Information Security Analyst Sr Principal
Job Description
This Senior/Principal Information Security Analyst role supports the US Battlefield Information Collection and Exploitation System eXtended (US BICES-X) by executing cybersecurity activities, performing audits and vulnerability assessments, and sustaining security accreditation and DoD RMF compliance.
Location and Work Model
- Location: Andrews AFB, MD
- Workplace: Onsite
Compensation
- Salary range: USD 119,000 - 161,000 per year
Role Responsibilities
- Perform cybersecurity activities (formally known as Information Assurance (IA)) for a large program, coordinating with government program staff, USAF, and other government agencies to support the creation, dissemination, direction, and auditing of program policy, standards, and operating procedures.
- Use available resources to conduct cybersecurity activities and report overall program security posture to senior GDIT and government personnel.
- Conduct network and system audits for vulnerabilities using STIGs, DISA SCAP, ACAS vulnerability scanner, and ESS Policy Auditor to mitigate findings across Linux, Windows, Cisco, Juniper, VMWare, and other associated operating systems.
- Create, track, and review Plan of Action and Milestones (POA&Ms), including solution identification to support problem remediation and resolution.
- Communicate tactical and strategic threat information to Government leaders, Cybersecurity-Ops, and A&A (formerly C&A) staff to enable cyber risk decisions and threat mitigation.
- Carry out DoD Risk Management Framework (RMF) in accordance with DoW 8510 by performing security control validation activities and coordinating security testing to ascertain information system security posture.
- Maintain security accreditation status, including documentation for multiple DoD classified networks and interconnected systems.
- Coordinate with AFRL, USAF, and other organizations to support audits and inspections, providing required documentation for SAVs, ST&Es, and CCRI.
- Evaluate firewall change requests and assess organizational risk.
- Provide guidance on vulnerability countermeasures and mitigation of non-compliant controls.
- Ensure integrity and protection of networks, systems, and applications by enforcing organizational security policies through monitoring of vulnerability scanning devices.
- Perform periodic and on-demand system audits and vulnerability assessments, including reviews of user accounts, application access, and file system to determine compliance.
- Provide guidance and work leadership to less-experienced technical staff members.
- Maintain current knowledge of relevant technology as assigned and participate in special projects as required.
Required Qualifications
- Experience: 10+ years required (8+ years preferred)
- Clearance: Must possess and maintain a Top Secret/SCI clearance
- Education: BA/BS degree (additional years of experience may substitute)
- Comprehensive knowledge of data security administration principles, methods, and techniques
- Must meet DOW 8570.01M requirements for IAT Level II (e.g., CASP CE)
- Understanding of DoW RMF (800-53 Rev 4 and Rev 5)
- Understanding of DoW policies and procedures, including FIPS 199, FIPS 200, NIST 800-53, and other applicable policies
Technologies and Frameworks
- Security Technical Implementation Guides (STIGs)
- DISA SCAP
- ACAS vulnerability scanner
- ESS Policy Auditor
- Linux, Windows
- Cisco, Juniper, VMWare
- DoW Risk Management Framework (RMF)
- DoW 8510
- FIPS 199, FIPS 200
- NIST 800-53; 800-53 Rev 4, 800-53 Rev 5
Additional Information
- Category: Cyber and IT Risk Management
- Requisition #: RQ229346
- Requisition type: Regular
- Travel required: None
- Public trust: None
- Citizenship: U.S. Citizenship Required
- Clearance level listed: Secret
Identity Verification Process
- You are expected to be on camera during virtual interviews.
- GDIT reserves the right to take your picture to verify your identity and prevent fraud.
- By proceeding, you authorize the collection, processing, and use of your biometric data for identity verification and security purposes.