Information Security Analyst Senior
Job Description
The Senior Information Security Analyst will coordinate vulnerability scanning and identification across network hosts, strengthen vulnerability management practices, and support remediation and audit or examination efforts. The role works closely with Engineering and Operations teams, along with vendors, to help protect information and reduce the risk of unauthorized access.
Key Responsibilities
- Manage system vulnerabilities in alignment with security requirements, applying NIST continuous monitoring standards and RMF critical security controls and countermeasures based on mission system risk assessments.
- Identify and evaluate emergency or priority vulnerabilities, incorporating input from cyber intelligence, engineering, or operations, and propose targeted remediation approaches.
- Analyze vulnerability data and assist with prioritization and remediation efforts in accordance with risk and vulnerability management standards.
- Develop a deep understanding of vulnerabilities, including impacts and mitigation techniques, and clearly document and communicate findings to stakeholders.
- Update and create security standards and templates to meet evolving regulatory, audit, and related requirements.
- Improve the effectiveness and efficiency of enterprise vulnerability management practices across identification, assessment, and remediation.
- Leverage and enhance existing vulnerability management frameworks, policies, and standards to support minimum industry best practices.
- Coordinate data collection and documentation needed for examinations and audits.
- Work with existing security solution vendors (for example, ACAS and HBSS) to identify potential solution approaches.
- Research, develop, implement, test, and review information security measures to protect information and prevent unauthorized access.
- Gather information necessary to maintain security and support external barrier capabilities such as firewalls and other security controls.
- Support ISSO activities by assessing and reviewing systems to identify weaknesses, recommending improvements to address vulnerabilities, implementing changes, and documenting upgrades.
Required Qualifications
- BA/BS and 3+ years of experience; additional years may be considered in lieu of degree (7+ years).
- Experience and training with Microsoft Server 2016/2019 or newer, including Active Directory, Radius, DNS, and Group Policy.
- Experience and training with virtual environments (such as VMware and Hyper-V).
- Familiarity with maintaining and operating Trellix ENS (formerly McAfee Endpoint Security) and Tenable Security Center (ACAS) scans.
- Familiarity with maintaining and operating SQL Server.
- Experience applying patches/updates and STIGs.
- Ability to possess and maintain a minimum IAT level II certification IAW the DoW directive 8140.01 (sec+, CCSP, CASP+).
- Secret clearance.
- On customer site.
Technologies and Tools
- NIST continuous monitoring standards
- RMF
- ACAS, HBSS
- Microsoft Server 2016, Microsoft Server 2019
- Active Directory, Radius, DNS, Group Policy
- VMware, Hyper-V
- Trellix ENS (formerly McAfee Endpoint Security)
- Tenable Security Center (ACAS)
- SQL Server
- STIGs
- Firewalls and other security measures
Benefits
- 401K with company match
- Comprehensive health and wellness packages
- Internal mobility team dedicated to helping you own your career
- Professional growth opportunities including paid education and certifications
- Cutting-edge technology you can learn from
- Paid vacation and holidays to help rest and recharge
Required Clearance and Work Details
- Clearance level: Secret
- Public trust: None
- Requisition type: Regular
- Location: Tyndall AFB, Florida (Onsite Workplace)
- Travel required: Less than 10%
- Citizenship: U.S. Citizenship Required
Identity Verification Process
- You are expected to be on camera during virtual interviews.
- The employer may take your picture to verify your identity and prevent fraud.
- Proceeding authorizes the collection, processing, and use of biometric data for identity verification and security purposes.