HireFT
Browse JobsHow it worksPricingAboutSuccess Stories
    Back to jobs
    GO

    Goldbelt

    Defense & Space

    Senior Information Security Analyst

    Petaluma, United StatesOn-SiteFull-time5+ yrs experience$100k – $140k / yearPosted 1mo ago
    All Goldbelt jobs

    Job description

    Overview

    Please note that this position is contingent upon the successful award of a contract currently under bid.

    Peregrine is a pioneer within the cybersecurity industrial control systems and the Internet of Things, supporting many federal and commercial customers. Peregrine's experienced staff knows the cybersecurity and operational technology environment and provides these capabilities for our customers daily.

    Summary:

    The Senior Information Security Analyst is responsible for the overall cybersecurity of assigned networks and devices.  They must have intimate knowledge of federal government, Department of Defense, and U.S. Coast Guard cybersecurity requirements.

    Responsibilities

    Essential Job Functions:

    • Aggressively manage Cyber security accreditation requirements by working closely with the Program Manager, system administrators, database administrators and other key personnel to ensure all system accreditations remain current.
    • Ensure that all initial and recurring certification and accreditation activities are completed in accordance with DoDI 8500.01, Cyber Security, and DoDI 8510.01, Risk Management Framework (RMF) for assigned information systems, as well as maintaining compliance with the Federal Information Security Management Act (FISMA) of 2002 and other applicable directives for the assigned information systems
    • Working directly with leadership, developers, engineers, system and database administrators to track changes to the system configurations and software, conducting regular reviews, updates and maintenance of certification and accreditation plans, topology drawings, and associated documents, and uploading completed documents to eMASS.
    • Schedule, oversee and document information system compliance testing, to include weekly Assured Compliance Assessment Solution (ACAS) scans and annual execution and testing of the Contingency Plans.
    • Manage accreditation and annual compliance actions using eMASS and the U.S. Coast Guard tracking tools to ensure annual reviews, control tests and contingency plan tests are completed on schedule to comply with FSMA requirements and keep the Program Manager informed of compliance and status of ATO efforts via updates to the PM’s Drumbeat and Metrics products.
    • Conduct a continuous review of all applications and database tools that make up the family of systems to ensure all software versions are registered and approved for use by the U.S. Coast Guard.
    • Conduct an annual review and update of all parent and child system profiles in the DHS approved repository system to ensure system’s registrations are complete and accurate, and that essential waivers for Data-At-Rest (DAR) and unsupported Commercial-Off-The-Shelf (COTS) software are documented and approved by U.S. Coast Guard CIO so that accreditations are not adversely affected.
    • Serve as Information Assurance Officer (IAO)/Information Systems Security Officer (ISSO), directly advising and assisting the Program Manager, developers, engineers, system and database administrators and staff on all cyber security policy, configuration and compliance matters.
      • This includes all aspects of cyber security that may affect the system security posture, to include emerging threats published in Cyber Alerts, Communication Tasking Orders, and vulnerability alerts and bulletins issued under the Information Assurance Vulnerability Management program.
    • As IAO/ISSO, advise the team on ports, protocols and services (PPS) approved for use by the U.S. Coast Guard, and register new PPS in the U.S. Coast Guard PPS Management Registry.
    • Prior to testing, identify Security Technical Implementation Guides (STIGs) to be applied to systems under development and test, and identify appropriate vulnerability scanning tools to be used during testing, to include the ACAS and Security Content Automation Protocol (SCAP) Compliance Checker automated scanning tools.
    • The IAO/ISSO will assist during scanning and advise the team on the remediation of findings identified during testing.
    • Following testing, the IAO will collect, collate, review and validate all test results and prepare supporting documentation, reports and artifacts to support the certification and accreditation of the system. Following accreditation, the IAO/ISSO will track and manage open findings in the Risk Assessment Report until mitigated or closed.
    • Provide expert advice in support of special projects, to include the development of an automated Cross Domain Solution (CDS) for use by the program and closely coordinate actions with the U.S. Coast Guard Cross Domain Solutions Office (USCGCDSO) and the Department of Homeland Security Unified Cross Domain Management Office (UCDMO).
      • This support includes authoring and submitting detailed system documentation and architectural drawings and working closely with both USCGCDSO and UCDMO personnel to navigate through a complex and highly technical approval process.
    • On a daily and weekly basis, provide authoritative cyber security advice during Internal Review Boards and make recommendations on open Configuration Change Requests (CCRs); Application Change Requests (ACRs), Database Change Requests (DBCRs), QA Trouble Reports (QTRs), Problem Reports (PRs), and Program Trouble Reports (PTRs).

    Qualifications

    Necessary Skills and Knowledge:

    • Proven record of honesty and integrity in all relationships.
    • Demonstrated leadership and organizational skills.
    • Excellent interpersonal skills and a collaborative management style.
    • Excellent communication skills, both verbal and written.
    • Excellent computer skills and proficient in Excel, Word, PowerPoint, Outlook, Visio, and Access.

    Minimum Qualifications:

    • Minimum of five (5) years relevant experience.
    • Detailed knowledge of DoD Risk Management Framework
    • Experience in an IAO/ISSO or Information Assurance Manager (IAM)/Information Systems Security Manager (ISSM) position.
    • Appropriate professional certifications per DoD 8570.01 (CISSP, GSLC or equivalent).
    • Must be eligible for a federal Public Trust clearance.

    Preferred Qualifications:

    • Bachelors degree in cybersecurity or related degree
    • CISSP Certification

    Pay and Benefits

    The annual salary range for this position is $100,000 to $140,000.

    At Goldbelt, we value and reward our team's dedication and hard work. We provide a competitive base salary commensurate with your qualifications and experience. As an employee, you'll enjoy a comprehensive benefits package, including medical, dental, and vision insurance, a 401(k) plan with company matching, tax-deferred savings options, supplementary benefits, paid time off, and professional development opportunities.

    Job details are sourced from the employer's original posting.

    Open job posting
    GO

    About the company

    Goldbelt

    Goldbelt Frontier, LLC is a wholly owned subsidiary of the Alaskan Native Corporation Goldbelt, Frontier places an emphasis on research and development, behavioral health, and medical and technological support services. Frontier is ideally suited to work with the Departments of Defense, Homeland Security, and Health and Human Services. Goldbelt Frontier’s leadership offers specific expertise related to medical staffing, behavioral health, and program development CONUS and OCONUS

    View all Goldbelt jobs
    Industry
    Defense & Space
    Open roles
    468

    Interested in this role?

    Apply with HireFT

    Free to start — no card required.

    Your fit

    How well do you match?

    Sign in to see how your résumé lines up with this role.