Information Security Analyst

Akhiok-Kaguyak, Inc.
Colorado Springs, United States of America
5 days ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Working hours
Regular working hours
Languages
English
Experience level
Intermediate

Job location

Colorado Springs, United States of America

Tech stack

Microsoft Active Directory
Computer Security
Information Systems
Linux
Information Security Management
Networking Basics
Systems Development Life Cycle
Zero Trust Network Access
Software Vulnerability Management
Windows Desktop
SARS Software Products
Information Technology
Scap Compliance Checker
Vulnerability Analysis

Job description

Sugpiat Defense is seeking an experienced Information Security Analyst to support the Missile Defense Agency (MDA) in Colorado Springs, Colorado. The selected candidate will assist in protecting mission-critical information systems by implementing cybersecurity policies, supporting Risk Management Framework (RMF) activities, monitoring system security posture, and ensuring compliance with Department of Defense (DoD) cybersecurity requirements.

The ideal candidate is detail-oriented, possesses strong analytical and problem-solving skills, and has experience supporting cybersecurity operations within a DoD environment. This role works closely with Information System Security Managers (ISSMs), engineers, system administrators, and government personnel to maintain the security and compliance of MDA information systems., * Support the implementation and maintenance of cybersecurity requirements for classified and unclassified information systems.

  • Assist with Risk Management Framework (RMF) activities throughout the system lifecycle.
  • Maintain and update RMF documentation, including System Security Plans (SSPs), Security Assessment Reports (SARs), Plans of Action and Milestones (POA&Ms), and supporting artifacts.
  • Perform continuous monitoring activities to ensure compliance with DoD cybersecurity requirements.
  • Review vulnerability scan results, document findings, and coordinate remediation efforts with technical teams.
  • Support implementation and validation of DISA Security Technical Implementation Guides (STIGs).
  • Assist with Assessment and Authorization (A&A) activities to maintain system Authority to Operate (ATO).
  • Monitor system security posture and report cybersecurity risks and compliance issues.
  • Support security audits, inspections, and cybersecurity assessments.
  • Assist with investigating and documenting cybersecurity incidents in accordance with established procedures.
  • Review proposed system changes to identify potential security impacts.
  • Collaborate with engineers, system administrators, and government stakeholders to ensure cybersecurity requirements are incorporated into system operations.
  • Prepare reports, metrics, and status updates related to cybersecurity compliance and continuous monitoring.
  • Stay current on DoD cybersecurity policies, emerging threats, and industry best practices.

Requirements

  • Bachelor's degree in Cybersecurity, Information Technology, Computer Science, Information Assurance, or a related field.
  • Minimum of 3-5 years of experience supporting information assurance or cybersecurity programs, preferably within the Department of Defense.
  • Experience supporting the DoD Risk Management Framework (RMF).
  • Working knowledge of:
  • NIST SP 800-53
  • NIST SP 800-37
  • DoD RMF
  • DISA STIGs
  • Vulnerability management
  • Security compliance and continuous monitoring
  • Experience with Enterprise Mission Assurance Support Service (eMASS) or similar RMF tools.
  • Familiarity with Windows and Linux operating systems, Active Directory, and basic networking concepts.
  • Strong analytical, organizational, written, and verbal communication skills.
  • Ability to work independently while contributing effectively within a collaborative team environment.

Preferred Qualifications

  • Experience supporting the Missile Defense Agency (MDA) or another DoD organization.
  • Experience using ACAS, SCAP Compliance Checker, or other DoD cybersecurity assessment tools.
  • Familiarity with cybersecurity engineering principles and secure system development practices.
  • Experience supporting classified information systems.
  • Knowledge of Zero Trust concepts and current DoD cybersecurity initiatives.

Certifications

One or more of the following certifications is preferred:

  • Security+
  • CySA+
  • CASP+
  • CISSP (Associate or full certification)
  • CAP

Certification must meet applicable DoD 8570/8140 requirements for the assigned position.

Benefits & conditions

  • Sugpiat Defense offers the opportunity to support the Missile Defense Agency's critical national security mission while working with a talented team of cybersecurity professionals. We provide competitive compensation, comprehensive benefits, opportunities for professional growth, and a collaborative environment where employees can make a meaningful impact.

Apply for this position