Cyber Risk Analyst (TS/SCI)
Reston, VA, United States
Red Gate Group
Red Gate is a certified SDVOSB whose core services include intelligence analysis, strategic planning, policy development, operational design, and technology integration services.Company Description
At RED GATE we do everything we can to serve our clients:
Using the right technical skills, unique methodologies, best practices, and integrated technology, we help clients implement bold solutions. New approaches to emerging and evolving threats. Non-traditional ways to overcome entrenched obstacles. Advantage through opportunity. If you have a serious challenge or problem, we can help you solve it. The below job description provides details on how this role will help to serve our clients.
Job Description
Job Description Summary:
Warnings about cyber threats are everywhere and the constantly evolving nature of these threats can make understanding them seem overwhelming to the DoD and the IC. In all of this “cyber noise,” how can these organizations understand their risks and how to mitigate them? The answer is you. Build your knowledge as an information security risk specialist who knows how to break down complex threats into manageable plans of action.
As a Cyber-Risk Analyst on our team, you’ll use your experience to work with DoD programs to discover their cyber risks, understand policies, and develop a mitigation plan. You’ll get technical, environmental, and personnel details from engineers and SMEs to assess the entire threat landscape. Then, you’ll help your team guide your client through a plan of action with presentations, white papers, and milestones. You’ll work on translating security concepts for your client so they can make the best decisions to secure their mission critical networks and systems. This is your opportunity to act as an information security subject matter expert while broadening your skills in cybersecurity, security and network tools, systems engineering, and data science.
Qualifications
- 5+ years of experience working in a professional IT environment
- 3+ years of experience with cybersecurity
- 3+ years of experience with Assessment and Authorization (A&A) in support of DoD and IC programs, including package development, artifact generation, and authority to operate (ATO)
- Experience with security hardening of Windows and Linux operating systems and security tools, such as ACAS, SCAP, STIG/SRGs, SCC, eMASS/Xacta, ESS, Prisma Cloud, Kubernetes, Rancher, and Docker
- Experience generating and maintaining System Security Plans (SSP), Implementation Plans, Privacy Impact Assessments, Security Assessment Plans (SAP), Risk Assessments, Plan of Action and Milestones (POA&M), and other A&A documentation
- Knowledge of Risk Management Framework (RMF) and the A&A activities needed to obtain and maintain an ATO, including National Institute of Standards and Technology (NIST) and Committee on National Security Systems Instruction (CNSSI), including NIST SP 800-60, NIST SP 800-53, and CNSSI 1253
- IAT Level II Certification, including a Security+ Certification
Desired Qualifications:
- Experience with DoD or IC cybersecurity projects or programs
- Experience with DevSecOps, Path-to-Production, and CI/CD
- Experience with Cloud Authorization and Cloud Migration
- Experience with administering Red Hat Enterprise Linux or Windows Server 2012 or higher
- Ability to provide subject matter expertise to system engineering documents, including technical requirements documents, interface control documents, and system specifications
- Ability to analyze and communicate complex technical challenges to both technical and non-technical clients and stakeholders
- Ability to communicate and integrate between multiple customer stakeholders
- Bachelor's degree
Additional Information
The Red Gate Group, Ltd. is an Equal Opportunity/Affirmative Action Employer. The Red Gate Group, Ltd. considers applicants without regard to race, color, religion, age, national origin, ancestry, ethnicity, gender, gender identity, gender expression, sexual orientation, marital status, veteran status, disability, genetic information, citizenship status, or membership in any other group protected by federal, state, or local law. Know Your Rights
* Salary range is an estimate based on our salary survey 💰
Tags: CI/CD Cloud DevSecOps Docker DoD Kubernetes Linux NIST Privacy Red Hat Risk assessment Risk management SAP SCAP Security assessment System Security Plan TS/SCI Windows
More jobs like this
Explore more InfoSec/Cybersecurity career opportunities
Find open roles in Ethical Hacking, Pen Testing, Security Engineering, Threat Research, Vulnerability Analysis, Cryptography, Digital Forensics and Cyber Security in general, filtered by job title or popular skill, toolset and products used.
- Open Information Security Specialist jobs
- Open Security Operations Analyst jobs
- Open Senior Information Security Analyst jobs
- Open Senior SOC Analyst jobs
- Open Staff Product Security Engineer jobs
- Open Security Operations Engineer jobs
- Open Senior Cybersecurity Engineer jobs
- Open Electronic Warfare Advanced Tactical Trainer jobs
- Open IT Security Engineer jobs
- Open IT Security Analyst jobs
- Open Information System Security Officer (ISSO) jobs
- Open Cyber Security Specialist jobs
- Open Manager Pentest H/F jobs
- Open Head of Information Security jobs
- Open Cyber Hunt SME jobs
- Open Security Consultant jobs
- Open Analyste CERT / Incident Responder senior (H/F) jobs
- Open Ethical hacker / Pentester H/F jobs
- Open Staff Application Security Engineer jobs
- Open Lead Security Engineer jobs
- Open Senior Security Operations Engineer jobs
- Open Senior Information Security Engineer jobs
- Open Staff Security Engineer jobs
- Open Analyste CERT / Incident Responder junior (H/F) jobs
- Open Senior Security Analyst jobs
- Open Application security-related jobs
- Open Governance-related jobs
- Open Network security-related jobs
- Open Risk assessment-related jobs
- Open Pentesting-related jobs
- Open ISO 27001-related jobs
- Open Clearance-related jobs
- Open DevOps-related jobs
- Open Kubernetes-related jobs
- Open Vulnerability management-related jobs
- Open DevSecOps-related jobs
- Open Analytics-related jobs
- Open Java-related jobs
- Open IAM-related jobs
- Open CISM-related jobs
- Open SaaS-related jobs
- Open APIs-related jobs
- Open CI/CD-related jobs
- Open Forensics-related jobs
- Open Malware-related jobs
- Open CISA-related jobs
- Open Threat intelligence-related jobs
- Open Terraform-related jobs
- Open IDS-related jobs
- Open OWASP-related jobs