Senior Cybersecurity Analyst / ISSO
Job Description
GovCIO LLC is looking for a Senior Cybersecurity Analyst / ISSO to support a U.S. Coast Guard (USCG) Software Yard mission system on a hybrid basis in Kearneysville, WV. In this role, you will serve as the designated alternate Information System Security Officer (aISSO) while embedding cybersecurity practices across the continuous software delivery lifecycle to help maintain secure, maintainable, and compliant operations.
Core responsibilities
- Lead the RMF process by generating, assessing, and maintaining tailored RMF documentation packages using Government tools, including SSP, CMP, IRP, CP, POA&Ms, Scorecards, SAR, threat models, and boundary diagrams, and ensure DoD IS documentation remains current and accessible to authorized personnel.
- Review, update, and publish artifacts across all DHS SELC phases for unclassified efforts, and support timely A&A submissions to avoid ATO expiration.
- Coordinate and support external inspections, audits, and assessments, including direct collaboration with stakeholders.
- Track system POA&Ms from creation through closure, validate AOR weakness remediations, manage proper channel routing, provide status reports, collect closure artifacts, and identify items requiring waivers or risk acceptance.
- Interpret system designs to identify data interconnections, interfaces, and protocols, then develop connection approval packages such as ISA, MOU, and SLA for USCG LANs (DoDIN, CGOne) to minimize risk.
- Support organizational Requests for Modification (RFM) processes and procedures, participate in change management boards, and conduct Security Impact Assessments (SIA).
- Perform testing and control assessments using automated DISA STIG/SRG tools, conduct Security Readiness Reviews (SRR), and analyze automated scans from DISA SCAP/SCC, ACAS, and Nessus.
- Initiate protective and corrective measures when issues are discovered, establish user reporting pipelines for threats, and coordinate forensic analysis with CGCyber CSOC.
- Maintain HBSS compliance by reviewing HBSS reports and monitoring and remediating rogue devices.
- Review exception and exclusion requests and provide technical recommendations for Government approval.
- Audit system logs and intrusion detection data weekly, request weekly audit triggers to correlate daily records, analyze threat vectors across disparate systems, and report any log data integrity gaps to the Government.
- Coordinate annual Contingency Plan (CP) training and testing before policy expiration, and manage annual Disaster Recovery (DR) Failover testing and documentation.
Required qualifications
- DoD 8570 IAT Level II certification (Security+ CE, CySA+, CCNA Security, or equivalent).
- 9+ years of DoD cybersecurity analysis experience, specializing in application security, software assurance, or cloud security within a federal environment.
- Experience analyzing and remediating vulnerabilities found by automated scanning tools within modern CI/CD software delivery models.
- Operational understanding of DISA STIGs, NIST RMF, and federal authorization boundaries.
- Experience embedding security requirements into Agile engineering frameworks, product backlogs, and rapid release environments.
- Ability to track, manage, and report cyber risks using enterprise tools such as Jira, Azure DevOps, Tenable Security Center, or ServiceNow.
- Foundational understanding of diverse IT domains including enterprise architectures.
- Clearance Required: Public Trust.
- Education: High School (plus 9+ years, or commensurate experience).
Technology and tools
- DISA STIG/SRG tools, DISA SCAP/SCC, ACAS, Nessus
- HBSS, Jira, Azure DevOps, Tenable Security Center, ServiceNow
- Agile, CI/CD, Kubernetes, Docker, AWS, Azure, OWASP Top 10
- RMF, SELC, STIG, SRG, SCAP, SCC, CP, DR
Preferred skills
- Experience supporting U.S. Coast Guard, Software Yard, or Department of Homeland Security (DHS) programs.
- Familiarity with USCG PEO C5I enterprise security strategies, software assurance policies, and continuous Authority to Operate (cATO) pathways.
- Relevant professional cybersecurity certifications (highly preferred), such as CISSP, CEH, CISM, or DevSecOps security credentials.
- Understanding secure containerization concepts (Kubernetes, Docker) and automated security gating in DevSecOps environments.
- Familiarity with hybrid-cloud architecture (AWS, Azure) and securing web applications against OWASP Top 10.
Location: Kearneysville, WV (hybrid).
Salary: USD $115,000 to $145,000 per year.