Cybersecurity Analyst / Information Systems Security Officer (ISSO)

KBR Careers

Colorado Springs (CO)

On-site

USD 90,000 - 105,000

Full time

14 days+
Application generator

Get a reply from this employer — a resume and cover letter tailored to exactly what they’re hiring for.

Get past ATS filters

Benefits offered by this job

401K with company match
Medical, dental, vision
Paid time off
Flexible work schedule

Job summary

KBR is seeking a Cybersecurity Analyst / Information Systems Security Officer (ISSO) to join our team at Peterson SFB in Colorado Springs, CO. An active TS/SCI clearance is required. The role involves applying RMF controls, vulnerability management, and maintaining security baselines for control systems.

Responsibilities include creating RMF artifacts, coordinating with teams, and ensuring compliance with DoD security policies. Onsite work with a focus on national security programs.

Qualifications

  • Active TS/SCI clearance required.
  • DoD Directive (DoDD) 8140.01 certification; 2+ years related experience.
  • Knowledge of RMF, eMASS/XACTA, vulnerability management.

Responsibilities

  • Convert accreditation packages from DoDRMF Rev.4 to Rev.5.
  • Compile and track vulnerabilities and mitigation results.
  • Apply security policies to meet system objectives.
  • Maintain security configuration baselines for control systems.
  • Perform asset management and inventories of control systems.
  • Develop RMF package documentation across networks.

Skills

TS/SCI clearance
DoD 8140.01 Certification
Agile lifecycle
Security policies
Vulnerability management
Analytical skills

Education

Bachelor’s Degree in IT or Cybersecurity
GSEC/SCNP/SSCP/CISSP or higher

Tools

RMF controls
eMASS
XACTA

Job description

Cybersecurity Analyst / Information Systems Security Officer (ISSO)

Belong. Connect. Grow. with KBR!

KBR’s National Security Solutions team provides high-end engineering and advanced technology solutions to our customers in the intelligence and national security communities. In this position, your work will have a profound impact on the country’s most critical role – protecting our national security.

Why Join Us?
  • Innovative Projects: KBR’s work is at the forefront of engineering, logistics, operations, science, program management, mission IT and cybersecurity solutions.
  • Collaborative Environment: Be part of a dynamic team that thrives on collaboration and innovation, fostering a supportive and intellectually stimulating workplace.
  • Impactful Work: Your contributions will be pivotal in designing and optimizing defense systems that ensure national security and shape the future of space defense.
Job Summary

KBR is seeking a Cybersecurity Analyst / Information Systems Security Officer (ISSO) to join our team at Peterson SFB in Colorado Springs, CO. An active TS/SCI clearance is required. The individual will work in close coordination with current team members to ensure systems are operated, maintained, and disposed of in accordance with applicable security policies and procedures. Duties may include but are not limited to: Perform activities to convert accreditation packages from DoDRMF Rev. 4 to Rev. 5 Compiling and tracking vulnerabilities and mitigation results in quantifying program effectiveness, creating and maintaining vulnerability management policies, procedures and training Apply security policies to meet security objectives of the system Apply updates, patches, and security technical implementation while maintaining control system performance and availability requirements Establish and maintain security configuration baseline for the control system(s), including IT components, interconnections, and interfaces Implement Risk Management Framework (RMF) Assessment requirements for control systems, and document/maintain records for them Maintain knowledge of the function and security of control system and IT technologies with which the control systems interface Perform asset management and maintain inventory of control system devices and components through physical inspection or logical scans Support risk assessments by reviewing and documenting the implementation status of security requirements of control systems Mitigate/correct security deficiencies identified during security/certification testing and/or recommend risk acceptance for the appropriate senior leader or authorized representative Provide input to the Risk Management Framework process activities and related documentation (e.g., system life-cycle support plans, concept of operations, operational procedures, and maintenance training materials) Reviewing and defining requirements for information security solutions, controls compliance and policy development Organizing network-based scans to identify possible network security attacks and host-based scans to identify vulnerabilities in workstations, servers and other network hosts determining critical security flaws and figuring out how to fix them Conduct audits and assessments focused on uncover vulnerabilities in the networks through scanning tools Assist in improving and automating existing vulnerability management lifecycle including but not limited to data ingestion & normalization, compliance metrics and detections on assets Assist in partnering with tools and technology teams to troubleshoot, develop, select, implement, and automate appropriate security solutions to keep system data protected from internal and external threats Assist in providing support and resolution for scanning and vulnerability remediation reporting issues Assist in working to effectively communicate the risks of identified vulnerabilities and make recommendations regarding the selection of cost-effective security controls to mitigate identified risks. Stay current with vulnerability information across all the products in the AVAC environment Work as part of an integrated team to develop and maintain RMF body of evidence documentation using Enterprise Mission Assurance Support Service (eMASS), XACTA or equivalent products Maintain repositories of all body of evidence documentation for systems under your purview Develop and execute security control assessment procedures to verify conformance with control requirements as part of ongoing continuous monitoring and authorization assessment activities Ensure all security-related vulnerabilities and deficiencies are documented in the Plan of Action and Milestones (POA&M) for each system Ensure configuration management policies and procedures for authorizing use of hardware/software are followed and coordinate any system baseline changes with the appropriate stakeholders prior to change Assisting with creating and maintaining RMF package documentation for multiple networks Advise ISSM of compliance issues, findings and status related to the system packages.

Duties may include but are not limited to:
  • Perform activities to convert accreditation packages from DoDRMF Rev. 4 to Rev. 5
  • Compiling and tracking vulnerabilities and mitigation results in quantifying program effectiveness, creating and maintaining vulnerability management policies, procedures and training
  • Apply security policies to meet security objectives of the system
  • Apply updates, patches, and security technical implementation while maintaining control system performance and availability requirements
  • Establish and maintain security configuration baseline for the control system(s), including IT components, interconnections, and interfaces
  • Implement Risk Management Framework (RMF) Assessment requirements for control systems, and document/maintain records for them
  • Maintain knowledge of the function and security of control system and IT technologies with which the control systems interface
  • Perform asset management and maintain inventory of control system devices and components through physical inspection or logical scans
  • Support risk assessments by reviewing and documenting the implementation status of security requirements of control systems
  • Mitigate/correct security deficiencies identified during security/certification testing and/or recommend risk acceptance for the appropriate senior leader or authorized representative
  • Provide input to the Risk Management Framework process activities and related documentation (e.g., system life-cycle support plans, concept of operations, operational procedures, and maintenance training materials)
  • Reviewing and defining requirements for information security solutions, controls compliance and policy development
  • Organizing network-based scans to identify possible network security attacks and host-based scans to identify vulnerabilities in workstations, servers and other network hosts determining critical security flaws and figuring out how to fix them
  • Conduct audits and assessments focused on uncover vulnerabilities in the networks through scanning tools
  • Assist in improving and automating existing vulnerability management lifecycle including but not limited to data ingestion & normalization, compliance metrics and detections on assets
  • Assist in partnering with tools and technology teams to troubleshoot, develop, select, implement, and automate appropriate security solutions to keep system data protected from internal and external threats
  • Assist in providing support and resolution for scanning and vulnerability remediation reporting issues
  • Assist in working to effectively communicate the risks of identified vulnerabilities and make recommendations regarding the selection of cost-effective security controls to mitigate identified risks.
  • Stay current with vulnerability information across all the products in the AVAC environment
  • Work as part of an integrated team to develop and maintain RMF body of evidence documentation using Enterprise Mission Assurance Support Service (eMASS), XACTA or equivalent products
  • Maintain repositories of all body of evidence documentation for systems under your purview
  • Develop and execute security control assessment procedures to verify conformance with control requirements as part of ongoing continuous monitoring and authorization assessment activities
  • Ensure all security-related vulnerabilities and deficiencies are documented in the Plan of Action and Milestones (POA&M) for each system
  • Ensure configuration management policies and procedures for authorizing use of hardware/software are followed and coordinate any system baseline changes with the appropriate stakeholders prior to change
  • Assisting with creating and maintaining RMF package documentation for multiple networks
  • Advise ISSM of compliance issues, findings and status related to the system packages
Required Qualifications
  • Active TS/SCI clearance required
  • DoD Directive (DoDD) 8140.01certification, Security+ 2+ years of related experience
  • Working knowledge of DoDRMF Rev.4 and/or 5, cyber technologies, NIST standards and DISA STIG governance
  • Must have experience in the Agile Lifecycle to include, requirements, design, development, implementation, deployment and remediation
  • Excellent technical document preparation and verbal communication skills are required
  • Strong working knowledge of Confidentiality, Integrity, and Availability (CIA) concepts such as patch management, multi-factor authentication, host-based security, intrusion detection, security event management and defense-in-depth
  • This position requires strong analytical skills for known vulnerabilities and system compliance
  • Effective interpersonal skills are required with a demonstrated ability to support complex organizational relationships
Desired Qualifications
  • Bachelor’s Degree (IT or Cybersecurity related) or equivalent related experience
  • GSEC, SCNP, SSCP, CISSP or higher
  • Experience with RMF controls, eMASS or XACTA, risk assessment, Plan of Actions and Milestones (POAMs), policy and plans documentation, Information Assurance Vulnerability Management (IAVM) and vulnerability assessment for mission systems
Work Environment

Location: Onsite

Work Hours: Standard

Compensation: For Colorado only, the salary range for this position is approximately $90,000 - $105,000. The offered rate will be based on the selected candidate’s knowledge, skills, abilities and/or experience and in consideration of internal parity.

Other Compensation: KBR may offer bonuses, commissions, or other forms of compensation to certain job titles or levels, per internal policy or contractual designation. Additional compensation may be in the form of sign on bonus, relocation benefits, short term incentives, long term incentives, or discretionary payments for exceptional performance.

KBR Benefits
  • KBR offers a selection of competitive lifestyle benefits which could include 401K plan with company match, medical, dental, vision, life insurance, AD&D, flexible spending account, disability, paid time off, or flexible work schedule.
  • We support career advancement through professional training and development.

Belong, Connect and Grow at KBR At KBR, we are passionate about our people and our Zero Harm culture. These inform all that we do and are at the heart of our commitment to, and ongoing journey toward being a People First company. That commitment is central to our team of team’s philosophy and fosters an environment where everyone can Belong, Connect and Grow. We Deliver – Together. KBR is an equal opportunity employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, disability, sex, sexual orientation, gender identity or expression, age, national origin, veteran status, genetic information, union status and/or beliefs, or any other characteristic protected by federal, state, or local law. KBR — Delivering Solutions, Changing the World. KBR brings together the best and brightest to deliver science, technology and engineering solutions that help governments and companies around the world accomplish their most critical missions and objectives. In everything we do, we are guided by our ONE KBR Values: We Value Our People – We create diverse, inclusive environments in which each person can feel safe, respected and valued, and where everyone has opportunities to grow and reach their full potential. We Deliver – We are uncompromising in our commitment to deliver innovative, high-quality, technology-led solutions for our customers and exceptional, sustainable value for all our stakeholders. We Are People of Integrity – We value honesty, trust, courage, fairness, prudence and tenacity. We believe doing what’s right for the planet, the communities where we work, and our people is good for business. We Empower – We empower our people with a shared purpose, the right tools and the supportive culture they need to be proactive decision-makers, to be adaptive to change, and to succeed. We Are a Team of Teams – We have a will to succeed, but we value the achievements of our team of teams over individual accomplishments. Our collective focus makes us a better, stronger, more effective company. We have also embedded environmental, social and governance (ESG) principles in every business operation and corporate function. Not only are we committed to operating safely, sustainably and equitably, but we are also committed to using our capabilities and expertise to help our customers accomplish their sustainability goals. Worldwide, KBR employs a diverse workforce approximately 29,000 people strong, with customers in more than 80 countries and operations in 40 countries. At KBR, We Deliver.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Information Systems Security Officer (ISSO)
Information Systems Security Officer (ISSO)

KBR Careers • Colorado Springs (CO)

On-site
USD 104,000 - 157,000
Sign-on bonus
Relocation benefits
Bonuses and incentives
Senior Information System Security Officer (ISSO)
Senior Information System Security Officer (ISSO)

KBR Careers • Town of Vienna (WI)

On-site
USD 160,000 - 196,000
401K
Medical insurance
Dental plan
+6
Information System Security Officer (ISSO)
Information System Security Officer (ISSO)

KBR Careers • Town of Vienna (WI)

On-site
USD 142,000 - 174,000
401K match
Medical insurance
Dental insurance
+7
Information System Security Officer (ISSO)
Information System Security Officer (ISSO)

KBR Careers • Washington

On-site
USD 110,000 - 140,000
Information System Security Engineer (ISSE)
Information System Security Engineer (ISSE)

KBR Careers • Lanham (MD)

On-site
USD 110,000 - 140,000
Cybersecurity Manager
Cybersecurity Manager

KBR Careers • Washington

On-site
USD 214,000 - 321,000
Cybersecurity SME
Cybersecurity SME

KBR Careers • Town of Vienna (WI)

On-site
USD 176,000 - 215,000
401K plan with company match
medical
dental
+3
Cybersecurity Practitioner
Cybersecurity Practitioner

KBR Careers • Oklahoma City (OK)

On-site
USD 85,000 - 120,000
Cybersecurity Analyst / Information Systems Security Officer (ISSO)
Cybersecurity Analyst / Information Systems Security Officer (ISSO)

KBR, Inc • Colorado Springs (CO)

On-site
USD 90,000 - 105,000
Cyber System Security Engineer (CSSE)
Cyber System Security Engineer (CSSE)

KBR Careers • El Segundo (CA)

On-site
USD 150,000 - 185,000