Senior Information Security Analyst

Wood River Federal

San Antonio (TX)

On-site

USD 100,000 - 150,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Wood River Federal is seeking a Senior Information Security Analyst to safeguard information systems across their lifecycle, enforcing RMF controls, maintaining ATOs, and guiding security posture. The role collaborates with system owners, admins, and users to enforce security controls and respond to threats.

The position requires deep expertise in RMF, NIST SP 800-53/37, STIGs, and vulnerability management, with responsibilities spanning policy development, incident response, and risk

Qualifications

  • A minimum of seven years of progressive information security experience.
  • At least three years as ISSO or RMF/ATO lead for DoD systems.
  • Must possess a current CompTIA Security+ CE certification (or higher) for DoD 8140 IAT Level II.
  • CASP+ CE and CISM are desirable.

Responsibilities

  • Lead the RMF/ATO process including development, maintenance and submission of documentation.
  • Coordinate with system owners and administrators to ensure timely remediation of vulnerabilities and POA&Ms.
  • Monitor security logs and alerts from SIEMs and other security tools; respond to incidents and perform eradication and recovery.
  • Develop, implement and enforce information security policies, procedures, and guidelines based on DoD, DAF, and NIST standards.

Skills

RMF knowledge
Incident response
Vulnerability management
Security monitoring
Policy guidance
Security training

Tools

ACAS/Nessus
SIEM tools
STIGs

Job description

The Senior Information Security Analyst is a highly experienced cybersecurity professionalresponsible for ensuring the confidentiality, integrity, and availability of an organization'sinformation systems. This role serves as a subject matter expert on all matters of operationalcybersecurity, leading efforts to secure systems, manage risks, and ensure compliance with allgoverning policies and regulations. The Senior Analyst is responsible for implementing andmanaging the security posture of assigned systems throughout their lifecycle, from initialauthorization to decommissioning. This individual works with system owners, administrators,and users to enforce security controls, respond to threats, and maintain the formal Authority toOperate (ATO).


Typical Task List:

Risk Management Framework (RMF) and Compliance:


  • Lead the development, maintenance, and submission of all documentation required to achieve and maintain the system's ATO under the RMF process.

  • Develop and maintain key security artifacts, including the System Security Plan (SSP), Contingency Plan, and Incident Response Plan.

  • Conduct periodic reviews of security controls to ensure ongoing compliance and prepare the system for security assessments and audits.


Vulnerability Management and Remediation:


  • Perform regular vulnerability scanning of systems and networks using approved tools (e.g., ACAS/Nessus).

  • Analyze scan results, prioritize vulnerabilities based on severity and mission impact, and coordinate with system administrators to ensure timely remediation.

  • Track and report on remediation progress, and develop Plans of Action and Milestones (POA&Ms) for vulnerabilities that cannot be immediately fixed.


Security Operations and Monitoring:


  • Monitor security logs and alerts from various sources (e.g., SIEM, firewalls, endpoint security tools) to identify, analyze, and respond to suspicious activity.

  • Serve as a key player in the security incident response process, including identifying the source of a threat, containing the impact, and leading eradication and recovery efforts.

  • Conduct regular audits of user accounts and system access logs to detect and report unauthorized activity.


Policy and Guidance:


  • Develop, implement, and enforce information security policies, procedures, and guidelines based on DoD, DAF, and NIST standards.

  • Provide expert cybersecurity guidance and consultation to system owners, developers, and administrators to ensure security is integrated into all phases of the system lifecycle (\"security by design\").

  • Promote security awareness by providing training and guidance to all system users.


Minimum Qualifications / Requirements

Experience:


  • A minimum of seven (7) years of progressive experience in an information security, cybersecurity, or Information Assurance (IA) role.

  • At least three (3) years of direct, hands-on experience serving as an Information Systems Security Officer (ISSO) or a similar role with responsibility for managing the RMF/ATO process for DoD systems.


Certifications (Baseline):


  • Must possess a current CompTIA Security+ CE certification (or higher) to meet DoD 8140 requirements for IAT Level II.


Certifications (ISSO Environment - Desired):


  • CASP+ CE

  • CISM (Certified Information Security Manager)


Must be eligible to obtain and hold a DoW security clearance


Technical Skills:


  • Expert-level knowledge of the Risk Management Framework (RMF) and NIST Special Publications (e.g., SP 800-53, SP 800-37).

  • Proficiency with vulnerability scanning tools such as ACAS/Nessus.

  • Strong understanding of network security, operating system hardening (Windows/Linux), and application security principles.

  • Experience with Security Information and Event Management (SIEM) systems and other security monitoring tools.

  • Familiarity with DoD Security Technical Implementation Guides (STIGs) and the STIGing process.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Information Security Analyst
Information Security Analyst

Sanmina • Huntsville (AL)

On-site
USD 95,000 - 125,000
Information Security Analyst
Information Security Analyst

SANMINA-SCI TECHNOLOGY INDIA PRIVATE LIMITED • Huntsville (AL)

On-site
USD 95,000 - 140,000
Information Security Specialists (Intermediate/Senior)
Information Security Specialists (Intermediate/Senior)

Vets Hired • Orlando (FL)

On-site
USD 90,000 - 130,000
Information Security Specialists (Intermediate/Senior)
Information Security Specialists (Intermediate/Senior)

Koitecc Solutions • Orlando (FL)

On-site
USD 85,000 - 110,000
Senior ISSO Security Analyst (AA SR)
Senior ISSO Security Analyst (AA SR)

STAFFXPERT LLC • United States

On-site
USD 120,000 - 180,000
Information System Security Officer
Information System Security Officer

Peraton • Maryland

On-site
USD 110,000 - 170,000
Information Systems Security Officer
Information Systems Security Officer

Peraton • Maryland

On-site
USD 100,000 - 130,000
Information Assurance Engineer
Information Assurance Engineer

Agile IT Synergy, LLC • Tampa (FL)

On-site
USD 90,000 - 130,000
Information System Security Officer (ISSO) / System Administrator
Information System Security Officer (ISSO) / System Administrator

SANMINA-SCI TECHNOLOGY INDIA PRIVATE LIMITED • Huntsville (AL)

On-site
USD 90,000 - 120,000
Information Assurance / Security Specialist
Information Assurance / Security Specialist

Diverse Systems Group, LLC • Bethesda (MD)

On-site
USD 110,000 - 150,000