Information Security Analyst - Security Clearance Required

SAIC
Beltsville, Maryland
$160K-$200K a year
Full-time

Description

SAIC is seeking a highly motivated Information Security Analyst. The successful candidate will provide support to the Cybersecurity Integrity Center (CIC) in the Department of State Bureau of Information Resource Management (IRM).

Duties are in the Washington, D.C. metropolitan area (30% in downtown D.C.; 70% in Beltsville, MD). The CIC supports cybersecurity monitoring, threat analysis, incident response, and infrastructure remediation within and across all of the State Department’s information technology (IT) infrastructure.

The CIC coordinates and collaborates with other State Department bureaus as well as other organizations within the Federal Government, and commercial partners.

Work is performed in a 24x7x365 operation.

The current shift is Mon-Fri 6am - 230pm. Onsite Monday and Thursday.

Description of Duties :

The Analyst provides Cybersecurity remediation through outreach to system owners and system administrators for the CIC, especially in Microsoft products and security systems, but also including other enterprise server & desktop operating systems enterprise applications, and in support of over 80,000 customers globally.

The Cyber Security Analyst will :

  • Apply sound technical and management principles to identify and remediate cybersecurity vulnerabilities across the State Department global IT enterprise infrastructure
  • Apply organizational and process change principals
  • Provide technical leadership and guidance to security and operational personnel
  • Evaluate system performance results, lead teams in response to incidents / problems, perform risk assessments, and evaluate performance metrics

Responsibilities include :

  • Develop, Identify, and resolve security vulnerabilities related to deployment and testing processes
  • Streamline and optimize processes and procedures to rapidly remediate vulnerabilities from cybersecurity threats
  • Collaborate with Department and external cyber stakeholders on cybersecurity technology implementations to meet specific operational needs.
  • Perform technical evaluations of recommended vulnerability mitigation actions and make recommendations based on impact and / or other countermeasures.
  • Develop strategies for CIC cyber defense technologies, ensuring integration and alignment for continued operation.
  • Develop policies and procedures.
  • Identify, diagnose, and prioritize anomalies in cyber defense infrastructure and resources.
  • Document, request and maintain ports, protocols, and services for CIC infrastructure
  • Perform cybersecurity testing of developed applications and / or systems. Identify and direct the remediation of technical problems encountered during testing and implementation of new systems.
  • Develop reports and dashboards and make tuning request to SIEM system owner(s) in support of enhancing cyber monitoring.
  • Perform security reviews and identify security gaps in architecture. Make recommendations based on trend analysis to enhance monitoring and hygiene activities.
  • Properly document all systems security implementation, operations, and maintenance activities and update as necessary.

Qualifications

Required Education & Experience :

  • Bachelors and nine (9) years or more experience; Masters and seven (7) years or more experience ; may accept additional experience in lieu of degree.
  • Experience reviewing breach notification rule policies and procedures. Reviews policies and procedures related to physical, administrative, and technical safeguards.
  • Experience providing compliance reports and participating in regular compliance meetings to discuss issues and mitigation strategies.
  • In-depth experience in planning, implementing, and managing large / global enterprise infrastructures
  • Knowledge of Cloud application security, Vulnerability Management and Security Information, and Event Management capabilities.
  • Understanding of Security Information and Event Management (SIEM) tools (Splunk, McAfee).
  • Familiarity with OMB, NIST, DHS, and related security guidelines and directives.
  • Interpersonal skills including the ability to collaborate effectively, and excellent written and oral communications.
  • Ability to communicate IT, networking, and security concepts to personnel at all levels of experience and responsibility.

Clearance Required :

  • US Citizenship.
  • Active secret clearance with the ability to obtain Top Secret Clearance.

Desired Education, Skills, & Experience :

  • Bachelor’s degree in a computer science / computer engineering related discipline or equivalent years of experience and expertise.
  • 8+ years Microsoft Operating Systems (OS) engineering and support experience focusing on Active Directory (AD), System Center Configuration Manager (SCCM), System Center Operations Manager (SCOM).
  • 2+ years extensive experience in penetration testing.
  • Familiarity of various analytical tools (Splunk, USBDeview, Netwitness, MimiKatz).
  • Security Assessment Plan (SAP).
  • Familiarity of Security Assessment Report (SAR), Security Assessment Results Table / RTM (Appendix in SAR).
  • Network security architecture concepts including topology, protocols, components, and principles (e.g., application of defense-in-depth).
  • Server / endpoint OS (Microsoft, Linux, IOS) along with mobile and cloud technologies.
  • Knowledge of identity and access management solutions (MFA, PKI, SAML, etc.).
  • Countermeasures / mitigations to identified cybersecurity risks.
  • Information protection technologies (e.g., firewalls, antivirus, threat protection, servers, routers, and others as appropriate).
  • Network systems management principles, models, methods (e.g., end-to-end systems performance monitoring), and tools.

Desired Certifications

  • GIAC Penetration Tester (GPEN) certification.
  • Microsoft Certifications (MCSE, MCSA, MCSD).
  • CISSP or CISM.
  • IAT / IAM / IASAE level III equivalent.
  • ISACA Certified Information Systems Auditor (CISA).
  • GIAC Security Expert (GSE).
  • SCP Security Certified Network Architect (SCNA).
  • ISACA Certified Information Security Manager (CISM).
  • Cisco Certified Network Associated (CCNA).
  • Certified Ethical Hacker (CEH).

Target salary range : $160,001 - $200,000. The estimate displayed represents the typical salary range for this position based on experience and other factors.

SAIC accepts applications on an ongoing basis and there is no deadline.

Covid Policy : SAIC does not require COVID-19 vaccinations or boosters. Customer site vaccination requirements must be followed when work is performed at a customer site.

2 days ago
Related jobs
Promoted
Northrop Grumman
Elkridge, Maryland

Requisition ID: R10169972 * *Category:* Manufacturing and Production * *Location:* Elkridge, Maryland, United States of America * *Clearance Type:* Secret * *Telecommute:* No- Teleworking not available for this position * *Shift:* 1st Shift (United States of America) * *Travel Required:* No * *Posit...

Promoted
CACI
Fort Meade, Maryland

Minimum Clearance Required to Start: TS/SCI with Polygraph. Percentage of Travel Required: Up to 10%. The Signals Analyst position involves analyzing and interpreting complex signals data in a projected work environment. As a Signals Analyst, you will. ...

Promoted
Peraton
Fort Meade, Maryland

Relevant experience must be in computer or information systems design/development, programming, information/cyber/network security, vulnerability analysis, penetration testing, computer forensics, information assurance and/or systems engineering, additionally, must have experience in network or syst...

Promoted
DCCA
Fort Meade, Maryland

Provide support for implementation, troubleshooting and maintenance of Information Technology (IT) systems. Security+ or equivalent IAT Level II certification. Required Education / Certifications:. ...

Promoted
Peraton
Fort Meade, Maryland

Our dynamic team delivers information security solutions that facilitate secure data flows and the detection/prevention of unauthorized behaviors, performs system security vulnerability assessments and solution development, provide enterprise-level network, server, desktop, and application security ...

Promoted
Lockheed Martin
Annapolis Junction, Maryland

Candidate must possess security clearance with a polygraph. Build on our proud legacy of achievement and contribute to shaping the future of aerospace, defense, and security solutions. Lockheed Martin is a global leader in aerospace, defense, and security solutions, committed to excellence and integ...

Promoted
Jacobs
Fort Meade, Maryland

TS/SCI clearance with polygraph. ...

Promoted
DCCA
Annapolis Junction, Maryland

Support for implementation, troubleshooting and maintenance of Information Technology (IT) systems. Required Education / Certifications. ...

Promoted
Nightwing
Annapolis Junction, Maryland

As a prospective employee of Nightwing, you’ll have the chance to contribute to our continued success and shape the future of our cybersecurity, intelligence, and services offerings. Thank you for considering joining us as we embark on this new journey and shape the future of cybersecurity and intel...

Next Step Systems – Recruiters for Information Technology Jobs Top IT Recruiting Firm
Annapolis Junction, Maryland

Java & NiFi Software Engineer, TS/SCI with a Full Scope Polygraph Security Clearance is Required, Annapolis Junction, MD. Keywords: Annapolis Junction MD Jobs, Java & NiFi Software Engineer, Java, NIAGARAFILES, Apache NiFi, Elasticsearch, Spring Boot, API Development, Docker, Kafka, Agile, Jira, Con...