Cyber Security Analyst II

Scientific Research Corporation

San Diego (CA)

On-site

USD 84,000 - 140,000

Full time

6 days ago
Be an early applicant
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Benefits offered by this job

Medical, dental, and vision plans
401(k) with company match
Paid time off & holidays
Tuition reimbursement

Job summary

Scientific Research Corporation is seeking an experienced cybersecurity professional in San Diego to develop authorization packages, perform continuous monitoring, and coordinate remediation actions with system engineers. The role requires DoD 8140/IAT II certification and RMF knowledge.

Ability to use ACAS/Nessus, SCAP, eMASS, and other tools, plus strong collaboration with admins and developers. U.S. citizenship and security clearance eligibility required.

Qualifications

  • 5-8 years of cybersecurity experience.
  • Must hold a DoD 8140-compliant IAT II certification (Security+CE with CE/OS) or IAT II within six months.
  • Knowledge of RMF v3 and v5 (processes/workflow).
  • Experience with SSPs, POA&Ms, ACAS/Nessus, SCAP, DISA STIGs, and ATO artifacts.
  • Ability to coordinate STIG remediation with admins and developers.
  • Experience with continuous monitoring tools such as LATTEART, BISCOTTI, and CYBORGBUNNY.
  • Proficient in using eMASS for RMF v5 documentation and status.
  • Open to new and innovative ideas.
  • Must be able to be appointed ISSO for NCS systems within 6 months.

Responsibilities

  • Develop and update assessment and authorization documents (Body of Evidence) for management and continuous monitoring.
  • Perform ongoing compliance assessments using ACAS/SCAP and other tools and document results.
  • Verify patches and virus definitions with automated tools.
  • Follow configuration and change-management policies before software implementation.
  • Conduct security audits to track events and anomalies.
  • Perform security assessments of NCS systems per NIST/Navy/NSA/NAVINTEL guidance.
  • Collaborate with sys admins and ISSEs to remediate issues.
  • Conduct Site Based Security Assessments (SBSA) and seek DAO authorization as a Trusted Agent.
  • Report incidents as per CIRP.
  • Ensure systems are operated, maintained, and disposed of per security policies.

Skills

Cybersecurity experience
DoD 8140 IAT II
RMF v3/v5
System security awareness

Tools

ACAS
Nessus
SCAP
eMASS
XACTA
HBSS
SPLUNK

Job description

Salary Statement
Estimated Starting Salary Range: USD $84,000.00/Yr. - USD $139,950.00/Yr. Salary to be determined by the education, experience, knowledge, skills, and abilities of the applicant, internal equity, and alignment with market data.
Description
  • Developing and updating assessment and authorization documentation (Body of Evidence) for management and continuous monitoring of information systems
  • Performing ongoing compliance assessments using tools, such as Assured Compliance Assessment Solution (ACAS), Secure Content Automation Protocol (SCAP), and Trellix Virus Scan Enterprise while reviewing, documenting, and maintaining all results
  • Verifying patches and virus definitions to the systems using existing automated tools
  • Adhering to pre-defined configuration management and change management policies and procedures for authorizing software prior to its implementation on systems
  • Performing security audits using to track multiple events including any signs of inappropriate or unusual activity, intrusion events, data transfers, etc.
  • Performing security assessments of NCS Family of Systems in accordance with NIST, Navy, NSA, and NAVINTEL IA guidance
  • Working with system engineers to take corrective action to resolve identified problems
  • Performing Site Based Security Assessments (SBSAs) of systems and recommending authorization to the Designated Authorizing Official (DAO) as a certified Trusted Agent
  • Reporting security incidents in accordance with the Command Incident Response Plan (CIRP)
  • Ensuring systems are operated, used, maintained, and disposed of in accordance with all applicable security policies and practices

#LI-AM1

Requirements
  • 5-8 years of cybersecurity experience
  • Must currently hold a DoD 8140-compliant IAT II certification (Security+CE with appropriate CE/OS certificate), or IAT level II certification within six months
  • Knowledge of Risk Management Framework (RMF) v3 and v5 (Processes, workflow, etc.)
  • Experience with System Security Plans (SSPs), POA&Ms, ACAS/Nessus, SCAP, DISA STIGs, and all ATO package artifacts
  • Ability to work collaboratively with sys admins/ISSE's, communicate effectively, and coordinate STIG remediation with system administrators and developers
  • Experience with continuous monitoring tools such as LATTEART, BISCOTTI, and CYBORGBUNNY
  • Ability to manage tasks with little to no oversight or support as well as manage multiple, and at times, competing priorities without loss of productivity
  • Ability to use eMASS to execute, RMF v5, to include document and update system status, identify, document, and manage implementation of operational and technical security controls, implementation and risk assessment tabs, non-compliant and non-validated controls, POAM management (entry, evidence, close-out), produce report and track Plan of Action and Milestone (POA&M) due dates, etc.
  • Beopen to new and innovative ideas
  • Must be able to be appointedISSOfor NCS systems within 6 months of employment
Desired Skills
  • Experience with Windows and UNIX based information systems standards with a working knowledge of networking devices
  • Knowledge of configuration and manual STIG reviews of various SQL databases, including MS SQL, PostgreSQL, MongoDB, MariaDB, MySQL, and Elasticsearch
  • Knowledge of web servers, including Apache Web Server, and Apache Tomcat
  • Experience with container security and DevSecOps
  • Knowledge of data flows and the ability to work up readable network topology and data flow diagrams
  • Experience with NAVINTEL IA and NSA enterprise services: Continuous Monitoring
  • Experience with the following systems/platforms/tools: XACTA, XACTA 360 (preferred), eMASS, HBSS, ACAS, Nessus, and SPLUNK
  • Experience implementing and/or monitoring for zero trust compliance
Clearance Information

SRC IS A CONTRACTOR FOR THE U.S. GOVERNMENT. THIS POSITION WILL REQUIRE U.S. CITIZENSHIP AS WELL AS A U.S. GOVERNMENT SECURITY CLEARANCE AT THE TOP SECRET / SCI LEVEL with CI POLY ELIGIBILITY

Travel Requirements
  • 1-2 annual trips possible
About Us

Scientific Research Corporation is an advanced information technology and engineering company that provides innovative products and services to government and private industry, as well as independent institutions. At the core of our capabilities is a seasoned team of highly skilled engineers and scientists with multidisciplinary backgrounds. This team is challenged daily to provide cutting edge technology solutions to our clients.

SRC offers a generous benefit package, including medical, dental, and vision plans, 401(k) with a company match, life insurance, vacation and sick paid time off accruals with amounts increasing based on role and years of service, 11 paid holidays, tuition reimbursement, and a work environment that encourages excellence and more. For positions requiring a security clearance, selected applicants will be subject to a government security investigation and must meet eligibility requirements for access to classified information.

EEO

Scientific Research Corporation is an equal opportunity employer that does not discriminate in employment.

All qualified applicants will receive consideration for employment without regard to their race, color, religion, sex, age, sexual orientation, gender identity, national origin, disability, protected veteran status, or any other protected characteristic under federal, state or local law.

Scientific Research Corporation endeavors to make www.scires.com accessible to any and all users. If you would like to contact us regarding the accessibility of our website or need assistance completing the application process, please contact jobs@scires.com for assistance. This contact information is for accommodation requests only and cannot be used to inquire about the status of applications.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Cyber Security Analyst II
Cyber Security Analyst II

Scientific Research Corporation • San Diego (CA)

On-site
USD 84,000 - 140,000
Cyber Security Analyst
Cyber Security Analyst

Scientific Research Corporation • Philadelphia

On-site
USD 90,000 - 120,000
Medical, dental, and vision plans
401(k) with company match
Life insurance
+2
Cyber Security Analyst
Cyber Security Analyst

Scires • Philadelphia

On-site
USD 85,000 - 105,000
Medical, dental, and vision plans
401(k) with company match
Tuition reimbursement
Security Engineer
Security Engineer

Scientific Research Corporation • Orlando (FL)

On-site
USD 90,000 - 130,000
Security Admin I (Part-time)
Security Admin I (Part-time)

Scientific Research Corporation • North Charleston (SC)

On-site
USD 28,000 - 41,000
Software Integrator
Software Integrator

Scientific Research Corporation • North Charleston (SC)

On-site
USD 90,000 - 150,000
Medical, dental, vision plans
401(k) with company match
Tuition reimbursement
+1
Systems Engineer II
Systems Engineer II

Scientific Research Corporation • San Diego (CA), Northern (KY)

Hybrid
USD 84,000 - 140,000
Cyber Security Analyst III
Cyber Security Analyst III

Scientific Research Corporation • North Charleston (SC)

On-site
USD 120,000 - 180,000
Medical, dental, vision plans
401(k) with company match
Paid time off (vacation and sick)
Cyber Security Architect
Cyber Security Architect

Scientific Research Corporation • San Angelo (TX)

On-site
USD 140,000 - 190,000
Cyber Range Event Systems Engineer
Cyber Range Event Systems Engineer

Scientific Research Corporation • United States

On-site
USD 80,000 - 120,000
Medical, dental, and vision plans
401(k) with company match
Tuition reimbursement
+1