Cyber Security Analyst / ISSO
Scientific Research Corporation - Washington, DC
Apply NowJob Description
Estimated Starting Salary Range: USD $157,400.00/Yr. - USD $262,300.00/Yr. Salary to be determined by the education, experience, knowledge, skills, and abilities of the applicant, internal equity, and alignment with market data.The Cyber Security Analyst / Information System Security Officer (ISSO) will be a member of a small team focusing on developing services and applications in a DevSecOps based environment in support of the Defense Intelligence Agency (DIA). Engineering will be performed on Joint Worldwide Intelligence Communications System (JWICS) and National Security Agency Network (NSANet) connected systems. As a Cyber Security Analyst/ ISSO, this position is responsible for supporting the Information System Owner to complete security assessment, continuous monitoring, and configuration management responsibilities. Responsibilities include, but are not limited to:Developing and updating assessment and authorization documentation (Body of Evidence) for management and continuous monitoring of information systemsPerforming ongoing compliance assessments using tools, such as Assured Compliance Assessment Solution (ACAS), Secure Content Automation Protocol (SCAP), and Trellis Virus Scan Enterprise reviewing, documenting, and maintaining all resultsVerifying patches and virus definitions to the systems using existing automated toolsAdhering to pre-defined configuration management and change management policies and procedures for authorizing software prior to its implementation on systemsPerforming security audits using to track multiple events including any signs of inappropriate or unusual activity, intrusion events, data transfers, etc.Performing security assessments of DoD Family of Systems in accordance with National Institute of Standards and Technology (NIST), Navy, and NAVINTEL IA guidance, working with system engineers to take corrective action to resolve identified problemsBecoming a NAVINTEL IA ICOP Trusted Agent within 6-monthsPerforming Site Based Security Assessments (SBSAs) of systems and recommending authorization to the Designated Authorizing Official (DAO) as a certified Trusted AgentReporting security incidents in accordance with the Command Incident Response PlanEnsuring systems are operated, used, maintained, and disposed of in accordance with all applicable security policies and practicesFILLING THIS POSITION IS CONTINGENT UPON FUNDING #LI-AM1Must possess an active Top Secret, SCI eligible clearanceAbility to obtain CI Poly clearance5 years of cybersecurity experienceMust currently hold a DoD 8570-compliant IAT II certification (SSCP or Security+CE with appropriate CE/OS certificate), and IAM II certification (CAP or CASP CE) or be able to obtain within six months, CE/OS certificate may include Windows or LinuxExperience with System Security Plans (SSPs), eMASS and/or Xacta, POA&Ms, ACAS/Nessus, SCAP, and DISA STIGsExperience with Risk Management Framework processesHave developed communication skills and the ability to express thoughts and ideas clearly and conciselyMust be a team player, dedicated to program support, capable of multitasking and working several complex and diverse tasks with simultaneous or near simultaneous deadlinesBe a self-starter who is accountable and requires minimal direction and supervisionBe open to new and innovative ideasMust be able to be appointed ISSO for NCS systems within 6-months of employmentBachelor's degree in relative technical disciplineActive TS/SCI with CI PolyExtensive training or experience with Windows based Information Systems standards with a working knowledge of networking devicesKnowledge of Container Security and best practices securing containerized applicationsKnowledge of configuration of various SQL databases: MS SQL, PostgreSQL, MongoDB, MariaDB, MySQL, ElasticsearchKnowledge of Web Servers: Apache Web Server, Apache Tomcat, Red Hat JBOSS, nginx, MS IISKnowledge of data flows and the ability to work up readable network topology and data flow diagramsExperience with NAVINTEL IA Enterprise Services (Continuous Monitoring)Experience with the following systems/platforms/tools: HBSS, ACAS/Nessus, and SPLUNKSRC IS A CONTRACTOR FOR THE U.S. GOVERNMENT. THIS POSITION WILL REQUIRE U.S. CITIZENSHIP AS WELL AS A U.S. GOVERNMENT SECURITY CLEARANCE AT THE TOP SECRET / SCI LEVEL with CI POLY ELIGIBILITY20% annual travelScientific Research Corporation is an advanced information technology and engineering company that provides innovative products and services to government and private industry, as well as independent institutions. At the core of our capabilities is a seasoned team of highly skilled engineers and scientists with multidisciplinary backgrounds. This team is challenged daily to provide cutting edge technology solutions to our clients.SRC offers a generous benefit package, including medical, dental, and vision plans, 401(k) with a company match, life insurance, vacation and sick paid time off accruals starting at 10 days of vacation and 5 days of sick leave annually, 11 paid holidays, tuition reimbursement, and a work environment that encourages excellence and more. For positions requiring a security clearance, selected applicants will be subject to a government security investigation and must meet eligibility requirements for access to classified information.Scientific Research Corporation is an equal opportunity employer that does not discriminate in employment.All qualified applicants will receive consideration for employment without regard to their race, color, religion, sex, age, sexual orientation, gender identity, national origin, disability, protected veteran status, or any other protected characteristic under federal, state or local law.Scientific Research Corporation endeavors to make accessible to any and all users. If you would like to contact us regarding the accessibility of our website or need assistance completing the application process, please contact assistance. This contact information is for accommodation requests only and cannot be used to inquire about the status of applications.
Created: 2025-11-01