Cyber Information Assurance Analyst

Penn State University (ARL)

Pennsylvania

On-site

USD 70,000 - 90,000

Full time

14 days+
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Job summary

Penn State University (ARL) is seeking a Cyber Information Assurance Analyst to assess risk, ensure compliance, and support the security posture of departmental systems in the Risk Management Department of the Applied Research Laboratory. The role involves vulnerability management and collaboration with stakeholders on policy and configuration improvements.

On-site position based in State College, PA with possible project-dependent hybrid options.

Qualifications

  • Bachelor's Degree in a related field
  • 1+ years of relevant experience; or an equivalent combination of education and experience
  • Active Top-Secret/SCI clearance required or eligible

Responsibilities

  • Conduct risk assessments and provide recommendations for system, network, and application design, implementation, and operation of departmental systems
  • Conduct vulnerability assessments of departmental systems and networks to identify deviations from acceptable configurations or policies
  • Meet with stakeholders regularly to assess needs and requirements at a departmental level
  • Monitor the corrective actions of departmental system audits; draft documentation of Plan of Action and Milestones (POAM) for review
  • Obtain certification and accreditation for departmental systems through the creation of process documentation support; may assist with unit or University wide process documentation
  • Participate in the establishment of program control processes to ensure risk mitigation
  • Perform periodic audits of departmental systems under general supervision
  • Participate in the implementation of required policies, procedures, and configurations; make recommendations for improvements
  • Participate in the preparation of requirements and procedures for forensic preservation
  • Research and stay current on industry best practices

Skills

Windows OS
Linux OS
RMF
DoD RMF
CI/CD pipeline
ACAS
STIG
Security+
CAP
GSEC
Top-Secret/SCI clearance

Education

Bachelor's Degree

Tools

Gitlab
Ansible
JIRA
Confluence
OpenSCAP
Trivy
Grype

Job description

POSITION SPECIFICS

We are searching for a Cyber Information Assurance Analyst to join the Risk Management Department in the Applied Research Laboratory (ARL) at Penn State. The CIAA evaluates system and network environments to implement effective cybersecurity programs and determines security controls and policies based on best practices, regulations, and contractual requirements. This role includes managing compliance assessments, mitigating risks to information systems, and ensuring confidentiality, integrity, and availability. CMS Division leverages M&S expertise and other resources to deliver prototypes, demonstrations, and accelerated transitions of emerging research and technologies vital to national security needs, in addition to performing research, development, testing, and evaluations facilitating innovation in practice and development of critical, in-demand capabilities. ARL is an authorized DoD SkillBridge partner and welcomes all transitioning military members to apply.



Approval of remote and hybrid work is not guaranteed regardless of work location. For additional information on remote work at Penn State, see Notice to Out of State Applicants.


You will:


  • Conduct risk assessments and provide recommendations for system, network, and application design, implementation, and operation of departmental systems

  • Conduct vulnerability assessments of departmental systems and networks to identify deviations from acceptable configurations or policies

  • Meet with stakeholders regularly to assess needs and requirements at a departmental level

  • Monitor the corrective actions of departmental system audits; draft documentation of Plan of Action and Milestones (POAM) for review

  • Obtain certification and accreditation for departmental systems through the creation of process documentation support; may assist with unit or University wide process documentation

  • Participate in the establishment of program control processes to ensure risk mitigation

  • Perform periodic audits of departmental systems under general supervision

  • Participate in the implementation of required policies, procedures, and configurations; make recommendations for improvements

  • Participate in the preparation of requirements and procedures for forensic preservation

  • Research and stay current on industry best practices


Additional responsibilities for higher level position includes:


  • Lead risk assessments and provide recommendations for system, network, and application design, implementation, and operation of unit-wide systems

  • Lead vulnerability assessments of unit-wide systems and networks to identify deviations from acceptable configurations or policies; conduct assessments of non-standard systems

  • Monitor the corrective actions of unit-wide system audits; develop and manage Plan of Action and Milestones (POAM)

  • Meet with stakeholders regularly to assess needs and requirements at a unit-wide level

  • Obtain certification and accreditation through the creation of process documentation; develop unit or University-wide process documentation

  • Establish program control processes to ensure risk mitigation

  • Perform periodic audits of systems

  • Implement required policies, procedures, and configurations; make recommendations for improvements

  • Develop requirements and procedures for forensic preservation

  • Assist in the development of policy, process, and standards of Cyber Incident Response Team (CIRT) program and participate in CIRT activities as needed

  • Assist in the development and delivery of information security training material

  • May interface with external entities including law enforcement and intelligence/government agencies

  • May provide guidance to lower level Analysts


Required skills/knowledge areas include:


  • Windows and Linux OS

  • CI/CD pipeline

  • Review of hardware and software vulnerabilities

  • DoD Risk Management Framework (RMF)

  • Understand and enforce policies and procedures within classified space

  • Previous success with collaborations in a multi-disciplinary, team-oriented culture

  • Assured Compliance Assessment Solution (ACAS) and Security Technical Implementation Guide (STIG)

  • Ability to multitask multiple programs

  • Security+, CAP, GSEC or equivalent

  • Active security clearance, at the Top-Secret level and possession of or eligible for SCI level


Preferred Skills/Knowledge Include:


  • Development and maintenance of Security Assessment Plans, Risk Assessment Reports, and POAMs

  • Containerized environments

  • Gitlab and Ansible

  • JIRA and Confluence

  • Vulnerability scanning tools (ACAS, OpenSCAP, Trivy, Grype, etc.)


Your working location will be fully on-site located in State College, PA, but options exist for hybrid of on-site/work from home based on project-dependent ability. Questions related to flexible work should be directed to the hiring manager during the interview process.


Travel is expected to be at 50% of the time to surrounding areas.


Minimum Education, Work Experience & Required Certifications


  • Bachelor's Degree

  • 1+ years of relevant experience; or an equivalent combination of education and experience accepted

  • Required Certifications:

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Cyber Information Assurance Analyst
Cyber Information Assurance Analyst

The Pennsylvania State University • Reston (VA)

On-site
USD 56,000 - 103,000
Comprehensive benefits package
75% tuition discount for employees
Paid time off
Cyber Information Assurance Analyst
Cyber Information Assurance Analyst

The Applied Research Laboratory at Penn State University • University Park (TX)

On-site
USD 69,000 - 132,000
Tuition discount
Cyber Information Assurance Analyst
Cyber Information Assurance Analyst

Penn State University • University Park (TX)

On-site
USD 69,000 - 132,000
75% tuition discount
Cyber Information Assurance Analyst
Cyber Information Assurance Analyst

The Applied Research Laboratory at Penn State University • Reston (VA)

On-site
USD 56,000 - 103,000
75% tuition discount
Comprehensive medical, dental, and vision coverage
Robust retirement plans
+1
Cyber Security Engineer
Cyber Security Engineer

The Applied Research Laboratory at Penn State University • Reston (VA)

On-site
USD 85,000 - 120,000
Secure Systems Research and Development Engineer
Secure Systems Research and Development Engineer

The Applied Research Laboratory at Penn State University • Reston (VA)

On-site
USD 110,000 - 241,000
Tuition discount 75%
Competitive benefits package
Vulnerability Research Engineer
Vulnerability Research Engineer

The Applied Research Laboratory at Penn State University • University Park (TX)

Hybrid
USD 127,000 - 277,000
IT Platform Administrator (ARL)
IT Platform Administrator (ARL)

The Applied Research Laboratory at Penn State University • University Park (TX)

On-site
USD 80,000 - 133,000
Tuition discount
Competitive benefits package
Cyber Security Engineer Intern
Cyber Security Engineer Intern

The Applied Research Laboratory at Penn State University • University Park (TX)

On-site
USD 2,066,000 - 3,031,000
Paid internship
IT Platform Administrator (ARL)
IT Platform Administrator (ARL)

Penn State University • University Park (TX)

Hybrid
USD 80,000 - 132,000
75% tuition discount