- Company Name
- StraCon Services Group, LLC.
- Job Title
- Information Security Analyst
- Job Description
-
**Job Title:**
Information Security Analyst
**Role Summary:**
Responsible for planning, implementing, monitoring, and maintaining cybersecurity controls for networked and information systems. Conducts vulnerability assessment, risk mitigation, policy enforcement, and supports the Security Assessment & Authorization process within a federal defense environment.
**Expactations:**
- Minimum 3 years of cyber‑security experience in secure network and system design, analysis, and implementation.
- Proven track record in vulnerability scanning, remediation, and maintaining RMF documentation.
- Familiarity with federal or defense security standards (e.g., DoD, NIST).
**Key Responsibilities:**
- Oversee the cybersecurity program for an information system or network—strategy, personnel, infrastructure, policy enforcement, and emergency planning.
- Execute integration, testing, operations, and maintenance of security controls; ensure proper documentation and updates.
- Conduct vulnerability assessments using ACAS, SCAP, STIG Viewer; manage remediation with VRAM.
- Participate in the Security Assessment & Authorization workflow, developing RMF “Assess & Authorize” documents and maintaining ATO in eMASS.
- Verify minimum security requirements for all applications; review and update security documentation.
- Coordinate cybersecurity inspections, tests, and reviews for the network environment.
- Assist in procurement and system life‑cycle planning by specifying security requirements for statements of work.
- Track audit findings, recommend mitigation actions, and ensure compliance with security policies.
- Lead and provide cybersecurity awareness training for IT and operations staff.
**Required Skills:**
- Vulnerability assessment tools (ACAS, SCAP, STIG Viewer).
- Risk Management Framework (RMF) processes, system authorization, and eMASS usage.
- Network and system hardening, secure design, and incident response.
- Strong documentation, audit tracking, and reporting capabilities.
- Ability to translate security requirements into procurement documents.
- Effective communication and training delivery skills.
**Required Education & Certifications:**
- Bachelor’s degree in Computer Science, Information Security, or related field (or equivalent experience).
- Certifications: CISSP, CISM, CompTIA Security+, or similar; familiarity with DoD/Defense security certifications preferred.