Cyber Security Analyst Associate
Job Description
Amentum is seeking a Cyber Security Analyst Associate to support Assessment and Authorization (A&A) activities within the Risk Management Framework (RMF) in support of USSOCOM and supported networks, systems, services, and devices. This full-time, onsite role is based in Tampa, FL and focuses on compliance validation, continuous monitoring support, and the development and management of A&A and connection approval packages.
Working within the USSOCOM cybersecurity mission, you will help coordinate assessment activities, evaluate security posture against applicable standards, and advise stakeholders on risks, mitigation approaches, and authorization artifacts across networks and environments governed by DoD and IC requirements.
Core Responsibilities
- Provide Assessment and Authorization (A&A) assistance using the RMF concept in support of defense-in-depth for USSOCOM networks, systems, services, and devices, including Component Commands, TSOCs, and deployed forces.
- Support assessment and authorization coordination and assist with RMF execution, including development of Plan and Action and Milestones (POA&Ms) to resolve network deficiencies in accordance with DODI 8510.01 and ICD 503.
- Assess network compliance against NIST 800-53 controls and create A&A packages.
- Perform assessment, compliance, and validation activities to support USSOCOM’s cybersecurity program, including comprehensive evaluations of customer networks to ensure regulatory and security standards compliance.
- Identify and mitigate potential shortcomings, vulnerabilities, and system risks through security evaluations and vulnerability assessments.
- Conduct vulnerability assessment and scanning using DoD Assured Compliance Assessment Solution (ACAS), Nessus, and Security Content Automation Protocol (SCAP) tooling.
- Identify applicable STIGs and perform STIG assessments using SCAP tools.
- Serve as a liaison with network and system administrators to address identified deficiencies.
- Review or scan for new systems and applications introduced into the SOF environment, identify issues, and draft certification letters for the government.
- Coordinate with the Site Integration Facility (SIF) to help ensure systems and applications meet standards in the DISA Security Technical Implementation Guides (STIG).
- Track A&A status for SIE governed ISs and ensure cybersecurity artifacts and documentation are available in the USSOCOM-selected automated tool.
- Maintain, track, and validate DISN, cloud, and DIA connection approval packages, including those from USSOCOM and subordinate organizations.
- Develop and maintain documentation supporting new and existing networks, cloud environments, information systems, and technologies introduced into the SIE.
- Develop and review A&A for SIE networks, cloud environments, systems, services, telecommunications circuits, and devices, to obtain an ATO, IATT, or ATC.
- Prepare risk assessment reports for submission to the SCA and Authorizing Official/Designated Authorizing Official/Designated Accrediting Authority (AO/DAO/DAA) in accordance with applicable policies and regulations.
- Support enforcement of A&A and connection standards for networks and systems, and maintain A&A databases, web sites, and tools used for cybersecurity documentation and management.
- Track and report to higher headquarters organizations (e.g., USCYBERCOM, DIA) regarding compliance with applicable cybersecurity regulations and directives, including timely notifications to help prevent accreditations from lapsing.
- Develop and maintain an Information Security Continuous Monitoring (ISCM) Plan and perform analytics on cybersecurity posture, providing reports as required per ISCM and AO/DAO direction.
- Validate patching of systems, perform validation scanning, develop POA&Ms, and report as directed by applicable policies and procedures.
- Provide DoD & IC RMF subject matter expertise to USSOCOM, Component Commands, TSOCs, deployed forces, and their delegates, and help support processes and capabilities to mitigate vulnerabilities and weaknesses for software and hardware deployment.
- Coordinate with USCYBERCOM, DoD, DIA, NSA, DISA, and subordinate organizations to support resolution of issues involving security, A&A, connection approvals, and waiver requests.
Required Qualifications
- Active TS/SCI clearance required (US Citizenship required to obtain a security clearance).
- Years of Experience: < 5 years.
- Education: BA/BS.
- Certification: Current DoD 8570.01-M (IAT- Level II). Example certifications include CCNA-Security, GICSP, GSEC, Security+ CE, SSCP, CISSP (or Associate), CASP+CE, CISA, GCED, or GCIH.
- Excellent written and oral communication and strong interpersonal skills.
- Knowledge and experience with DoD IA processes and policies, including DODI 8510.01, NIST, CNSS, other cybersecurity policies, and CJCSM 65101.01 along with Incident Response and IA policies.
- Working knowledge of the RMF.
- Experience with US Combatant Commands (USCENTCOM/USSOCOM) is desired.
- Technical background in system administration, architecture/engineering is preferred, and technical background in networking, identity management, and Microsoft and Linux operating systems is required/expected; database and mobility expertise is also referenced.
- Knowledge of Telos Xacta or eMASS is desired.
- Independent personal transportation to the office or work site is required.
Technologies
- Risk Management Framework (RMF)
- NIST 800-53
- DoD Assured Compliance Assessment Solution (ACAS)
- Nessus
- Security Content Automation Protocol (SCAP) / SCAP tool
- STIGs and DISA Security Technical Implementation Guides (STIG)
- Telos Xacta
- Enterprise Mission Assurance Support Services (eMASS)
- SIEM
- DISN
- DoD 8570.01
Compensation and Benefits
- Salary: $57,000 - $63,000 per year.
- Health, dental, and vision insurance
- Paid time off and holidays
- Retirement benefits, including 401(k) matching
- Educational reimbursement
- Parental leave
- Employee stock purchase plan
- Tax-saving options
- Disability and life insurance
- Pet insurance
Additional Notes
- Travel: up to 10% to and from customer locations and test locations may be required, potentially involving airline travel.
- Work schedule: Monday to Friday, 6:00am to 4:00pm (attendance is essential except for approved time off and applicable leave).
- Working conditions: may involve indoor or outdoor work depending on assigned tasks; no unusual hazards are listed.
- Physical requirements: may include lifting up to 20 pounds as necessary.
Posting: 10/07/2026 - Until Filled. Amentum anticipates the requisition will remain open for at least three days, with a closing date no earlier than three days after the original posting.