Senior Cybersecurity Analyst / ISSO (SWY-CD)

GovCIO

Kearneysville (WV)

Hybrid

USD 115,000 - 145,000

Full time

43 hours ago
Be an early applicant
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Job summary

GovCIO in Kearneysville, WV is seeking a Senior Cybersecurity Analyst to serve as an aISSO for a US Coast Guard program. This hybrid role ensures mission software and platforms remain secure and compliant throughout the software delivery lifecycle.

As a primary technical resource, you will enforce RMF, perform vulnerability assessments, manage POA&Ms, and coordinate with CGCyber CSOC to protect critical systems.

Qualifications

  • DoD 8570 IAT Level II certification required (Security+ CE, CySA+, CCNA Security, or equivalent).
  • DoD cybersecurity analysis experience in federal environments (application security, software assurance, or cloud security).
  • Experience remediating vulnerabilities from automated scanning tools in CI/CD environments.
  • Operational understanding of DISA STIGs, NIST RMF, and federal authorization boundaries.
  • Experience embedding security into Agile frameworks, backlogs, and rapid releases.
  • Proficient with enterprise tools to track and report cyber risks (Jira, Azure DevOps, Tenable, ServiceNow).
  • Strong foundation in diverse IT domains including enterprise architectures.
  • Clearance: Public Trust

Responsibilities

  • Lead RMF process and maintain tailored documentation packages.
  • Support A&A lifecycles and external inspections and assessments.
  • Track POA&Ms and coordinate risk remediations and waivers.
  • Interpret designs to minimize risk; develop approval packages for USCG LANs.
  • Maintain change control and conduct Security Impact Assessments.
  • Perform vulnerability assessments using DISA tools and SRR analyses.
  • Coordinate incident response with CGCyber CSOC and HBSS compliance.
  • Review logs and audit data; report data integrity gaps to Government.
  • Coordinate annual contingency and disaster recovery testing.

Skills

DoD 8570 IAT II
Cybersecurity analysis
Vulnerability remediation
RMF/STIGs knowledge
Security in Agile
Cyber risk tooling
Enterprise architecture

Education

High School or equivalent

Tools

Jira
Azure DevOps
Tenable Security Center
ServiceNow

Job description

Overview

GovCIO is seeking a

Overview

GovCIO is seeking a Senior Cybersecurity Analyst to support a critical government computer system for the U.S. Coast Guard (USCG) Software Yard – Capability Development Branch. Located in Kearneysville, WV as a hybrid position, this role primarily ensures that all mission software, applications, and technology platforms remain secure, maintainable, and compliant with federal regulations throughout the continuous software delivery lifecycle. The successful candidate will serve as the designated alternate Information System Security Officer (aISSO) for assigned systems.

Responsibilities

As a Senior Cybersecurity Analyst and aISSO, you will serve as a primary technical resource for enforcing architectural coherence, enterprise security standards, and long-term sustainability across platform-aligned Product Teams. You will embed cybersecurity practices into modern delivery models to prevent vulnerabilities, manage risk, and maintain authorizations. Key responsibilities are:

  • RMF & Compliance: Lead the RMF process. Generate, assess, and maintain tailored RMF documentation packages (including SSP, CMP, IRP, CP, POA&Ms, Scorecards, SAR, threat models, and boundary diagrams) using Government tools. Ensure all DoD IS documentation is current and accessible to authorized personnel.
  • A&A Lifecycles: Review, update, and publish artifacts supporting unclassified efforts across all DHS SELC phases. Ensure timely A&A submissions to prevent ATO expiration. Provide direct collaboration and support for external inspections, audits, and assessments.
  • POA&M Management: Track all system POA&Ms from creation to closure. Coordinate with stakeholders to validate AOR weakness remediations, manage proper channel routing, provide status reports, gather closure artifacts, and identify items requiring waivers or risk acceptance.
  • Engineering & Architecture: Interpret system designs to identify data interconnections, interfaces, and protocols to minimize USCG risk. Develop connection approval packages (ISA, MOU, SLA) for USCG LANs (DoDIN, CGOne).
  • Change Control: Maintain processes and procedures enabling adherence to organizational Requests for Modification (RFM). Participate in change management boards and conduct Security Impact Assessments (SIA).
  • Vulnerability Assessments: Perform testing and control assessments using automated DISA STIG/SRG tools. Conduct Security Readiness Reviews (SRR) and analyze automated scans from DISA SCAP/SCC, ACAS, and Nessus.
  • Incident Response & HBSS: Initiate protective/corrective measures upon discovery and establish user reporting pipelines for threats. Coordinate forensic analysis with CGCyber CSOC. Maintain HBSS compliance, review HBSS reports, and monitor/remediate rogue devices.
  • Log Auditing & Reviews: Review exception/exclusion requests and provide technical recommendations for Government approval. Audit system logs and intrusion detection data weekly. Request weekly audit triggers to correlate daily records, analyze threat vectors across disparate systems, and report log data integrity gaps to the Government.
  • Testing: Coordinate annual Contingency Plan (CP) training/testing before policy expiration, and manage annual Disaster Recovery (DR) Failover testing/documentation.
Qualifications

High School with 9+ years (or commensurate experience)

Required Skills & Experience
  • DoD 8570 IAT Level II certification (Security+ CE, CySA+, CCNA Security, or equivalent).
  • DoD Cybersecurity analysis experience specializing in application security, software assurance, or cloud security within a federal environment.
  • Proven experience analyzing and remediating vulnerabilities identified by automated scanning tools within modern software delivery models (CI/CD).
  • Comprehensive operational understanding of DISA STIGs, NIST Risk Management Framework (RMF), and federal authorization boundaries.
  • Strong experience embedding security requirements into Agile engineering frameworks, product backlogs, and rapid release environments.
  • Proficiency tracking, managing, and reporting cyber risks using enterprise tools (such as Jira, Azure DevOps, Tenable Security Center, or ServiceNow).
  • Strong foundational understanding of diverse IT domains including enterprise architectures.

Clearance Required: Public Trust

Preferred Skills & Experience
  • Experience supporting U.S. Coast Guard, Software Yard, or Department of Homeland Security (DHS) programs.
  • Familiarity with USCG PEO C5I enterprise security strategies, software assurance policies, and continuous Authority to Operate (cATO) pathways.
  • Relevant professional cybersecurity certifications highly preferred (e.g., CISSP, CEH, CISM, or DevSecOps security credentials).
  • Understanding secure containerization concepts (Kubernetes, Docker) and automated security gating within DevSecOps environments.
  • Familiarity with hybrid-cloud architecture (AWS, Azure) and securing web applications against OWASP Top 10 vulnerabilities.

Posted Salary Range: USD $115,000.00 - USD $145,000.00 /Yr.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Senior Cybersecurity Analyst / ISSO (SWY-CD)
Senior Cybersecurity Analyst / ISSO (SWY-CD)

GovCIO • US Coast Guard - Operations Systems Center (WV)

Hybrid
USD 115,000 - 145,000
Journeyman Cybersecurity Analyst
Journeyman Cybersecurity Analyst

GovCIO • Alexandria (VA)

On-site
USD 100,000 - 130,000
Senior Information Security Analyst
Senior Information Security Analyst

Peregrine Technical Solutions, LLC • Petaluma (CA)

On-site
USD 100,000 - 140,000
Medical insurance
Dental insurance
Vision insurance
+3
Senior Information Security Analyst
Senior Information Security Analyst

Peregrine Technical Solutions • Petaluma (CA)

On-site
USD 100,000 - 140,000
Senior Information Security Analyst
Senior Information Security Analyst

Goldbelt, Inc. • Petaluma (CA)

On-site
USD 100,000 - 140,000
Senior Functional Analyst (SWY-CD)
Senior Functional Analyst (SWY-CD)

GovCIO • Kearneysville (WV)

On-site
USD 65,000 - 85,000
Senior Information System Security Engineer (ISSE)
Senior Information System Security Engineer (ISSE)

Central Strategies, LLC • Alexandria (VA), Northern (KY)

Hybrid
USD 140,000 - 190,000
Senior Cybersecurity Analyst & aISSO (Hybrid) - RMF/A&A
Senior Cybersecurity Analyst & aISSO (Hybrid) - RMF/A&A

GovCIO • Kearneysville (WV)

Hybrid
USD 115,000 - 145,000
Hybrid Senior Cybersecurity Analyst — RMF, A&A Lead
Hybrid Senior Cybersecurity Analyst — RMF, A&A Lead

GovCIO • US Coast Guard - Operations Systems Center (WV)

Hybrid
USD 115,000 - 145,000
Senior Systems Engineer (NSGS)
Senior Systems Engineer (NSGS)

GovCIO • Alexandria (VA)

On-site
USD 120,000 - 145,000