Sr Cyber Sec Analyst

Scientific Research Corporation

North Charleston, Northern (SC, KY)

Hybrid

USD 150,000 - 190,000

Full time

34 hours ago
Be an early applicant
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Benefits offered by this job

Medical, dental, vision plans
401(k) with company match
Paid time off and holidays
Tuition reimbursement

Job summary

Scientific Research Corporation is seeking a senior cybersecurity professional to integrate secure practices across the software development lifecycle for government programs. You will review designs, perform RMF activities, coordinate remediation, and deliver technical reports to stakeholders.

The role requires TS/SCI clearance, CISSP, and extensive DevSecOps experience in fast-paced environments, with collaboration across developers and program managers on risk and security controls.

Qualifications

  • Active TS/SCI clearance with eligibility throughout employment
  • Active CISSP certification in good standing
  • Bachelor’s degree in cybersecurity, computer science, information systems, software engineering, engineering, or a related technical field
  • Eight or more years of progressive experience in cybersecurity, information assurance, application security, systems security engineering, or a related technical discipline
  • Three or more years of experience supporting cybersecurity activities on software development, software modernization, systems integration, or DevSecOps programs
  • Demonstrated experience applying cybersecurity principles within the SDLC, including requirements analysis, design review, development, testing, deployment, and sustainment
  • Experience with security-control assessment, risk analysis, vulnerability management, and remediation tracking
  • Working knowledge of NIST cybersecurity guidance and risk-management practices (RMF, 800-53, 800-37, 800-218)
  • Experience reviewing or analyzing vulnerability scans, SAST/DAST/ SCA findings and remediation
  • Familiarity with secure coding concepts and OWASP risks
  • Experience producing cybersecurity documentation and briefing materials
  • Experience obtaining ATO packages and continuous monitoring actions
  • Ability to communicate cybersecurity risks effectively to developers and stakeholders
  • Ability to work independently in a mission-focused government program environment

Responsibilities

  • Integrating cybersecurity requirements and security controls into the SDLC from requirements through deployment and sustainment
  • Reviewing system, application, interface, and architecture designs for cybersecurity risks and compliance with government requirements
  • Supporting implementation and maintenance of secure DevSecOps practices, including automated security testing and continuous monitoring
  • Conducting or supporting security assessments, control validation, risk analysis, and remediation tracking for software applications and infrastructure
  • Analyzing vulnerability scan results, application security findings, code-scanning results, and configuration-compliance data; validate findings and coordinate mitigation actions
  • Performing RMF activities, including preparation and maintenance of security documentation, assessment artifacts, risk registers, and POA&Ms
  • Evaluating security impacts of software releases, configuration changes, third-party components, and architecture modifications
  • Collaborating with developers to implement secure coding practices and remediate security defects
  • Supporting security incident analysis, root-cause analysis, corrective-action development, and after-action reporting
  • Developing technical reports, executive summaries, risk briefings, security recommendations, and status updates for stakeholders
  • Providing technical mentorship and quality review for junior cybersecurity analysts
  • Participating in Agile ceremonies and cybersecurity working groups

Skills

TS/SCI clearance
CISSP certification
Security communication
DevSecOps experience
SDLC cybersecurity
RMF/NIST knowledge
OWASP awareness
Independent worker
Risk communication

Education

Bachelor’s degree in a technical field
Master’s degree in cybersecurity/related field

Tools

GitLab
GitHub
Jira
Bitbucket
Docker
Kubernetes
OpenShift

Job description

#LI-LL1

Description
  • Integrating cybersecurity requirements and security controls into the software development lifecycle, from requirements definition through deployment and sustainment
  • Reviewing system, application, interface, and architecture designs for cybersecurity risks and compliance with applicable government requirements
  • Supporting implementation and maintenance of secure DevSecOps practices, including automated security testing and continuous monitoring
  • Conducting or supporting security assessments, control validation, risk analysis, and remediation tracking for software applications and supporting infrastructure
  • Analyzing vulnerability scan results, application security findings, code-scanning results, and configuration-compliance data; validate findings and coordinate mitigation actions
  • Performing Risk Management Framework (RMF) activities, including preparation and maintenance of security documentation, assessment artifacts, risk registers, and plans of action and milestones (POA&Ms)
  • Evaluating security impacts of software releases, configuration changes, third-party components, and architecture modifications
  • Collaborating with developers to implement secure coding practices and remediate security defects
  • Supporting security incident analysis, root-cause analysis, corrective-action development, and after-action reporting
  • Developing technical reports, executive summaries, risk briefings, security recommendations, and status updates for program and government stakeholders
  • Providing technical mentorship and quality review for junior cybersecurity analysts
  • Participating in Agile ceremonies, technical interchange meetings, architecture reviews, release-readiness reviews, and cybersecurity working groups
Requirements
  • Active TS/SCI clearance with the ability to maintain eligibility throughout employment
  • Active CISSP certification in good standing
  • Bachelor’s degree in cybersecurity, computer science, information systems, software engineering, engineering, or a related technical field
  • Eight or more years of progressive experience in cybersecurity, information assurance, application security, systems security engineering, or a related technical discipline
  • Three or more years of experience supporting cybersecurity activities on software development, software modernization, systems integration, or DevSecOps programs
  • Demonstrated experience applying cybersecurity principles within the SDLC, including requirements analysis, design review, development, testing, deployment, and sustainment
  • Experience with security-control assessment, risk analysis, vulnerability management, and remediation tracking
  • Working knowledge of NIST cybersecurity guidance and risk-management practices, including:
    • NIST Risk Management Framework (RMF)
    • NIST Special Publication 800-53 security and privacy controls
    • NIST Special Publication 800-37 risk-management guidance
    • NIST Special Publication 800-218 Secure Software Development Framework (SSDF)
  • Experience reviewing or analyzing findings from vulnerability-scanning, configuration-compliance, web application security, static application security testing (SAST), dynamic application security testing (DAST), software composition analysis (SCA), or similar tools
  • Familiarity with secure coding concepts, common application vulnerabilities, and remediation approaches, including OWASP risks
  • Experience producing cybersecurity documentation, such as security assessment reports, system security plans, risk registers, POA&Ms, vulnerability-management reports, and briefing materials
  • Experience obtaining system authorization, performing continuous monitoring, obtaining Authority to Operate (ATO) packages, and performing control-assessment activities
  • Ability to communicate cybersecurity risks and recommendations effectively to software developers, engineers, program managers, and government stakeholders
  • Ability to work independently, manage competing priorities, and operate effectively in a mission-focused government program environment
Desired Skills
  • Master’s degree in cybersecurity, computer science, software engineering, systems engineering, or a related technical discipline
  • Ten or more years of cybersecurity, information assurance, application security, or systems security engineering experience
  • Five or more years supporting government software-development, enterprise IT, cloud, intelligence, defense, or national-security programs
  • Experience supporting Agile, Scrum, Scaled Agile Framework (SAFe), DevSecOps, continuous integration/continuous delivery (CI/CD), or automated release-management environments
  • Experience integrating security tools into CI/CD pipelines, including SAST, DAST, SCA, infrastructure-as-code scanning, container scanning, secrets detection, or dependency management
  • Experience with software-development and DevSecOps platforms, such as GitLab, GitHub, Jira, Bitbucket, or comparable tools
  • Experience securing containerized or orchestrated environments, including Docker, Kubernetes, OpenShift, or similar platforms
  • Familiarity with Zero Trust architecture, identity and access management, privileged-access management, encryption, key management, endpoint security, network segmentation, and API security
  • Experience serving as an Information System Security Officer (ISSO), Information System Security Manager (ISSM), security control assessor, security engineer, application security analyst, or comparable position
  • Additional relevant certifications, such as:
    • Certified Cloud Security Professional (CCSP)
    • Certified Information Security Manager (CISM)
    • GIAC Web Application Penetration Tester (GWAPT)
    • GIAC Cloud Security Automation (GCSA)
    • AWS Certified Security – Specialty
    • Microsoft Certified: Azure Security Engineer Associate
    • Security+ or CASP+
  • Experience developing scripts or automation using Python, PowerShell, Bash, or similar languages
  • Experience conducting threat modeling, architecture risk assessments, secure code reviews, penetration-test coordination, or security test planning
  • Demonstrated experience leading cybersecurity workstreams, mentoring analysts, and briefing senior government or contractor leadership
Clearance Information

SRC IS A CONTRACTOR FOR THE U.S. GOVERNMENT, THIS POSITION WILL REQUIRE U.S. CITIZENSHIP AS WELL AS, A U.S. GOVERNMENT SECURITY CLEARANCE AT THE TOP SECRET / SCI LEVEL

Travel Requirements
  • No travel is required for this position
About Us

Scientific Research Corporation is an advanced information technology and engineering company that provides innovative products and services to government and private industry, as well as independent institutions. At the core of our capabilities is a seasoned team of highly skilled engineers and scientists with multidisciplinary backgrounds. This team is challenged daily to provide cutting edge technology solutions to our clients.

SRC offers a generous benefit package, including medical, dental, and vision plans, 401(k) with a company match, life insurance, vacation and sick paid time off accruals with amounts increasing based on role and years of service, 11 paid holidays, tuition reimbursement, and a work environment that encourages excellence and more. For positions requiring a security clearance, selected applicants will be subject to a government security investigation and must meet eligibility requirements for access to classified information.

EEO

Scientific Research Corporation is an equal opportunity employer that does not discriminate in employment.

All qualified applicants will receive consideration for employment without regard to their race, color, religion, sex, age, sexual orientation, gender identity, national origin, disability, protected veteran status, or any other protected characteristic under federal, state or local law.

Scientific Research Corporation endeavors to make www.scires.com accessible to any and all users. If you would like to contact us regarding the accessibility of our website or need assistance completing the application process, please contact jobs@scires.com for assistance. This contact information is for accommodation requests only and cannot be used to inquire about the status of applications.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Senior Cybersecurity Engineer
Senior Cybersecurity Engineer

Scientific Research Corporation • North Charleston (SC)

On-site
USD 140,000 - 190,000
Cyber Security Analyst III
Cyber Security Analyst III

Scientific Research Corporation • North Charleston (SC)

On-site
USD 120,000 - 180,000
Medical, dental, vision plans
401(k) with company match
Paid time off (vacation and sick)
Sr Software Developer
Sr Software Developer

Scientific Research Corporation • San Antonio (TX)

On-site
USD 130,000 - 170,000
Security Engineer
Security Engineer

Scientific Research Corporation • Orlando (FL)

On-site
USD 90,000 - 130,000
IS/ Network Security Specialist III
IS/ Network Security Specialist III

Scientific Research Corporation • North Charleston (SC)

On-site
USD 120,000 - 150,000
Cyber Security Analyst
Cyber Security Analyst

Scientific Research Corporation • Philadelphia

On-site
USD 90,000 - 120,000
Medical, dental, and vision plans
401(k) with company match
Life insurance
+2
Sr Program Manager
Sr Program Manager

Scires • Orlando (FL)

On-site
USD 150,000 - 190,000
Medical, dental, vision coverage
401(k) with company match
Life insurance
+2
Cyber Mission Systems Integrator
Cyber Mission Systems Integrator

Scientific Research Corporation • Huntsville (AL)

On-site
USD 120,000 - 190,000
Medical, dental, vision
401(k) with match
Paid time off
+1
Software Integrator
Software Integrator

Scientific Research Corporation • North Charleston (SC)

On-site
USD 90,000 - 150,000
Medical, dental, vision plans
401(k) with company match
Tuition reimbursement
+1
Sr Systems Engineer
Sr Systems Engineer

Scientific Research Corporation • North Charleston (SC)

On-site
USD 120,000 - 160,000
401(k) with company match
Medical, dental, and vision plans
Tuition reimbursement