Cyber Security Analyst

Cyber Security Analyst

09 Mar 2025
Virginia, Virginiabeach, 23453 Virginiabeach USA

Cyber Security Analyst

Req ID: RQ195997Type of Requisition: RegularClearance Level Must Be Able to Obtain: Top Secret SCI + PolygraphPublic Trust/Other Required: NoneJob Family: Cyber SecuritySkills:Cybersecurity,Nessus Vulnerability Scanner,System Security,Vulnerability Assessments,Vulnerability ScanningCertifications:CompTIA - Security+ - CompTIA - CompTIAExperience:4 + years of related experienceUS Citizenship Required:YesJob Description:The Analyst shall operate and maintain the ACAS solution, to support network and application scanning and ensure configuration assessments are conducted and incidents are resolved in accordance with the incident response table and client SOPs.Familiar in the utilization of Tenable NESSUS Assured Compliance Asset Solution (ACAS) scanning agent and Vulnerability Remediation Asset Manager (VRAM) across seven shipboard enclaves.-Perform Nessus vulnerability scans, Nessus agent scans, and Passive vulnerability scans.-Installation, monitoring, testing, troubleshooting, and administration of the Nessus and Passive Vulnerability Scanner applications.-Create ACAS queries to optimize processes, procedures, and analysis.-Configures, optimizes, and tests vulnerability scans against new and existing Operating Systems and platforms.-Conduct vulnerability analysis, research, and script analysis to verify potential false positives.-Perform scan policy analysis & configuration to determine the impact of vulnerability scanning against target devices.-Interprets, analyzes, and reports all events and anomalies in accordance with computer network directives, including initiating, responding, and reporting discovered events.-Evaluates, tests, recommends, coordinates, monitors, and maintains cybersecurity policies, procedures, and systems, including access management for hardware, firmware, and software.-Ensures that cybersecurity plans, controls, processes, standards, policies, and procedures are aligned with cybersecurity standards.-Identifies security risks and exposures, determines the causes of security violations, and suggests procedures to halt future incidents and improve security.-Develops techniques and procedures for conducting cybersecurity risk assessments and compliance audits, the evaluation and testing of hardware, firmware, and software for possible impact on system security, and the investigation and resolution of security incidents such as intrusion, frauds, attacks or leaks.-Maintain system documentation.Education and Experience:-BA/BS in Cyber Security or equivalent or documented 8+ years of experience.-2+ yrs Knowledge and experience with ACAS Security Center (SC) and Nessus Vulnerability Scanners (NVS).-Possess understanding and experience with common cybersecurity toolsets and processes to include STIGS, CAS, IAVA Management and Implementation, and OPORD/FRAGO support.-ATO process.DOD RMF Configuration Management.NIST SP800-53 and NIST SP800-37.Qualifications:TS/SCI eligible with POLY.DoD 8570 IAT II certification.Security+ / LinuxUS Citizenship RequiredThe likely salary range for this position is $102,000 - $138,000. This is not, however, a guarantee of compensation or salary. Rather, salary will be set based on experience, geographic location and possibly contractual requirements and could fall outside of this range.Our benefits package for all US-based employees includes a variety of medical plan options, some with Health Savings Accounts, dental plan options, a vision plan, and a 401(k) plan offering the ability to contribute both pre and post-tax dollars up to the IRS annual limits and receive a company match. To encourage work/life balance, GDIT offers employees full flex work weeks where possible and a variety of paid time off plans, including vacation, sick and personal time, holidays, paid parental, military, bereavement and jury duty leave. To ensure our employees are able to protect their income, other offerings such as short and long-term disability benefits, life, accidental death and dismemberment, personal accident, critical illness and business travel and accident insurance are provided or available. We regularly review our Total Rewards package to ensure our offerings are competitive and reflect what our employees have told us they value most.We are GDIT. A global technology and professional services company that delivers consulting, technology and mission services to every major agency across the U.S. government, defense and intelligence community. Our 30,000 experts extract the power of technology to create immediate value and deliver solutions at the edge of innovation. We operate across 30 countries worldwide, offering leading capabilities in digital modernization, AI/ML, Cloud, Cyber and application development. Together with our clients, we strive to create a safer, smarter world by harnessing the power of deep expertise and advanced technology.We connect people with the most impactful client missions, creating an unparalleled work experience that allows them to see their impact every day. We create opportunities for our people to lead and learn simultaneously. From securing our nation’s most sensitive systems, to enabling digital transformation and cloud adoption, our people are the ones who make change real.Equal Opportunity Employer / Individuals with Disabilities / Protected Veterans

Related jobs

  • Description

  • Title: SECURITY CONTROL ASSESSOR (SCA) Location: United States-Virginia-Virginia Beach Job Number: 250000T5 Job Summary: The Security Control Assessor SCA oversees NEXCOM NAF IT cybersecurity risk assessment process which determines aggregate cybersecurity risk in support of an Authorization. Duties and Responsibilities: Incumbents of this position must be U.S. Citizens. Responsibilities include: - Provides NEXCOM cybersecurity support, by performing full package analysis of all IT systems, as defined by the Navy Risk Management Framework (RMF) guide. - Assists in the development of risk assessment requirements and participates in the execution of RMF assessment processes for authorization of systems to the Navy Exchange enterprise network to include ensuring that system hardware and software adheres to security standards that minimize risk to the Navy Exchange enterprise from cyber security threats based on the POA&M and other supporting documentation. - Participates in the development and maintenance of Navy Exchange cyber defense architectures, processes, standards, specifications, cyber threat profiles and enterprise risk assessments. - Independently and impartially assess and quantify aggregate cybersecurity risk using metrics consistent with DON guidance for both inherent system residual risks and system accessibility related risks in support of the Risk Management Program (RMP). - Produce the risk determination using the security assessment plan (SAP) and make a recommendation regarding system authorization. - Provides review and analysis of FedRAMP, PCI, and other third party package authorizations for reciprocity and use within the NEXCOM organization. - Provide initial concurrence on the SAP, ensuring all appropriate security controls will be assessed for compliance. - Support NEXCOM’s NAF IT continuous monitoring requirements. Determines and documents compliance with the assigned security controls. - Actively work with the Cybersecurity Compliance Assessor and Validator, and program management office to provide support and guidance throughout the RMF cybersecurity assessment and lifecycle. - Represent the system during DoD and DON Cybersecurity inspections, while responding to information requests and addressing identified findings. - Provides RMF/RMP Subject Matter Expert (SME) guidance. Provide guidance on the following: o Understanding of the RMF/RMP risk assessment process o Knowledge of implementation and applicability of security controls o Use of appropriate test procedures and tools and mitigation measures o Understanding of policies and their effects on the risk of a system. o Review and assessment of individual vulnerabilities in the POA&M - Keeps supervisors up to date on all assignments. - Performs other related duties as assigned. SECNAV M-5239.2, DoN, Information Assurance (IA) Workforce Manual requires incumbents of this position to possess and maintain current, two types of certifications as follows: IA Certification: Certified Information Security Manager (CISM), Certified Information Systems Security Professional (CISSP), CompTIA Advanced Security Practitioner (CASP ), GIAC Security Leadership Certification (GSLC) Technical Certification: Operating System/Computing Environment (OS/CE) certificate of training as dictated by Supervisor and approved by Command Cyber IT/CSWF-PM. Candidate is also required to sign a Privileged Access Agreement. Candidates without the required certification may be placed into this job but must obtain the required certification within 6 months of appointment; failure to obtain this requirement will result in termination of employment. Qualifications: A total of 8 years of experience, consisting of the following: Qualified candidates must be U.S. Citizens. GENERAL EXPERIENCE: 3 years’ experience in security, technical or investigative work which demonstrated the ability and aptitudes required to perform technical, managerial or analytical work involving management information systems. OR SUBSTITUTION OF EXPERIENCE FOR EDUCATION: One year of related academic study above the high school level may be substituted for 9 months of experience up to a maximum of a 4 year bachelor\'s degree in IT security or computer information systems for 3 years of general experience. AND SPECIALIZED EXPERIENCE: 5 years of demonstrated experience in at least two of the following: - Risk management validation - IT security compliance and reporting; - Technical risk analysis; - Authorization and accreditation And experience in the performance of: - System Security Assurance: ensuring that entire systems meet security requirements, function securely, and undergo comprehensive testing for overall security assurance. - Security Assessments: conducting security assessments and developing Security Assessment Plans (SAPs). - Technical Understanding: interpreting network diagrams, vulnerability scans, and compliance scans. - Security Documentation: creating and maintaining various security documents, including Security Assessment Plans. - Risk Management Framework: conducting security control assessments following a Risk Management Framework approach, along with conducting risk assessments and developing security assessment reports. And in-depth knowledge of: - NIST 800-53, risk mitigation strategies for computer operating systems, networks, or cloud services, and security controls and compliance frameworks. This position is designated in accordance with SECNAV M-5510.30 and will require a favorable Single Scope Background Investigation (SSBI). Candidates must be eligible for and obtain a Top Secret Clearance, within 6 months of appointment. Failure to obtain will result in termination. Job: Infrastructure

  • Allied Universal®, North America’s leading security and facility services company, provides rewarding careers that give you a sense of purpose. While working in a dynamic, diverse and inclusive workplace, you will be part of a team that fuels a culture that will reflect in our communities and customers we serve. We offer medical, dental and vision coverage, life insurance, retirement plan, employee assistance programs, company discounts, perks and more for most full-time positions!

  • Allied Universal®, North America’s leading security and facility services company, provides rewarding careers that give you a sense of purpose. While working in a dynamic, diverse and inclusive workplace, you will be part of a team that fuels a culture that will reflect in our communities and customers we serve. We offer medical, dental and vision coverage, life insurance, retirement plan, employee assistance programs, company discounts, perks and more for most full-time positions!

Job Details

Jocancy Online Job Portal by jobSearchi.