Senior Information Security Analyst

Wood River Federal, LLC

San Antonio (TX)

On-site

USD 120,000 - 180,000

Full time

3 days ago
Be an early applicant
Application generator

Get a reply from this employer — a resume and cover letter tailored to exactly what they’re hiring for.

Get past ATS filters

Job summary

Wood River Federal, LLC is seeking a Senior Information Security Analyst to lead RMF/ATO activities, develop security artifacts, and ensure compliance with DoD and NIST standards. The role emphasizes risk management, vulnerability remediation, and security operations across the system lifecycle.

The ideal candidate will have extensive RMF experience, strong vulnerability management skills with ACAS/Nessus, proficiency with SIEM, and the ability to guide system owners and admins in enforcing

Qualifications

  • :// Must possess a minimum of seven (7) years of progressive experience in an information security, cybersecurity, or IA role.
  • // At least three (3) years of direct, hands-on experience serving as an ISSO or RMF/ATO process for DoD systems.
  • // DoD 8140 IAT Level II requirements via Security+ CE or higher.
  • // Advanced certifications such as CASP+ CE and CISM are highly desired.
  • // Eligible to obtain and hold a DoW security clearance.

Responsibilities

  • Lead RMF/ATO documentation and maintain SSP, Contingency Plan, and Incident Response Plan.
  • Perform vulnerability scanning and coordinate remediation with system administrators.
  • Monitor SIEM and other security tools to detect, respond to threats and conduct investigations.
  • Develop and enforce DoD-based security policies, STIGs, and security guidance across the system lifecycle.

Skills

RMF/NIST
Vulnerability Scanning
SIEM/Monitoring
DoD STIGs
Network Security
OS Hardening
Policy Guidance
Security Clearance Eligibility

Tools

ACAS/Nessus

Job description

The Senior Information Security Analyst is a highly experienced cybersecurity professionalresponsible for ensuring the confidentiality, integrity, and availability of an organization'sinformation systems. This role serves as a subject matter expert on all matters of operationalcybersecurity, leading efforts to secure systems, manage risks, and ensure compliance with allgoverning policies and regulations. The Senior Analyst is responsible for implementing andmanaging the security posture of assigned systems throughout their lifecycle, from initialauthorization to decommissioning. This individual works with system owners, administrators,and users to enforce security controls, respond to threats, and maintain the formal Authority toOperate (ATO).

Typical Task List:
Risk Management Framework (RMF) and Compliance:
  • - Lead the development, maintenance, and submission of all documentation required to achieve and maintain the system's ATO under the RMF process.
  • - Develop and maintain key security artifacts, including the System Security Plan (SSP), Contingency Plan, and Incident Response Plan.
  • - Conduct periodic reviews of security controls to ensure ongoing compliance and prepare the system for security assessments and audits.
Vulnerability Management and Remediation:
  • - Perform regular vulnerability scanning of systems and networks using approved tools (e.g., ACAS/Nessus).
  • - Analyze scan results, prioritize vulnerabilities based on severity and mission impact, and coordinate with system administrators to ensure timely remediation.
  • - Track and report on remediation progress, and develop Plans of Action and Milestones (POA&Ms) for vulnerabilities that cannot be immediately fixed.
Security Operations and Monitoring:
  • - Monitor security logs and alerts from various sources (e.g., SIEM, firewalls, endpoint security tools) to identify, analyze, and respond to suspicious activity.
  • - Serve as a key player in the security incident response process, including identifying the source of a threat, containing the impact, and leading eradication and recovery efforts.
  • - Conduct regular audits of user accounts and system access logs to detect and report unauthorized activity.
Policy and Guidance:
  • - Develop, implement, and enforce information security policies, procedures, and guidelines based on DoD, DAF, and NIST standards.
  • - Provide expert cybersecurity guidance and consultation to system owners, developers, and administrators to ensure security is integrated into all phases of the system lifecycle ("security by design").
  • - Promote security awareness by providing training and guidance to all system users.
Minimum Qualifications / Requirements
Experience:
  • - A minimum of seven (7) years of progressive experience in an information security, cybersecurity, or Information Assurance (IA) role.
  • - At least three (3) years of direct, hands-on experience serving as an Information Systems Security Officer (ISSO) or a similar role with responsibility for managing the RMF/ATO process for DoD systems.
Certifications (Baseline):
  • - Must possess a current CompTIA Security+ CE certification (or higher) to meet DoD 8140 requirements for IAT Level II.
Certifications (ISSO Environment - Desired):
  • - Advanced certifications demonstrating subject matter expertise are highly desired, such as:
  • CASP+ CE
  • CISM (Certified Information Security Manager)
Security Clearance:
  • Must be eligible to obtain and hold a DoW security clearance
Technical Skills:
  • - Expert-level knowledge of the Risk Management Framework (RMF) and NIST Special Publications (e.g., SP 800-53, SP 800-37).
  • - Proficiency with vulnerability scanning tools such as ACAS/Nessus.
  • - Strong understanding of network security, operating system hardening (Windows/Linux), and application security principles.
  • - Experience with Security Information and Event Management (SIEM) systems and other security monitoring tools.
  • - Familiarity with DoD Security Technical Implementation Guides (STIGs) and the STIGing process.
Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Information System Security Manager (ISSM)
Information System Security Manager (ISSM)

JFL Consulting LLC • Springfield (VA)

On-site
USD 155,000 - 175,000
Salary 155k-175k
Medical/dental/vision premiums
FSA accounts
+4
Information System Security Manager (Skill Level 2-3)
Information System Security Manager (Skill Level 2-3)

strategic-analytix-careers • Fort Meade (MD)

On-site
USD 120,000 - 160,000
Cyber Security Analyst (ISSO)
Cyber Security Analyst (ISSO)

General Dynamics IT • United States

Remote
USD 110,000 - 170,000
Information System Security Manager (Skill Level 2-3)
Information System Security Manager (Skill Level 2-3)

Strategic Analytix • Fort Meade (MD)

On-site
USD 120,000 - 180,000
Information Systems Security Officer (ISSO)
Information Systems Security Officer (ISSO)

The Mission Essential Group, LLC • Fairfax (VA)

On-site
USD 120,000 - 135,000
Medical insurance
Dental insurance
Vision insurance
+4
Senior Information System Security Manager
Senior Information System Security Manager

Cornerstone Defense LLC • Odenton (MD)

On-site
USD 145,000 - 165,000
Medical plan
Dental plan
Vision plan
+15
Information System Security Officer
Information System Security Officer

Peraton • Maryland

On-site
USD 110,000 - 170,000
Cybersecurity Analyst 1
Cybersecurity Analyst 1

Military, Veterans and Diverse Job Seekers • Stafford (VA)

On-site
USD 120,000 - 170,000
Information Systems Security Manager - Basic (ISSM-Basic)
Information Systems Security Manager - Basic (ISSM-Basic)

ACQCENTRIC INC • Huntsville (AL)

On-site
USD 90,000 - 140,000
Senior Information System Security Manager with Security Clearance
Senior Information System Security Manager with Security Clearance

Cornerstone Defense LLC • Odenton (MD)

On-site
USD 145,000 - 165,000
Medical/Dental/Vision plans
401(k) with match
HSA/FSA options
+1