Cloud Information Security Analyst
Job Description
SAIC is seeking a Cloud Information Security Analyst to support IT Service Management efforts for USTRANSCOM at Scott Air Force Base (AFB) in Illinois. This onsite role centers on authorization and assessment activities for cloud and enclave systems, including documentation, control assessment and monitoring, risk assessments, and security and privacy evaluation work.
In this position, you will help coordinate authorization deliverables, manage security profiles through established tools, and support decision-making that impacts system and network security. The work includes preparing for contingency and incident response assessments and aligning security practices to NIST-based evaluations.
Responsibilities
- Develop and coordinate authorization documentation, including Systems Categorization, Systems Security Plan, and systems risk assessment.
- Support control assessment, reporting, and monitoring processes using the Cyber Security and Assessment Management (CSAM) system.
- Create and maintain minor and major modification documentation.
- Maintain waivers and risk assessments for the ISSMs.
- Assist ISSMs with decisions that affect the security of systems and networks.
- Facilitate preparation for Contingency/Incident response assessments.
- Perform and document risk assessments, including analysis of security vulnerabilities and metrics used to measure associated risk.
- Design and develop comprehensive Systems Security Plans defining the enclave systems security profile, including infrastructure, policies, and procedures.
- Review and validate System Test and Evaluation (ST&E) and Interim Authority to Test (IATT) reviews for new and/or legacy systems.
- Review and conduct NIST-based Self Assessments, identify weaknesses, and develop a POA&M for each weakness based on industry best practices.
- Request risk acceptance for vulnerabilities that cannot be remediated or mitigated.
- Create and track Plan of Action and Milestones (POA&M) for mitigation of risks identified via ACAS and STIG processes.
- Design and develop Initial Privacy Assessment (IPA) and Privacy Impact Assessments (PIAs) for major Federal Government IT systems, and support Independent Verification and Validation (IV&Vs) of security profiles.
- Use the eMass tool to manage the system security profile.
- Use PPSM tool and processes to register ports, protocols, and services used by the enclaves.
Requirements
- 5+ years of experience with a BS (or 3+ years with an MS).
- 0 years with a PhD.
- DoD Secret clearance or higher.
- At least one IAT Level II certification: Security+, CECCNA-Security, CySA+, GICSP, GSEC, CND, or SSCP.
- At least one Computing Environment (CE) certification or certificate aligned to the technical area of responsibility for Network support/defense (for example: Splunk, Cisco, McAfee) or Operating System (for example: Microsoft, Linux, Solaris, AWS Cloud Practitioner, AWS Solutions Architect).
- Familiarity with AWS cloud concepts and services.
- Familiarity with DevOps practices in an agile environment.
Technologies
- Cyber Security and Assessment Management (CSAM) system
- NIST
- POA&M
- eMass tool
- PPSM tool
- ACAS
- STIG
- System Test and Evaluation (ST&E)
- Interim Authority to Test (IATT)
- Initial Privacy Assessment (IPA)
- Privacy Impact Assessments (PIAs)
- Independent Verification and Validation (IV&Vs)
- Splunk, Cisco, McAfee
- Microsoft, Linux, Solaris
- AWS Cloud Practitioner, AWS Solutions Architect
- Security+; CECCNA-Security; CySA+; GICSP; GSEC; CND; SSCP
- CAP, CASP+ CE, CISM, CISSP (and Associate), GSLC, CCISO, HCISPP
- ITIL Foundations (v4 or higher)
Location, Schedule, and Clearance
- Location: Scott AFB, IL, US (onsite)
- Schedule: Full-Time
- Shift: Day Job
- Travel: No
- Minimum clearance required: Secret
- Clearance level must be able to obtain: None
- Potential for remote work: ORA_ON_SITE
Compensation
Target salary range: USD 80,001 - 120,000 per year (based on experience and other factors).