FedRAMP, NIST SP 800-171, NIST SP 800-53, or other USG cybersecurity frameworks.
  • Hands-on experience with AWS security services (e.g., IAM, KMS, CloudTrail, GuardDuty, Security Hub, Config) and securing workloads at IL5 or similar impact levels.
  • Experience with cloud security architecture and best practices for multi-account AWS environments, including network segmentation, zero trust concepts, and secure landing zones.
  • Experience with GRC (Governance, Risk, and Compliance) platforms.
  • Knowledge of supply chain risk management requirements (e.g., NIST SP 800-161).
  • Experience with SIEM tools, vulnerability scanners, and other cybersecurity monitoring platforms.
  • Relevant certifications such as CISSP, Security+, CISM, CISA, CRISC, AWS Certified Security - Specialty, or AWS Certified Solutions Architect.
  • Experience supporting RMF or other authorization processes for cloud-based USG information systems.

About the company

General Atomics Integrated Intelligence, Inc. (GA Intelligence), an affiliate of General Atomics, was founded in 1989. It provides custom software development and innovative information engineering solutions to customers in government and private industry. We build and develop best-in-class all domain and globally focused situational awareness capabilities that process petabytes of data from numerous streaming data sources in near real time. Our systems apply state-of-the-art algorithms and machine learning techniques to extract features and fuse data from multiple phenomenologies to form a rich live view of objects in the sky, on the sea, and on the ground. These analytics are designed to determine not just where something is, but what it is, where it’s been and what it’s doing. All of this “data to knowledge” is made available to end users in our own browser-based application for visualization, analysis, and understanding. We always want to do more, and that’s where you come in!

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.clearancejobs.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

2:57 min

Securing sensitive defense infrastructure with dual-vendor cloud strategies

Boris Hecker Boris Hecker +3 · World Congress 2025

1:10 min

Exposing sensitive information through partial search logs

Dennis Schulz Dennis Schulz +1 · World Congress 2026 Europe

1:48 min

Automating exploratory data analysis within training pipelines

Dora Petrella · World Congress 2023

2:41 min

Transitioning artificial intelligence infrastructure into scalable commodity cloud services

juarezjunior juarezjunior · World Congress 2024

6:13 min

Defining cloud proficiency by technical role

Piet Van Dongen · LIVE

1:56 min

Discovering incidents using logs, metrics, and traces

Nele Uhlemann · World Congress 2023

Videos

See all

Related articles

See all