Senior Information Security Analyst

Goldbelt, Inc.

Petaluma (CA)

On-site

USD 100,000 - 140,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Goldbelt, Inc. is seeking a Senior Information Security Analyst to oversee the cybersecurity of assigned networks and devices, with intimate knowledge of DoD RMF, FISMA, and U.S. Coast Guard requirements.

You will work with program managers, system and database administrators, and engineers to maintain accreditations, coordinate testing (ACAS), and document compliance in eMASS, while advising on cross-domain solutions for USCGCDSO and UCDMO.

Qualifications

  • Five (5) years relevant experience in DoD RMF or related field.
  • Detailed knowledge of DoD Risk Management Framework (RMF).
  • Experience in an IAO/ISSO or IAM/ISSM position.
  • DoD 8570.01 certifications (CISSP, GSLC or equivalent).
  • Eligible for a federal Public Trust clearance.
  • Bachelor’s degree in cybersecurity or related field.
  • CISSP Certification preferred.

Responsibilities

  • Manage cyber security accreditation requirements with Program Manager and admins to keep accreditations current.
  • Ensure compliance with DoDI 8500.01, DoDI 8510.01, FISMA for assigned information systems.
  • Coordinate with leadership, developers, engineers, and DBAs to track changes and maintain documentation in eMASS.
  • Schedule and document information system compliance testing, including ACAS scans.
  • Advise on cross-domain solutions with USCG and DHS; author system documentation and drawings.
  • Provide cyber security guidance during reviews and various change requests.

Skills

Leadership
Interpersonal skills
Communication skills
Honesty
Excel
Word
PowerPoint
Outlook
Visio
Access

Education

Bachelor's degree in cybersecurity or related field
CISSP Certification

Tools

Excel
Word
PowerPoint
Outlook
Visio
Access

Job description

Overview

Please note that this position is contingent upon the successful award of a contract currently under bid.

Peregrine is a pioneer within the cybersecurity industrial control systems and the Internet of Things, supporting many federal and commercial customers. Peregrine's experienced staff knows the cybersecurity and operational technology environment and provides these capabilities for our customers daily.

Summary:

The Senior Information Security Analyst is responsible for the overall cybersecurity of assigned networks and devices. They must have intimate knowledge of federal government, Department of Defense, and U.S. Coast Guard cybersecurity requirements.

Responsibilities

Essential Job Functions:

  • Aggressively manage Cyber security accreditation requirements by working closely with the Program Manager, system administrators, database administrators and other key personnel to ensure all system accreditations remain current.
  • Ensure that all initial and recurring certification and accreditation activities are completed in accordance with DoDI 8500.01, Cyber Security, and DoDI 8510.01, Risk Management Framework (RMF) for assigned information systems, as well as maintaining compliance with the Federal Information Security Management Act (FISMA) of 2002 and other applicable directives for the assigned information systems.
  • Working directly with leadership, developers, engineers, system and database administrators to track changes to the system configurations and software, conducting regular reviews, updates and maintenance of certification and accreditation plans, topology drawings, and associated documents, and uploading completed documents to eMASS.
  • Schedule, oversee and document information system compliance testing, to include weekly Assured Compliance Assessment Solution (ACAS) scans and annual execution and testing of the Contingency Plans.
  • Manage accreditation and annual compliance actions using eMASS and the U.S. Coast Guard tracking tools to ensure annual reviews, control tests and contingency plan tests are completed on schedule to comply with FSMA requirements and keep the Program Manager informed of compliance and status of ATO efforts via updates to the PM’s Drumbeat and Metrics products.
  • Conduct a continuous review of all applications and database tools that make up the family of systems to ensure all software versions are registered and approved for use by the U.S. Coast Guard.
  • Conduct an annual review and update of all parent and child system profiles in the DHS approved repository system to ensure system’s registrations are complete and accurate, and that essential waivers for Data-At-Rest (DAR) and unsupported Commercial-Off-The-Shelf (COTS) software are documented and approved by U.S. Coast Guard CIO so that accreditations are not adversely affected.
  • Serve as Information Assurance Officer (IAO)/Information Systems Security Officer (ISSO), directly advising and assisting the Program Manager, developers, engineers, system and database administrators and staff on all cyber security policy, configuration and compliance matters.
    • This includes all aspects of cyber security that may affect the system security posture, to include emerging threats published in Cyber Alerts, Communication Tasking Orders, and vulnerability alerts and bulletins issued under the Information Assurance Vulnerability Management program.
  • As IAO/ISSO, advise the team on ports, protocols and services (PPS) approved for use by the U.S. Coast Guard, and register new PPS in the U.S. Coast Guard PPS Management Registry.
  • Prior to testing, identify Security Technical Implementation Guides (STIGs) to be applied to systems under development and test, and identify appropriate vulnerability scanning tools to be used during testing, to include the ACAS and Security Content Automation Protocol (SCAP) Compliance Checker automated scanning tools.
  • The IAO/ISSO will assist during scanning and advise the team on the remediation of findings identified during testing.
  • Following testing, the IAO will collect, collate, review and validate all test results and prepare supporting documentation, reports and artifacts to support the certification and accreditation of the system. Following accreditation, the IAO/ISSO will track and manage open findings in the Risk Assessment Report until mitigated or closed.
  • Provide expert advice in support of special projects, to include the development of an automated Cross Domain Solution (CDS) for use by the program and closely coordinate actions with the U.S. Coast Guard Cross Domain Solutions Office (USCGCDSO) and the Department of Homeland Security Unified Cross Domain Management Office (UCDMO).
    • This support includes authoring and submitting detailed system documentation and architectural drawings and working closely with both USCGCDSO and UCDMO personnel to navigate through a complex and highly technical approval process.
  • On a daily and weekly basis, provide authoritative cyber security advice during Internal Review Boards and make recommendations on open Configuration Change Requests (CCRs); Application Change Requests (ACRs), Database Change Requests (DBCRs), QA Trouble Reports (QTRs), Problem Reports (PRs), and Program Trouble Reports (PTRs).
Qualifications

Necessary Skills and Knowledge:

  • Proven record of honesty and integrity in all relationships.
  • Demonstrated leadership and organizational skills.
  • Excellent interpersonal skills and a collaborative management style.
  • Excellent communication skills, both verbal and written.
  • Excellent computer skills and proficient in Excel, Word, PowerPoint, Outlook, Visio, and Access.

Minimum Qualifications:

  • Minimum of five (5) years relevant experience.
  • Detailed knowledge of DoD Risk Management Framework.
  • Experience in an IAO/ISSO or Information Assurance Manager (IAM)/Information Systems Security Manager (ISSM) position.
  • Appropriate professional certifications per DoD 8570.01 (CISSP, GSLC or equivalent).
  • Must be eligible for a federal Public Trust clearance.

Preferred Qualifications:

  • Bachelors degree in cybersecurity or related degree.
  • CISSP Certification.
Pay and Benefits

The annual salary range for this position is $100,000 to $140,000.

At Goldbelt, we value and reward our team's dedication and hard work. We provide a competitive base salary commensurate with your qualifications and experience. As an employee, you'll enjoy a comprehensive benefits package, including medical, dental, and vision insurance, a 401(k) plan with company matching, tax-deferred savings options, supplementary benefits, paid time off, and professional development opportunities.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Information Security Analyst
Senior Information Security Analyst

Peregrine Technical Solutions • Petaluma (CA)

On-site
USD 100,000 - 140,000
Senior Information Security Analyst
Senior Information Security Analyst

Peregrine Technical Solutions, LLC • Petaluma (CA)

On-site
USD 100,000 - 140,000
Medical insurance
Dental insurance
Vision insurance
+3
Cybersecurity Engineer
Cybersecurity Engineer

Socket.dev • Alexandria (VA)

On-site
USD 130,000 - 160,000
Flexible scheduling
On-site in Suitland, MD
Senior Cybersecurity Analyst
Senior Cybersecurity Analyst

GovCIO • Kearneysville (WV)

Hybrid
USD 112,000 - 142,000
Journeyman Cybersecurity Analyst
Journeyman Cybersecurity Analyst

GovCIO • Alexandria (VA)

Hybrid
USD 100,000 - 130,000
Sr. Experienced Cybersecurity Engineer - Charleston, SC
Sr. Experienced Cybersecurity Engineer - Charleston, SC

Serco Canada Inc • Charleston (SC)

On-site
USD 80,000 - 120,000
Medical, dental, and vision insurance
401(k) plan with employer matching
Tuition reimbursement
Information Security Analyst
Information Security Analyst

ARMADA, Ltd. • Washington

On-site
USD 80,000 - 100,000
Cybersecurity Analyst/Information Systems Security Manager
Cybersecurity Analyst/Information Systems Security Manager

CACI International Inc • Alexandria (VA)

On-site
USD 73,000 - 149,000
Information Security Analyst
Information Security Analyst

Armada LTD • Washington

On-site
USD 70,000 - 90,000
Cybersecurity Systems Analyst, Sr.
Cybersecurity Systems Analyst, Sr.

TJ Consulting Group • Coronado (CA)

On-site
USD 120,000 - 170,000
PTO
Holiday Pay
401K with a 4% Match
+13