Cyber Security Analyst I
- Discuss this with your agent
- Open in Claude
- Open in ChatGPT
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Role details
Tech stack
+3 more
Job description
- Verifying configuration management and tracking security update implementation to the systems using existing automated tools
- Adhering to pre-defined configuration management and change management policies and procedures for authorizing software prior to its implementation on systems
- Ensuring systems are operated, used, maintained, and disposed of in accordance with all applicable security policies and practices
- Performing cybersecurity testing, analysis, and reporting by conducting the following: Assured Compliance Assessment Solution (ACAS) scans, Security Technical Implementation Guide (STIG) checks, port scanning, application code review, Risk Management Framework (RMF) control review, and Plan of Action and Milestone (POAM)
- Providing in depth analysis on cybersecurity test results, remediation steps, and potential mitigating factor(s)
- Supporting the Information System Security Manager (ISSM) and Cybersecurity Lead in meeting all RMF documentation, process, policy, risk assessment, testing, and continuous monitoring requirements per the NIST SP-800 series
- Providing RMF support for all future and/or new Assessment and Authorization (A-A)
- Maintaining security reporting compliance requirements outlined in the System SLCM Strategy
Requirements
- Must currently hold a DoD 8570-compliant IAT II certification (SSCP or Security+CE with appropriate CE/OS certificate) or be able to obtain within six months
- CE/OS certificate may include Windows or Linux
- Experience with eMASS, SSPs, POAMs, ACAS/Nessus, SCAP, Security Checklists, and STIG Viewer
- Experience with risk management framework processes
- Have developed communication skills and the ability to express thoughts and ideas clearly and concisely
- Must be capable of multitasking and working several complex and diverse tasks with simultaneous or near simultaneous deadlines
- Be a self-starter who is accountable and requires minimal direction and supervision
- Be open to new and innovative ideas
- Be a team player willing to interface with client(s) and relay information back to team
Desired Skills
- Experience in a RHEL environment
- Experience with Networking Devices
- Experience with DevSecOps
- Experience with EvaluateSTIG and/or STIGManager
- Experience with Virtual Machines (VMware, Vsphere)
- Experience with Cisco products (Switches & Routers)
Benefits & conditions
SRC offers a generous benefit package, including medical, dental, and vision plans, 401(k) with a company match, life insurance, vacation and sick paid time off accruals with amounts increasing based on role and years of service, 11 paid holidays, tuition reimbursement, and a work environment that encourages excellence and more. For positions requiring a security clearance, selected applicants will be subject to a government security investigation and must meet eligibility requirements for access to classified information.
About the company
Scientific Research Corporation is an advanced information technology and engineering company that provides innovative products and services to government and private industry, as well as independent institutions. At the core of our capabilities is a seasoned team of highly skilled engineers and scientists with multidisciplinary backgrounds. This team is challenged daily to provide cutting edge technology solutions to our clients.
Apply for this position
This job is hosted externally. Click below to view the full posting and apply.
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Good distractions
Talks and stories from around this role — technically off-topic, practically not.
Moments
Explore playlistsVideos
See allRelated articles
See all
Dev Digest 134 - Where pixels sing?
Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.
How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again
Dev Digest 191: Malware interviews, EU ❤️ Open Source and Skilled Agents