Job Title: Information Security Analyst Senior
Company: Sugpiat Defense, LLC
Program: Missile Defense Agency (MDA)
Location: Colorado Springs, CO – On-Site
Employment Status: Regular, Full-Time
FLSA Status: Exempt
Security Clearance: Active Top Secret with SCI Eligibility Required
Position Status: Contingent upon Contract Award
The Information Security Analyst Senior is responsible for providing senior-level information assurance, cybersecurity, and risk management support to the Missile Defense Agency (MDA). This position supports the protection and secure operation of classified and unclassified mission-critical information systems through the implementation and maintenance of Department of Defense (DoD) cybersecurity requirements, Risk Management Framework (RMF) activities, continuous monitoring, vulnerability management, security control assessments, and Assessment and Authorization (A&A) activities.
The Information Security Analyst Senior works closely with Information System Security Managers (ISSMs), Information System Security Officers (ISSOs), engineers, system administrators, Authorizing Officials, Government personnel, and other program stakeholders to maintain system security posture and compliance. The position provides technical cybersecurity guidance throughout the system lifecycle, identifies and communicates cybersecurity risks, supports incident response and corrective actions, and provides technical leadership and mentorship to junior cybersecurity personnel.
-
Support the implementation and maintenance of cybersecurity requirements across classified and unclassified information systems.
-
Maintain system compliance with the DoD Risk Management Framework (RMF), National Institute of Standards and Technology (NIST) guidance, MDA requirements, and applicable DoD cybersecurity policies.
-
Support Assessment and Authorization (A&A) activities necessary to obtain and maintain system Authority to Operate (ATO).
-
Develop, review, update, and maintain RMF documentation and supporting cybersecurity artifacts, including:
-
System Security Plans (SSPs)
-
Security Assessment Reports (SARs)
-
Plans of Action and Milestones (POA&Ms)
-
Security control documentation
-
Supporting authorization and compliance artifacts
-
Conduct continuous monitoring activities, including vulnerability management, configuration compliance, security control assessments, and ongoing evaluation of system security posture.
-
Analyze vulnerability scan results, assess findings, track identified vulnerabilities, and coordinate remediation efforts with system administrators, engineers, and program leadership.
-
Support the implementation, review, and validation of Defense Information Systems Agency (DISA) Security Technical Implementation Guides (STIGs).
-
Support Security Content Automation Protocol (SCAP) compliance activities.
-
Support security audits, inspections, assessments, and cybersecurity compliance reviews.
-
Monitor cybersecurity posture and identify vulnerabilities, compliance deficiencies, and risks that may affect mission systems.
-
Investigate cybersecurity incidents and support incident response, documentation, reporting, remediation, and corrective actions in accordance with established requirements.
-
Review proposed system changes, configurations, and technical modifications to identify cybersecurity impacts and recommend appropriate security controls.
-
Ensure cybersecurity activities comply with applicable DoD, MDA, NIST, and federal cybersecurity requirements.
-
Coordinate cybersecurity activities with ISSMs, ISSOs, Authorizing Officials, engineers, system administrators, Government personnel, and other program stakeholders.
-
Provide cybersecurity guidance to engineering, technical, and operational teams throughout the system lifecycle.
-
Participate in cybersecurity working groups, technical reviews, program meetings, and other cybersecurity-related activities.
-
Provide technical leadership and guidance on cybersecurity initiatives and compliance activities.
-
Mentor and provide technical guidance to junior cybersecurity personnel.
-
Support cybersecurity engineering and secure system development activities as required.
-
Maintain cybersecurity records, documentation, evidence, and other required artifacts in accordance with applicable requirements.
-
Prepare and present cybersecurity reports, briefings, metrics, risk assessments, and status updates to program leadership and other stakeholders.
-
Identify cybersecurity concerns, compliance deficiencies, and potential risks and elevate matters requiring management or Government attention.
-
Maintain awareness of emerging cybersecurity threats, technologies, DoD policies, MDA requirements, and industry best practices.
-
Protect classified, sensitive, and controlled information in accordance with applicable security requirements.
-
Perform other cybersecurity and information assurance duties as assigned.
-
Bachelor's degree in Cybersecurity, Information Technology, Computer Science, Information Assurance, or a related field.
-
Minimum of eight (8) years of progressively responsible experience supporting Department of Defense information assurance or cybersecurity programs.
-
Demonstrated experience implementing and supporting the DoD Risk Management Framework (RMF).
-
Experience supporting Assessment and Authorization (A&A) activities for DoD information systems.
-
Experience developing, maintaining, and reviewing RMF documentation and cybersecurity compliance artifacts.
-
Experience conducting or supporting security control assessments, continuous monitoring, vulnerability management, and configuration compliance activities.
-
Experience using Enterprise Mission Assurance Support Service (eMASS) or comparable RMF tools.
-
Experience supporting classified information systems and environments.
-
Experience working with Windows and Linux operating systems, Active Directory, networking, and cybersecurity best practices.
-
Advanced working knowledge of Department of Defense cybersecurity and information assurance requirements.
-
Strong working knowledge of the DoD Risk Management Framework (RMF).
-
Working knowledge of NIST SP 800-53 security and privacy controls.
-
Working knowledge of NIST SP 800-37 Risk Management Framework guidance.
-
Working knowledge of DISA Security Technical Implementation Guides (STIGs).
-
Knowledge of security control assessments, vulnerability management, configuration compliance, and continuous monitoring.
-
Knowledge of Assessment and Authorization (A&A) processes and Authority to Operate (ATO) requirements.
-
Strong understanding of Windows and Linux operating systems, Active Directory, networking concepts, and cybersecurity best practices.
-
Ability to analyze vulnerability scan results, assess cybersecurity risks, and coordinate appropriate remediation activities.
-
Ability to evaluate system changes and configurations for cybersecurity impacts and recommend appropriate controls.
-
Ability to develop, review, and maintain technical cybersecurity documentation and RMF artifacts.
-
Ability to identify complex cybersecurity risks and compliance issues and appropriately communicate or elevate concerns.
-
Ability to provide technical cybersecurity guidance to engineering and operational personnel.
-
Ability to mentor and provide technical guidance to junior cybersecurity personnel.
-
Strong analytical and problem-solving skills.
-
Strong attention to detail and accuracy.
-
Strong organizational and time-management skills.
-
Excellent written and verbal communication skills.
-
Ability to prepare and present technical reports, briefings, metrics, and status updates.
-
Ability to communicate effectively with Government personnel, program leadership, engineers, system administrators, cybersecurity personnel, and other stakeholders.
-
Ability to manage multiple priorities, requirements, and deadlines in a fast-paced, mission-focused environment.
-
Ability to work independently and collaboratively within integrated Government/contractor teams.
-
Ability to maintain confidentiality and appropriately handle classified, sensitive, and controlled information.
-
Previous experience supporting the Missile Defense Agency (MDA).
-
Experience supporting Command and Control (C2) or other mission-critical defense systems.
-
Experience with cybersecurity engineering principles throughout the system development lifecycle.
-
Experience with Assured Compliance Assessment Solution (ACAS), SCAP Compliance Checker (SCC), Host Based Security System (HBSS)/Endpoint Security Solution (ESS), or other DoD cybersecurity tools.
-
Familiarity with Zero Trust Architecture and cloud security initiatives.
-
Experience leading cybersecurity compliance efforts on large DoD acquisition programs.
One or more of the following certifications is preferred:
-
CompTIA Security+
-
Certified Information Systems Security Professional (CISSP)
-
CompTIA Advanced Security Practitioner (CASP+), or current equivalent
-
Certified Information Security Manager (CISM)
-
GIAC Security Leadership Certification (GSLC)
-
Certified Authorization Professional (CAP), or current equivalent
Certification must meet applicable DoD 8570/8140 requirements for the assigned position.
-
Active Top Secret security clearance with SCI eligibility is required.
-
The employee must maintain the required security clearance and eligibility as a condition of continued employment in this position.
-
The employee must comply with all applicable Company, customer, DoD, and federal security requirements.
The work environment and physical demands described below are representative of those required to successfully perform the essential functions of this position. Reasonable accommodations may be made to enable qualified individuals with disabilities to perform the essential functions.
While performing the duties of this position, the employee is regularly required to communicate verbally and in writing and frequently sit, stand, or walk for extended periods. The position routinely requires the use of standard office and technical equipment, including computers, phones, printers, and other electronic or audiovisual equipment.
The employee is frequently required to use hands and fingers to operate computers and other equipment and may occasionally be required to reach, stoop, kneel, crouch, climb stairs, or move and configure computer, audiovisual, VTC, or related technical equipment. The employee must occasionally lift and/or move equipment or other objects weighing up to 50 pounds.
Specific vision abilities required by this position include close and distance vision, color vision, depth perception, and the ability to adjust focus.
Work is primarily performed in an office, technical, or Government facility environment and may include work in controlled or secure areas. The employee may occasionally be exposed to varying environmental conditions associated with Government facilities or operational environments. This position may require travel.
Note: This job description does not state or imply that these are the only duties to be performed by the employee. The employee may be required to follow other job-related instructions and perform other duties as assigned by their supervisor. The statements contained herein are intended to describe the general nature and level of work performed and are not intended to be an exhaustive list of all responsibilities, duties, qualifications, or skills required for this position. This job description does not constitute a contract of employment and is subject to change at the discretion of Sugpiat Defense, LLC.
Sugpiat Defense, LLC is an Equal Opportunity Employer. Qualified applicants will receive consideration for employment without regard to race, color, religion, national origin, sex, sexual orientation, gender identity, disability, protected veteran status, or any other status protected by applicable law.
Sugpiat Defense offers preference to qualified Akhiok-Kaguyak Native Corporation Shareholders and their descendants and spouses, and to shareholders of other corporations created pursuant to the Alaska Native Claims Settlement Act, in accordance with applicable law, including 43 U.S.C. § 1626(g) and 42 U.S.C. § 2000e-2(i).
Position Contingent on Contract Award.