Senior Information Security Analyst

Peregrine Technical Solutions, LLC

Petaluma (CA)

On-site

USD 100,000 - 140,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Medical insurance
Dental insurance
Vision insurance
401(k) with company matching
Paid time off
Professional development

Job summary

Peregrine Technical Solutions, LLC is seeking a Senior Information Security Analyst to own the cybersecurity posture for assigned networks and devices. The role requires deep knowledge of DoD RMF, DoDI directives, and U.S. Coast Guard cybersecurity requirements.

The candidate will manage accreditation activities, coordinate with PMs, engineers, and DBAs, and lead testing and documentation efforts across eMASS and DHS/DHS-related repositories. A federal clearance is a plus.

Qualifications

  • Minimum of five (5) years relevant experience.
  • Detailed knowledge of DoD Risk Management Framework (RMF).
  • Experience in IAO/ISSO or IAM/ISSM positions.
  • Appropriate professional certifications per DoD 8570.01 (CISSP, GSLC or equivalent).
  • Must be eligible for a federal Public Trust clearance.
  • Preferred: CISSP Certification.

Responsibilities

  • Manage Cyber security accreditation requirements with Program Manager and key personnel.
  • Ensure accreditation activities comply with DoDI 8500.01/8510.01 and RMF; maintain FISMA compliance.
  • Collaborate with leadership, developers, engineers, and DBAs to track system changes and maintain documentation in eMASS.
  • Schedule and document information system compliance testing including ACAS scans and contingency plan testing.
  • Use eMASS and Coast Guard tools to manage annual reviews and control tests.
  • Conduct annual reviews of system profiles and register essential waivers.
  • Serve as IAO/ISSO advising on security policy, configurations, and compliance.
  • Advise on ports, protocols, services (PPS) and register PPS in Coast Guard registry.
  • Identify STIGs for development/test and select vulnerability scanning tools (ACAS/SCAP).
  • Assist scanning and remediation of findings; prepare documentation for accreditations.
  • Provide security guidance for special projects including CDS development with USCG/CDSO/UCDMO.
  • Draft system documentation and architecture drawings for review by USCG/CDSO/UCDMO.
  • Offer authoritative cyber security input during reviews and guidance on CCRs, ACRs, DBCRs, QTRs, PRs, PTRs.

Skills

Leadership
Communication skills
Interpersonal skills
Collaboration
Excel proficiency

Education

Bachelor's degree in cybersecurity or related field
DoD 8570.01 certification (CISSP/GSLC or equivalent)

Tools

Excel
Word
PowerPoint
Outlook
Visio
Access

Job description

Overview

Please note that this position is contingent upon the successful award of a contract currently under bid.

Peregrine is a pioneer within the cybersecurity industrial control systems and the Internet of Things, supporting many federal and commercial customers. Peregrine's experienced staff knows the cybersecurity and operational technology environment and provides these capabilities for our customers daily.

Summary

The Senior Information Security Analyst is responsible for the overall cybersecurity of assigned networks and devices. They must have intimate knowledge of federal government, Department of Defense, and U.S. Coast Guard cybersecurity requirements.

Responsibilities
  • Aggressively manage Cyber security accreditation requirements by working closely with the Program Manager, system administrators, database administrators and other key personnel to ensure all system accreditations remain current.
  • Ensure that all initial and recurring certification and accreditation activities are completed in accordance with DoDI 8500.01, Cyber Security, and DoDI 8510.01, Risk Management Framework (RMF) for assigned information systems, as well as maintaining compliance with the Federal Information Security Management Act (FISMA) of 2002 and other applicable directives for the assigned information systems
  • Working directly with leadership, developers, engineers, system and database administrators to track changes to the system configurations and software, conducting regular reviews, updates and maintenance of certification and accreditation plans, topology drawings, and associated documents, and uploading completed documents to eMASS.
  • Schedule, oversee and document information system compliance testing, to include weekly Assured Compliance Assessment Solution (ACAS) scans and annual execution and testing of the Contingency Plans.
  • Manage accreditation and annual compliance actions using eMASS and the U.S. Coast Guard tracking tools to ensure annual reviews, control tests and contingency plan tests are completed on schedule to comply with FSMA requirements and keep the Program Manager informed of compliance and status of ATO efforts via updates to the PM's Drumbeat and Metrics products.
  • Conduct a continuous review of all applications and database tools that make up the family of systems to ensure all software versions are registered and approved for use by the U.S. Coast Guard.
  • Conduct an annual review and update of all parent and child system profiles in the DHS approved repository system to ensure system's registrations are complete and accurate, and that essential waivers for Data-At-Rest (DAR) and unsupported Commercial-Off-The-Shelf (COTS) software are documented and approved by U.S. Coast Guard CIO so that accreditations are not adversely affected.
  • Serve as Information Assurance Officer (IAO)/Information Systems Security Officer (ISSO), directly advising and assisting the Program Manager, developers, engineers, system and database administrators and staff on all cyber security policy, configuration and compliance matters.
    • This includes all aspects of cyber security that may affect the system security posture, to include emerging threats published in Cyber Alerts, Communication Tasking Orders, and vulnerability alerts and bulletins issued under the Information Assurance Vulnerability Management program.
  • As IAO/ISSO, advise the team on ports, protocols and services (PPS) approved for use by the U.S. Coast Guard, and register new PPS in the U.S. Coast Guard PPS Management Registry.
  • Prior to testing, identify Security Technical Implementation Guides (STIGs) to be applied to systems under development and test, and identify appropriate vulnerability scanning tools to be used during testing, to include the ACAS and Security Content Automation Protocol (SCAP) Compliance Checker automated scanning tools.
  • The IAO/ISSO will assist during scanning and advise the team on the remediation of findings identified during testing.
  • Following testing, the IAO will collect, collate, review and validate all test results and prepare supporting documentation, reports and artifacts to support the certification and accreditation of the system. Following accreditation, the IAO/ISSO will track and manage open findings in the Risk Assessment Report until mitigated or closed.
  • Provide expert advice in support of special projects, to include the development of an automated Cross Domain Solution (CDS) for use by the program and closely coordinate actions with the U.S. Coast Guard Cross Domain Solutions Office (USCGCDSO) and the Department of Homeland Security Unified Cross Domain Management Office (UCDMO).
    • This support includes authoring and submitting detailed system documentation and architectural drawings and working closely with both USCGCDSO and UCDMO personnel to navigate through a complex and highly technical approval process.
  • On a daily and weekly basis, provide authoritative cyber security advice during Internal Review Boards and make recommendations on open Configuration Change Requests (CCRs); Application Change Requests (ACRs), Database Change Requests (DBCRs), QA Trouble Reports (QTRs), Problem Reports (PRs), and Program Trouble Reports (PTRs).
Qualifications
Necessary Skills and Knowledge
  • Proven record of honesty and integrity in all relationships.
  • Demonstrated leadership and organizational skills.
  • Excellent interpersonal skills and a collaborative management style.
  • Excellent communication skills, both verbal and written.
  • Excellent computer skills and proficient in Excel, Word, PowerPoint, Outlook, Visio, and Access.
Minimum Qualifications
  • Minimum of five (5) years relevant experience.
  • Detailed knowledge of DoD Risk Management Framework
  • Experience in an IAO/ISSO or Information Assurance Manager (IAM)/Information Systems Security Manager (ISSM) position.
  • Appropriate professional certifications per DoD 8570.01 (CISSP, GSLC or equivalent).
  • Must be eligible for a federal Public Trust clearance.
Preferred Qualifications
  • Bachelors degree in cybersecurity or related degree
  • CISSP Certification
Pay and Benefits

The annual salary range for this position is $100,000 to $140,000.

We provide a comprehensive benefits package, including medical, dental, and vision insurance, a 401(k) plan with company matching, tax-deferred savings options, supplementary benefits, paid time off, and professional development opportunities.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Information Security Analyst
Senior Information Security Analyst

Peregrine Technical Solutions • Petaluma (CA)

On-site
USD 100,000 - 140,000
Senior Information Security Analyst
Senior Information Security Analyst

Goldbelt, Inc. • Petaluma (CA)

On-site
USD 100,000 - 140,000
Cybersecurity Engineer
Cybersecurity Engineer

Socket.dev • Alexandria (VA)

On-site
USD 130,000 - 160,000
Flexible scheduling
On-site in Suitland, MD
Senior Cybersecurity Analyst
Senior Cybersecurity Analyst

GovCIO • Kearneysville (WV)

Hybrid
USD 112,000 - 142,000
Journeyman Cybersecurity Analyst
Journeyman Cybersecurity Analyst

GovCIO • Alexandria (VA)

Hybrid
USD 100,000 - 130,000
Sr. Experienced Cybersecurity Engineer - Charleston, SC
Sr. Experienced Cybersecurity Engineer - Charleston, SC

Serco Canada Inc • Charleston (SC)

On-site
USD 80,000 - 120,000
Medical, dental, and vision insurance
401(k) plan with employer matching
Tuition reimbursement
Information Systems Security Officer
Information Systems Security Officer

Future Technologies Inc. • King George (VA)

On-site
USD 105,000 - 140,000
Information Systems Security Manager (ISSM)
Information Systems Security Manager (ISSM)

Abacus Technology Corporation • Lincoln (MA)

On-site
USD 175,000 - 196,000
Health and Dental Insurance
401(k) and Matching
Life Insurance
+4
Cybersecurity Systems Analyst, Sr.
Cybersecurity Systems Analyst, Sr.

TJ Consulting Group • Coronado (CA)

On-site
USD 120,000 - 170,000
PTO
Holiday Pay
401K with a 4% Match
+13
Cybersecurity Analyst/Information Systems Security Manager
Cybersecurity Analyst/Information Systems Security Manager

CACI International Inc • Alexandria (VA)

On-site
USD 73,000 - 149,000