Senior Cyber Security Analyst
Senior
Cyber Defense
Cybersecurity Tools
Data Security
Engineer
Incident Response
Information Security
InfoSec
Risk Governance
Risk Management
Security
Security Architecture
Security Clearance
Security Compliance
Security Operations
Security Standards
Security Testing
Solution Architecture
Threat Modeling
Job Description
SAIC is hiring a Senior Cyber Security Analyst (Wasatch ISSE) to support IS Governance, Risk & Compliance at Hill AFB, UT with onsite work.
Responsibilities
- Design, implement, and maintain security controls and architectures for classified information systems and networks, aligning with DoD and customer cybersecurity requirements.
- Perform and document risk and vulnerability assessments, threat modeling, and security audits; provide mitigation recommendations to the ISSM and program leadership.
- Develop, update, and maintain Body of Evidence (BoE) artifacts (including SSPs, POA&Ms, and ST&E documentation) and support certification/accreditation activities under RMF and related frameworks.
- Lead or support incident response and digital forensics for high-severity events; conduct root cause analyses and drive corrective actions to closure.
- Use and optimize security tools such as SIEM, EDR/XDR, firewalls, and vulnerability scanners to monitor, detect, and remediate threats across classified and associated unclassified environments.
- Collaborate with technical and business stakeholders to translate mission or business needs into a security roadmap; communicate complex cyber risk to non-technical leadership.
Requirements
- Bachelor’s degree in Computer Science, Cybersecurity, Information Technology, or a related engineering field.
- 5+ years of relevant experience.
- Active final Secret clearance required on date of hire.
- Must meet DoD 8570.01-M IAT Level II or IAM Level I (or higher) certification requirements, such as Security+ CE, CySA+, CASP+, or CISSP.
- Proven professional experience leading large-scale information security projects or programs, preferably in defense or aerospace.
- Experience designing and implementing secure network architectures, including Zero Trust environments and cloud security frameworks on AWS, Azure, or GCP.
- Strong working knowledge of regulatory frameworks including NIST 800-53/800-171, ISO 27001, CMMC, or SOC 2, with hands-on experience performing risk, vulnerability, and security control assessments.
- Expert-level familiarity with security tooling, including SIEM (e.g., Splunk, Sentinel), EDR/XDR, firewalls, and vulnerability scanners such as Nessus and Qualys.
- Experience integrating security into CI/CD pipelines using SAST and DAST.
Technologies
- DoD, RMF
- SIEM, EDR/XDR, firewalls, vulnerability scanners
- Splunk, Sentinel, Nessus, Qualys
- Zero Trust
- AWS, Azure, GCP
- NIST 800-53, NIST 800-171, ISO 27001, CMMC, SOC 2
- SAST, DAST
- DoD 8570.01-M, IAM, Security+ CE, CySA+, CASP+, CISSP
- SSP, POA&M, ST&E, Body of Evidence (BoE)
- CI/CD
Desired Skills
- Experience in Cross-Domain Solutions (CDS), air-gapped networks, and highly classified defense environments, including work supporting legacy-to-cloud or hybrid-cloud security transitions.
- Security leadership experience as a Lead, Architect, or ISSE responsible for the security roadmap of a product line, program, or business unit.
- Proficiency in Python, Go, or PowerShell for security automation (SOAR) and infrastructure as code such as Terraform and Ansible; familiarity with PKI, HSMs, and emerging quantum-resistant encryption.
- Experience with red teaming and adversarial simulation, and applying ML/AI techniques for anomaly detection and threat hunting, plus a history of security community contributions (white papers, conferences, open-source).