Cyber Security Analyst (ISSO)

General Dynamics Information Technology, Inc.

Ramstein-Miesenbach

Remote

EUR 90,000 - 125,000

Full time

5 days ago
Be an early applicant
Application generator

A complete application in a minute — tailored resume and cover letter, ready to send.

Get past ATS filters

Job summary

General Dynamics Information Technology, Inc. is seeking a Cyber Security Analyst (ISSO) to maintain the DoD system security posture, perform continuous monitoring, and ensure RMF/DoD baselines across coalition environments.

You will work with ISSMs, system owners, and network teams to enforce security controls throughout the system lifecycle. The role requires hands-on experience with Splunk Enterprise/ES, ACAS/Tenable, and Trellix ePO, plus eMASS for compliance management and POA&M

Qualifications

  • Bachelor’s degree or equivalent experience in a technical field.
  • 7+ years of progressive experience in cybersecurity or security operations supporting DoD systems.
  • Active DoD 8570.01-M / DoD 8140 baseline certification at IAT Level III.

Responsibilities

  • Perform daily security event reviews, log analysis, and system auditing across servers, network infrastructure, and operating systems in coalition enclaves.
  • Develop and execute SPL queries, correlate events across data sources, and design Splunk dashboards and alerts.
  • Monitor and manage vulnerability programs with ACAS/Tenable; triage findings and support POA&Ms.
  • RMF & eMASS administration: SSPs, continuous monitoring, control assessments, and POA&Ms.

Skills

Splunk SPL queries
Dashboard creation
RMF/DoD compliance
Scripting (Bash/Python/PowerShell)
Communication to ISSMs
Cybersecurity operations

Education

Bachelor’s degree in Cybersecurity/CS/IT or related field

Tools

Splunk Enterprise/ES
ACAS/Tenable
Trellix ePO
eMASS

Job description

The Cyber Security Analyst (ISSO) is responsible for maintaining the operational security posture, continuous monitoring, and regulatory compliance of assigned Department of Defense (DoD) information systems and coalition network environments. The Cyber Security Analyst (ISSO) works closely with the Information System Security Manager (ISSM), system owners, and network/systems engineering teams to enforce DoD cybersecurity baselines and technical controls throughout the system lifecycle.

This role requires hands-on experience with core enterprise cybersecurity tools, including Splunk Enterprise/Enterprise Security (ES), Tenable/ACAS, and Trellix ePolicy Orchestrator (ePO), to drive real-time telemetry analysis, vulnerability management, endpoint compliance, and continuous monitoring (ConMon) under the NIST Risk Management Framework (RMF). All compliance tracking, documentation, and authorization management for assigned systems is executed within eMASS.

Primary Responsibilities
1. SIEM, Security Analytics & Continuous Monitoring
  • Perform daily security event reviews, log analysis, and system auditing across servers, network infrastructure, and operating systems in coalition enclaves.
  • Develop and execute complex Search Processing Language (SPL) queries in Splunk Enterprise/ES to aggregate and correlate events across multiple data sources.
  • Design, implement, and maintain Splunk dashboards, visualizations, and alerts to detect anomalous activity, policy violations, and unauthorized access attempts.
  • Troubleshoot log ingestion, forwarding, parsing, and telemetry issues, ensuring comprehensive and accurate data collection.
  • Validate NTP time synchronization and log integrity across distributed network devices and servers.
  • Ensure audit records are collected, retained, and protected in accordance with DoD policies and applicable regulations.
2. Vulnerability Management & Endpoint Administration
  • Operate and maintain the Assured Compliance Assessment Solution (ACAS) utilizing Tenable Security Center and Nessus scanners across enclave infrastructure.
  • Configure, schedule, and execute authenticated/unauthenticated credentialed scans for servers, network devices, databases, and workstations.
  • Manage ACAS scan policies, credentials, and plugin updates to ensure comprehensive vulnerability coverage.
  • Analyze scan results, validate findings, triage false positives, and track remediation in support of Plans of Action and Milestones (POA&Ms).
  • Administer Trellix ePO within the enterprise enclave, including agent deployment, policy enforcement, update scheduling, and verification of signature/definition compliance.
  • Produce endpoint compliance metrics and operational reports for leadership, system administrators, and inspection teams.
3. Enclave Boundary Defense & Security Administration
  • Monitor and maintain the security posture of enclave gateways, firewalls, boundary devices, and intrusion detection/prevention systems (IDS/IPS).
  • Help protect enclave resources against unauthorized access, modification, destruction, or disclosure.
  • Review change requests and conduct Security Impact Analyses (SIA) for system modifications, port/protocol changes, and routing updates.
  • Coordinate with systems and network administrators to ensure security and monitoring requirements are integrated into system deployments and changes.
4. Risk Management Framework (RMF) & eMASS Administration
  • Support end-to-end RMF activities in eMASS, including maintaining System Security Plans (SSPs), continuous monitoring strategies, and security control implementation statements.
  • Populate, update, and manage system milestones, control assessments, test results, and POA&Ms within eMASS.
  • Verify implementation and enforcement of DISA Security Technical Implementation Guides (STIGs) and Security Requirements Guides (SRGs) across assigned systems.
Required Qualifications

Education & Experience

  • Bachelor’s degree in Cybersecurity, Computer Science, Information Technology, or a related technical discipline.Equivalent relevant experience, military training, or technical certifications may be considered in lieu of a degree.
  • 7+ years of progressive experience in cybersecurity, information assurance, or security operations supporting DoD systems and networks.

Certifications

  • Active DoD 8570.01-M / DoD 8140 baseline certification meeting IAT Level III

Technical Experience

  • Hands-on operational experience with Splunk Enterprise and/or Splunk Enterprise Security (ES), including SPL query development, correlation searches, dashboard creation, alerting, and forwarder troubleshooting.
  • Demonstrated experience configuring, executing, and troubleshooting ACAS/Tenable scans; managing plugins and credentials; and assessing vulnerability findings in support of POA&M management.
  • Experience administering Trellix ePO in an enterprise environment, including policy tuning, agent management, and endpoint compliance reporting.
  • Proven proficiency using eMASS as the primary RMF governance tool for managing packages, documenting controls, uploading test results, and managing POA&Ms.
  • In-depth experience implementing and remediating DISA STIGs and SCAP benchmarks for Windows/Linux systems, applications, and network infrastructure.

Clearance

  • Active DoD Secret security clearance (or higher), with the ability to maintain the clearance as a condition of employment.

Preferred Qualifications

  • Active IAT Level III certification (e.g., CASP+ CE, CISSP, or equivalent).
  • Prior experience securing and monitoring coalition or partner network enclaves (e.g., CENTRIXS, BICES, Mission Partner Environments [MPE]).
  • Advanced proficiency with eMASS package management, workflow transitions, and artifact mapping.
  • Tool-specific certifications such as Splunk Certified Power User/Enterprise Admin or Tenable Certified Nessus Auditor.
  • Scripting experience (e.g., Bash, Python, PowerShell) to support automation of log parsing, reporting, and administrative workflows.
  • Strong written and verbal communication skills, including experience presenting technical risk and compliance posture to ISSMs, system owners, and other stakeholders.

#DefenseOCONUS

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Cybersecurity Lead
Cybersecurity Lead

Lucayan Technology Solutions LLC • Germany

On-site
EUR 80,000 - 116,000
User Activity Monitoring (UAM) Analyst
User Activity Monitoring (UAM) Analyst

The Mission Essential Group • Stuttgart

On-site
EUR 90,000 - 130,000
Cyber Response Analyst / Active TS/SCI
Cyber Response Analyst / Active TS/SCI

Peraton • Wiesbaden

Hybrid
EUR 70,000 - 100,000
Systems Engineer - SOC
Systems Engineer - SOC

Grohe • Germany

On-site
EUR 60,000 - 90,000
Sr Information Assurance Engineer
Sr Information Assurance Engineer

Intrepid Global Solutions • Wiesbaden

On-site
EUR 90,000 - 130,000
CMS ISSO- Project 1032 (Computer Sys Security Anlyst 3)- 30554
CMS ISSO- Project 1032 (Computer Sys Security Anlyst 3)- 30554

Mission Technologies, a division of HII • Ramstein-Miesenbach

On-site
EUR 93,000 - 116,000
Cybersecurity Engineer - Cloud, Ops (human)
Cybersecurity Engineer - Cloud, Ops (human)

NEURA Robotics • Germany

On-site
USD 120,000 - 160,000
Security Specialist - EUCOM Planning & Facilities Support
Security Specialist - EUCOM Planning & Facilities Support

AMERICAN SYSTEMS • Ramstein-Miesenbach

On-site
EUR 120,000 - 180,000
Vulnerability Management / Incident Response Specialist
Vulnerability Management / Incident Response Specialist

Hhw Group • Germany

On-site
EUR 70,000 - 90,000
Offensive Security Analyst
Offensive Security Analyst

Sonoco • Hub

On-site
EUR 60,000 - 85,000